KYC diligences
Due Diligence types
For the Electronic_Signature workflow, the due diligences expected are :
- Identity document & selfie
- Electronic signature
For the Identity workflow, the due diligences expected are :
- Identity document
- Sepa Credit Transfer IN (this SEPA transfer could be an instant payment, a standard one)
For these two workflows, when configuring your environment, you can choose to accept one or more of the following forms of identification:
- ID card
- passport
- resident permit
Identity checks are subject to SLAs: 5 minutes maximum in 90% of cases.
Due Diligence state diagram
Diligence Status (webview mode)
stateDiagram state fork_state <<fork>> state fork_state2 <<fork>> [*] --> fork_state fork_state --> To_Review_Manually: provider needs to check manually the diligence fork_state --> Validated: provider valides diligence To_Review_Manually --> fork_state2 fork_state2--> Refused: provider rejects the diligence after manual check fork_state2--> Validated: provider validates the diligence after manual check
Diligence Status (API mode)
stateDiagram state fork_state <<fork>> state fork_state2 <<fork>> [*] --> Received Received --> fork_state fork_state --> To_Review_Manually: Diligence needs manual review fork_state --> Validated : provider valides diligence To_Review_Manually --> fork_state2 fork_state2 --> Validated: provider validates the diligence after manual check fork_state2 --> Refused: provider rejects validates the diligence after manual check fork_state --> Refused: provider refuses diligence
Each time the status of a due diligence changes, a callback 4 is sent.
Due Diligence sequence diagram : case electronic_sign
Best scenario: due diligences validated
sequenceDiagram
autoNumber
Actor User
Participant Partner
Participant XPO
Partner ->> XPO: POST /api/v3.0/user/{appUserId}/kyc/demand<br/>workflowCode: Electronic_Sign
XPO -->> Partner : HTTP/201
XPO --) Partner : Callback 4 - KYC Demand<br/>status:PENDING <br/> expectedDiligences{type,possibleDiligenceSubTypes}
XPO --) Partner : Callback 48 - Web View URL
XPO --) Partner : Callback 35 - SCA Wallet Initialization
Partner -->> User : Display WebViewURL
User -->> XPO : Identity document
User -->> XPO : Liveness
XPO --) Partner : Callback 4 - KYC Demand<br/>status:Incomplete <br/>receivedDiligences{diligenceType, status:To_Review_Manually}
break Controls (5mins)
XPO --> XPO: Controls (5mins)
end
XPO --) Partner : Callback 4 - KYC Demand<br/>status:Incomplete <br/>receivedDiligences[{diligenceType Identity, status:Validated}],<br/>expectedDiligences [{diligenceType Complementary: ESIGN}]
Partner -->> User : Display WebViewURL for CGU signature
XPO -->> User : SMS sent for strong authentification
User -->> XPO : CGU signature
XPO --) Partner : Callback 4 - KYC Demand<br/>status:Complete
The strong authentification code expires after 10 minutes. A second SMS is sent after the first expires.
Due Diligence sequence diagram : case identity
Two important pieces of information about workflow:
- the identity document can be sent either via the webview or the API
- the cgu must be signed by API
Best scenario: due diligences validated
sequenceDiagram
autoNumber
Actor User
Participant Partner
Participant XPO
Partner -->> XPO: POST /api/v3.0/user/{appUserId}/kyc/demand<br/>workflowCode: Identity
XPO -->> Partner : HTTP/201
XPO --) Partner : Callback 4 - KYC Demand<br/>status:PENDING <br/> expectedDiligences{type,possibleDiligenceSubTypes}
XPO --) Partner : Callback 48 - Web View URL
XPO --) Partner : Callback 35 - SCA Wallet Initialization
par
alt Webview
Partner -->> User : Display WebViewURL
User -->> XPO : Identity document
else API
User -->> XPO : POST /api/v2.0/users/{appUserId}/kyc/attachments
end
XPO --) Partner : Callback 4 - KYC Demand<br/>status:Incomplete <br/>receivedDiligences{diligenceType, status:To_Review_Manually}
break Controls (5mins)
XPO --> XPO: Controls (5mins)
end
XPO --) Partner : Callback 34 - KYC Demand<br/>status:Incomplete <br/>receivedDiligences[{diligenceType Identity, status:Validated}],<br/>expectedDiligences [{diligenceType Complementary}]
Partner -->> User: display IBAN & RIB
User -->> XPO: Sepa Credit Transfer
XPO --) Partner : Callback 31 - KYC complementary diligence
XPO --) Partner : Callback 4 - KYC Demand<br/>status:Complete
and
Partner --) Partner : SCA Wallet Initialization <br/> -with SCA provider
end
Note over User, Partner: Note: for the identity workflow, <br/> the CGU validation has to be done by <br/> API to validate the userRecordStatus
Partner -->> User : Display CGU
User -->> Partner : Validate CGU
Partner -->> XPO: POST /api/sca/v2.0/users/{AppUserId}/cgu
XPO --) Partner : Callback 34 - userRecordStatus: Validated
The Identity workflow can also be processed by API.
