KYC diligences


Due Diligence types

For the Electronic_Signature workflow, the due diligences expected are :

  1. Identity document & selfie
  2. Electronic signature

For the Identity workflow, the due diligences expected are :

  1. Identity document
  2. Sepa Credit Transfer IN (this SEPA transfer could be an instant payment, a standard one)

For these two workflows, when configuring your environment, you can choose to accept one or more of the following forms of identification:

  • ID card
  • passport
  • resident permit
👍

Identity checks are subject to SLAs: 5 minutes maximum in 90% of cases.


Due Diligence state diagram

Diligence Status (webview mode)

stateDiagram
state fork_state <<fork>>
state fork_state2 <<fork>>

  [*] --> fork_state
 fork_state --> To_Review_Manually: provider needs to check manually the diligence
 fork_state --> Validated: provider valides diligence 
 
 To_Review_Manually --> fork_state2
	fork_state2--> Refused: provider rejects the diligence after manual check
	fork_state2--> Validated: provider validates the diligence after manual check

Diligence Status (API mode)

stateDiagram
state fork_state <<fork>>
state fork_state2 <<fork>>

  [*] --> Received
  Received --> fork_state
  fork_state --> To_Review_Manually: Diligence needs manual review
  fork_state --> Validated : provider valides diligence
  
  To_Review_Manually --> fork_state2
  fork_state2 --> Validated: provider validates the diligence after manual check
 fork_state2 --> Refused: provider rejects validates the diligence after manual check
   fork_state --> Refused: provider refuses diligence
👍

Each time the status of a due diligence changes, a callback 4 is sent.


Due Diligence sequence diagram : case electronic_sign

Best scenario: due diligences validated

sequenceDiagram
autoNumber
Actor User
Participant Partner
Participant XPO
Partner ->> XPO: POST /api/v3.0/user/{appUserId}/kyc/demand<br/>workflowCode: Electronic_Sign
XPO -->> Partner : HTTP/201
XPO --) Partner : Callback 4 - KYC Demand<br/>status:PENDING <br/> expectedDiligences{type,possibleDiligenceSubTypes}
XPO --) Partner : Callback 48 - Web View URL
XPO --) Partner : Callback 35 - SCA Wallet Initialization
Partner -->> User : Display WebViewURL
User -->> XPO : Identity document
User -->> XPO : Liveness
XPO --) Partner : Callback 4 - KYC Demand<br/>status:Incomplete <br/>receivedDiligences{diligenceType, status:To_Review_Manually}
break Controls (5mins)
    XPO --> XPO: Controls (5mins) 
end
XPO --) Partner : Callback 4 - KYC Demand<br/>status:Incomplete <br/>receivedDiligences[{diligenceType Identity, status:Validated}],<br/>expectedDiligences [{diligenceType Complementary: ESIGN}]

Partner -->> User : Display WebViewURL for CGU signature
XPO -->> User : SMS sent for strong authentification
User -->> XPO : CGU signature
XPO --) Partner : Callback 4 - KYC Demand<br/>status:Complete
❗️

The strong authentification code expires after 10 minutes. A second SMS is sent after the first expires.


Due Diligence sequence diagram : case identity

Two important pieces of information about workflow:

  • the identity document can be sent either via the webview or the API
  • the cgu must be signed by API

Best scenario: due diligences validated


sequenceDiagram
autoNumber
Actor User
Participant Partner
Participant XPO
Partner -->> XPO: POST /api/v3.0/user/{appUserId}/kyc/demand<br/>workflowCode: Identity
XPO -->> Partner : HTTP/201
XPO --) Partner : Callback 4 - KYC Demand<br/>status:PENDING <br/> expectedDiligences{type,possibleDiligenceSubTypes}
XPO --) Partner : Callback 48 - Web View URL
XPO --) Partner : Callback 35 - SCA Wallet Initialization
par
	alt Webview
		Partner -->> User : Display WebViewURL
		User -->> XPO : Identity document
	else API
		User -->> XPO : POST /api/v2.0/users/{appUserId}/kyc/attachments
	end
	XPO --) Partner : Callback 4 - KYC Demand<br/>status:Incomplete <br/>receivedDiligences{diligenceType, status:To_Review_Manually}
	break Controls (5mins)
		XPO --> XPO: Controls (5mins) 
	end
	XPO --) Partner : Callback 34 - KYC Demand<br/>status:Incomplete <br/>receivedDiligences[{diligenceType Identity, status:Validated}],<br/>expectedDiligences [{diligenceType Complementary}]
	Partner -->> User: display IBAN & RIB
	User -->> XPO: Sepa Credit Transfer
	XPO --) Partner : Callback 31 - KYC complementary diligence
	XPO --) Partner : Callback 4 - KYC Demand<br/>status:Complete 
and
	Partner --) Partner : SCA Wallet Initialization <br/> -with SCA provider
end
Note over User, Partner: Note: for the identity workflow, <br/> the CGU validation has to be done by <br/> API to validate the userRecordStatus
Partner -->> User : Display CGU
User -->> Partner : Validate CGU
Partner -->> XPO: POST /api/sca/v2.0/users/{AppUserId}/cgu
XPO --) Partner : Callback 34 - userRecordStatus: Validated

