Identity checks · How it works

The Vendor Chain Behind an Identity Check

You upload a document and wait for a verdict, and it is natural to assume the platform produced it. Often the decision happened somewhere else entirely — at a company with its own retention period, its own regional coverage, and its own memory of you.

Independent guide · Not affiliated with any platform · Not investment advice

Article cover: ink-blue document page layout titled The Vendor Chain, subtitled who is on it, beside a vermilion-and-gold round stamp reading HOW IT WORKS
You upload a document and wait. The verdict usually comes from a company whose name you were never told.

After a rejection the two standard reactions are “this platform is broken” and “something is wrong with my document”. Either can be true, and both skip the layer in the middle.

A verification typically passes through three stages:

  1. The platform decides what must be checked, where the threshold sits, and whether you are let through;
  2. A verification vendor receives your document and face, judges document authenticity, matches face to photo, runs the liveness check, and returns a result or a score;
  3. Data sources and screening lists answer a different class of question: sanctions exposure, whether an address reconciles with public records.

The interface only ever shows you the first. The second rarely introduces itself — and it is the one that most often decides the outcome.

None of this is a grey area. Directive (EU) 2015/849 has a section titled “Performance by third parties”. Article 25 is two sentences, and the second is the one that matters:

Member States may permit obliged entities to rely on third parties to meet the customer due diligence requirements laid down in points (a), (b) and (c) of the first subparagraph of Article 13(1). However, the ultimate responsibility for meeting those requirements shall remain with the obliged entity which relies on the third party.

That sentence has a practical use: when an outcome is unreasonable, your counterparty is the platform, never the vendor whose name you were never told. “A third party made that call, there is nothing we can do” is not a position the regulation supports.

Article 26 also gates who may occupy this layer: such third parties must apply customer due diligence and record-keeping requirements consistent with the directive and be supervised accordingly, and reliance on third parties established in high-risk third countries is prohibited.

You have already agreed to this

It is not hidden, merely filed where nobody reads. Clause 7.3 of Binance's terms of use has you authorise it to make whatever enquiries it considers necessary directly or through third parties to verify your identity and protect against fraud, money laundering, terrorist financing and other financial crime; and to acknowledge that in doing so your personal data may be disclosed to identity verification, compliance data recording, credit reference, fraud prevention or financial crime agencies, and that those agencies may respond to its enquiries in full.

Three facts in one clause: the outsourcing is authorised; the recipient is a category of agency rather than one named company; and the flow is bidirectional — they do not just receive, they answer questions about you.

Who is actually on this layer

Most platforms never publish their vendors, so “which ones” is usually unanswerable. A few do, and those lists show what the layer looks like.

Coinbase maintains a public page naming the identity verification vendors it may use. On the day we read it the page showed a last-updated date of 9 December 2025 and named Jumio, Onfido, Au10tix, Shufti, Refinitiv, Unico and Persona, with a line on what each does. Its opening sentence describes the layer's job bluntly: your information is shared with these services to prevent fraud, allowing identity to be confirmed by comparing what you provide against public records and other third party databases.

We cite it because published vendor lists are rare, not as an endorsement or assessment of that platform — and nothing about it can be extrapolated to who any other platform uses.

One vendor name does surface inside a flow: in the onboarding update for users moving to Binance's locally licensed UAE entity, one route for address verification is to link your bank account via Lean.

A sense of scale

This is not a market of three or four firms. NIST's September 2023 evaluation, NIST IR 8491, tested 82 passive, software-only algorithms from 45 developers — and that covers face presentation attack detection alone, not document authentication, list screening or address checks. Which one you met is generally unknowable.

The counterintuitive part: it remembers you

If this layer merely ran a procedure on request, moving to another platform would be a blank slate. It is not.

In that same vendor list, the entries for Onfido, Au10tix and Refinitiv each say the same thing: facial scan data may be used to determine whether that vendor has previously verified your identity on the platform's behalf.

The middle layer keeps records across attempts. It is not a machine that resets each time; it has a history of you. (Whether that history also spans different platforms is not something the page states, and we do not infer it.) Which is another reason the same document set can produce very different outcomes in different places — you may be meeting one vendor's second look, or another vendor's first.

The same page states that biometric information handled by Persona is stored for no more than three years. That period and the platform's own anti-money-laundering retention are two independent clocks; neither subsumes the other. How many copies of your data sit where, and for how long, is covered separately in where your identity documents actually go.

Three familiar situations, re-explained

What changes when the vendor layer is in the picture
What you sawThe usual self-diagnosisAn equally consistent explanation
Passed on A, failed on B“B is stricter”Different vendors and different technical approaches, plus separately set thresholds — the two are not comparable
Same platform, you passed and a friend did not“My document is better”Vendors can be assigned by region. On the published list, Unico is stated to be for Brazil users
Fine last year, stuck this year“My account is flagged”The platform changed vendor or version. Such changes are not usually announced, and need not be

This is not reassurance; it is about not spending effort on a wrong premise. The third row especially — reading a process change as an account problem tends to trigger a chain of unnecessary moves.

