The NeuroVision platform supports on-premises, on-cloud and hybrid deployment models to meet localization and environment isolation requirements. Biometric data can be stored within the country, while access control and action logging are implemented through blockchain registries. This architecture simplifies building a verifiable audit trail for KYC operations without combining biometrics and application-form data in a single storage.
What personal data is processed in KYC and why its protection is critical
KYC (Know Your Customer) procedures work with an array of personal information whose leakage can cause critical damage to both the customer and the business.
In 2024, the volume of stolen personal data in Russia grew by 37% compared with the previous year, while the average cost of recovery after an incident exceeded 12 million rubles. Every third leak is connected specifically with the processes of customer identification and verification.
KYC systems process information sufficient for the full digital identification of a person. This creates an attractive target for attackers: having gained access to a KYC database, fraudsters can take out loans, open accounts, and make deals in the victim’s name. The reputational risks for a company from a KYC data leak often exceed the direct financial losses — restoring customer trust takes years.
Modern legislation imposes strict requirements on the protection of personal data in KYC. Fines for violating Federal Law 152-FZ reach 18 million rubles for legal entities, and non-compliance with the requirements of Federal Law 115-FZ entails the revocation of a financial organization’s license. In 2024, Roskomnadzor initiated more than 4,500 inspections of personal data operators, identifying violations in 62% of cases.
The main categories of personal data in KYC (application form, documents, contact details)
| Category | Description |
|---|---|
| Application-form data | Form the basic customer profile in the KYC system. This includes full name, date and place of birth, registered and actual residential address, INN, SNILS. Financial organizations additionally collect information about income, sources of funds, and beneficial owners. This data makes it possible to unambiguously identify an individual and check them against government databases and sanctions lists. |
| Document verification | Requires processing copies of a passport, driver’s license, international passport, and legal entity registration certificates for entrepreneurs. Modern KYC platforms recognize more than 10,000 document types from over 200 countries. At the same time, the systems extract not only text data but also analyze security features, holograms, microtext, and machine-readable zones to detect forgeries. |
| Contact information | Includes phone numbers, email addresses, messengers, and social network profiles. This data is used for two-factor authentication, sending transaction notifications, and conducting additional checks for suspicious operations. A leak of contact data opens the way for social engineering and targeted phishing. |
| Additional data categories | Depend on the industry and the customer’s risk level. Banks may request income statements, account statements from other organizations, and credit history information. Crypto exchanges record IP addresses, device data, and transaction history on the blockchain. Marketplaces retain purchase history and payment details. |
On the NeuroVision platform, the IDP / AI-OCR module supports 10,000+ document types from 200+ countries and 90+ languages. The pipeline includes detecting the document in the frame, automatically determining its type, correcting rotation/distortion, image quality control (glare, cropped fields, sufficient resolution), and MRZ verification with checksums. Integrity and forgery-sign checks are available (tampering, printout, photo of a screen, photocopy), as well as OCR of printed and handwritten text for Russian passports. Document recognition time — < 1 second, document recognition accuracy — 99.85%.
Biometric data in KYC (face recognition, voice, behavior)
Has become the standard of modern KYC processes. Face recognition technologies have reached an accuracy of 99.9% with a false-acceptance rate of less than one in a million comparisons. Modern algorithms are robust to the presence of glasses or a mask.
Analyzes more than 100 speech parameters: timbre, frequency characteristics, pronunciation features, speech rate. The technology makes it possible to identify a person from a phrase 3-5 seconds long with 98% accuracy. Voice prints are used in banks’ contact centers for fast authentication without the need to state passwords or code words.
Tracks the unique patterns of a person’s interaction with devices. The systems analyze the speed and rhythm of typing, the pressure of taps on a smartphone screen, the cursor movement trajectory, and the tilt angle of the device during use. This data forms a behavioral profile that is virtually impossible to forge or copy.
The liveness check has become a mandatory element of biometric verification. The technologies determine the “live” presence of a person in front of the camera, protecting against the use of photos, video recordings, masks, deepfake. The algorithms analyze micro-movements of the eyes, blood pulsation in the capillaries, the three-dimensional structure of the face, and the reaction to the system’s random commands.
In the NeuroVision system, the IDP Liveness module performs active liveness-check scenarios: randomized head turns and moving the head in a circle. Additionally, the absence of extraneous faces in the frame is monitored, and attempts to present a photo, video, masks and deepfake are blocked. The accuracy of liveness/anti-spoofing for attacks with masks, photos and deepfake — up to 99.9%.