The Identity workflow can also be processed by API.

It will require to send the ID Documents using the 🔗 Upload documentAPI.

In this case, it is not neccessary to handle the webview URL provided in callback 48.

❗️

Identity workflow requires an addionnal identity verification diligence.

The additionnal diligence supported by XPollens in an incoming money transfer originating from an account owned by the user (name, firstname, .. are checked at the receipt of the money transfer by XPollens)






Due Diligence SCT IN

❗️

the IBAN for SCT IN due diligence is displayed IF AND ONLY IF the ID due diligence has been completed.

Otherwise, a comparison could be made between an issuer and the wrong identity.

The minimum and maximum amount of the Sepa Credit Transfer (as a diligence) is set when the environment is created. Usually, the minimum amout is 1€ and the maximum amount 1000€.

In order to be accepted, the issuer of the SCT must be the same person as the account holder.To achieve this, the account from which the transfer is made must be in the customer's first and last name.Depending on the degree of consistency between the two names, the diligence may be validated, manually reviewed by an operator or rejected.

This due diligence process takes much longer, with the SCT taking around 2 working days to be transmitted from the issuing bank to Xpollens.

sequenceDiagram
autoNumber
Actor User
Participant Partner
Participant XPO
		Partner ->> XPO: GET /api/v2.0/accounts/{accountId}
		XPO ->> Partner :http 200 {bic, iban}
    Partner -->> User: display IBAN & RIB

alt With standard SCT
	User -->> XPO: Sepa Credit Transfer
		XPO --) Partner : Callback 31 - KYC complementary diligence {status: To_Review_Manually}
		break Diligence review ~ 2 days max
				XPO --) XPO : Diligence review
		end
    XPO --) Partner : Callback 31 - KYC complementary diligence {status: Validated}
    XPO --) Partner : Callback  - SCTIN {status: 1}
	
else With Instant Payment
	  User -->> XPO: Instant Payment
    XPO --) Partner : Callback 31 - KYC complementary diligence {status: To_Review_Manually}
		break Diligence review ~ 10 sec
				XPO --) XPO : Diligence review
		end
	XPO --) Partner : Callback 31 - KYC complementary diligence {status: Validated}
    XPO --) Partner : Callback 16 - SCTIN {status: 1}
end


Due Diligence sequence diagram : refused

Due diligence ID refused : issue during the identity document checks

sequenceDiagram
autoNumber
Actor User
Participant Partner
Participant XPO
break Identity controls (5mins)
    XPO --> XPO: Identity controls (5mins) 
end
XPO --) Partner : Callback 4 - KYC Demand<br/>status:Incomplete <br/>receivedDiligences[{reason, diligenceType Identity, status:Refused}]

alt Electronic_sign
    XPO --) Partner : Callback 48 - Web View URL
    Note over User, Partner: new attempt with <br/>the same WebViewURL
    Partner -->> User : Display WebViewURL
    User -->> XPO : Identity document
    
else Identity
    alt Webview
        User -->> XPO : Identity document
    else API
        User -->> XPO : POST /api/v2.0/users/{appUserId}/kyc/attachments
    end
end

📘

The WebViewUrl remains the same for the next attempt(s).

