What to count as a KYC check, an approved customer, and an error
Any calculation of KYC costs begins not with figures but with definitions. Three key concepts — a KYC check, an approved customer, and an error — are interpreted differently in different companies, and until each of them is fixed unambiguously, comparing costs loses its meaning: the same amount of expenses may reflect diametrically different volumes of work.
A KYC check in this article is the full cycle of operations necessary to make a decision on verifying a specific user: from data collection to the system’s final decision (approved / rejected / sent for manual review).
An approved customer is a user who has successfully passed all the required verification stages and gained the right to perform the target action (opening an account, topping up, registering).
An error in KYC is a deviation of the result of the automated check from the correct decision: a false rejection (rejecting a real user) or a false approval (letting a fraudster through). Both types carry direct financial consequences, the calculation methodology for which is examined in the following sections.
Application, session, or unique customer
In the economics of KYC, these three concepts are often used as synonyms — and this is a key error that distorts both budgeting and the assessment of effectiveness.
An application is a business event: a user’s intention to pass verification, recorded by the system. One application corresponds to one onboarding process of a specific person at a specific moment in time and may include several attempts — for example, if the user uploaded an unreadable document and repeated the attempt.
A session is one verification attempt: from the moment data collection begins to the receipt of a result. It is precisely the session that is most often the billing unit of API providers: each call to a module (document check, liveness, biometric comparison) is billed separately and independently of the final decision. From this follows a practical conclusion: unsuccessful sessions — technically incorrect data, repeat uploads, interrupted attempts — also generate costs, even if the customer was never approved.
A unique customer is an individual regardless of the number of applications and sessions they have initiated. One person can submit an application again: after the verification period expires, when changing a document, after an initial rejection. Each new application means new costs, but the same unique customer.
For a correct calculation of the cost of an approved customer, the number of unique approved customers is placed in the denominator of the formula, while the numerator includes all the costs of all sessions and applications — including unsuccessful ones. If the number of sessions is taken as the basis, the result will be understated; if only successful sessions are counted — even more distorted.
Which KYC stages and expenses are included in the calculation
The full cycle of KYC verification consists of several technological stages, each of which generates its own costs. The error of most budget calculations is to account for only the cost of API calls and ignore everything else.
The technological stages of a typical KYC pipeline and the associated expenses:
- Data collection (SDK/widget, hosting, traffic): the costs of the client side, which are usually not included in the cost of the check, although at high volumes they can be significant.
- Document check (AI-OCR / IDP): field extraction, document type classification, verification of the security features and the MRZ — billed per call, including repeat attempts with a poor-quality image.
- Liveness and PAD: the check of the user’s “liveness” and protection against presentation attacks — a separate call with its own billing.
- Biometric comparison (face matching): matching the selfie with the photo from the document — also a separate operation.
- Compliance checks (AML, sanctions, PEP): each search query to the databases is billed independently; depending on the set of sources, the cost varies substantially.
- Additional database checks: FSSP, tax debt, wanted lists, phone confirmation — optional steps, each of which adds to the cost of the session.
- Manual review (back office): the labor costs of operators on disputed cases. This is one of the most underestimated components: the share of cases that reach the operator directly determines the final cost, since manual review costs an order of magnitude more than an automatic one.
- Integration and infrastructure expenses: developing the integration, supporting the API, server infrastructure — at low volumes they can constitute a significant share of the unit costs.
The calculation of the cost of an approved customer must include all of the listed components, distributed over the real number of approved users.
It is impossible to calculate a real CPAC if the cost of even one component of the pipeline remains opaque. The NeuroVision platform covers the full verification chain within a single integration: AI-OCR for checking and extracting document data, face matching via the Enface module, liveness/PAD, 40+ anti-fraud algorithms, and AML compliance checks.
