BlockChain and KYC
What is KYC Blockchain?
What is AML and KYC in banking?
What are good examples of blockchain KYC use cases?
What are the three 3 components of KYC?
·
KYC (Know Your Customer) is a
process by which banks obtain information about the identity and address
of the purchasers.
· It’s a regulator
governed process of performing due thoroughness for verifying the
identity of clients.
·
This process helps to make sure that banks’
services aren’t misused.
· The banks are responsible for completing the KYC procedure
while opening an accounts.
· Banks also are required to periodically update their
customers’ KYC details.
·
KYC may be a manual, time-consuming, and redundant across
institutions.
· Sharing
KYC information on Blockchain would
enable financial institutions to deliver better compliance outcomes, increase
efficiency, and improve customer experience.
1.
Work wiped out collecting KYC information unnecessarily replicated by multiple
institutions.
2. Isolated view of consumers and their transactions insufficient to detect
concealment.
3.
Uncertainty in knowing if implemented practices are sufficient.
1.
Redundancy: Most large files use similar data and processes to
verify an equivalent client. The
solution benefit is to eliminate the redundancy
documentations that got to be verified only once before the approval
information is shared.
2.
Inefficiency: Manual and time-consuming process to collect and
verify documentary evidence. The
solution benefit is to extend automation where documents
and approvals are digitized and may be verified without manual intervention.
3.
Lack of specificity: Requirements for due-diligence
are often fuzzy, creating uncertainty on
compliance to avoid legal sanctions. The
solution benefit is to standardize process i.e.
standardized, automated KYC processes sanctioned by the regulators.
·
Each company must
verify your identity somehow, and it’s particularly
important for financial institutions.
·
From this know
your customer or KYC protocols was the rise to assist companies to ensure
they know who they’re doing business with.
·
Typically,
this involves an extended, drawn-out practice where certain documents are
shown, and a few kinds of background checks or verification takes place.
·
In the traditional KYC system, each bank will conduct its identity
check i.e. each user is checked individually by
an individual organization or government structure.
o Hence, there is a waste of time for checking each identity
from scratch.
·
The
blockchain architecture and the DLT (Distributed
Ledger Technology) allow us to
collect information from various service providers into one cryptographically
secure and unchanging
database that does not need a third party to verify the authenticity of
the knowledge.
o It makes it possible to form a system where
the user will only need to undergo the KYC procedure once to verify his/her
identity.
The process is as follows:
1.
For KYC
procedure a user submits
documents to one of the banks where he wants to take a loan or use
another service.
2.
Individual
participants are responsible for collecting personal data (banks, government
agencies, companies, or users themselves) and stored in a decentralized
network.
3.
The bank
checks and confirms the passage of KYC if everything is normal.
4.
The bank is
responsible for entering the data about the user into the blockchain platform,
to which other banks, organizations and state structures have access. All
parties can control and regulate the KYC process. The system will monitor
changes and updating of the user data, and if someone breaks the rules, it will become known to all
parties.
5.
When a user
wants to use the services of another bank, this second bank accesses the system
and thus confirms the user’s identity.
6.
The access to
user data will be based solely on its consent. The user must log in with
cryptocurrency transactions i.e. use the private key
to initiate the information exchange operation.
·
The KYC
practices vary by the institution as there are no global standards. This leads
to redundant work and limits the ability for different financial institutions
to collaborate to verify identity.
·
Customers are
subject to time-consuming and difficult-to-accomplish onboarding processes when
opening new accounts.
·
There are
changes in the regulations and this is creating costly and effort-intensive
obligations for companies to comply.
·
Also, the
customer information is not being updated in material changes, which causes
inaccurate information in many bank systems.
·
Also known as “Identity and Access Management”,
or IAM, identity management comprises all the processes and technologies within
an organisation that are used to identify,
authenticate and authorize someone
to access services or systems in that said organisation or other associated
ones.
·
Examples of this would range from
customers and/or employees accessing software or hardware inside a
company/enterprise – and the level of access, privileges
and restrictions each user has while doing so – or, in a governmental setting,
the issuing and
verification of birth certificates, national id cards, passports or driver’s
licenses (that allow a user/citizen to not only prove his
identity but also access services from the government and other organisations).