Biometric data belongs to a special category of personal data under Federal Law 152-FZ. Its processing requires separate written consent from the subject, the use of certified cryptographic protection tools, and compliance with localization requirements within the Russian Federation. The Unified Biometric System (UBS) sets additional standards for financial organizations working with the biometrics of Russian citizens.
Protecting biometric data is critically important because of its immutability — a person cannot “change” their face or voice like a password. A leak of biometric templates creates lifelong risks for a person, making them vulnerable to the most sophisticated types of fraud and identity forgery.
What legal requirements regulate the protection of personal data in KYC (Federal Law 152-FZ and related laws)
KYC procedures in Russia operate at the intersection of several legal domains, where each law sets its own requirements for the processing and protection of personal data. Central to this is Federal Law No. 152-FZ “On Personal Data”, which defines the basic principles of working with citizens’ personal information. Alongside it, there is specialized regulation through Federal Law 115-FZ “On Countering the Legalization of Proceeds” and the sectoral regulations of the Bank of Russia, FSTEC and Roskomnadzor.
The complexity of the legal regulation creates a multi-level system of requirements: from general principles of personal data protection to specific rules for financial identification and biometric verification. Companies have to simultaneously comply with personal data protection requirements, fulfill customer identification obligations, and ensure the technical security of all processes.
Legal grounds for processing data in KYC and the connection with Federal Law 152-FZ and 115-FZ
The processing of personal data within KYC relies on specific legal grounds provided for in Article 6 of Federal Law 152-FZ. The main ground is the fulfillment of the requirements of a federal law — in this case Federal Law 115-FZ, which directly obliges organizations to identify customers when establishing business relations. This obligation extends to banks, payment systems, telecom operators, marketplaces and other entities listed in the law.
Federal Law 115-FZ establishes the minimum volume of data for identification: surname, first name, patronymic, date of birth, details of the identity document, migration card data for foreigners, and INN if available.
With simplified identification through the Unified Biometric System, the list may be reduced. An organization is not entitled to require excessive data not provided for by the anti-money laundering legislation.
Customer consent to the processing of personal data for the purpose of fulfilling the requirements of Federal Law 115-FZ is not required — this follows directly from clause 2 of part 1 of Article 6 of Federal Law 152-FZ. However, if an organization plans to use the collected data for additional purposes (marketing, analytics, scoring), separate consent must be obtained specifying these purposes. Mixing mandatory identification and voluntary data processing often becomes a cause of violations and fines from Roskomnadzor.
An important nuance concerns retention periods: Federal Law 115-FZ requires storing identification data and documents for at least five years from the day the business relationship ends, whereas Federal Law 152-FZ prescribes destroying personal data after the processing purposes are achieved. The special rule of Federal Law 115-FZ takes priority, but after the five-year period expires, the data must be destroyed in accordance with the requirements of personal data legislation.
The roles of the operator, the entrusted party and the KYC provider in processing personal data
The distribution of roles and responsibilities among the participants in the KYC process is critically important for complying with the requirements of Federal Law 152-FZ. The personal data operator is the organization that determines the purposes and content of the processing — as a rule, this is a bank, a fintech company or a marketplace obliged to identify customers. It is the operator that bears the main responsibility before the regulator and the personal data subjects.
Article 6 of Federal Law 152-FZ allows the operator to entrust processing to a third party, but only if certain conditions are met. A contract or supplementary agreement must be concluded between the operator and the provider containing mandatory conditions: a list of actions with personal data, the purposes of processing, the obligation to maintain confidentiality and ensure data security, and requirements for personal data protection.
At the same time, the provider must ensure a level of protection no lower than that established by Decree of the Government of the Russian Federation No. 1119 for the corresponding level of personal data security. A provider’s violation of the processing conditions entails its direct liability to the operator and possible subsidiary liability to the regulator.
A special situation arises when a KYC provider offers services through a single platform to many clients. In this case, it is important to properly structure the technical architecture and legal relationships to avoid unauthorized access by some operators to the data of other operators’ customers. Roskomnadzor pays particular attention to isolating the data of different operators when cloud KYC solutions are used.
The special regime for biometric personal data and the UBS
Biometric personal data is subject to a stricter legal regime under Article 11 of Federal Law 152-FZ. Its processing is permitted only with the written consent of the subject, except in cases directly provided for by law. For KYC processes, the key exception is established by Federal Law No. 572-FZ on the Unified Biometric System — using biometrics for remote identification in the UBS takes place on the basis of the law without additional consent.