It will require to send the ID Documents using the 🔗 Upload documentAPI.
In this case, it is not neccessary to handle the webview URL provided in callback 48.
Identity workflow requires an addionnal identity verification diligence.The additionnal diligence supported by XPollens in an incoming money transfer originating from an account owned by the user (name, firstname, .. are checked at the receipt of the money transfer by XPollens)
Due Diligence SCT IN
the IBAN for SCT IN due diligence is displayed IF AND ONLY IF the ID due diligence has been completed.Otherwise, a comparison could be made between an issuer and the wrong identity.
The minimum and maximum amount of the Sepa Credit Transfer (as a diligence) is set when the environment is created. Usually, the minimum amout is 1€ and the maximum amount 1000€.
In order to be accepted, the issuer of the SCT must be the same person as the account holder.To achieve this, the account from which the transfer is made must be in the customer's first and last name.Depending on the degree of consistency between the two names, the diligence may be validated, manually reviewed by an operator or rejected.
This due diligence process takes much longer, with the SCT taking around 2 working days to be transmitted from the issuing bank to Xpollens.
sequenceDiagram
autoNumber
Actor User
Participant Partner
Participant XPO
Partner ->> XPO: GET /api/v2.0/accounts/{accountId}
XPO ->> Partner :http 200 {bic, iban}
Partner -->> User: display IBAN & RIB
alt With standard SCT
User -->> XPO: Sepa Credit Transfer
XPO --) Partner : Callback 31 - KYC complementary diligence {status: To_Review_Manually}
break Diligence review ~ 2 days max
XPO --) XPO : Diligence review
end
XPO --) Partner : Callback 31 - KYC complementary diligence {status: Validated}
XPO --) Partner : Callback - SCTIN {status: 1}
else With Instant Payment
User -->> XPO: Instant Payment
XPO --) Partner : Callback 31 - KYC complementary diligence {status: To_Review_Manually}
break Diligence review ~ 10 sec
XPO --) XPO : Diligence review
end
XPO --) Partner : Callback 31 - KYC complementary diligence {status: Validated}
XPO --) Partner : Callback 16 - SCTIN {status: 1}
end
Due Diligence sequence diagram : refused
Due diligence ID refused : issue during the identity document checks
sequenceDiagram
autoNumber
Actor User
Participant Partner
Participant XPO
break Identity controls (5mins)
XPO --> XPO: Identity controls (5mins)
end
XPO --) Partner : Callback 4 - KYC Demand<br/>status:Incomplete <br/>receivedDiligences[{reason, diligenceType Identity, status:Refused}]
alt Electronic_sign
XPO --) Partner : Callback 48 - Web View URL
Note over User, Partner: new attempt with <br/>the same WebViewURL
Partner -->> User : Display WebViewURL
User -->> XPO : Identity document
else Identity
alt Webview
User -->> XPO : Identity document
else API
User -->> XPO : POST /api/v2.0/users/{appUserId}/kyc/attachments
end
end
TheWebViewUrlremains the same for the next attempt(s).