KO qualityExpected action
Poor quality of documentReopen webview
Document badly framedReopen webview
Missing document pageReopen webview
Expired documentReopen webview
Restricted country
Document type not allowedReopen webview
Poor quality of biometryReopen webview
Unauthorized country of document
Error when providing an identity document.
Document is too large
The document is empty
The lines of the MRZ (identity documents) are not valid.
The document could not be read (corrupted file)
Image is too blurry
Image is not contrasted enough
Image is too small (does not contain enough pixels)
The image is too big (contains too many pixels)
Processed image is binarised, but the server does not accept them
The font of the text in an image is too small to be read.
The document received does not match the expected one.
The type of document received is not recognized.
The image processing system did not respond.
No text found in the document
Participant's name not found in document
The date of the document was not found.
The document is too old.
The country of issue of the document is not allowed.
The document has expired.
MRZ lines not found in the identity document
The first name of the MRZ does not match the name on the face of the identity document.
Document number of the ZRM does not match the number on the face of the identity document
The date of birth of the MRZ does not match the date of birth on the face of the identity
Document expiry date could not be read (only for identity documents)
The same file has already been submitted: same participant and same file or same type of document requested and same data read
Expiration date is not consistent with the MRZ

Due diligence ID refused: inconsistency between the data declared and the data on the identity document

Use 🔗 Modify User Datato modify the wrong data.

sequenceDiagram
autoNumber
Actor User
Participant Partner
Participant XPO

loop

break Identity controls (5mins)
    XPO --> XPO: Identity controls (5mins) 
end
XPO --) Partner : Callback 4 - KYC Demand<br/>status:Incomplete <br/>receivedDiligences[{reason, diligenceType Identity, status:Refused}]

Partner -->> User: Checking declared information
User -->> Partner: Forwarding information  
Partner -->> XPO: PUT /api/v2.0/users/{appUserId}
Note over User, XPO: automatic relaunches the check with <br/> the identity document and the selfie

end

XPO --) Partner : Callback 4 - KYC Demand<br/>status:Incomplete <br/>receivedDiligences[{diligenceType Identity, status:Validated}],



Error codes

Inconsistency between the data declared and the information on the identity documentExpected action
Inconsistent birthDate between ID document and user’s informationPUT user data
Inconsistent fullName between ID document and user’s informationPUT user data
Inconsistent birthName between ID document and user’s informationPUT user data
Inconsistent lastName between ID document and user’s informationPUT user data
Inconsistent firstName between ID document and user’s informationPUT user data
Data inversion: birthName and lastNamePUT user data
Inconsistent civility between ID document and user’s informationPUT user data
Data inversion: firstName and lastNamePUT user data
Nationality on id card does not match with user's nationality. Case will be reopenedPUT user data

Due diligence ID refused: diligence type undefined

In some cases, the Netheos robot is unable to recognise the type of identity document sent to it (e.g. the user sends an image containing the front and back of their identity document). The diligence status changes to "refused", and callback 4 is sent as follows, the refusal may be for different reasons. If this is the case, ask your customer to scan the ID again, making sure that the accepted documents are respected.

{
    "Payload": {
        "type": "4",
        "status": "Incomplete",
        "appUserId": "68968-1694163949661",
        "kycLevel": "High",
        "workflowCode": "Electronic_Sign",
        "receivedDiligences": [
            {
                "diligenceType": "UNDEFINED",
                "status": "Refused",
                "attachments": [
                    {
                        "FileName": "name1.jpg",
                        "AttachmentKey": "xxx"
                    },
                    {
                        "FileName": "name2.jpg",
                        "AttachmentKey": "yyy"
                    }
                ]
            },
            {
                "diligenceType": "SELFIE",
                "status": "Refused",
                "attachments": [
                    {
                        "FileName": "name3.jpg",
                        "AttachmentKey": "zzz"
                    }
                ]
            }
        ],
        "expectedDiligences": [
            {
                "type": "Identity",
                "expectedCount": 1,
                "possibleDiligenceSubTypes": [
                    "ID_CARD",
                    "PASSPORT",
                    "RES_CARD"
                ]
            },
            {
                "type": "Complementary",
                "expectedCount": 1,
                "possibleDiligenceSubTypes": [
                    "SCTIN",
                    "DELEGATED_COMPLEMENTARY_DILIGENCE",
                    "ESIGN"
                ]
            }
        ]
    },
}

Due diligence SCT IN refused: inconsistency between the data declared and the data on the identity document

sequenceDiagram
autoNumber
Actor User
Participant Partner
Participant XPO

	Partner -->> User: display IBAN & RIB
    User -->> XPO: Sepa Credit Transfer IN or Instant Payment IN
	XPO --) Partner : Callback 31 - KYC complementary diligence {status: Refused}
        XPO -->> User : Sepa Credit Transfer Refund
        XPO -->> Partner : Callback 16 {status 2}
	Partner -->> User: ask for a new SCT IN 
    User -->> XPO: Sepa Credit Transfer IN or Instant Payment IN
	XPO --) Partner : Callback 31 - KYC complementary diligence {status: Validated}
Error
The beneficiary's name is different from the transmitter's name

Due diligence electronic_signature T&C refused by the enduser

If :

  • the enduser refuses to sign the T&C,
  • the user does not sign within 90 days
  • the user makes all his sms OTP attempts without successthe status of the due diligence changes to "Refused".