On September 1, 2024, changes came into force that significantly expanded the use of the UBS. Banks with a universal license are obliged to ensure the collection of biometric data and its placement in the UBS, and from 2025 — to accept biometrics for identification when providing financial services. In parallel, the use of organizations’ own biometric systems is allowed, but only with the customer’s written consent and provided that the requirements of GOST R 58624-2019 on the protection of biometric data are met.
Processing biometrics outside the UBS requires mandatory encryption of biometric templates and their separation from the subject’s other personal data. It is prohibited to store the original biometric samples (photographs, audio recordings) after the biometric template has been created, unless this is required for the purposes of repeated verification. When using biometrics for authentication (repeated login), it is necessary to implement anti-spoofing mechanisms — a liveness detection with an effectiveness of at least 99% in accordance with the Bank of Russia’s requirements.
Regulators pay special attention to the cross-border transfer of biometric data. Using foreign face recognition services for KYC effectively means a cross-border transfer of biometrics and requires compliance with all the conditions of Article 12 of Federal Law 152-FZ, including the existence of adequate protection in the recipient country or the written consent of the subject with all the risks specified.
Localization and cross-border transfer of KYC data
The requirements for the localization of databases of Russian citizens are established by part 5 of Article 18 of Federal Law 152-FZ: when collecting personal data, the operator is obliged to ensure its recording, systematization, accumulation, storage, clarification and extraction using databases located on the territory of the Russian Federation. This rule extends to all personal data collected within KYC, including copies of documents and biometrics.
Primary processing and storage must take place in Russia, but the law does not prohibit subsequent cross-border transfer if the conditions of Article 12 of Federal Law 152-FZ are met. An adequate level of protection is recognized only in countries that have ratified Council of Europe Convention No. 108, and in certain states by decision of Roskomnadzor. For transfer to other jurisdictions, the written consent of the subject is required, or a contract with the receiving party containing obligations to protect personal data.
Using international KYC providers creates additional complications. If a provider processes data exclusively on the territory of Russia through local infrastructure, no cross-border transfer takes place. However, access by the provider’s foreign specialists to the data from abroad may be qualified by Roskomnadzor as a cross-border transfer requiring compliance with all the established conditions.
Since March 2024, control over compliance with localization requirements has been strengthened: fines for legal entities have been increased to 18 million rubles for a first violation. When choosing a KYC solution, it is critically important to make sure there is Russian infrastructure and that all data processing processes are properly formalized legally. The optimal option remains using Russian providers with fully localized infrastructure and data processing processes.
How to organize the storage and lifecycle of personal data in KYC
The proper organization of personal data storage in KYC systems determines not only compliance with legal requirements but also the operational efficiency of the entire identification process. Modern KYC platforms process terabytes of sensitive information, and each type of data requires a special approach to storage, processing and deletion. A well-built personal data lifecycle reduces the risks of leaks, minimizes infrastructure costs and simplifies passing regulatory inspections.
Minimizing the composition of data and its retention periods in KYC processes
The principle of data minimization is enshrined in Article 5 of Federal Law 152-FZ and requires collecting only the personal data that is necessary to achieve the stated processing purposes. In the context of KYC, this means the targeted collection of information sufficient to identify the customer and meet the requirements of Federal Law 115-FZ, without excessive accumulation of information “just in case”.
The basic set of data for KYC includes:
- full name,
- date of birth,
- details of the identity document,
- registered address.
Additional information — INN, SNILS, contact details — is collected only when there are specific business requirements or regulatory obligations. Financial organizations are obliged to store customer files for five years after the termination of contractual relations in accordance with clause 4 of Article 7 of Federal Law 115-FZ. At the same time, certain categories of data may be deleted earlier: for example, scanned copies of documents can be replaced with hashed checksums after successful verification, retaining only the main details.
To optimize the composition of the collected data, a risk-based approach is applied: simplified identification for low-risk operations (up to 15,000 rubles under Federal Law 115-FZ) requires a minimal set of data, while full identification requires an extended package of documents. This gradation makes it possible to reduce the volume of stored information by 30-40% without violating regulatory requirements.
Automating the control of retention periods through built-in retention policy mechanisms prevents the excessive accumulation of outdated data. The system automatically flags records for deletion after the established periods expire, generates reports on upcoming cleanup operations, and keeps a log of all actions with personal data.