| KO quality | Expected action |
|---|---|
| Poor quality of document | Reopen webview |
| Document badly framed | Reopen webview |
| Missing document page | Reopen webview |
| Expired document | Reopen webview |
| Restricted country | |
| Document type not allowed | Reopen webview |
| Poor quality of biometry | Reopen webview |
| Unauthorized country of document |
| Error when providing an identity document. |
|---|
| Document is too large |
| The document is empty |
| The lines of the MRZ (identity documents) are not valid. |
| The document could not be read (corrupted file) |
| Image is too blurry |
| Image is not contrasted enough |
| Image is too small (does not contain enough pixels) |
| The image is too big (contains too many pixels) |
| Processed image is binarised, but the server does not accept them |
| The font of the text in an image is too small to be read. |
| The document received does not match the expected one. |
| The type of document received is not recognized. |
| The image processing system did not respond. |
| No text found in the document |
| Participant's name not found in document |
| The date of the document was not found. |
| The document is too old. |
| The country of issue of the document is not allowed. |
| The document has expired. |
| MRZ lines not found in the identity document |
| The first name of the MRZ does not match the name on the face of the identity document. |
| Document number of the ZRM does not match the number on the face of the identity document |
| The date of birth of the MRZ does not match the date of birth on the face of the identity |
| Document expiry date could not be read (only for identity documents) |
| The same file has already been submitted: same participant and same file or same type of document requested and same data read |
| Expiration date is not consistent with the MRZ |
Due diligence ID refused: inconsistency between the data declared and the data on the identity document
Use 🔗 Modify User Datato modify the wrong data.
sequenceDiagram
autoNumber
Actor User
Participant Partner
Participant XPO
loop
break Identity controls (5mins)
XPO --> XPO: Identity controls (5mins)
end
XPO --) Partner : Callback 4 - KYC Demand<br/>status:Incomplete <br/>receivedDiligences[{reason, diligenceType Identity, status:Refused}]
Partner -->> User: Checking declared information
User -->> Partner: Forwarding information
Partner -->> XPO: PUT /api/v2.0/users/{appUserId}
Note over User, XPO: automatic relaunches the check with <br/> the identity document and the selfie
end
XPO --) Partner : Callback 4 - KYC Demand<br/>status:Incomplete <br/>receivedDiligences[{diligenceType Identity, status:Validated}],
Error codes
| Inconsistency between the data declared and the information on the identity document | Expected action |
|---|---|
| Inconsistent birthDate between ID document and user’s information | PUT user data |
| Inconsistent fullName between ID document and user’s information | PUT user data |
| Inconsistent birthName between ID document and user’s information | PUT user data |
| Inconsistent lastName between ID document and user’s information | PUT user data |
| Inconsistent firstName between ID document and user’s information | PUT user data |
| Data inversion: birthName and lastName | PUT user data |
| Inconsistent civility between ID document and user’s information | PUT user data |
| Data inversion: firstName and lastName | PUT user data |
| Nationality on id card does not match with user's nationality. Case will be reopened | PUT user data |
Due diligence ID refused: diligence type undefined
In some cases, the Netheos robot is unable to recognise the type of identity document sent to it (e.g. the user sends an image containing the front and back of their identity document). The diligence status changes to "refused", and callback 4 is sent as follows, the refusal may be for different reasons. If this is the case, ask your customer to scan the ID again, making sure that the accepted documents are respected.
{
"Payload": {
"type": "4",
"status": "Incomplete",
"appUserId": "68968-1694163949661",
"kycLevel": "High",
"workflowCode": "Electronic_Sign",
"receivedDiligences": [
{
"diligenceType": "UNDEFINED",
"status": "Refused",
"attachments": [
{
"FileName": "name1.jpg",
"AttachmentKey": "xxx"
},
{
"FileName": "name2.jpg",
"AttachmentKey": "yyy"
}
]
},
{
"diligenceType": "SELFIE",
"status": "Refused",
"attachments": [
{
"FileName": "name3.jpg",
"AttachmentKey": "zzz"
}
]
}
],
"expectedDiligences": [
{
"type": "Identity",
"expectedCount": 1,
"possibleDiligenceSubTypes": [
"ID_CARD",
"PASSPORT",
"RES_CARD"
]
},
{
"type": "Complementary",
"expectedCount": 1,
"possibleDiligenceSubTypes": [
"SCTIN",
"DELEGATED_COMPLEMENTARY_DILIGENCE",
"ESIGN"
]
}
]
},
}Due diligence SCT IN refused: inconsistency between the data declared and the data on the identity document
sequenceDiagram
autoNumber
Actor User
Participant Partner
Participant XPO
Partner -->> User: display IBAN & RIB
User -->> XPO: Sepa Credit Transfer IN or Instant Payment IN
XPO --) Partner : Callback 31 - KYC complementary diligence {status: Refused}
XPO -->> User : Sepa Credit Transfer Refund
XPO -->> Partner : Callback 16 {status 2}
Partner -->> User: ask for a new SCT IN
User -->> XPO: Sepa Credit Transfer IN or Instant Payment IN
XPO --) Partner : Callback 31 - KYC complementary diligence {status: Validated}
| Error |
|---|
| The beneficiary's name is different from the transmitter's name |
Due diligence electronic_signature T&C refused by the enduser
If :
- the enduser refuses to sign the T&C,
- the user does not sign within 90 days
- the user makes all his sms OTP attempts without successthe status of the due diligence changes to "Refused".
