Back To Home

BlockChain and KYC

What is KYC Blockchain?

What is AML and KYC in banking?

What are good examples of blockchain KYC use cases?

What are the three 3 components of KYC?

 

·       KYC (Know Your Customer) is a process by which banks obtain information about the identity and address of the purchasers.

·       It’s a regulator governed process of performing due thoroughness for verifying the identity of clients.

·       This process helps to make sure that banks’ services aren’t misused.

·       The banks are responsible for completing the KYC procedure while opening an accounts.

·       Banks also are required to periodically update their customers’ KYC details.

·       KYC may be a manual, time-consuming, and redundant across institutions.

·       Sharing KYC information on Blockchain would enable financial institutions to deliver better compliance outcomes, increase efficiency, and improve customer experience.

 

Problems and Deficiencies

 

1.  Work wiped out collecting KYC information unnecessarily replicated by multiple institutions.

2.  Isolated view of consumers and their transactions insufficient to detect concealment.

3.  Uncertainty in knowing if implemented practices are sufficient.

 

Key Problem Areas and Solution Benefits

 

1.  Redundancy: Most large files use similar data and processes to verify an equivalent client. The solution benefit is to eliminate the redundancy documentations that got to be verified only once before the approval information is shared.

2.  Inefficiency: Manual and time-consuming process to collect and verify documentary evidence. The solution benefit is to extend automation where documents and approvals are digitized and may be verified without manual intervention.

 

3.  Lack of specificity: Requirements for due-diligence are often fuzzy, creating uncertainty on compliance to avoid legal sanctions. The solution benefit is to standardize process i.e. standardized, automated KYC processes sanctioned by the regulators.

 

The Idea Behind Blockchain and KYC

 

·       Each company must verify your identity somehow, and it’s particularly important for financial institutions.

·       From this know your customer or KYC protocols was the rise to assist companies to ensure they know who they’re doing business with.

·       Typically, this involves an extended, drawn-out practice where certain documents are shown, and a few kinds of background checks or verification takes place.

 

KYC Blockchain Implementation

 

·       In the traditional KYC system, each bank will conduct its identity check i.e. each user is checked individually by an individual organization or government structure.

 

o  Hence, there is a waste of time for checking each identity from scratch.

 

·       The blockchain architecture and the DLT (Distributed Ledger Technology) allow us to collect information from various service providers into one cryptographically secure and unchanging database that does not need a third party to verify the authenticity of the knowledge.

 

o  It makes it possible to form a system where the user will only need to undergo the KYC procedure once to verify his/her identity.

 

The process is as follows:

 

1.  For KYC procedure a user submits documents to one of the banks where he wants to take a loan or use another service.

 

2.  Individual participants are responsible for collecting personal data (banks, government agencies, companies, or users themselves) and stored in a decentralized network.

 

3.  The bank checks and confirms the passage of KYC if everything is normal.

 

4.  The bank is responsible for entering the data about the user into the blockchain platform, to which other banks, organizations and state structures have access. All parties can control and regulate the KYC process. The system will monitor changes and updating of the user data, and if someone breaks the rules, it will become known to all parties.

 

5.  When a user wants to use the services of another bank, this second bank accesses the system and thus confirms the user’s identity.

 

6.  The access to user data will be based solely on its consent. The user must log in with cryptocurrency transactions i.e. use the private key to initiate the information exchange operation.

 

 

Blockchain and KYC: Current Challenges

 

·       The KYC practices vary by the institution as there are no global standards. This leads to redundant work and limits the ability for different financial institutions to collaborate to verify identity.

·       Customers are subject to time-consuming and difficult-to-accomplish onboarding processes when opening new accounts.

·       There are changes in the regulations and this is creating costly and effort-intensive obligations for companies to comply.

·       Also, the customer information is not being updated in material changes, which causes inaccurate information in many bank systems.

What is Identity Management?

·       Also known as “Identity and Access Management”, or IAM, identity management comprises all the processes and technologies within an organisation that are used to identify, authenticate and authorize someone to access services or systems in that said organisation or other associated ones.

·       Examples of this would range from customers and/or employees accessing software or hardware inside a company/enterprise – and the level of access, privileges and restrictions each user has while doing so – or, in a governmental setting, the issuing and verification of birth certificatesnational id cards, passports or driver’s licenses (that allow a user/citizen to not only prove his identity but also access services from the government and other organisations).