Separate storage of application-form, documentary and biometric data
A segmented architecture for storing different types of personal data increases the security of the KYC system and simplifies access management. Application-form data, documents and biometrics are stored in isolated repositories with independent security policies and encryption mechanisms.
| Category | Description |
|---|---|
| Application-form data | Are placed in relational databases with field-level encryption for sensitive information. Passport data, INN and other identifiers are encrypted with individual keys, while search indexes are built on the basis of irreversible hashes. This makes it possible to perform fast searches without decrypting the entire data array. |
| Documentary data — scans of passports, driver’s licenses, certificates | Are stored in object storage with deduplication and compression. Each document undergoes a tokenization procedure: the original file is placed in a secure repository, while only a token identifier remains in the main system. Access to the originals is provided through a separate authorization service with multi-factor authentication. |
| Biometric templates | Require a special approach to storage in accordance with the requirements of clause 10 of Article 11 of Federal Law 152-FZ. Biometric face vectors are stored separately from personal identifiers in specialized systems with a hardware security module (HSM). The link between the biometric template and the identity is established through intermediate identifiers that are regularly updated. If one repository is compromised, an attacker does not obtain the full set of data needed to reconstruct the identity. |
The physical separation of repositories is implemented by placing them on different servers or in different virtualization containers. Each repository has its own backup rules, log rotation, and disaster recovery procedures. Inter-service interaction is carried out through secure APIs with mutual authentication and integrity control of the transmitted data.
Anonymization, depersonalization and secure deletion of KYC data
Anonymization and depersonalization make it possible to preserve the analytical value of data while reducing the risks to personal data subjects. In KYC systems, these mechanisms are used to prepare machine learning datasets, generate statistical reporting, and store historical data for the long term.
| Category | Description |
|---|---|
| Depersonalization | Depersonalization, in accordance with Roskomnadzor Order No. 996 of 05.09.2013, means the processing of personal data in which, without the use of additional information, it is impossible to determine that the data belongs to a specific subject. In practice, for analytics and model training tasks, reversible pseudonymization is often used (replacing the original identifiers with tokens while storing the key separately). In KYC processes, dynamic depersonalization is applied: critical fields are replaced with pseudonyms, and the mapping keys are stored in an isolated system with an increased level of protection. If it is necessary to conduct an investigation or meet regulatory requirements, the data can be restored by authorized personnel. |
| Anonymization | Full anonymization is applied to data that has lost its operational value but retains its statistical significance. The k-anonymity and l-diversity algorithms guarantee that it is impossible to identify a specific subject in a de-identified dataset. For example, exact dates of birth are replaced with age ranges, addresses with regions, and transaction amounts with categories. |
| Secure deletion of KYC data | Secure deletion of personal data is performed through a multi-stage process. First, the data is flagged for deletion and moved to a quarantine zone for 30 days to allow recovery in case of erroneous deletion. Then cryptographic wiping is performed: the data is overwritten with random values at least three times in accordance with the DoD 5220.22-M standard. For SSD drives, the Secure Erase command is used, followed by verification of complete deletion. Logging of all deletion operations provides an audit trail for regulatory inspections. The logs record the time of deletion, the initiator of the operation, the grounds for deletion, and the checksum of the deleted data. At the same time, the personal data itself is not stored in the logs — only de-identified operation metadata. |
Automating anonymization and deletion processes through workflow orchestrators reduces the risk of human error. The system automatically applies processing rules depending on the type of data, the retention period and the business context, generates reports on completed operations, and monitors compliance with the established data lifecycle policies.
What technical measures ensure data security in KYC systems
Technical protective measures form the foundation of a KYC system’s security. The protection of customers’ personal data, compliance with regulators’ requirements, and users’ trust in the service depend on their correct implementation. Modern KYC platforms apply a multi-level approach to protection: from cryptographic protocols at the data transmission level to specialized algorithms for protecting biometrics.
Protecting transmission channels and the API during KYC identification
The data transmission channel is the first critical point in the KYC security chain. All connections between the client application and the KYC server must use the TLS 1.3 protocol or higher with mandatory certificate verification. The transmission of personal data over unprotected channels is unacceptable, even within the internal infrastructure.
API interaction requires additional levels of protection. Authentication via OAuth 2.0 using access tokens with a limited validity period (usually 15-60 minutes) minimizes the risks of compromise. Each API request is signed with a unique key through the HMAC-SHA256 mechanism, which rules out data substitution during transmission.
The NeuroVision platform is implemented as a server-side system with a REST API and a set of SDKs: a Web-SDK for embedding into web interfaces and an SDK for mobile applications. For operation, an administrative control panel, monitoring dashboards, manual moderation tools and report export are provided. The average integration time — < 1 hour.
Protection against man-in-the-middle attacks through the Certificate Pinning mechanism in mobile applications is critically important. The application stores the fingerprint of the KYC server’s certificate and rejects connections with mismatched certificates, even if they are valid from the system’s point of view.