The benchmark for the full cycle — document, face, liveness, and AML — is from 35 to 50 rubles per check; the exact cost depends on the set of modules and the volume. Connection via a REST API or SDK takes from 24 hours when using ready-made components, the full launch on the customer’s side — 3–7 days. The platform supports more than 10,000 document types from 200+ countries and is available in cloud, on-premises, and hybrid formats. We will break down the composition of your pipeline, clarify the required modules, and calculate the cost for your volume and scenario.
The total costs are determined not only by the volume of checks but also by the share of those that ended in approval: it is precisely this ratio that shapes the real economics of the KYC process.
The cost of an approved customer in KYC
The cost of a KYC check and the cost of an approved customer are different values. The first reflects the costs of one verification request or session. The second shows what each customer who has successfully passed the check and been admitted to the product really costs: it takes into account not only the direct costs of the check but also the costs of unsuccessful attempts, manual reviews, and rejections. Without it, it is impossible to correctly compare alternative automation scenarios or justify investment in KYC infrastructure.
How to calculate the cost of a manual KYC check
Manual review remains a significant part of KYC processes even in automated systems: according to a global study by Fenergo (2022-2023), more than half of banks perform from 31 to 60% of KYC review tasks manually. It is precisely manual labor that makes KYC expensive: one full corporate KYC case costs large banks $1,500–$3,500, and in 21% of cases — more than $3,000 per check. Retail onboarding is cheaper, but manual sessions still form the bulk of the costs.
The cost of one manual KYC check is made up of four components.
| Category | Description |
|---|---|
| Direct labor costs | The starting point is the full cost of a compliance specialist’s working hour, taking into account taxes, insurance contributions, and regular training (which is mandatory when working with changing regulatory requirements). The average time to check one case depends on the document type and the risk profile: simple sessions (a standard document, good image quality) take 5-10 minutes, complex ones (blurry photos, a non-standard document, signs of manipulation) — 20-40 minutes and more. |
| Operational overhead | Added to the direct labor costs are the expenses for the workplace, software, secure data storage, IT support, and quality control. Practice shows that the overhead constitutes 40-80% of the cost of the analyst’s net working time depending on the organizational structure. |
| Management and QA | Compliance with the regulator’s requirements implies a selective audit of decisions and feedback to operators. This is an additional resource that is distributed across the entire flow of checks. |
| Infrastructure and compliance | Database updates, support for integrations with external registries, legal support for changes in regulation — constant expenses that are allocated per check through the volume. |
The final formula for the cost of one manual check:
C_manual = (Specialist’s monthly salary × Load coefficient) / Number of checks per month + Share of overhead and QA per check
The load coefficient takes into account vacations, sick leave, meetings, and training: usually 0.75-0.85 of the working time fund. A realistic analyst productivity is 200-350 checks per month with a standard flow of retail applications.
Manual review is the most costly component of the KYC process: with a standard flow of retail applications, one operator closes 200–350 cases per month, and a growth in the share of manual review multiplies operating costs. The task of automation is not to eliminate the operator but to reduce the share of cases that reach them.
The NeuroVision platform makes it possible to automatically close up to 90% of cases without operator involvement: 40+ anti-fraud algorithms, a face-matching accuracy of 99.74%, and liveness of 99.9% cut off most disputed cases already at the automatic check stage. Only borderline cases are routed to manual review — a non-standard document, a data conflict, the triggering of risk rules. The scenarios, thresholds, and routing are configured in the platform’s back office for your risk model and the regulator’s requirements. We will select a configuration in which the share of manual review is reduced while decision quality control is preserved.
The formula for the cost of an approved customer
The cost of an approved customer (Cost per Approved Customer, CPAC) is the ratio of the total costs of the KYC process to the number of customers who received a positive decision:
CPAC = (C_auto × N_total + C_manual × N_manual + C_fixed) / N_approved
Where:
- C_auto — the cost of one automatic request to the KYC service (the API rate or the calculated cost price for on-premises);
- N_total — the total number of requests processed (all sessions, including unsuccessful and repeat ones);
- C_manual — the full cost of one manual check (calculated by the formula above);
- N_manual — the number of cases sent for manual review;
- C_fixed — the fixed costs of the period: platform licenses, integration, SLA support, allocated per customer;
- N_approved — the number of customers successfully approved over the same period.