As a consequence, the KYC status changes for Rejected. This status is an final status: if the enduser changes his mind and wishes to sign the GCU, a new KYC demand is required.

Callback 4 example: refuse to sign T&C
{ 
   "Payload": {
        "type": "4",
        "status": "Rejected",
        "appUserId": "7297826676138718614",
        "kycLevel": "High",
        "workflowCode": "Electronic_Sign",
        "receivedDiligences": [
            {
                "reason": "",
                "diligenceType": "ID_CARD",
                "status": "Validated",
                "attachments": [
                    {
                        "fileName": "xxx_FRONT_SIDE_1.jpg",
                        "attachmentKey": "5966c914-02dc-49f2-84c6-62d65b220a35"
                    },
                    {
                        "fileName": "xxx_BACK_SIDE_1.jpg",
                        "attachmentKey": "e0289fc6-5141-47db-8b0f-4017d94da69d"
                    }
                ]
            },
            {
                "diligenceType": "SELFIE",
                "status": "Validated",
                "attachments": [
                    {
                        "fileName": "1_alexis_bonnet_hevin_SELFIE_1.jpg",
                        "attachmentKey": "83bd84a5-4e98-407c-a574-18cd49c14ecc"
                    },
                    {
                        "fileName": "1_alexis_bonnet_hevin_SELFIE_2.jpg",
                        "attachmentKey": "74bbda94-5a71-4691-bc92-fdc1a7ba8220"
                    },
                    {
                        "fileName": "1_alexis_bonnet_hevin_SELFIE_3.jpg",
                        "attachmentKey": "a8ee8219-f2ef-4560-960a-c9b3089bb757"
                    }
                ]
            },
            {
                "reason": "Refusal to sign the T&Cs",
                "diligenceType": "ESIGN",
                "status": "Refused",
                "attachments": [
                    {
                        "fileName": "document_cgu_testAgent.pdf",
                        "attachmentKey": "317c6b36-6c77-4de4-9425-015a15ec2863"
                    }
                ]
            }
        ],
        "expectedDiligences": [
            {
                "type": "Complementary",
                "expectedCount": 1,
                "possibleDiligenceSubTypes": [
                    "SCTIN",
                    "DELEGATED_COMPLEMENTARY_DILIGENCE",
                    "ESIGN"
                ]
            }
        ]
    },

Here is an example of GET KYC/demand

{
    "status": "Rejected",
    "creationDate": "2023-11-07T13:22:32",
    "lastUpdate": "2023-11-07T13:35:19",
    "diligences": [
        {
            "type": "ID_CARD",
            "status": "Validated",
            "reason": "",
            "files": [
                {
                    "name": "1_corinne_berthier_FRONT_SIDE_1.jpg",
                    "key": "8e053965-382a-4b35-8d26-a5a9e40b661b"
                },
                {
                    "name": "1_corinne_berthier_BACK_SIDE_1.jpg",
                    "key": "c8bc9f16-98db-43a6-84f5-29ad472a566e"
                }
            ],
            "creationDate": "2023-11-07T13:26:23",
            "lastUpdate": "2023-11-07T13:26:23"
        },
        {
            "type": "SELFIE",
            "status": "Validated",
            "files": [
                {
                    "name": "1_corinne_berthier_SELFIE_1.jpg",
                    "key": "89ef63f8-36a3-43f9-adb4-9febe66c7f5e"
                },
                {
                    "name": "1_corinne_berthier_SELFIE_2.jpg",
                    "key": "cac978d7-fab8-4ce1-bd9f-0e4b9b4d98a8"
                },
                {
                    "name": "1_corinne_berthier_SELFIE_3.jpg",
                    "key": "4b935737-b235-447b-8ad4-e217b646e987"
                }
            ],
            "creationDate": "2023-11-07T13:26:23",
            "lastUpdate": "2023-11-07T13:26:23"
        },
        {
            "type": "ESIGN",
            "status": "Refused",
            "reason": "Refusal to sign the T&Cs",
            "files": [
                {
                    "name": "document_cgu_testAgent.pdf",
                    "key": "59592f49-277f-4f5e-8ec1-286f80a8b859"
                }
            ],
            "creationDate": "2023-11-07T13:35:19",
            "lastUpdate": "2023-11-07T13:35:19"
        }
    ],
    "decision": "Abandoned"
}




Did this page help you?