Rate limiting prevents automated attacks. Typical limits: no more than 10 requests per second for verification from a single IP address, no more than 100 identification attempts per day for a single document. Exceeding the limits blocks the source for a temporary period, with an exponential increase in the blocking time for repeat violations.
The performance of the NeuroVision modules makes it possible to design rate limiting and anti-bot loops based on real load characteristics: processing 10,000+ requests per minute, face comparison — < 0.1 sec, document recognition — < 1 sec. These parameters are used to configure per-session/per-document limits, detect an anomalous request frequency, and automatically block on signs of brute force and replay attacks.
Encrypting KYC data repositories and managing cryptographic keys
Personal data in a KYC system is encrypted at three levels: during transmission, in RAM, and at rest. For storage, the AES-256 algorithm in GCM mode is used, providing both the confidentiality and the integrity of the data. Each category of data (application-form, documents, biometrics) is encrypted with separate keys.
Key management is built on the principle of regular rotation. Master keys are updated quarterly, and data encryption keys monthly. Old key versions are retained only for decrypting archived data and are automatically destroyed after the retention period of the corresponding data expires.
Hardware Security Modules (HSM) or their software analogues protect cryptographic operations. Key generation, key storage and encryption operations are performed inside a secure module, ruling out the possibility of extracting keys even if the main system is compromised.
The database uses Transparent Data Encryption, where the DB files are encrypted automatically at the file system level. Backups are created already encrypted using a separate set of keys, which prevents leaks through backups.
Access control, logging and monitoring of operations with personal data
The Zero Trust model defines the access control architecture: we trust no one by default and verify every request. Access is granted on the principle of least privilege — an employee receives rights only to the data and operations necessary to perform their functions.
A role-based access model (RBAC) delimits authority. The basic roles include: a verification operator (viewing check results without access to the source documents), a security administrator (configuring policies without access to the data), an auditor (viewing logs without the ability to modify them).
Every operation with personal data is recorded in an immutable audit log. The record includes: a timestamp accurate to the millisecond, the user/system identifier, the type of operation, the object affected, the IP address, and the result of the operation. Logs are stored separately from the main system with protection against modification through digital signatures.
The real-time monitoring system analyzes access patterns. Anomalies (mass downloading of data, access during non-working hours, attempts to access data outside one’s area of responsibility) generate alerts to the security team. Critical events (an attempt to export biometric templates, a change of roles by administrators) require confirmation through a second channel.
Protecting biometrics in KYC: templates, liveness checks and protection against forgery and leaks
Biometric data represents a special category of risk — it cannot be changed if compromised. Therefore, protection is built on the principle of irreversible transformation: it is impossible to reconstruct the original face image or other biometric characteristics from a biometric template.
The template creation process involves extracting mathematical characteristics (feature vectors) through neural network algorithms. The resulting vector of 128-512 values undergoes additional hashing with a salt unique to each user. The result is an irreversible biometric hash, suitable for comparison but useless for reconstructing the face.
The liveness check protects against the presentation of photos, videos or masks instead of a live person. Modern algorithms analyze facial micro-movements, pupil reflexes, and skin texture in the infrared spectrum. The passive liveness check works imperceptibly for the user, analyzing natural movements during capture. The accuracy of detecting forgeries reaches 99.9% with a False Acceptance Rate of less than 0.01%.
Secure storage of biometric templates and separate storage of identifiers
The biometrics storage architecture rules out a direct link between the template and the identity. The biometric template is stored in one database under a random UUID, while the personal data is in another database with its own identifier. The mapping table linking the identifiers is located in a third, isolated system with heightened access requirements.
Templates are additionally fragmented — the feature vector is divided into several parts stored on different servers. To perform a comparison, the system temporarily assembles the fragments in secure memory, performs the operation, and immediately clears the buffers. Even if one server is compromised, an attacker obtains only a useless fragment of data.
Template versioning makes it possible to track changes in biometrics over time without storing historical data. When a template is updated, the old version is replaced with the new one, retaining only the timestamp of the last update and a version counter.
Reducing biometric fraud risks (deepfake, tampered videos and photos)
Protection against deepfake requires multi-factor analysis. The algorithms check the temporal consistency of movements (synchrony of blinking, lip movements during speech), analyze compression artifacts characteristic of synthesized images, and detect inconsistencies in the lighting of different parts of the face.
