By NHI Mgmt Group Editorial TeamBased on SumSub: “Belo taps Sumsub to ensure long-term compliance and maintain user trust during its rapid growth” (June 8, 2026)

TL;DR: User verification and KYC/AML compliance are central to a digital wallet expanding across Brazil, Argentina, and wider Latin America through its partnership with belo, according to SumSub. The real issue is not verification speed alone, but whether identity controls can keep pace with cross-border growth without weakening trust or fraud defences.


At a glance

What this is: This is a partnership update about SumSub and belo, with the key finding that LATAM fintech growth is pushing KYC and AML controls to work harder across cross-border wallet use.

Why it matters: It matters because IAM and risk teams in fintechs need identity controls that support growth, fraud prevention and compliance at the same time, especially when users, payment rails and jurisdictions expand together.


Context

LATAM fintech growth puts pressure on identity and financial crime controls because onboarding volume, cross-border usage and regulatory obligations all rise together. In practice, that means KYC and AML cannot be treated as a one-time gate at account creation; they have to remain consistent as customers move between countries, currencies and product flows.

The article centres on a digital wallet business that wants to expand across Brazil, Argentina and wider Latin America while maintaining trust with clients and partners. That makes identity assurance part of the operating model, not just a compliance checkpoint, because user verification quality directly affects fraud exposure, pass rates and market expansion.


Key questions

Q: How should fintech teams balance user onboarding speed with KYC and AML control?

A: Fintech teams should separate conversion metrics from control metrics. Fast onboarding is useful only if the programme can still explain who was verified, what evidence was accepted, and when exceptions were made. The right balance comes from policy-driven routing, documented escalation, and monitoring that continues after account opening.

Q: What breaks when FinTech identity verification only happens at onboarding?

A: Onboarding-only verification leaves the highest-risk actions unprotected, including recovery, payee changes, withdrawals, and instant transfers. Attackers can wait until the account is trusted, then use a legitimate session to redirect funds. The result is a control that proves identity once but fails when financial risk actually changes.

Q: How do teams know whether AI-assisted verification is actually helping?

A: Look for fewer manual exceptions, stable or lower fraud rates, and consistent approval outcomes across markets rather than just faster processing. If automation increases pass rates but also raises post-onboarding fraud or review noise, the control is shifting risk instead of reducing it.

Q: Who should own KYC and AML decisions when a fintech expands across multiple countries?

A: Ownership should sit with the compliance and risk functions, but the operating model has to involve product, operations and fraud teams as well. Cross-border expansion changes the customer evidence, regulatory expectations and exception patterns, so no single team can own the outcome in isolation.


Technical breakdown

KYC and AML as growth controls in cross-border fintech

KYC and AML in a multi-market fintech are not just regulatory paperwork. They are the controls that determine whether onboarding, payment activity and customer trust can scale together without creating a weak link between identity proofing and transaction monitoring. When a wallet spans crypto, stablecoin and fiat flows, the identity layer has to support jurisdictional variation, risk-based verification and ongoing monitoring rather than a single static onboarding decision.

Practical implication: treat identity verification as an operating control for expansion, not a front-door formality.

Why user pass rates matter to compliance design

User pass rates are often discussed as a conversion metric, but in regulated fintech they also reflect how well policy, document checks and risk scoring are tuned. If controls are too rigid, legitimate customers fail unnecessarily; if they are too loose, fraud and compliance risk rises. The balance matters most when a platform is moving into new LATAM markets where customer populations, document formats and risk patterns differ across borders.

Practical implication: tune verification rules by market and customer segment, then monitor false rejects and fraud leakage together.

AI-first verification changes the verification workload, not the obligation

AI-first identity verification can help process volume and spot anomalies faster, but it does not remove the need for accountable KYC and AML governance. The core obligation remains the same: know who the customer is, assess risk appropriately, and preserve auditability across the user lifecycle. Automation changes the speed and consistency of decisioning, while governance still has to define thresholds, exceptions and escalation paths.

Practical implication: use automation to increase consistency, but keep policy ownership and exception handling under human governance.


NHI Mgmt Group analysis

Cross-border fintech growth turns identity assurance into a market-entry control. In a wallet business that spans Brazil, Argentina and wider Latin America, identity verification is part of the mechanism that determines whether expansion can happen without raising fraud or compliance risk. The question is no longer whether onboarding works once, but whether the same control set stays defensible as products, users and jurisdictions multiply. Practitioners should treat KYC and AML coverage as a prerequisite for scalable market expansion.

Compliance-first growth is only credible when verification quality and customer experience move together. If verification is too strict, the business loses legitimate users and slows adoption. If it is too permissive, fraud pressure and remediation costs rise later. That trade-off is especially sharp for fintechs handling crypto, stablecoin and fiat flows, where the tolerance for identity uncertainty is lower and the audit burden is higher. Practitioners should design for balanced pass rates, not maximum approval volume.

