AOne·The Enterprise Digital Experience Platform of AO Group

All products
Powered by Facephi

AO Identity

Verify identities with confidence.

The platform

What AO Identity is

AO Identity is a digital identity capability for secure onboarding, identity verification and biometric authentication, powered by Facephi technology and implemented, integrated and supported by AO. It brings document verification, liveness detection, facial and voice biometrics, identity orchestration and fraud signals into a single journey that can be embedded into digital channels. AO Identity is designed for organisations that need to know who they are dealing with at onboarding, at login and at high-risk moments in a customer journey, without forcing customers into branches or manual processes.

The challenge

What makes this hard today

Onboarding drop-off

Manual, document-heavy onboarding journeys lose customers before an account is ever opened.

Identity fraud

Stolen documents, synthetic identities, deepfakes and presentation attacks target digital channels first.

Fragmented verification

Document checks, biometrics, database lookups and manual review often live in disconnected systems.

Regulatory pressure

KYC, AML and data-protection obligations require evidence, auditability and lawful processing of biometric data.

Weak authentication

Passwords and OTPs are inherited from an older era and are routinely bypassed by social engineering.

Inconsistent channels

Web, mobile, contact centre and branch journeys apply different identity standards to the same customer.

Capabilities

A complete digital identity capability

Facephi technology provides the verification and biometric engines. AO provides the architecture, integration, governance and operating model around them.

Digital onboarding and eKYC

Remote onboarding that verifies an identity document, extracts its data and confirms the person presenting it, inside your own digital channel.

  • Guided document capture
  • Document authenticity checks
  • OCR extraction
  • Face match to document
  • Liveness detection
  • Configurable decisioning

Biometric authentication

Return customers are recognised by who they are rather than by what they can remember, with step-up available for higher-risk actions.

  • Facial authentication
  • Voice authentication
  • Passwordless login
  • Step-up authentication
  • Session and device signals

Fraud and attack defence

Detection of presentation attacks, tampered documents and manipulated media at the point of capture.

  • Passive liveness
  • Active liveness
  • Presentation-attack detection
  • Deepfake and injection signals
  • Document tamper detection

Identity orchestration

Verification steps are sequenced into journeys that differ by product, channel, market and risk appetite.

  • Journey configuration
  • Risk-based routing
  • Fallback and assisted paths
  • Manual review workflow
  • Evidence and audit trail
How it works

From first interaction to every return visit

AO Identity applies verification and authentication across the full customer lifecycle rather than only at sign-up.

  1. Stage 1: Capture

    Capture an identity document and a live selfie inside the digital channel.

    • Guided document capture
    • Selfie capture
    • Mobile SDK
    • Web SDK
    • Assisted and remote channels
  2. Stage 2: Verify the document

    Check the identity document for authenticity, tampering and data consistency.

    • Document authenticity checks
    • OCR data extraction
    • Security-feature validation
    • Expiry and format checks
    • Supported document types by market
  3. Stage 3: Prove the person

    Confirm that a real, present person is presenting the document.

    • Passive and active liveness
    • Presentation-attack detection
    • Face matching against the document
    • Deepfake and injection signals
  4. Stage 4: Enrol

    Create a governed biometric identity record with lawful consent captured.

    • Biometric template creation
    • Consent capture
    • Data-minimisation controls
    • Retention configuration
  5. Stage 5: Decide

    Orchestrate results into an approve, refer or decline outcome.

    • Configurable thresholds
    • Risk rules
    • Manual review queue
    • Audit evidence
  6. Stage 6: Authenticate

    Re-authenticate the returning customer at login and at high-risk actions.

    • Facial authentication
    • Voice authentication
    • Step-up authentication
    • Passwordless journeys
  7. Stage 7: Monitor and tune

    Review outcomes and tune thresholds against fraud and conversion performance.

    • Verification analytics
    • False-rejection review
    • Threshold calibration
    • Ongoing AO support
Core components

How a verification journey runs

A journey is assembled from capture, verification, biometric and decision components. Each component can be tuned per product, channel and market without rebuilding the journey.

Capture SDKs

Embedded web and mobile capture components that guide the customer through document and selfie capture with quality checks applied on device.

Verification services

Document authenticity, data extraction, face matching and liveness services that return structured results and confidence scores.

Biometric identity store

Governed storage of biometric templates with consent, retention and data-minimisation controls applied to the deployment model chosen.

Decision and orchestration layer

Configurable thresholds, rules and routing that turn verification results into approve, refer or decline outcomes with an audit trail.

Review and operations console

Queues and evidence views for the teams that handle referred cases, exceptions and assisted onboarding.

Architecture

A layered identity architecture

01

Experience layer

Capture and authentication components embedded into your own web and mobile channels so the journey stays inside your brand.

  • Web SDK
  • Mobile SDK
  • Assisted capture
  • Accessibility considerations
  • Journey UX configuration
02

Identity services layer

Facephi verification, biometric and anti-fraud services that evaluate documents, faces, voices and attack signals.