The NeuroVision anti-fraud module detects source substitution and synthetic content: a photo of a screen, photocopies, traces of tampering with a graphics editor, deepfake and fully generated faces. The loop also performs checks for logical inconsistencies in the data, age estimation from the face with comparison against the date of birth, and matching against the customer blacklist. For anti-fraud, 40+ fraud protection algorithms are applied.
An additional level of protection is random challenge-response checks. The system requests the performance of an unpredictable action: turning the head in a specified direction, saying random numbers, changing facial expression. Deepfake algorithms cannot generate correct responses.
Behavioral biometrics creates an additional barrier for fraudsters. The system analyzes unique patterns: the speed and trajectory of head movement, blinking frequency, micro-expressions. Even a high-quality deepfake does not reproduce the individual behavioral features of a specific person.
The constant updating of detection algorithms is critically important in the race with the development of forgery technologies. The machine learning models are retrained weekly on new examples of attacks collected from real fraud attempts. The system automatically adapts to new forgery methods, maintaining a high level of protection without the need for manual intervention.
What organizational measures are needed for the secure processing of personal data in KYC
Technical protection tools are only half of the KYC process security system. Without the right organizational structure, clear procedures and trained personnel, even the most advanced technologies will not ensure reliable personal data protection. Organizational measures create a controlled environment where every employee understands the limits of their responsibility, and all processes are documented and controllable.
Policies, regulations and a threat model for KYC processes
Must define the principles of working with each type of information: from basic application-form data to biometric templates. The document records the processing purposes, legal grounds, categories of subjects and operators, retention periods, and the procedure for destroying data.
Detail each stage of identification: what data is requested at the input, how its accuracy is verified, who has access to the check results, and how decisions on accepting or rejecting a customer are documented. Particular attention is paid to the separation of authority — a front-office employee sees only the verification result, without gaining access to the source documents and biometrics.
Identifies potential risks at each stage of data processing. External threats include attempts to intercept data during transmission, hacking of repositories, and the use of forged documents or deepfake to bypass biometrics. Internal risks are associated with unlawful access by employees, leaks through insiders, and errors in configuring systems. For each threat, the probability of occurrence and the potential damage are determined.
A regulation on cross-border data transfer becomes mandatory when working with international clients or using foreign KYC providers. The document defines the countries with an adequate level of data protection, the requirements for contracts with foreign counterparties, and the procedure for obtaining subjects’ consent to transfer their data abroad.
Roles, responsibilities and training of personnel working with KYC data
A matrix of roles and responsibilities clearly distributes authority among the participants in the KYC process. The security administrator configures the protection systems and monitors compliance with policies. The KYC operator performs the initial verification of documents and cross-checking against databases. The compliance officer makes decisions on disputed cases and interacts with the regulator. The IT specialist ensures the technical integration and monitoring of the systems’ operability.
For each role, the minimum necessary volume of data access is defined. The principle of least privilege rules out excessive rights — a technical support specialist should not see customers’ passport data, and a marketer does not need access to the results of AML checks.
The personnel training program covers the legal aspects of working with personal data, the specifics of processing biometrics, the signs of fraud schemes, and the procedure for acting when incidents are detected. New employees undergo an introductory briefing before receiving access to KYC systems. Regular professional development (at least once a year) updates knowledge about changes in legislation and new types of threats.
A non-disclosure and confidentiality agreement is signed by every employee who receives access to personal data within KYC. The document defines liability for information leaks, including the period after dismissal. Disciplinary measures for violating data processing rules must be recorded in employment contracts and local regulations.
Regular audits, security testing and response to personal data incidents
| Category | Description |
|---|---|
| The internal audit schedule | Provides for a quarterly check of compliance with personal data processing procedures in KYC. The auditor analyzes access logs, checks the correctness of system configurations, and assesses the completeness of compliance with the regulations. Particular attention is paid to controlling retention periods — the data of customers who have not passed verification must be deleted within the established periods. |
| External security audit | Is conducted at least once a year by an independent organization with the appropriate FSTEC or FSB license. The check includes penetration testing, an analysis of infrastructure security, and an assessment of compliance with the requirements of Federal Law 152-FZ and sectoral standards. The audit results are recorded in a report, and the identified deficiencies are eliminated within the agreed timeframes. |
| The incident response plan | Defines the actions to take when a data leak, unauthorized access attempts or compromise of biometric templates is detected. The first hour after detection is the critical period for localizing the threat, assessing the scale of the incident, and deciding whether to notify the regulator and the affected subjects. The incident notification procedure complies with the requirements of part 3.1 of Article 21 of Federal Law No. 152-FZ of 27.07.2006 “On Personal Data”: Roskomnadzor is informed within 24 hours of detecting the incident through a special form on the portal персональныеданные.рф. Personal data subjects are notified within 72 hours if the incident creates a high risk of violating their rights. |
| Incident analysis and lessons learned | Completes the security management cycle. Each case of a violation is investigated to identify the root causes, assess the effectiveness of existing protective measures, and adjust procedures to prevent recurrence. A knowledge base of incidents helps recognize new threats faster and improve the protection system. |
The security metrics of KYC processes include the number of unauthorized access attempts, the percentage of false positives from the protection systems, the time to detect and eliminate incidents, and the level of staff awareness based on testing results. Regular monitoring of these indicators makes it possible to assess the effectiveness of organizational measures and adjust the approach to personal data protection in a timely manner.
