TL;DR: Reusable KYC can cut onboarding friction, with Noah reporting 63% faster user onboarding, 56% lower abandonment, and more than 220% year-on-year verification growth after its Sumsub integration. The compliance shift is not fewer controls but moving identity reuse under fresh screening, consent, and jurisdiction-aware risk assessment.
At a glance
What this is: This is a partnership analysis of Reusable KYC, where SumSub and Noah describe faster onboarding through consented identity reuse, fresh screening, and risk-based assessment.
Why it matters: It matters because compliance teams need to decide when reusable identity reduces friction without undermining KYC, sanctions screening, jurisdictional controls, or onboarding accountability.
By the numbers:
- Successful verifications for Noah's clients have increased by more than 220% year-on-year.
- Firms now onboard users, on average, 63% faster.
- Abandonment rates have fallen by 56%.
Context
Reusable KYC lets a verified identity profile be accepted again without forcing the user to repeat the full onboarding flow. In this article, SumSub and Noah position that reuse as a way to reduce friction for financial firms while keeping consent, screening, and risk assessment in place.
The governance question is whether identity portability can be controlled well enough to preserve regulatory confidence across multiple jurisdictions and use cases. For compliance teams, the issue is not whether to verify less, but how to govern when prior verification can be reused and when a fresh check is still required.
Key questions
Q: When should organisations allow reusable KYC instead of starting verification again?
A: Use reusable KYC when the prior verification is recent enough, the identity data is still valid, the user has consented to reuse, and local rules allow it. If jurisdiction, risk level, product type, or screening obligations differ materially, organisations should treat the onboarding as a fresh decision rather than a reuse case.
Q: Why do consent and fresh screening still matter if identity can be reused?
A: Consent protects the reuse of identity data, while fresh screening confirms the person still meets current sanctions, PEP, and risk requirements. Reuse can remove duplicate data capture, but it does not erase the receiving organisation's accountability for the current onboarding decision or its regulatory obligations.
Q: What breaks when reusable KYC is treated like a one-time approval?
A: The model breaks when prior verification becomes a standing assumption with no expiry or context check. That creates false confidence, especially across jurisdictions or higher-risk use cases. The receiving firm still needs a current decision, not just a historical verification record.
Q: How should compliance teams balance onboarding speed with regulatory oversight?
A: Treat speed as an outcome of better control design, not as a replacement for oversight. The right balance is to reuse verified identity only where policy permits, while preserving local screening, consent, and accountability for the final onboarding decision.
Technical breakdown
How reusable KYC changes the onboarding control point
Reusable KYC shifts the control point from repeated document collection to trust in a previously verified identity profile. Instead of treating every platform onboarding as a fully new proofing event, the receiving platform accepts validated identity data from a prior verification, then overlays its own screening and risk assessment. That changes the operating model from repeated capture to controlled reuse. The security and compliance challenge is that reuse only works when provenance, consent, and screening remain intact across the handoff. Without those guardrails, portability becomes friction reduction at the expense of assurance.
Practical implication: build reuse rules around verified provenance, not just around user convenience.
Why consent and fresh screening still matter in reusable identity
Reusable KYC does not replace compliance obligations. The article states that users must consent to profile reuse and that Noah still performs fresh sanctions and PEP screening at onboarding, even when identity data is reused. That matters because screening is not a one-time event, and jurisdictional expectations can change between verifications. Reuse may reduce duplicate collection, but it does not eliminate the need to confirm that the current onboarding context still meets local and risk-based requirements. The architecture only works when reuse and re-screening are treated as separate controls.
Practical implication: separate identity reuse logic from sanctions, PEP, and jurisdictional screening decisions.
How reusable KYC affects identity lifecycle governance
Reusable KYC creates an identity lifecycle problem, not just a user experience improvement. A verified identity profile becomes a portable asset that can travel across institutions, products, and markets, which means governance must cover issuance, reuse, revocation, and the point at which prior trust expires. This is closer to lifecycle management than simple onboarding automation. If organisations do not define when a reused profile remains acceptable, they risk turning prior verification into a standing assumption. The article points to a model where trusted identity is reused only under active governance, not left to drift between platforms.
Practical implication: treat reusable identity as a governed lifecycle object with explicit reuse and expiry rules.
Breaches seen in the wild
- Coupang Signing Key Breach: Unrevoked signing key credentials expose 33.7 million records after employee offboarding failure at Coupang.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Reusable KYC is really lifecycle governance for portable identity. The core change is not faster onboarding alone, but the creation of an identity object that can be carried across firms, platforms, and jurisdictions. That makes consent, provenance, and reuse scope first-class governance controls rather than administrative details. Practitioners should treat reusable identity as a governed lifecycle state, not a one-time verification outcome.
