Identity, financial and business verifications for South African KYC: Every verification. One flow.

This is the full library, across people, money and companies, drawn from Home Affairs (DHA), the CIPC, government payroll, participating banks, credit bureau data and sanctions and money-laundering watchlists. Every verification returns its result in real time. Run just the ones you need, or chain several into a single flow your customer walks once.

How it fits together

A verification answers one question. A flow answers all of them at once.

A flow is several verifications, chained into one journey. Instead of running one verification at a time and stitching the results together afterwards, you bundle the ones your process actually needs and run them as a single sequence. Build it once in the portal, or call it from the API.

Every verification below works either way. Send the flow as a link for the customer to complete remotely, run it face to face on the spot, or bulk-send it to a whole list. The verifications are the same in every channel, and so is the record you get back.

  1. SA ID
  2. Facial Match
  3. Bank account
  4. AML & PEP

See a whole branded onboarding journey →

People & identity verifications

Who the person is, whether they are there in person, and how to reach them.

ID Verification

  • Source: Home Affairs (DHA)

Confirms a South African ID against Department of Home Affairs records.

Queries the details on record at the Department of Home Affairs against the South African ID number, confirms the validity of the identity, and returns the record Home Affairs holds in real time, in seconds. Facial Match, which runs after it, compares a selfie against the latest photograph Home Affairs holds for the number. It is the verification most South African KYC flows open with, because every result after it is easier to read once the ID number itself is confirmed.

What ID Verification confirms, and what it does not

Facial Match

  • Source: Home Affairs (DHA)
  • Biometric data
  • Camera required

Compares a selfie with the latest photo the DHA holds for the ID number and returns a match probability.

Compares a selfie provided by the ID holder with the latest photograph the Department of Home Affairs holds for the ID number (ID Verification runs first) and returns a probability that the two faces match; you set the probability you accept. Camera access is required; the customer can complete it in front of you or over a remote link.

What Facial Match confirms, and what it does not

Liveness Test

  • Source: Biometric capture
  • Biometric data
  • Camera required

Returns a pass or fail result for whether a living person, not a photograph or a recording, completed the verification.

Returns a pass or fail result for whether a living person, rather than a photograph or a recording, completed the capture. The person is asked to move their face into the on-screen frame. It runs together with ID Verification and Facial Match.

What Liveness Test confirms, and what it does not

Contact Verification

  • Source: Credit bureau data
  • Bureau-sourced

Retrieves the contact information linked to a South African ID number.

To corroborate the contact details your customer gave you, it returns what bureau-sourced records hold for their South African ID number: mobile, landline and work numbers, known addresses and email addresses, each item date-stamped. Because the answer comes from bureau records rather than from what the person typed into your form, you can compare the two. The results are for verification, not marketing or tracing.

What Contact Verification confirms, and what it does not

Financial verifications

Whether the account is registered to them, what their credit profile says, and when they are most likely to be able to pay.

Bank Account Verification

  • Source: Participating banks

Confirms a bank account exists and is registered to the customer.

Verifies whether the provided bank account details exist and are registered to the customer’s name and South African ID number, or, for a business account, a company registration number. It also answers whether the account has been open for more than three months, whether it accepts debits and credits, and whether the mobile number you were given matches the number the bank holds. Pair it with ID Verification when you need the person and the account confirmed in the same flow.

What Bank Account Verification confirms, and what it does not

Credit Score Indicator

  • Source: Credit bureau data
  • Bureau-sourced

Returns the customer’s credit score and risk rating.

Provides insight into the customer’s credit profile, including their credit score and risk rating. The score is issued by a registered credit bureau. You need a lawful ground for the enquiry, and you certify its purpose to the bureau.

What Credit Score Indicator confirms, and what it does not

Collection Date Indicator

  • Source: Credit bureau data
  • Bureau-sourced

The three days of the month a customer is most likely to have funds for a debit order, ranked, from credit bureau data on past successful collections.

