AO Identity is a digital identity capability for secure onboarding, identity verification and biometric authentication, powered by Facephi technology and implemented, integrated and supported by AO. It brings document verification, liveness detection, facial and voice biometrics, identity orchestration and fraud signals into a single journey that can be embedded into digital channels.
AO Identity is designed for organisations that need to know who they are dealing with at onboarding, at login and at high-risk moments in a customer journey, without forcing customers into branches or manual processes.
The challenge
What makes this hard today
Onboarding drop-off
Manual, document-heavy onboarding journeys lose customers before an account is ever opened.
Identity fraud
Stolen documents, synthetic identities, deepfakes and presentation attacks target digital channels first.
Fragmented verification
Document checks, biometrics, database lookups and manual review often live in disconnected systems.
Regulatory pressure
KYC, AML and data-protection obligations require evidence, auditability and lawful processing of biometric data.
Weak authentication
Passwords and OTPs are inherited from an older era and are routinely bypassed by social engineering.
Inconsistent channels
Web, mobile, contact centre and branch journeys apply different identity standards to the same customer.
Capabilities
A complete digital identity capability
Facephi technology provides the verification and biometric engines. AO provides the architecture, integration, governance and operating model around them.
Digital onboarding and eKYC
Remote onboarding that verifies an identity document, extracts its data and confirms the person presenting it, inside your own digital channel.
—Guided document capture
—Document authenticity checks
—OCR extraction
—Face match to document
—Liveness detection
—Configurable decisioning
Biometric authentication
Return customers are recognised by who they are rather than by what they can remember, with step-up available for higher-risk actions.
—Facial authentication
—Voice authentication
—Passwordless login
—Step-up authentication
—Session and device signals
Fraud and attack defence
Detection of presentation attacks, tampered documents and manipulated media at the point of capture.
—Passive liveness
—Active liveness
—Presentation-attack detection
—Deepfake and injection signals
—Document tamper detection
Identity orchestration
Verification steps are sequenced into journeys that differ by product, channel, market and risk appetite.
—Journey configuration
—Risk-based routing
—Fallback and assisted paths
—Manual review workflow
—Evidence and audit trail
How it works
From first interaction to every return visit
AO Identity applies verification and authentication across the full customer lifecycle rather than only at sign-up.
1
Stage 1: Capture
Capture an identity document and a live selfie inside the digital channel.
Guided document capture
Selfie capture
Mobile SDK
Web SDK
Assisted and remote channels
2
Stage 2: Verify the document
Check the identity document for authenticity, tampering and data consistency.
Document authenticity checks
OCR data extraction
Security-feature validation
Expiry and format checks
Supported document types by market
3
Stage 3: Prove the person
Confirm that a real, present person is presenting the document.
Passive and active liveness
Presentation-attack detection
Face matching against the document
Deepfake and injection signals
4
Stage 4: Enrol
Create a governed biometric identity record with lawful consent captured.
Biometric template creation
Consent capture
Data-minimisation controls
Retention configuration
5
Stage 5: Decide
Orchestrate results into an approve, refer or decline outcome.
Configurable thresholds
Risk rules
Manual review queue
Audit evidence
6
Stage 6: Authenticate
Re-authenticate the returning customer at login and at high-risk actions.
Facial authentication
Voice authentication
Step-up authentication
Passwordless journeys
7
Stage 7: Monitor and tune
Review outcomes and tune thresholds against fraud and conversion performance.
Verification analytics
False-rejection review
Threshold calibration
Ongoing AO support
Core components
How a verification journey runs
A journey is assembled from capture, verification, biometric and decision components. Each component can be tuned per product, channel and market without rebuilding the journey.
Capture SDKs
Embedded web and mobile capture components that guide the customer through document and selfie capture with quality checks applied on device.
Verification services
Document authenticity, data extraction, face matching and liveness services that return structured results and confidence scores.
Biometric identity store
Governed storage of biometric templates with consent, retention and data-minimisation controls applied to the deployment model chosen.
Decision and orchestration layer
Configurable thresholds, rules and routing that turn verification results into approve, refer or decline outcomes with an audit trail.
Review and operations console
Queues and evidence views for the teams that handle referred cases, exceptions and assisted onboarding.
Architecture
A layered identity architecture
01
Experience layer
Capture and authentication components embedded into your own web and mobile channels so the journey stays inside your brand.
Web SDK
Mobile SDK
Assisted capture
Accessibility considerations
Journey UX configuration
02
Identity services layer
Facephi verification, biometric and anti-fraud services that evaluate documents, faces, voices and attack signals.
Document verification
Facial biometrics
Voice biometrics
Liveness and attack detection
Biometric matching
03
Orchestration and governance layer
AO-implemented integration, decisioning, consent, retention and audit controls that make the capability operable and defensible.