How to choose and vet a KYC provider with secure processing of personal and biometric data
The choice of a KYC provider determines not only the effectiveness of the identification processes but also the company’s legal protection when working with customers’ personal data. The wrong choice of partner can lead to fines of up to 18 million rubles for violating Federal Law 152-FZ, reputational losses due to data leaks, and the blocking of accounts by Rosfinmonitoring for non-compliance with the requirements of Federal Law 115-FZ.
When evaluating a provider, it is critically important to check three key aspects: the legal cleanliness of data handling, the technical security of the infrastructure, and the quality of the anti-fraud algorithms. Each of these components requires detailed verification through specific questions, documents and technical tests.
Questions for the provider about Federal Law 152-FZ, 115-FZ and the data processing agreement
The initial vetting of a provider begins with the legal documentation. Ask the potential partner for a certificate of registration in Roskomnadzor’s register of personal data operators — the absence of registration means illegal data processing from the moment the contract is concluded. The register number must be active, which is checked on the website rkn.gov.ru.
NeuroVision is registered in the register of personal data operators and included in the register of IT companies. For environments with localization and access control requirements, the platform supports on-premises and hybrid deployment, as well as the separation of modules (documents, biometrics, database checks) into isolated perimeters
Study the standard personal data processing agreement. It should clearly spell out: the specific purposes of processing data within KYC processes, an exhaustive list of actions with the data (collection, systematization, storage, clarification, blocking, deletion), the processing periods and the conditions for their extension, and the procedure for returning or destroying the data after the contract ends.
Questions about subprocessors are critically important. If the provider engages third parties to process data (cloud storage, recognition services, analytics platforms), the contract must contain an exhaustive list of such companies with an indication of their role and jurisdiction. The absence of this information is a sign of an opaque work scheme with a high risk of leaks.
Under Federal Law 115-FZ, the provider must provide algorithms and procedures that comply with the requirements of Bank of Russia Regulation No. 683-P. Request a description of the procedures for identification, simplified identification, and updating customer information. Check for mechanisms to block the operations of suspicious customers and procedures for transferring information to Rosfinmonitoring.
On the NeuroVision platform, the AML module performs checks of individuals and legal entities against 1,700+ databases and supports regular continuous monitoring. International sanctions sources are available: OFAC, the EU, the United Kingdom (HMT/OFSI), the UN, and the national sanctions lists of more than 50 countries. For Russian environments, checks are available against the FSSP (debts), tax debts, bankruptcies, arbitration cases, the list of terrorists, the register of foreign agents, PEP, disqualifications, pre-bankruptcy scoring, and the sanctions lists of the Russian Federation.
Pay attention to the distribution of liability. The contract must specify concrete fines for a data leak, failure to meet data deletion deadlines, and the transfer of data to third parties without approval. The extent of the provider’s liability must cover your company’s potential fines from regulators.
Requirements for infrastructure, certification and KYC data storage models
The provider’s technical infrastructure must comply with the requirements of FSTEC Order No. 21 on ensuring the security of personal data. Request a certificate of compliance with information security requirements or a certificate of compliance of the information security management system with ISO/IEC 27001:2022.
Critically assess the data storage model. In the case of cloud storage, the data centers must be physically located on the territory of Russia — this is the requirement of Federal Law 242-FZ on the localization of the personal data of RF citizens. Check whether the data center has an FSTEC license for the technical protection of confidential information and Tier III or higher certificates according to the Uptime Institute classification.
For on-premise solutions, assess the deployment possibilities in your infrastructure. The provider must provide detailed system requirements, including the necessary computing power, storage volumes, and communication channel requirements. Support for operation in an isolated environment without internet access is important for processing especially sensitive data.
Study the backup architecture. Backups must be created at least once a day and stored in encrypted form in geographically distributed locations. The recovery time objective (RTO) must not exceed 4 hours for critical systems, and the recovery point objective (RPO) must be no more than 1 hour.
