API-first KYC for South African fintech startups.
Use one VerifyNow API to check identity, face match, AML/PEP risk, bank accounts, companies and directors before you activate customers, merchants or payouts. Build faster without stitching together a dozen verification vendors.
In short: what VerifyNow does for a South African fintech
A defensible fintech onboarding workflow in South Africa can combine Home Affairs SA ID verification, Face Match and separate Passive Liveness, AML/PEP/sanctions screening, bank account verification, CIPC for business customers, and — depending on product risk — document authentication and consumer/person trace. The accountable institution owns its Risk Management & Compliance Programme and reporting to the FIC.
Available through VerifyNow: Home Affairs SA ID verification, Face Match, separate Passive Liveness, AML/PEP/sanctions screening, bank account verification (AVS), CIPC company and director verification, document authentication, consumer/person trace, phone trace and white-label API. A fintech can retain separate credit checks, SAPS criminal checks and qualification evidence in the same customer file when its policy requires them.
Who ships with VerifyNow
Fintech teams that need real-time, API-delivered KYC without a dozen vendor contracts or a six-month integration.
Neobanks & wallets
Onboard a retail customer with ID + face match + AML before the first transaction. SARB-supervised where e-money is issued.
Payment service providers
Onboard merchants and sub-merchants with CIPC + AVS + AML/PEP under PASA, SARB and FICA Schedule 1 obligations.
Lending platforms (NCR)
KYC the borrower with Home Affairs ID + AVS; obtain credit bureau data separately from a registered bureau for affordability.
E-money issuers
SARB-supervised EMIs pair VerifyNow KYC with their RMCP for wallet and prepaid-card issuance.
Open-banking aggregators
Resolve account holder identity against the account they are connecting via AVS and Home Affairs ID.
Embedded-finance APIs
Offer your partner a branded KYC step via the white-label VerifyNow API, one endpoint per verification primitive.
Six endpoints behind every onboarding
Each service is a single API call. Labelled by source so your compliance team can see what VerifyNow delivers and what must come from elsewhere.
Home Affairs SA ID Verification
Real-time HANIS-sourced identity verification returning name, date of birth, ID status and the Home Affairs photograph for downstream face match.
Face Match + Passive Liveness
Use Face Match to compare the selfie with the reference photo, and Passive Liveness as a separate live-presence signal.
Bank Account Verification (AVS)
Confirm account number, branch and holder details before a payout, debit-order or wallet top-up.
AML / PEP / Sanctions screening
Screen customers and directors against PEP and international sanctions lists at onboarding and on an ongoing basis.
CIPC Company & Director Verification
Resolve the business customer for KYB: registered name, status, registration number, directors and their AML screening.
Document Authentication
Authenticate ID documents (OCR + tamper detection) when customers submit passports or IDs as part of the onboarding flow.
Related evidence for the customer file
- • Credit bureau reports / affordability: obtained from a registered South African credit bureau under NCA Section 19(3) and the lender’s own affordability assessment.
- • SAPS criminal record clearance: obtained from SAPS or an authorised provider where your fit-and-proper or director-screening process requires it.
- • Qualification verification: obtained from the issuing institution or SAQA for FAIS representative fit-and-proper.
A real-time onboarding flow, end to end
One typical retail fintech sign-up, chained through the VerifyNow API from consent capture to activation.
- 01
Consent + ID collection at sign-up
Customer enters their SA ID and accepts a POPIA consent statement. The VerifyNow API records the consent reference against the verification job.
- 02
Real-time Home Affairs ID verification
The ID request returns the Home Affairs status, available name and date-of-birth fields, and the official photograph where returned. That photograph can become the reference for a separate Face Match.
- 03
Face Match + Passive Liveness
The customer captures one selfie. Passive Liveness assesses the capture, while Face Match separately compares it with the approved reference photo.
- 04
AML/PEP screening
Run a separate AML/PEP API request to screen the verified identity against supported PEP and international sanctions sources, then read the result directly or process its async webhook.
- 05
Bank account verification on first payout
Before the first outbound payment or payout, AVS confirms the customer's account holder name and ID number match the identity already verified.
- 06
Ongoing monitoring
Periodic AML re-screening picks up new sanctions and PEP list additions. Your RMCP defines the cadence; VerifyNow provides the hook.