The denominator contains only approved customers, whereas the numerator contains the costs of the entire flow, including rejections and abandoned sessions. That is why CPAC is always higher than the average cost of a single check, and reducing the share of unsuccessful sessions directly reduces CPAC without changing the rates.
Example: if there are 700 approved customers per 1,000 sessions, and the total costs amounted to 50,000 rubles, CPAC = 71.4 rubles, although the average cost of a session is 50 rubles. The gap of 43% is the price of unsuccessful attempts and rejections.
How to account for repeat attempts, unsuccessful sessions, and the share of manual review
A real flow of KYC applications does not consist of single attempts with an unambiguous outcome. Three factors substantially change the final CPAC.
| Category | Description |
|---|---|
| Repeat attempts | Some customers pass verification several times: due to poor shot quality, incorrect lighting during the selfie, or technical errors on the user’s side. The retry rate is 10-30% depending on the UI/UX and the strictness of the configured image quality thresholds. Each repeat attempt generates an API request and additional cost. The key question in the calculation is how exactly the provider bills: per API call or only for successfully completed sessions; this difference directly affects the numerator of the formula. |
| Unsuccessful sessions (drop-off) | The share of applications that the customer started but did not complete — abandoned at some step of onboarding. According to industry data, with a high level of friction in the verification process, the share of abandoned applications reaches 25%. These sessions carry costs (API requests at intermediate steps) without resulting in an approved customer. |
| Share of manual review (manual review rate) | The share of cases that the automation could not resolve on its own and sent to an operator. The higher it is, the more each approved customer costs. The borderline cases that form this share: low document quality, a non-standard type, a data conflict, the triggering of anti-fraud rules. |
The adjusted formula with the explicit inclusion of these factors:
CPAC = [C_auto × N_attempts + C_manual × (N_completed × m)] / [N_completed × (1 − d_reject)]
Where:
- N_attempts — the total number of API requests taking repeat attempts into account (N_unique × (1 + r), where r is the average retry coefficient);
- N_completed — the number of applications brought to a final decision (without drop-off);
- m — the share of cases that went through manual review;
- d_reject — the share of final rejections among completed applications.
Each of the listed parameters is manageable. Reducing the retry rate through a quality UI and real-time prompts, cutting drop-off by simplifying the user path, lowering the manual review rate through more precisely calibrated threshold values — each of these improvements reduces CPAC without changing the rate. This is a key tool for optimizing the economics of KYC at the operational level.
A retry rate of 10–30%, a share of abandoned applications of up to 25%, and a high share of manual review — three manageable parameters, each of which directly affects the final CPAC. Understanding which pipeline step exactly forms them is possible only through measurement: which stage generates repeat attempts, on which screen users leave, which rules most often route cases to an operator.
The NeuroVision platform includes a back office with dashboards for operations, conversions, and incidents — this gives a detailed picture of losses at each funnel step. We will analyze your current flow, agree on which thresholds and scenarios are worth reconsidering, and propose a configuration that reduces CPAC without changing the rate. If some modules are not yet connected, integration via a REST API or SDK takes from 24 hours. For the diagnosis, the current metrics of your KYC flow will be required.
The price of errors in KYC
A KYC system makes two types of errors with fundamentally different consequences: a false rejection and a false approval. The first deprives the company of a customer it should have accepted. The second lets through a fraudster it was obliged to block. Both types carry measurable losses and lend themselves to precise calculation.
How to calculate the price of a false rejection
A false rejection (in international terminology — a false positive, FP; in biometric systems — the False Rejection Rate, FRR) is a situation where the KYC system blocks the verification of a legitimate customer: flags a correct document as suspicious, fails the biometric comparison due to low photo quality, or rejects the application because of an erroneously triggered anti-fraud rule.
The price of a false rejection is made up of three terms.
