The short answer
What does this use case involve?
Reusable identity can reduce repeated collection of verified attributes, but an earlier KYC check does not automatically satisfy a new institution's obligations. Each receiving organization must assess assurance, freshness, permissions and its own screening and eligibility requirements.
Where the current process breaks down
Users repeatedly submit documents while platforms still need sanctions checks, risk scoring and eligibility controls. Useful for investor onboarding, marketplace access, gated token transfers, broker workflows and compliance operations.
From input to outcome
How does the workflow operate?
The following is an illustrative operating model, not a claim about a specific deployment. Ownership, approvals and exception handling should be agreed before implementation.
- 01
Verify the identity
Establish the evidence, assurance level and issuing provider. Record which attributes were verified and when.
- 02
Share permitted attributes
Let the user authorize a narrowly scoped presentation. Avoid sharing complete documents when a smaller verified attribute is sufficient.
- 03
Apply current checks
Refresh sanctions and risk screening as required and assess the product's investor eligibility. Link wallets only through an approved association process.
- 04
Maintain status
Revoke compromised credentials, update expired evidence and preserve the receiving institution's audit and access rights.
Build the operating stack
Which infrastructure is needed?
These capabilities may sit inside an existing system, a specialist service or an integrated platform. Map each one to a responsible owner; do not assume a single vendor covers every function.
- Identity verification
- KYC and AML screening
- Wallet risk scoring
- Transfer eligibility
Evidence and context
FATF Guidance on Digital IdentityBackground on digital identity assurance and customer due diligence. Institution and jurisdiction-specific reliance rules still need assessment.
Design for the exceptions
What can go wrong?
Stale screening reused
Separate persistent identity attributes from time-sensitive sanctions and risk checks.
Reliance responsibilities unclear
Document assurance, access to evidence and institution-specific acceptance with compliance owners.
Cross-platform identity correlation
Minimize disclosed attributes and evaluate correlation and consent risks.
When this is not the right fit
Do not promise one-time KYC for every product or jurisdiction. Reuse is unsuitable when the receiving institution cannot obtain required evidence or trust the assurance process.
A bounded first deployment
How should a team start?
Start with one workflow and named operational owners. A pilot should show that the process works through exceptions, not just that a transaction can succeed once.
- Choose one verified attribute and two cooperating institutions.
- Agree on evidence access, assurance and refresh responsibilities.
- Test expired credentials, sanctions changes and compromised wallet association.
- Review the evidence pack with the receiving compliance team.
What should the pilot measure?
- Onboarding completion time
- Repeat-document requests
- Expired evidence and screening exceptions
Set a baseline and acceptance thresholds before choosing technology. Include support effort and failed cases in the comparison, and validate the result with the teams that will operate it.
Procurement questions
What should you ask vendors?
- Which checks must be refreshed at every onboarding?
- Can our institution access the underlying evidence when required?
- Who is responsible if the originating identity check was wrong?
Request evidence from comparable workflows, a clear responsibility matrix, integration documentation and an export or exit plan. Confirm current capabilities directly rather than relying on a category listing.
Relevant vendor directories
Common questions
Does reusable identity mean permanent KYC approval?
No. Identity attributes and current screening have different lifecycles, and each institution must assess its own obligations.
Can a wallet address prove investor eligibility?
Not alone. Associate it with an approved identity and current product-specific eligibility through a controlled process.
Sources and further reading
Independent implementation guidance, not legal, investment or regulatory advice. Requirements depend on your product, jurisdiction and operating model.
Last updated