As a consequence, the KYC status changes for Rejected. This status is an final status: if the enduser changes his mind and wishes to sign the GCU, a new KYC demand is required.
Callback 4 example: refuse to sign T&C
{
"Payload": {
"type": "4",
"status": "Rejected",
"appUserId": "7297826676138718614",
"kycLevel": "High",
"workflowCode": "Electronic_Sign",
"receivedDiligences": [
{
"reason": "",
"diligenceType": "ID_CARD",
"status": "Validated",
"attachments": [
{
"fileName": "xxx_FRONT_SIDE_1.jpg",
"attachmentKey": "5966c914-02dc-49f2-84c6-62d65b220a35"
},
{
"fileName": "xxx_BACK_SIDE_1.jpg",
"attachmentKey": "e0289fc6-5141-47db-8b0f-4017d94da69d"
}
]
},
{
"diligenceType": "SELFIE",
"status": "Validated",
"attachments": [
{
"fileName": "1_alexis_bonnet_hevin_SELFIE_1.jpg",
"attachmentKey": "83bd84a5-4e98-407c-a574-18cd49c14ecc"
},
{
"fileName": "1_alexis_bonnet_hevin_SELFIE_2.jpg",
"attachmentKey": "74bbda94-5a71-4691-bc92-fdc1a7ba8220"
},
{
"fileName": "1_alexis_bonnet_hevin_SELFIE_3.jpg",
"attachmentKey": "a8ee8219-f2ef-4560-960a-c9b3089bb757"
}
]
},
{
"reason": "Refusal to sign the T&Cs",
"diligenceType": "ESIGN",
"status": "Refused",
"attachments": [
{
"fileName": "document_cgu_testAgent.pdf",
"attachmentKey": "317c6b36-6c77-4de4-9425-015a15ec2863"
}
]
}
],
"expectedDiligences": [
{
"type": "Complementary",
"expectedCount": 1,
"possibleDiligenceSubTypes": [
"SCTIN",
"DELEGATED_COMPLEMENTARY_DILIGENCE",
"ESIGN"
]
}
]
},Here is an example of GET KYC/demand
{
"status": "Rejected",
"creationDate": "2023-11-07T13:22:32",
"lastUpdate": "2023-11-07T13:35:19",
"diligences": [
{
"type": "ID_CARD",
"status": "Validated",
"reason": "",
"files": [
{
"name": "1_corinne_berthier_FRONT_SIDE_1.jpg",
"key": "8e053965-382a-4b35-8d26-a5a9e40b661b"
},
{
"name": "1_corinne_berthier_BACK_SIDE_1.jpg",
"key": "c8bc9f16-98db-43a6-84f5-29ad472a566e"
}
],
"creationDate": "2023-11-07T13:26:23",
"lastUpdate": "2023-11-07T13:26:23"
},
{
"type": "SELFIE",
"status": "Validated",
"files": [
{
"name": "1_corinne_berthier_SELFIE_1.jpg",
"key": "89ef63f8-36a3-43f9-adb4-9febe66c7f5e"
},
{
"name": "1_corinne_berthier_SELFIE_2.jpg",
"key": "cac978d7-fab8-4ce1-bd9f-0e4b9b4d98a8"
},
{
"name": "1_corinne_berthier_SELFIE_3.jpg",
"key": "4b935737-b235-447b-8ad4-e217b646e987"
}
],
"creationDate": "2023-11-07T13:26:23",
"lastUpdate": "2023-11-07T13:26:23"
},
{
"type": "ESIGN",
"status": "Refused",
"reason": "Refusal to sign the T&Cs",
"files": [
{
"name": "document_cgu_testAgent.pdf",
"key": "59592f49-277f-4f5e-8ec1-286f80a8b859"
}
],
"creationDate": "2023-11-07T13:35:19",
"lastUpdate": "2023-11-07T13:35:19"
}
],
"decision": "Abandoned"
}Updated 4 months ago