The first — direct operating costs. Each falsely rejected case requires manual review: the specialist spends time, the system registers an incident, the customer waits. If an operator check costs the company 500-1,500 rubles (at a norm of 15-30 minutes per case), each false rejection adds this amount to the already paid cost of the automatic check — the total cost of processing such an application doubles or triples.
The second — a lost customer. A false rejection not resolved through manual review means a lost user. According to Fenergo (a 2025 study covering 600 executives of banks, management companies, and fund administrators), 70% of financial organizations lost customers due to inefficient onboarding — the figure grew from 48% in 2023 to 67% in 2024 and to 70% in 2025. The average level of incomplete applications is about 10%.
The price of a lost customer is calculated by the formula:
The price of a false rejection (per unit) = CAC + LTV × Churn_probability
Where:
- CAC (Customer Acquisition Cost) — the cost of acquiring a customer up to the moment of verification: marketing costs, the lead, the initial contact;
- LTV (Lifetime Value) — the projected revenue from a customer over the entire period of cooperation;
- Churn_probability — the probability that the customer will not return after a rejection (studies record: up to 70% of users who encountered a problem during onboarding go to an alternative service and do not return).
For most digital services, CAC alone already makes a false rejection unprofitable — even without taking LTV into account. If acquiring one user costs 2,000 rubles, and the share of false rejections is 5% of the application flow, then with 1,000 applications per month the company loses 100,000 rubles on marketing costs alone that did not convert into customers.
The third — the deterioration of operational metrics. A growth in the share of false rejections increases the load on operators, reduces onboarding conversion, and worsens the NPS. Indirectly, this reduces the effectiveness of all paid acquisition channels: the same costs convert into a smaller number of active customers.
To calculate the cumulative impact, an aggregated indicator is used:
Monthly losses from false rejections = N_applications × FRR × (CAC + LTV × p_churn) + N_applications × FRR × Cost_manual_review
Where FRR is the share of false rejections out of the total number of legitimate applications, and p_churn is the share of customers who did not return after a rejection.
An FRR above 3-5% for a typical digital service means that the operational savings from KYC automation are partially or fully offset by losses from missed customers. The boundary value is individual and depends on the ratio of LTV to CAC of the specific business.
An FRR above 3–5% means that a significant part of the marketing budget burns up already at the verification stage: legitimate customers are rejected for technical reasons, and the CAC already invested in acquiring them does not convert into revenue. Reducing FRR without a growth in FAR is a task of algorithm accuracy rather than tightening thresholds.
The Enface module ensures a biometric comparison accuracy of 99.74% — the probability of error is 1 in 1 million comparisons. Liveness/PAD works with an accuracy of 99.9%, AI-OCR verifies documents with an accuracy of 99.85% for printed formats. Together, this reduces the number of false rejections caused by the limitations of the algorithms — based on implementation practice, the increase in onboarding conversion is up to 15%. The exact effect depends on the initial FRR in your flow and the quality of the incoming data. We will assess your scenario and propose the optimal configuration.
How to calculate the price of a false approval
A false approval (a false negative, FN; in biometric systems — the False Acceptance Rate, FAR) is a situation where the KYC system lets a fraudster through: approves a forged document, accepts someone else’s biometrics, ignores anti-fraud signals. Unlike a false rejection, it carries not only direct losses but also regulatory and reputational risk.
The price of a false approval is made up of four components.
The first — direct damage from fraud. A fraudster who was let through uses the opened account: takes out a loan, initiates transactions, uses bonuses, makes returns. The size of the damage depends on the product: for microloans — the amount of the loan issued, for a payment service — the volume of unauthorized operations, for a marketplace — the cost of fraudulent orders.
The second — regulatory fines. A person on a sanctions list, a PEP, or a participant in laundering schemes who is let through is a direct violation of the requirements of Federal Law 115-FZ (for the Russian market), the AMLD directive (for the European one), and the international FATF standards. The global volume of AML fines in 2024 amounted to $4.6 billion (Fenergo, 2024), and in the first half of 2025 alone — $1.23 billion, which is 4.2 times higher than the same period of 2024. The size of the fine for a specific incident can exceed the direct damage from fraud by orders of magnitude: in 2025, the regulator NYDFS imposed a fine of $48.5 million on Paxos Trust for systematic gaps in KYC and AML control.
