TL;DR: Compliance is shifting from a separate control layer to a platform-native governance requirement that teams cannot treat as optional, according to Sumsub. Monavate’s integration of Sumsub verification into its API-driven onboarding flow embeds KYC, liveness checks, sanctions screening, and ongoing monitoring directly into regulated payments operations, with support for more than 220 countries and territories and 14,000 document types.
At a glance
What this is: This is a partnership analysis showing how Monavate has embedded SumSub verification into onboarding so KYC, screening, and monitoring run natively inside the payments flow.
Why it matters: It matters because compliance teams can no longer treat identity verification as a separate utility; in regulated onboarding, governance, auditability, and operational ownership now sit inside the platform design.
By the numbers:
- SumSub says its 2025-2026 Identity Fraud Report found an 180% YoY increase in sophisticated fraud attempts.
Context
Embedded KYC means identity checks are performed inside the onboarding workflow rather than in a separate control layer. In regulated payments, that changes who owns the control, how it is audited, and whether compliance is native to the platform or bolted on later.
The article centres on Monavate’s API-driven onboarding flow and the compliance obligations that come with regulated issuance. For payments and identity teams, the key issue is not only what checks are available, but whether the operating model preserves regulatory accountability across jurisdictions and programme managers.
Key questions
Q: How should payments teams govern KYC when it is embedded in an onboarding platform?
A: They should treat embedded KYC as part of the regulated identity control plane, not as a separate vendor feature. That means defining ownership for verification decisions, preserving audit evidence, and ensuring exceptions are reviewable. The control must be consistent across programmes, jurisdictions, and customer types, or compliance becomes fragmented and hard to defend.
Q: Why does embedding verification in onboarding reduce compliance risk?
A: It reduces hand-offs and removes the gap between customer admission and identity verification, which is where many compliance failures start. When screening, liveness, and monitoring sit in the same workflow, the organisation can apply one standard consistently and retain evidence of each decision. The trade-off is that the platform must be designed for auditability from the start.
Q: What are the signs that embedded KYC is failing in a payments programme?
A: Common signals include inconsistent approval outcomes across programmes, missing decision logs, delayed sanctions updates, and repeated applicants slipping through deduplication. If programme managers cannot reconstruct how a customer was admitted, the embedded control is not functioning as a governed process. That is an auditability failure, not just an operational glitch.
Q: Why do synthetic identities and social engineering make customer service workflows harder to secure?
A: Synthetic identities, doctored media, voice spoofing, and persuasive social engineering make service interactions harder to trust because agents can no longer rely on a single proof point. Organisations need a network view of identity, behavioural signals, and risk scoring to identify repeat abuse patterns, especially when requests look legitimate but are part of coordinated fraud.
Technical breakdown
How embedded KYC changes the control boundary
When KYC is embedded, the identity verification engine becomes part of the transaction journey rather than an external review step. That matters because programme managers no longer orchestrate separate infrastructure, intermediate queues, or hand-offs between systems. The control boundary moves into the platform’s onboarding API, where document checks, liveness, sanctions screening, and monitoring can be enforced consistently. In governance terms, the important question is no longer whether a check exists somewhere in the stack, but whether it is natively bound to the regulated workflow and logged as part of the platform record.
Practical implication: Treat the onboarding flow itself as the control surface and verify that every identity check is enforced at the same point in every programme.
Why ongoing monitoring belongs with onboarding, not after it
KYC is not a one-time gate when regulators expect ongoing monitoring as part of the customer relationship. In the model described here, PEP and sanctions screening, adverse media review, and deduplication extend the control past initial verification into continuous due diligence. That is important because fraud and risk do not stop at account creation. Once onboarding and monitoring are separated, organisations tend to lose consistency, create audit gaps, and weaken their ability to prove that the same identity standard is applied throughout the lifecycle.
Practical implication: Align onboarding and ongoing monitoring under one governance owner so the same identity record drives both entry and post-entry review.
API-driven onboarding needs auditability by design
An API-driven onboarding flow can simplify operations, but it also concentrates trust in the orchestration layer. If the verification process is opaque, the organisation may satisfy functional onboarding while failing to demonstrate who approved what, on which evidence, and under which jurisdictional rule set. Embedded controls only help if they produce traceable outcomes that regulators and internal reviewers can reconstruct later. That is the real governance shift: the platform must not only verify identities, it must prove that verification happened within a controlled and reviewable process.
Practical implication: Demand event-level evidence, decision logs, and jurisdiction-aware reporting for each onboarding outcome.
Threat narrative
Attacker objective: The objective is to obtain legitimate-looking access to payments infrastructure by defeating identity verification and onboarding controls.
- Entry begins at regulated onboarding, where attackers target the customer acquisition flow rather than a downstream payment credential. Stronger onboarding controls push fraudsters toward identity manipulation techniques.
- Credential harvesting and identity abuse then shift into synthetic identities, social engineering, and device manipulation, which SumSub links to its 180% YoY increase in sophisticated fraud attempts.
- If those checks are weak or decoupled, the attacker reaches account creation and programme access with an apparently valid identity record, enabling abuse of the payments rail.
- The impact is fraudulent access to regulated financial infrastructure and weaker confidence that onboarding decisions satisfy the compliance obligations attached to the programme.
Breaches seen in the wild
- Spain's first AI agent data breach 2026: Spain's AEPD logged its first breach notification attributed to an attacker's AI agent, which altered personal data and accessed invoices.