  • Document verification
  • Facial biometrics
  • Voice biometrics
  • Liveness and attack detection
  • Biometric matching
03

Orchestration and governance layer

AO-implemented integration, decisioning, consent, retention and audit controls that make the capability operable and defensible.

  • Journey orchestration
  • Core and CRM integration
  • Consent and retention controls
  • Audit and evidence
  • Monitoring and analytics
Platform depth

What each journey produces

Every verification and authentication event produces structured, reviewable evidence rather than a simple pass or fail.

Verification evidence

  • Document authenticity result
  • Extracted identity data
  • Face-match score
  • Liveness result
  • Attack-detection signals
  • Captured media references

Decision record

  • Approve, refer or decline outcome
  • Thresholds applied
  • Rules triggered
  • Reviewer actions
  • Timestamped audit trail

Operational insight

  • Conversion and drop-off by step
  • False-rejection indicators
  • Attack attempt patterns
  • Channel and device breakdown
  • Threshold tuning inputs
Outcomes

What the capability is designed to improve

  • 01Open accounts and activate customers remotely, without branch visits.
  • 02Reduce onboarding drop-off caused by manual document processes.
  • 03Detect presentation attacks, tampered documents and manipulated media at capture.
  • 04Replace password and OTP dependence with biometric authentication.
  • 05Apply one identity standard across web, mobile and assisted channels.
  • 06Produce consistent, auditable evidence for KYC and AML processes.
  • 07Reduce manual review volumes through better calibration.
Delivered by AO

How AO delivers AO Identity

Facephi supplies the identity technology. AO is responsible for assessment, architecture, integration, rollout and ongoing support.

AO implementation services

Identity and onboarding assessment
Review current onboarding, verification, fraud exposure, channel mix and regulatory obligations.
Journey and solution design
Design verification journeys, thresholds, fallback paths and the target integration architecture.
Integration
Integrate identity services with core banking, CRM, case management, customer channels and existing fraud controls.
Privacy and compliance enablement
Support consent, lawful basis, retention, data-residency and audit requirements with your legal and compliance teams.
Testing and rollout
Pilot with controlled volumes, calibrate thresholds and roll out by product, channel or market.

AO managed and support services

Operational support
Ongoing support for the deployed identity capability and its integrations.
Threshold and performance tuning
Review verification outcomes, drop-off and fraud signals, and tune configuration accordingly.
Change and release management
Manage configuration changes, upgrades and new journey rollouts under governance.
Reporting
Provide verification, conversion and attack-pattern reporting to business and risk stakeholders.
Where it applies

Where AO Identity is applied

Bank account opening

Remote account opening with document verification and liveness before activation.

Mobile money and wallet registration

Verify subscribers at registration and at upgrade to higher transaction tiers.

Lending and credit applications

Confirm applicant identity before affordability and credit decisioning.

Insurance onboarding and claims

Verify policyholders at onboarding and at claim submission.

Passwordless login

Replace password and OTP journeys with biometric authentication.

High-risk transaction step-up

Re-verify the customer before payments, beneficiary changes or profile updates.

Contact-centre verification

Verify callers with voice biometrics instead of knowledge-based questions.

Employee and contractor onboarding

Verify workforce identities in distributed or remote operating models.

Government and public services

Verify citizens for digital service access where policy permits.

Telecommunications SIM registration

Meet subscriber registration obligations through verified digital journeys.

Delivery model

Deployment models

Deployment depends on data-residency, privacy, security, integration and volume requirements. The final model is confirmed during assessment and licensing.

Cloud

Identity services consumed as a managed cloud capability, integrated into your channels.

Regional or in-country

Deployment aligned to data-residency and sovereignty requirements where that is supported for the licensed configuration.

On-premise or private cloud

Deployment inside your own environment where regulatory or security policy requires it.

Hybrid

Capture and orchestration in your environment with selected services consumed externally.

Proof in practice

AO and Facephi

Approach

AO Identity is delivered through AO's partnership with Facephi, a specialist digital identity provider. Facephi supplies the identity verification, biometric and anti-fraud technology. AO provides the assessment, architecture, integration, deployment, governance support and ongoing services that turn the technology into an operating capability.

Where it applies

Typical engagement profiles include banks, mobile-money and wallet providers, insurers, lenders, telecommunications operators and public-sector programmes that need remote onboarding and stronger authentication.

Customer identities are withheld. Engagements are described at a level agreed for public reference.

Questions

Frequently asked

AO Identity supports identity verification, onboarding and authentication processes. It does not replace legal advice, sanctions screening platforms, accountable customer due diligence decisions or regulatory reporting obligations. Verification outcomes, thresholds and fallback processes remain the responsibility of the customer. Supported document types, biometric modalities, languages and jurisdictional coverage depend on the Facephi product configuration licensed for the engagement and are confirmed during assessment. Any accuracy, performance or certification claims are only made where they can be evidenced for the specific configuration deployed.

A discovery session is a working conversation about scope, constraints and what a credible first release looks like.