What changes once you know

  1. Escalate to the platform, always. Article 25 is the reason: ultimate responsibility does not travel with the outsourcing. There is no point chasing the vendor, and usually no way to.
  2. “Try a different platform” is not superstition, but it is not a plan either. Different vendors genuinely return different results, but you cannot steer that, and it is no reason to keep resubmitting — attempt counts are limited in many flows.
  3. The input is still the only thing you control. Image quality, document legibility, form fields matching the document exactly. The mechanics are in what a liveness check is actually testing; the field-level traps are in entering your name exactly as your ID shows it.
  4. Never hand material to anyone outside this chain. You cannot choose the vendor, but you can guarantee the file only travels through official channels. Anyone claiming inside access, or offering to submit on your behalf, is opening a route that sits outside it entirely.
What we cannot look up, and will not guess

Which vendor a platform uses in a given region, where its thresholds sit, what drove a particular decision — none of that is published. Clause 20.2(b) of Binance's terms states outright that it is under no obligation to disclose details of its risk management and security procedures. So this article describes the structure of the chain only. It makes no claim about any platform's configuration and offers no technique for working around any vendor.

What this article is based on

Reliance on third parties and the retention of ultimate responsibility come from Article 25 of the consolidated Directive (EU) 2015/849 (EUR-Lex, version of 9 July 2024); the eligibility conditions for such third parties and the high-risk third country prohibition are Article 26. Read on 2 September 2026.

The authorisation to enquire “directly or through third parties” and the categories of recipient are clause 7.3 of Binance's terms of use; the absence of any obligation to disclose risk management and security procedures is clause 20.2(b). The Lean bank-linking route for address verification comes from the same help centre's page on updating verification for the transition to its UAE entity (update date 2025-12-19, English only).

The vendor list, per-vendor roles, Persona's three-year biometric retention, the Brazil-only note on Unico and the statements about recognising a previously verified face come from Coinbase's published third-party identity verification vendors page (last updated 9 December 2025 as displayed). We cite it because such disclosure is rare, not as an endorsement, and it supports no inference about any other platform's vendors. The 45 developers / 82 algorithms figure is from NIST IR 8491 (September 2023).

While writing this we did not log into any account, did not submit any verification, and had no contact with any vendor. Nothing here asserts which vendor any platform uses in any region beyond what the disclosure page states about itself, quotes approval rates, or describes any vendor's internal decision logic.

Questions people actually ask

Is a person at the platform looking at my document?

Frequently not. Directive (EU) 2015/849 has a section on performance by third parties, and Article 25 permits obliged entities to rely on third parties to meet customer due diligence requirements. Platform terms usually carry the matching authorisation: clause 7.3 of Binance's terms has you authorise enquiries made directly or through third parties, and acknowledges that your personal data may be disclosed to identity verification, compliance data recording, credit reference, fraud prevention or financial crime agencies, which may respond to those enquiries in full.

If a third party made the decision, who do I take it up with?

The platform. Article 25 of Directive (EU) 2015/849, immediately after permitting reliance on third parties, states that ultimate responsibility for meeting those requirements remains with the obliged entity relying on them. Responsibility does not travel with the outsourcing, so “a third party decided, nothing we can do” is not a position the regulation supports. Practically you also have no route to the vendor, since most platforms never name it.

Why does the same document pass in one place and fail in another?

Quite possibly because it was not the same system judging. Platforms use different vendors and different technical approaches and set their own thresholds; a single platform may also assign vendors by region — on Coinbase's published vendor page, Unico is stated to be used for Brazil users. Platforms also change vendor or version without announcing it, so “fine last year, stuck this year” can simply mean the process changed rather than that anything is wrong with your account.

Is switching platforms a clean slate?

Not entirely. In Coinbase's published vendor descriptions, the entries for Onfido, Au10tix and Refinitiv each state that facial scan data may be used to determine whether that vendor has previously verified your identity on the platform's behalf. So the middle layer retains records across attempts rather than resetting each time. Whether you would meet the same vendor is something we cannot determine and do not speculate about.

Can I ask which vendor was used, or why I was rejected?

Usually not. That configuration is not published, and clause 20.2(b) of Binance's terms states it is under no obligation to disclose details of its risk management and security procedures. What remains in your control is the input: image quality, document legibility, and form fields matching the document character for character. This site offers no vendor-specific workarounds.

Sources

Legal text (read 2 September 2026): reliance on third parties and the retention of ultimate responsibility are in Article 25 of the consolidated Directive (EU) 2015/849; the conditions on such third parties are Article 26 of the same text.

Platform terms and flow (read 2 September 2026): clauses 7.3 and 20.2(b) are in Binance’s terms of use; the Lean bank-linking route is in its help centre page on updating verification for the UAE entity transition (update date 2025-12-19, English only).

Vendor side and scale (read 2 September 2026): the vendor list, roles, retention and regional assignment are in Coinbase: Third Party Identity Verification Service Vendors (last updated 9 December 2025). The 45 developers / 82 algorithms figure is from NIST IR 8491 (September 2023).

Splitting the chain into platform / vendor / data source, and the alternative explanations in the table, are this site's synthesis of the material above and represent no institution's or platform's position.

KYC Lane EditorialIndependent guide · not BinanceFees and limits as shown on the platformCorrections [email protected]