The third — remediation costs. After a case of false approval is identified, the company incurs costs for the investigation, blocking the account, refunding the affected parties (if applicable), and fixing the systematic vulnerability. In the corporate segment, the remediation of one major incident can cost more than the annual budget for KYC checks.
The fourth — reputational damage. The most difficult component to quantify. A publicly known case of letting through a fraudster or a sanctions violator leads to customer churn, a decline in investor confidence, and media damage, the elimination of which requires prolonged effort.
The formula for calculating the cost of one false approval:
The price of a false approval (per unit) = Direct_fraud_loss + Fine_risk + Remediation_cost + Reputational_cost
Where:
- Direct_fraud_loss — the direct damage from a specific fraudulent operation (the average check for the product multiplied by the statistical coefficient of the fraudster’s use of the account before detection);
- Fine_risk — the expected cost of regulatory risk: the probability of the regulator initiating an inspection multiplied by the typical range of sanctions for this type of violation;
- Remediation_cost — the direct costs of investigation and correction;
- Reputational_cost — the estimated losses from customer churn and reduced conversion, calculated using the LTV and CAC models.
In practice, Fine_risk and Reputational_cost are often not included in the calculation due to the difficulty of assessment — this is precisely what leads to the underestimation of the real price of a false approval. A more workable approach: calculate the expected direct losses (FAR × average damage per incident), and include regulatory and reputational risk as non-financial constraints when choosing the acceptable FAR threshold.
A boundary benchmark for FAR: for most regulated financial services, practically any non-zero FAR value for PEP/sanctions is unacceptable from a regulatory standpoint — regardless of its economic effect. In segments with a lower regulatory burden (online services, retail), the acceptable FAR is determined by the ratio of the direct losses from fraud to the cost of tightening the verification thresholds.
FRR and FAR are inversely related. Lowering the acceptance threshold reduces the share of false rejections but increases the risk of false approvals — and vice versa. The task of the system is not to minimize one of the indicators but to find a working point on the FRR/FAR curve at which the total losses (from rejections and from approvals) are minimal for the specific business model. Reducing FRR at an unchanged FAR is a direct increase in revenue rather than just a technical indicator of the system.
Choosing a point on the FRR/FAR curve is a commercial decision that relies on concrete figures: the acquisition cost, LTV, regulatory constraints, and the real losses from each type of error. Translating this calculation into a working configuration is impossible without a configurable system.
The NeuroVision platform makes it possible to manage decision thresholds in the back office without changing the integration code — shifting the FRR/FAR balance for a specific product, channel, or audience risk profile. The AML module with daily database updates controls FAR for sanctions lists and PEP — areas where any non-zero FAR value is regulatorily unacceptable. The platform’s availability SLA is 99.99%, the trial period is up to one month, which makes it possible to check the operation of the configuration on a real flow before the full launch. We will agree on the parameters of your business model and select a scenario with the optimal balance for your product.
The economics of KYC becomes manageable exactly when three key parameters — the cost of an approved customer, the price of a false rejection, and the price of a false approval — are translated into concrete figures. CPAC reveals the real unit cost of onboarding and shows where exactly money is lost: in repeat attempts, in unsuccessful sessions, or in the share of manual checks. The price of errors completes the picture: a false rejection is a burned marketing budget and lost revenue; a false approval is direct damage plus regulatory and reputational risk that is hard to quantify but impossible to ignore.
Choosing a working point on the FRR/FAR curve is a commercial rather than a technical decision. It is determined by the ratio of LTV to CAC, regulatory constraints, and the real losses from each type of error, calculated using the described formulas. A verification system for which these parameters are known and regularly measured ceases to be a cost item with an unpredictable impact on the business — and becomes a tool for managing conversion and compliance at the same time.