- Coupang Signing Key Breach: Unrevoked signing key credentials expose 33.7 million records after employee offboarding failure at Coupang.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Embedded KYC is a governance model, not a feature integration. Once verification runs inside the onboarding flow, the control is no longer a standalone service that downstream teams can opt into or out of. It becomes part of regulated operating responsibility, which means accountability, audit evidence, and workflow design all move closer to the platform layer. Programme managers should therefore evaluate embedded KYC as a governance architecture decision, not a procurement convenience.
Compliance by API only works when the platform can prove control placement. Embedding verification inside a customer journey is only useful if the organisation can show where decisions were made and under which rule set. That shifts emphasis from feature availability to traceable control execution, especially in multi-jurisdiction onboarding. The real standard is whether the platform can sustain regulator-grade evidence across every customer path, not whether the check exists in theory.
Fraud pressure is pushing compliance into the same layer as revenue acquisition. As onboarding controls tighten, attackers adapt by shifting toward synthetic identities, social engineering, and device manipulation. That means identity governance is increasingly inseparable from product design in payments. Teams that still treat verification as a separate compliance stack will continue to understate how quickly fraud adapts to the shape of the onboarding journey.
Global onboarding demands a single identity standard with local accountability. Support for multiple countries, document types, and screening checks only matters if the underlying decision model remains consistent enough to defend. The strategic challenge is not just geographic coverage, but whether local regulatory expectations can be mapped into one auditable workflow. Practitioners should assess whether their onboarding model can scale without fragmenting governance across markets.
From our research library:
- Gartner predicts that by 2026, 30% of enterprises will consider identity verification solutions unreliable in isolation because of AI-driven attacks.
What this signals
Embedded KYC changes where governance lives: for regulated payments, identity verification no longer sits beside the platform as a supporting service. It sits inside the platform’s operating model, which means programme managers and compliance leads should review the onboarding flow as an auditable control boundary, not just a user journey.
Fraud now pressures the onboarding layer directly: the article’s own fraud reference shows why compliance teams cannot assume the old separation between identity verification and payment execution still holds. Synthetic identities and social engineering are now part of the onboarding threat model, so control design has to anticipate that pressure before account creation succeeds.
For practitioners
- Define the control boundary inside onboarding Map each KYC, liveness, screening, and monitoring step to the point where the customer is admitted into the programme. If the step sits outside the regulated flow, treat it as a governance gap.
- Unify onboarding and ongoing monitoring Use one identity record and one owner for initial verification, PEP and sanctions monitoring, and adverse media review so the lifecycle does not split across teams or tools.
- Require audit evidence at decision time Insist on immutable logs that show what was checked, what rule fired, and what jurisdiction applied before the customer could proceed.
- Test fraud controls against synthetic identity pressure Rehearse how the onboarding flow handles synthetic identities, social engineering, and device manipulation, because the article shows these attacks are already increasing.
- Review cross-jurisdiction consistency Check that the same onboarding control outcomes can be defended across the UK, the EEA, and any additional markets you support, even when document and sanctions rules differ.
Key takeaways
- Embedded KYC turns onboarding into a governed compliance boundary instead of a separate verification step.
- The article links the shift to rising fraud pressure, including sophisticated identity abuse that is harder to detect once it reaches the payments flow.
- Practitioners should align ownership, monitoring, and audit evidence around the onboarding workflow itself, not around disconnected identity tools.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, NIST CSF 2.0 and NIST SP 800-63 set the technical controls, while SOC 2 (AICPA) and GDPR define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Embedded verification depends on managing identity proofing and ongoing credential evidence. |
| Recommendation — Apply IA-5 to govern lifecycle handling of authentication evidence and verification artifacts. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is about who is admitted into a regulated payment programme and under what authorization. |
| Recommendation — Map onboarding decisions to PR.AA-05 so identity admission is consistently authorized and auditable. | ||
| NIST SP 800-63 | SP 800-63A — Enrollment and Identity Proofing | The source focuses on KYC, document verification, and identity proofing in onboarding. |
| Recommendation — Use SP 800-63A to structure identity proofing evidence before account admission. | ||
| SOC 2 (AICPA) | CC6.1 — Logical and Physical Access Controls | Embedded compliance depends on demonstrable access and admission controls within the service workflow. |
| Recommendation — Document CC6.1 evidence for how onboarding access and admission controls are enforced inside the platform. | ||
| GDPR | Art.32 — Security of Processing | Identity verification and monitoring in onboarding process personal data across jurisdictions. |
| Recommendation — Apply Art.32 safeguards to keep onboarding verification and monitoring secure, auditable, and appropriately protected. | ||
Key terms
- Embedded KYC: Embedded KYC is the practice of placing customer identity verification directly inside the onboarding workflow instead of managing it as a separate process. In regulated environments, it creates a single control path for identity proofing, sanctions screening, and audit evidence, which can improve consistency if governance is clear.
- Continuous Monitoring: Continuous Monitoring is the ongoing evaluation of access, activity, and control state rather than a periodic snapshot. In practice, it helps teams spot privilege drift, conflicting transactions, and configuration changes before they become audit findings or operational losses.
- Identity proofing: The process of verifying that a person is who they claim to be before granting or restoring access. In higher-risk recovery paths, proofing can include stronger evidence checks such as government ID validation or liveness-based facial verification so the assurance level matches the sensitivity of the request.
- Auditability: Auditability is the ability to reconstruct who or what acted, what permissions were used, and what data or tools were touched. For AI and NHI governance, it is the minimum evidence needed to investigate incidents, validate controls, and prove that autonomous actions stayed within approved scope.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org