Journey orchestration
Core and CRM integration
Consent and retention controls
Audit and evidence
Monitoring and analytics
Platform depth
What each journey produces
Every verification and authentication event produces structured, reviewable evidence rather than a simple pass or fail.
Verification evidence
Document authenticity result
Extracted identity data
Face-match score
Liveness result
Attack-detection signals
Captured media references
Decision record
Approve, refer or decline outcome
Thresholds applied
Rules triggered
Reviewer actions
Timestamped audit trail
Operational insight
Conversion and drop-off by step
False-rejection indicators
Attack attempt patterns
Channel and device breakdown
Threshold tuning inputs
Outcomes
What the capability is designed to improve
01Open accounts and activate customers remotely, without branch visits.
02Reduce onboarding drop-off caused by manual document processes.
03Detect presentation attacks, tampered documents and manipulated media at capture.
04Replace password and OTP dependence with biometric authentication.
05Apply one identity standard across web, mobile and assisted channels.
06Produce consistent, auditable evidence for KYC and AML processes.
07Reduce manual review volumes through better calibration.
Delivered by AO
How AO delivers AO Identity
Facephi supplies the identity technology. AO is responsible for assessment, architecture, integration, rollout and ongoing support.
AO implementation services
Identity and onboarding assessment
Review current onboarding, verification, fraud exposure, channel mix and regulatory obligations.
Journey and solution design
Design verification journeys, thresholds, fallback paths and the target integration architecture.
Integration
Integrate identity services with core banking, CRM, case management, customer channels and existing fraud controls.
Privacy and compliance enablement
Support consent, lawful basis, retention, data-residency and audit requirements with your legal and compliance teams.
Testing and rollout
Pilot with controlled volumes, calibrate thresholds and roll out by product, channel or market.
AO managed and support services
Operational support
Ongoing support for the deployed identity capability and its integrations.
Threshold and performance tuning
Review verification outcomes, drop-off and fraud signals, and tune configuration accordingly.
Change and release management
Manage configuration changes, upgrades and new journey rollouts under governance.
Reporting
Provide verification, conversion and attack-pattern reporting to business and risk stakeholders.
Where it applies
Where AO Identity is applied
Bank account opening
Remote account opening with document verification and liveness before activation.
Mobile money and wallet registration
Verify subscribers at registration and at upgrade to higher transaction tiers.
Lending and credit applications
Confirm applicant identity before affordability and credit decisioning.
Insurance onboarding and claims
Verify policyholders at onboarding and at claim submission.
Passwordless login
Replace password and OTP journeys with biometric authentication.
High-risk transaction step-up
Re-verify the customer before payments, beneficiary changes or profile updates.
Contact-centre verification
Verify callers with voice biometrics instead of knowledge-based questions.
Employee and contractor onboarding
Verify workforce identities in distributed or remote operating models.
Government and public services
Verify citizens for digital service access where policy permits.
Telecommunications SIM registration
Meet subscriber registration obligations through verified digital journeys.
Delivery model
Deployment models
Deployment depends on data-residency, privacy, security, integration and volume requirements. The final model is confirmed during assessment and licensing.
Cloud
Identity services consumed as a managed cloud capability, integrated into your channels.
Regional or in-country
Deployment aligned to data-residency and sovereignty requirements where that is supported for the licensed configuration.
On-premise or private cloud
Deployment inside your own environment where regulatory or security policy requires it.
Hybrid
Capture and orchestration in your environment with selected services consumed externally.
Proof in practice
AO and Facephi
Approach
AO Identity is delivered through AO's partnership with Facephi, a specialist digital identity provider. Facephi supplies the identity verification, biometric and anti-fraud technology. AO provides the assessment, architecture, integration, deployment, governance support and ongoing services that turn the technology into an operating capability.
Where it applies
Typical engagement profiles include banks, mobile-money and wallet providers, insurers, lenders, telecommunications operators and public-sector programmes that need remote onboarding and stronger authentication.
Customer identities are withheld. Engagements are described at a level agreed for public reference.
Questions
Frequently asked
AO Identity supports identity verification, onboarding and authentication processes. It does not replace legal advice, sanctions screening platforms, accountable customer due diligence decisions or regulatory reporting obligations. Verification outcomes, thresholds and fallback processes remain the responsibility of the customer. Supported document types, biometric modalities, languages and jurisdictional coverage depend on the Facephi product configuration licensed for the engagement and are confirmed during assessment. Any accuracy, performance or certification claims are only made where they can be evidenced for the specific configuration deployed.
Bring us the problem that hasn't moved in two years.
A discovery session is a working conversation about scope, constraints and what a credible first release looks like.