Identity has a problem. If it’s paper-based, such as birth certificates sitting idly in
a basement of a town hall, it’s subject to loss, theft of fraud.
·
A digital identity reduces
the level of bureaucracy and increases the speed of
processes within organisations by allowing for a greater interoperability
between departments and other institutions. But if this digital identity is
stored on a centralised server, it becomes a target for hackers. Since 2017
alone, more than 600 million personal details – such as addresses or credit
card numbers – have been hacked, leaked or breached
from organisations.
·
Most of the current identity management systems
are weak and outdated.
Identities
need to be portable
and verifiable everywhere, any time, and digitization can
enable that. But being digital is not enough. Identities also need to be private and secure.
Several
industries suffer the problems of current identity management systems:
·
Government: The lack of interoperability between departments and government
levels takes a toll in the form of excess bureaucracy. Which, in turn,
increases processes’ times and costs.
·
Healthcare: half of the world’s population does not have access to quality
healthcare. The lack of interoperability between actors in the healthcare space
(Hospitals, clinics, insurance companies, doctors, pharmacies, etc) leads to
inefficient healthcare and delayed care and frustration for patients.
·
Education: It is estimated that two hundred thousand fake academic
certificates are sold each year in the USA alone. The difficulty in verifying
the authenticity of
these credentials leads to hiring of unqualified professionals, brand damage to
the universities and the hiring companies.
·
Banking: the need for login details such as passwords decreases the
security of banking for users.
·
Businesses in
general: the current need to store
clients’ and employees’ personal data is a source of liability for companies.
A personal data breach
may result in huge fines due to GDPR infringement
– such as the British Airways case – or simply due to customer trust loss and consequential damage
to the organisation’s brand.
·
The first model of digital identity management
was a siloed one. Each organisation issued a digital identity credential to a
user to allow them to access its services. Each user needed a new digital
identity credential for every new organisation he engages with.
That provided a poor user experience. Just remember all the websites you
had to register and create new passwords and login details for.
· The second model of digital identity management
is called the “Federated” one. Because of the poor user experience of the first
model, third parties began issuing digital identity credentials that allow
users to login to services and other websites. The best examples of this are
“Login with Facebook” and “Login with Google” functionalities. Companies
“outsourced” their identity management to major corporations who have an
economic interest in ammassing such large databases
of personal data. This, of course, raises privacy and security concerns.
Facebook, Google and others became
the middlemen of
trust.
The emergence of Blockchain technology, Decentralized Identifiers and Verifiable Credentials allowed
the creation of a third model of identity management: Self-Sovereign
Identity.
As
conceptualised and standardised by the W3C, the three pillars of Self-Sovereign
Identity are the Verifiable Credentials protocol, the Decentralized
Identifiers protocol and Distributed Ledger Technology
(or Blockchain).
·
According to W3C (World Wide Web Consortium), “Verifiable credentials represent statements made by an issuer
in a tamper-evident and privacy-respecting manner.”
· Verifiable Credentials, in essence, allow
for the digital
watermarking of claims data through a combination of
public key cryptography and privacy-preserving techniques to prevent
correlation.
·
The effect of this is that now, not
only can physical credentials safely be turned digital, holders
of such credentials can selectively disclose specific information from
this credential without exposing the actual data (imagine proving you are above
the age of 21 without having to show your ID card!), where third-parties are
instantly able to verify this data without having to call upon the issuer.
· Decentralized Identifiers are
globally, unique and persistent identifiers. They are
entirely controlled by the identity owner. DIDs are
independent of centralised registries, authorities or
identity providers.
·
When an organisation issues you
a Verifiable Credential, they attach their Public DID to that credential.
That same Public DID is also stored on the blockchain, an immutable record of data.
When someone wants to verify the authenticity/validity of the Credential, they
can check the DID on the blockchain to see who issued it without having to
contact the issuing party.
·
The Blockchain acts as a verifiable data registry.
A “phonebook” that anyone can consult to verify what organisation a specific
Public DID belongs to.
·
In identity management, a
distributed ledger (a “blockchain”) enables everyone in the network to have
the same source of
truth about which credentials are valid and who attested to the
validity of the data inside the credential, without revealing the actual data.