The problem with current Identity Management Systems

Identity has a problem. If it’s paper-based, such as birth certificates sitting idly in a basement of a town hall, it’s subject to loss, theft of fraud.

·       digital identity reduces the level of bureaucracy and increases the speed of processes within organisations by allowing for a greater interoperability between departments and other institutions. But if this digital identity is stored on a centralised server, it becomes a target for hackers. Since 2017 alone, more than 600 million personal details – such as addresses or credit card numbers – have been hacked, leaked or breached from organisations.

·       Most of the current identity management systems are weak and outdated.

Identities need to be portable and verifiable everywhere, any time, and digitization can enable that. But being digital is not enough. Identities also need to be private and secure.

Several industries suffer the problems of current identity management systems:

·         Government: The lack of interoperability between departments and government levels takes a toll in the form of excess bureaucracy. Which, in turn, increases processes’ times and costs.

·         Healthcare: half of the world’s population does not have access to quality healthcare. The lack of interoperability between actors in the healthcare space (Hospitals, clinics, insurance companies, doctors, pharmacies, etc) leads to inefficient healthcare and delayed care and frustration for patients.

·         Education: It is estimated that two hundred thousand fake academic certificates are sold each year in the USA alone. The difficulty in verifying the authenticity of these credentials leads to hiring of unqualified professionals, brand damage to the universities and the hiring companies.

·         Banking: the need for login details such as passwords decreases the security of banking for users. 

·         Businesses in general: the current need to store clients’ and employees’ personal data is a source of liability for companies. A personal data breach may result in huge fines due to GDPR infringement – such as the British Airways case – or simply due to customer trust loss and consequential damage to the organisation’s brand.

Models of Digital Identity Management

·       The first model of digital identity management was a siloed one. Each organisation issued a digital identity credential to a user to allow them to access its services. Each user needed a new digital identity credential for every new organisation he engages with. That provided a poor user experience. Just remember all the websites you had to register and create new passwords and login details for.

·       The second model of digital identity management is called the “Federated” one. Because of the poor user experience of the first model, third parties began issuing digital identity credentials that allow users to login to services and other websites. The best examples of this are “Login with Facebook” and “Login with Google” functionalities. Companies “outsourced” their identity management to major corporations who have an economic interest in ammassing such large databases of personal data. This, of course, raises privacy and security concerns.

Facebook, Google and others became the middlemen of trust.

The emergence of Blockchain technology, Decentralized Identifiers and Verifiable Credentials allowed the creation of a third model of identity management: Self-Sovereign Identity.

A Blockchain based Identity Management Solution

As conceptualised and standardised by the W3C, the three pillars of Self-Sovereign Identity are the Verifiable Credentials protocol, the Decentralized Identifiers protocol and Distributed Ledger Technology (or Blockchain).

The relationship between Decentralized Identifiers, Verifiable Credentials and Blockchain in identity management

·       According to W3C (World Wide Web Consortium), “Verifiable credentials represent statements made by an issuer in a tamper-evident and privacy-respecting manner.” 

·       Verifiable Credentials, in essence, allow for the digital watermarking of claims data through a combination of public key cryptography and privacy-preserving techniques to prevent correlation.

·       The effect of this is that now, not only can physical credentials safely be turned digital, holders of such credentials can selectively disclose specific information from this credential without exposing the actual data (imagine proving you are above the age of 21 without having to show your ID card!), where third-parties are instantly able to verify this data without having to call upon the issuer.

·       Decentralized Identifiers are globally, unique and persistent identifiers. They are entirely controlled by the identity owner. DIDs are independent of centralised registries, authorities or identity providers.

·       When an organisation issues you a Verifiable Credential, they attach their Public DID to that credential. That same Public DID is also stored on the blockchain, an immutable record of data. When someone wants to verify the authenticity/validity of the Credential, they can check the DID on the blockchain to see who issued it without having to contact the issuing party.

·       The Blockchain acts as a verifiable data registry. A “phonebook” that anyone can consult to verify what organisation a specific Public DID belongs to.

·       In identity management, a distributed ledger (a “blockchain”) enables everyone in the network to have the same source of truth about which credentials are valid and who attested to the validity of the data inside the credential, without revealing the actual data.

 

Back To Home