Identity reuse does not remove the need for fresh risk decisions. The article is explicit that sanctions and PEP screening still occur at onboarding, even when prior verification exists. That separation matters because a verified profile can be acceptable while the current onboarding context is not. Compliance teams should preserve the distinction between identity proofing history and present-day screening obligations.
The named concept here is reusable trust inheritance. A previously verified identity profile inherits enough trust to reduce friction, but that trust is still conditional on consent, jurisdiction, and current risk appetite. That is a useful concept because it explains why reuse is not a shortcut around compliance but a controlled transfer of assurance. Practitioners should map where inherited trust ends and local obligation begins.
This model accelerates scale, but it also concentrates governance responsibility. As onboarding becomes faster and more portable, the decision to accept a reused identity profile becomes more consequential. The receiving organisation is still accountable for the onboarding outcome, even if part of the identity evidence came from elsewhere. Practitioners should reassess where responsibility sits when verification is shared across ecosystems.
What this signals
Reusable trust inheritance: the useful way to think about this model is that trust can move, but only inside explicit governance boundaries. That means the receiving organisation must still decide how far prior verification can travel before it needs new evidence or a fresh policy check.
For compliance programmes, reusable KYC shifts the highest-value work from repeated collection to reuse policy design. The practical question is no longer whether to verify identity, but when a previously verified profile remains acceptable, where jurisdiction changes override reuse, and how consent is recorded.
This also changes how teams think about onboarding metrics. Faster verification is only a positive signal if screening, accountability, and identity provenance remain intact at the point of reuse.
For practitioners
- Define reusable identity acceptance rules Specify when a prior verification can be reused, which jurisdictions it applies to, and which product lines require a fresh check regardless of prior status.
- Separate reuse from screening controls Keep consented profile reuse distinct from sanctions, PEP, and risk-based screening so one control cannot silently substitute for another.
- Document profile provenance and consent Record where the verified identity came from, when the user consented to reuse, and when that consent or verification state expires.
- Set jurisdiction-specific reuse thresholds Use local regulatory requirements to decide when reusable KYC is acceptable and when onboarding must restart with new evidence.
Key takeaways
- Reusable KYC reduces friction by letting verified identity data travel across platforms, but the governance burden does not disappear.
- The article pairs faster onboarding with continued sanctions and PEP screening, showing that reuse and compliance are separate controls.
- Compliance teams should define when identity reuse is allowed, when a fresh check is required, and how consent and provenance are recorded.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack surface, NIST CSF 2.0 and NIST SP 800-63 set the technical controls, and PCI DSS v4.0 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Reuse rules need explicit expiry, otherwise prior identity trust persists too long. |
| NHI-09 — NHI Reuse | This article is centered on identity reuse across institutions and onboarding flows. | |
| Recommendation — Define reuse expiry and revoke acceptance when prior identity assurance is no longer valid. Limit profile reuse to approved contexts and document when prior verification may be reused. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article concerns who can be accepted into a service after identity and screening checks. |
| Recommendation — Align onboarding acceptance rules with explicit authorization criteria for reusable identity. | ||
| NIST SP 800-63 | SP 800-63A — Enrollment and Identity Proofing | Reusable KYC depends on how previously proofed identity evidence is accepted and reused. |
| Recommendation — Apply enrollment and proofing rules to decide when prior identity evidence can be accepted again. | ||
| PCI DSS v4.0 | 3.2.1 — Sensitive Authentication Data not stored after authorization | The article touches regulated financial onboarding, but not PCI-specific storage controls. |
| Recommendation — Ensure payment onboarding workflows do not retain identity evidence beyond required use. | ||
Key terms
- Embedded KYC: Embedded KYC is the practice of placing customer identity verification directly inside the onboarding workflow instead of managing it as a separate process. In regulated environments, it creates a single control path for identity proofing, sanctions screening, and audit evidence, which can improve consistency if governance is clear.
- Identity Provenance: Identity provenance is the record of how an agent was created, what authority it received, and what actions it performed over time. It turns agent activity into an auditable chain of trust that supports compliance, incident response, and post-event accountability.
- Risk-based assessment model: A risk-based assessment model evaluates security posture by tying controls to actual exposure, business criticality, and operational consequences. In identity governance, it is stronger than static maturity scoring because it can account for changing access patterns, third-party relationships, and privileged accounts that create real business risk.
- Consent-based reuse: Permission from the user to let verified identity data be used again by another platform or service. In practice, consent is a governance control over portability, making reuse conditional rather than assumed and limiting how far a verified profile can travel.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org