AI-assisted verification does not replace governance, it shifts where governance must sit. The operational burden moves from manual review volume to policy calibration, exception management and evidence retention. That matters for any programme trying to support scale across multiple countries, because governance has to prove that automated decisioning remains explainable enough for compliance, risk and customer disputes. Practitioners should keep humans accountable for the policy, even when software handles the screening.

LATAM expansion exposes the limits of single-country identity assumptions. A control set built for one regulatory environment often breaks when document types, customer risk profiles and payment behaviours vary across borders. This is where KYC, AML and fraud prevention converge into one operating problem rather than three separate functions. Practitioners should plan for region-specific verification design instead of assuming one onboarding flow fits every market.

Long-term trust depends on treating verification as a lifecycle discipline. The article points to a model where compliance supports product innovation rather than blocking it, but that only works if the programme can sustain controls after onboarding. Identity governance for fintech has to extend beyond sign-up into monitoring, revalidation and escalation. Practitioners should evaluate whether their identity model still holds once customer growth becomes the dominant risk variable.

What this signals

Verification policy has to become regional, not generic. A single onboarding flow rarely survives expansion across multiple LATAM jurisdictions because document formats, risk profiles and customer behaviours differ. The practical shift is to build market-specific decisioning while keeping a common governance model for review, escalation and evidence retention.

Identity assurance is now part of fintech product design. When wallets combine crypto, stablecoin and fiat transfers, the verification layer directly affects adoption, fraud exposure and regulator confidence. Teams should design KYC and AML so they support growth rather than lagging behind it.


For practitioners

  • Map verification rules to each LATAM market Align document checks, risk scoring and exception handling to the jurisdictions where customers actually onboard and transact. Use local patterns in Brazil, Argentina and neighboring markets to tune false-reject thresholds and escalation paths.
  • Tie pass rates to fraud and compliance outcomes Review user pass rates together with fraud signals, manual review load and AML alerts so that higher conversion does not hide weaker assurance. Treat conversion alone as an incomplete control signal.
  • Separate policy ownership from automation Assign clear human ownership for verification thresholds, exception approval and audit evidence even when AI-assisted tools handle document analysis and screening at scale.
  • Extend identity governance beyond onboarding Add revalidation, monitoring and escalation checkpoints for users whose behaviour changes after account creation, especially in wallets that support crypto and fiat transfers across borders.

Key takeaways

  • LATAM fintech expansion makes identity assurance a core operating control, not a back-office compliance task.
  • The main risk is misalignment between growth ambitions, verification quality and cross-border regulatory expectations.
  • Teams should tune KYC and AML by market, monitor pass rates alongside fraud outcomes, and keep governance accountable for automated decisions.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while GDPR defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63SP 800-63A — Enrollment and Identity ProofingThe article centres on user verification and onboarding across a regulated fintech expansion.
Recommendation — Apply SP 800-63A principles to strengthen identity proofing and reduce false approvals across markets.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsIdentity decisions here shape who can access financial services and under what conditions.
GV.RM-01 — Risk Management StrategyThe partnership is framed around balancing growth, compliance and fraud risk.
Recommendation — Use PR.AA-05 to align verification outcomes with risk-based access and entitlement decisions. Set a risk management strategy that ties onboarding thresholds to business and regulatory exposure.
NIST SP 800-53 Rev 5IA-8 — Identification and Authentication (Non-Organizational Users)The wallet serves external users whose identities must be verified before service access.
Recommendation — Apply IA-8 to govern external-user identity proofing and authentication for customer onboarding.
GDPRArt.5 — Principles Relating to Processing of Personal DataCross-border user verification and data handling require lawful, proportionate personal-data processing.
Recommendation — Minimise personal data collection and retain only the evidence needed to satisfy verification and audit needs.

Key terms

  • KYC Compliance: KYC compliance is the set of controls used to verify a customer’s identity and assess whether onboarding meets legal and policy requirements. In practice, it includes collecting identity evidence, checking it against trusted sources, and retaining auditability. The control must be designed to match jurisdiction, risk level, and business model.
  • AML: Anti-Money Laundering is the broader control framework used to detect, prevent, and report financial crime across the customer lifecycle. It includes monitoring, screening, escalation, record-keeping, and reporting obligations. AML depends on reliable identity evidence at the start, then extends that evidence through ongoing oversight.
  • User Pass Rate: User pass rate is the share of applicants who successfully complete identity verification and move through onboarding. In regulated fintech, it is a control signal as much as a conversion metric, because it shows how well verification policy balances customer experience, fraud prevention and compliance.
  • Risk-Based Verification: A control approach that adjusts assurance strength to the context of the transaction, such as jurisdiction, wallet type, and value at stake. It avoids one-size-fits-all checks and lets firms apply stronger proof where the compliance and fraud risk is higher.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org