FSCA, FICA, SARB, NCR and POPIA
South African fintechs operate under a stack of regulators: the FSCA (financial services licensing, including FAIS for advice and intermediary services), SARB (banking, national payment system, e-money), the NCR (credit providers), PASA (participation in the payment system), and the FIC (FICA / AML). Most fintechs are accountable institutions under FICA Schedule 1, which means they must run a board-approved RMCP (Section 42), perform CDD (Section 21), keep records (Sections 22–23), and file CTRs and STRs where required.
Crypto asset service providers were added to Schedule 1 as Item 22 in the 2022 FICA amendment, bringing them inside the same framework. Payment service providers and e-money issuers face additional SARB directives and the National Payment System Act. Credit providers must register with the NCR and, for affordability, pull credit bureau data from a registered bureau — not from VerifyNow.
Every verification flowing through VerifyNow is processed under POPIA-compliant consent. You remain the responsible party and the accountable institution; VerifyNow supplies the documented verification evidence your compliance and inspection defensibility relies on.
FICA workflow checklist for Fintech
Use this path for API-driven sign-up, step-up checks, payouts, business onboarding and ongoing screening.
Many fintech models are accountable institutions and need an RMCP-backed CDD process.
Practical onboarding sequence
- 1Confirm whether your business is a FICA accountable institution for this workflow.
- 2Identify the customer, counterparty or responsible person before the relationship starts.
- 3Verify identity using the right report and save the verification receipt.
- 4Risk-rate the person or entity and decide whether AML/PEP or enhanced due diligence is needed.
- 5Verify bank account ownership before deposits, payouts, refunds or settlements move.
- 6Keep a CDD record, consent/lawful-basis evidence, timestamp and transaction reference.
- 7Use the FICA Toolkit and RMCP generator where your business needs documented procedures.
Toolkit links
Need to screen a customer list?
If your organisation is an accountable institution, or your RMCP calls for a customer-book review, Batch AML lets you upload 10 to 1,000 people or entities and keep one consolidated result file. It is an optional workflow based on your duties and risk controls, not a requirement for every business in this industry.
Educational guidance only. Your accountable-institution status, RMCP, customer risk rating and lawful basis determine the final checks and records you must keep.
Fintech questions
Is a fintech a FICA accountable institution in South Africa?
Many fintech business models are accountable institutions under FICA Schedule 1 — payment service providers, money remitters, e-money issuers, crypto asset service providers (Item 22), and credit providers registered with the NCR. Accountable institutions must run a Risk Management & Compliance Programme (RMCP) under Section 42, perform CDD under Section 21, and keep records under Sections 22–23. VerifyNow supplies the verification primitives (Home Affairs ID, AVS, AML/PEP, CIPC, face match, document authentication) that your RMCP relies on — you remain the accountable institution.
Which VerifyNow checks support fintech onboarding?
VerifyNow supports fintech onboarding with Home Affairs SA ID Verification, Bank Account Verification, AML/PEP screening, CIPC company and director checks, Home Affairs Face Match, Passive Liveness, document authentication and Consumer Trace. Each check returns its own evidence and transaction reference so the fintech can apply its onboarding and review rules.
How fast is the API for real-time onboarding?
VerifyNow submits each selected verification request and returns its own status, reference and available source fields. Source response times vary, so a fintech onboarding flow should handle completed, pending, unavailable and review outcomes for Home Affairs ID, AVS, AML/PEP and CIPC checks.
Can VerifyNow support our FSCA licence application and RMCP documentation?
VerifyNow supplies documented verification evidence for the CDD controls described in your FSCA application and RMCP. Each completed check provides a transaction reference, result and audit record that your compliance team can attach to the customer file. Your appointed legal or compliance advisor defines the licence application, risk method and statutory reporting process.
How does VerifyNow handle POPIA for fintech onboarding?
Every verification is executed under an explicit POPIA-compliant consent capture — either through VerifyNow's consent collection flow or the fintech's own front-end with consent artefacts passed into the API. Only the data fields needed for the specific verification are processed, purpose-limited to your CDD obligations, and the audit log records who ran the check, when, and under which consent reference. You remain the responsible party under POPIA.
Does VerifyNow offer a white-label API?
Yes. The VerifyNow API can be white-labelled end-to-end — your own domain, branded verification UI for consent and selfie capture, and branded email receipts — so a customer onboarding into your fintech sees only your product. Each requested verification, including Face Match and separate Passive Liveness, returns its own result. See /white-label for the full scope.
Ship your KYC flow this sprint
Wire Home Affairs ID, face match, AML/PEP, AVS and CIPC into one API call. Free sandbox, with published credit rates from R2.99 to R2.69. Purchases above 10,000 credits use self-service EFT invoicing, with custom rates applied to assigned accounts.