Check the mechanisms for delimiting data between clients in a multi-tenant architecture. Each client must operate in an isolated logical perimeter with separate encryption keys. Using shared databases or repositories for the data of different companies is unacceptable.
Assessing the security of biometrics, anti-fraud algorithms and liveness checks
Biometric systems require special attention during vetting. Request the results of testing the face recognition algorithms in NIST FRVT or other recognized international benchmarks. An acceptable level of accuracy is a FAR (False Acceptance Rate) of no more than 0.01% with an FRR (False Rejection Rate) of no more than 1%.
The NeuroVision face recognition algorithms participate in NIST testing (03/23) and rank in the top 24. In KYC scenarios, the platform performs biometric verification with an accuracy of 99.74% and a face comparison time of up to 0.09–0.1 seconds. For high-load environments, performance of up to 10,000 requests per minute is supported.
Check the mechanisms for protecting biometric templates. The provider must use irreversible hash functions to transform the biometric data, ruling out the possibility of reconstructing the original face image from the template. Storing face photographs in the clear is unacceptable — only encrypted data with separation of the encryption keys.
The liveness check must recognize all types of attacks: photos on device screens, printed photos, video recordings, 3D masks, deepfake videos. Request statistics on the successful passing of the liveness check by legitimate users (it should be above 95%) and the percentage of detection of deception attempts (no lower than 99%).
The anti-fraud algorithms must analyze at least 40 parameters: device metadata, geolocation, behavioral patterns, data entry speed, the use of emulators and VPNs. The system must update its machine learning models at least once a month based on new data about fraud schemes.
Conduct practical testing of the system. Try to pass identification using a photograph instead of a live person, with altered lighting, in a mask or glasses. The system must correctly handle all scenarios, requiring the check to be repeated in case of suspicious actions.
In the NeuroVision banking environment, the load exceeds 1 million checks per month. The following implementation results have been recorded: a reduction in fraud to 0.1% (from 15%), a 15% increase in conversion, and an ROI of 586%. These figures can be used as benchmarks for a test plan: load scenarios, resistance to attempts to bypass liveness/anti-spoofing, and conversion control on real user traffic.
A checklist for a company before launching or changing a KYC solution
Before the final decision, go through the checklist of critically important items:
| Legal check: | – Registration in the register of personal data operators – Compliance of the contract with the requirements of Federal Law 152-FZ and 115-FZ – A transparent scheme for working with subprocessors – An adequate distribution of liability and fines – The presence of procedures for responding to data subject requests |
| Technical infrastructure: | – Localization of data storage within the Russian Federation – FSTEC or ISO 27001 compliance certificates – Encryption of data in transit (TLS 1.3) and at rest (AES-256) – Backups with an RTO < 4 hours – Logging of all operations with data |
| Biometrics and anti-fraud: | – Recognition accuracy of FAR < 0.01%, FRR < 1% – Irreversible hashing of biometric templates – Liveness check effectiveness > 99% – Analysis of at least 40 parameters to detect fraud – Regular updating of the ML models |
| Operational aspects: | – 24/7 technical support – An SLA with a guaranteed response time – The ability to export all data in a structured format – API documentation and integration examples – A trial period with full functionality |
| Financial terms: | – A transparent pricing model with no hidden charges – Per-transaction cost vs a subscription fee – Scaling terms as volumes grow – Penalties for SLA violations – Contract termination terms |
Checking against this checklist takes 2-3 weeks, but it makes it possible to avoid critical problems after launching the system. Pay particular attention to practical testing on the real scenarios of your business — many problems are revealed only when working with live data and processes.
Remember that changing a KYC provider after launch will cost 5-10 times more than the initial implementation due to the need for data migration, retraining employees, and potential downtime. That is why the time invested in thorough vetting at the selection stage pays off many times over.
Personal data protection in KYC is built on three interconnected components: compliance with the legal requirements of Federal Law 152-FZ and related legislation, the application of modern technical tools, and well-established organizational procedures. Each element — from minimizing the information collected and the separate storage of biometrics to access control and regular audits — reinforces the overall protection and reduces the risks for the business and customers.
Companies implementing biometric verification and identification automation must ensure the full set of security measures, including encryption of repositories, protection of transmission channels, logging of operations, and staff training. Choosing a KYC provider with confirmed security infrastructure, transparent processing procedures, and compliance with regulators’ requirements makes it possible not only to fulfill legal obligations but also to strengthen customer trust, minimize the threat of leaks, and reduce the likelihood of fraud.