KYC AML software: what to look for, and when to build
Short answer: KYC AML software covers two different jobs that vendors sell as one. Identity verification reads and checks documents; anti-money-laundering screening matches people and businesses against sanctions, politically exposed person lists and adverse media, then keeps matching them. Judge the first on field accuracy against your worst documents and the second on false positive rate, because false positives are what actually consume your compliance team.
The two jobs inside KYC AML software
Verification answers whether this document is genuine and belongs to the person submitting it. Document classification, field extraction, security-feature checks, and a portrait match against a selfie with liveness.
Screening answers whether this person or company is someone you are permitted to onboard. Sanctions lists, PEP status, adverse media, and ongoing rescreening as those lists change.
They fail differently. Verification fails on image quality and unusual document types. Screening fails on name matching, which is a genuinely hard problem across transliteration, ordering conventions, and common names.
False positives are the real cost
Every vendor quotes match accuracy. Almost none lead with false positive rate, and that is the number that determines your headcount.
Screening “Mohammed Ali” against a global sanctions list generously will return matches. Screening it strictly will miss a real one. Where you set that threshold is a business decision with a regulator attached, and the software should let you set it per list, per risk tier, and per customer type rather than offering one global dial.
Ask any vendor for the false positive rate on a sample of your own customer names, not theirs. If they cannot run that, you are buying blind.
What to evaluate in KYC AML software
Document coverage on your mix. Not “hundreds of document types”, but the specific ones your customers hold. A vendor strong on EU passports may be weak on the West African national IDs that make up a third of your volume.
Field accuracy on degraded input. Test on your worst photographs, not clean scans. Ask for accuracy at field level against a labelled sample.
Confidence and escalation. Every extracted field should carry a score, and low-confidence cases should escalate with context attached rather than passing through.
Threshold control. Per list, per risk tier, adjustable without a support ticket.
Audit trail. Reconstructing why a decision was made, by whom, and against which list version. The first time a regulator asks, logs are not an answer.
Total cost at your volume. Per-check pricing multiplied by annual checks, including the rechecks a high false positive rate generates.
When building wins
Four conditions, the same ones that decide any build-versus-buy question in this space.
Per-check pricing dominates. At high volume the licence becomes the largest line in the business case.
Your document mix is unusual and vendor coverage is poor on exactly the types you see most.
Documents cannot leave your environment. Data residency or network isolation rules out a hosted service.
Your decision logic is specific enough that you keep fighting the vendor’s model rather than configuring it.
Note what is not on that list: screening data. Building your own sanctions and PEP feed is almost never right. The lists are licensed, they change constantly, and maintaining them is a full-time function. A sensible build uses a commercial screening feed behind a pipeline you control.
That is how we structure KYC and KYB automation: own the extraction, validation, thresholds and case management, license the list data.
What a build actually removes
For one FinTech, automating the verification half removed €40,000 a year of manual review at 98% field-detection accuracy, on 70% less compute than the baseline. Roughly the routine 90% of the queue disappeared and the reviewer stayed on cases that genuinely needed judgement. The detail is in the KYC OCR automation case study.
The screening half was not rebuilt, because there was nothing to gain by rebuilding it.
KYB needs different software
Business verification is not customer verification with extra fields. It starts with incorporation documents and a registry record, then has to resolve beneficial ownership through holding structures and nominee directors, and finally run each identified owner through the individual pipeline.
Many KYC AML software products treat KYB as an afterthought. If business onboarding is a meaningful share of your volume, evaluate it as a separate product rather than a checkbox.
What a shortlist evaluation should involve
Not a feature matrix. Two weeks with your own data.
Give each vendor fifty real submissions, deliberately weighted toward the difficult end: poor photographs, unusual document types, the nationalities your applicant base actually holds. Measure three things separately. Field-level accuracy against labels you keyed yourself. The share of submissions where every field was right, which is a much harsher and more honest number. And the share the system passed without review at its default settings.
That third number is your straight-through rate on your documents, and it is the only comparison that means anything. Published benchmarks are run on datasets that look nothing like your intake.
One caution: a vendor offering to tune on your sample before demonstrating should be allowed to, then tested on a second sample they have never seen. The gap between the two runs is the part of their result you cannot rely on.
The questions that sort vendors
- What is your straight-through rate at an institution with our applicant mix, and what moves it?
- Can we set our own confidence thresholds, or are they yours?
- Which document types have the weakest coverage, and how do you find out about a new one?
- What does a reviewer see when a case falls out, and how much evidence is assembled automatically?
- What does the audit trail record, and can it reconstruct a decision three years later after two staff changes?
The second question matters more than it looks. A system that returns a pass or fail has made a policy choice for you; one that returns scores and evidence lets your compliance function own the judgement, which is where it belongs.
What it costs to run
Three components, and licence fees are rarely the largest.
Per-check pricing, which scales directly with your growth and with your retry rate. A system with poor capture guidance bills you twice for the same applicant, so retry rate is a pricing question rather than a user-experience one.
Reviewer headcount, set by your straight-through rate. This exceeds software spend at most volumes within the first year, which is why alert and exception quality is the number to negotiate on rather than the per-check price.
And recurring model validation and audit, which is scheduled work with an owner rather than a one-off. Whatever decides your outcomes has to be explainable to an examiner and periodically revalidated.
The takeaway
KYC AML software bundles verification and screening, and you should evaluate them separately because they fail for different reasons. Test document coverage on your own mix, demand a false positive rate on your own names, and remember that building the pipeline rarely means building the list data.
EpochC builds KYC and KYB automation on intelligent document processing services, with confidence scoring and an audit trail from the first commit. See the KYC OCR automation case study or start a project.