Determines the three days of the month (for example the 20th or 25th) on which a customer is most likely to have funds available for payment, based on successful collections made against their accounts by other creditors, listed in order of preference.

What Collection Date Indicator confirms, and what it does not

Business & compliance verifications

For when your customer is a company, and for the screening a compliance function has to be able to evidence.

CIPC Company Verification

  • Source: CIPC

Confirms company registration details with the CIPC.

Verifies company registration details with the CIPC (Companies and Intellectual Property Commission) and returns the report the CIPC holds on the registered entity: address, directors and whether they are active, business history, auditors, tax number, enterprise type, and whether it is in business or liquidated. This is the verification to run when the customer in front of you is a business rather than an individual.

What CIPC Company Verification confirms, and what it does not

Director Search

  • Source: CIPC

Finds the companies a person is a director of.

Confirms whether an individual is listed as a director of any company registered with the CIPC in South Africa, and whether each directorship is active. Useful for corroborating identity, or for insight into a person’s business affiliations before you extend them credit or sign them on.

What Director Search confirms, and what it does not

Public Servant Verification

  • Source: Government payroll

Checks, from a South African ID number, whether a public-service employment record exists and returns the department.

Returns whether a public-service employment record exists for the South African ID number you submit and, where one does, the department it sits in.

What Public Servant Verification confirms, and what it does not

AML & PEP Screening

  • Source: Sanctions and money-laundering watchlists

Screens against politically exposed persons (PEP), sanctions and money-laundering watchlists in one verification.

Screens individuals and businesses against politically exposed persons (PEP), sanctions and money-laundering watchlists in one verification. Where your process requires screening, this is the step that produces a screening record you can file. Each screening is a point-in-time result: no match means nothing in the list data screened matched, as that data stood when the screening ran.

What AML & PEP Screening confirms, and what it does not

Where it comes from

Where the answers come from

Each answer comes from the source shown in the table above. Contact Verification, Credit Score Indicator and Collection Date Indicator return bureau-sourced information about a person, while AML & PEP Screening returns entries on lists compiled by third parties, not something a South African credit bureau holds about your customer. That difference matters when you write your own privacy notice.

About results. Veriflow will perform the Services with the reasonable skill and care of a competent provider of identity-verification services in South Africa. Veriflow transmits results sourced from third-party data sources, including registered South African credit bureaux, banks, official registers and published watchlists. Veriflow does not compile that underlying data, does not warrant its accuracy, completeness or currency, and gives no warranty that any verification result is correct.

The result

A result you can act on, and the record behind it.

In a flow, the record builds as your customer completes each verification, with the full audit trail underneath. When it lands, download the PDF and hand it to your compliance officer, or file it.

01

The result

One filed record instead of a dozen loose results: the identity record, the account confirmation, the score and risk rating, the screening outcome, all in one place and all timestamped.

02

The audit trail

Every flow that runs is logged: which flow, who ran it, and exactly when. A workflow record gives your auditor one place to look.

03

Retention and deletion

You set how long records are kept for each flow; when that period ends they are deleted automatically, and you can delete a record at any time, for example when your customer asks. Where you configure a retention period for your data, you set that period and are the responsible party for the choice. Deleting a record you are not required to keep takes a click, and you keep the proof you did.

POPIA and FICA duties stay yours. Veriflow gives you the tooling to meet them: access control, retention controls, an audit trail, and record deletion. See the compliance tooling →

Questions about the library

What verifications does Veriflow offer?

The verifications fall into three groups: people and identity (ID Verification, Facial Match, Liveness Test, Contact Verification), financial (Bank Account Verification, Credit Score Indicator, Collection Date Indicator) and business and compliance (CIPC Company Verification, Director Search, Public Servant Verification, AML and PEP Screening).

Can I run a single verification on its own?

Most can. Two cannot: Facial Match runs after ID Verification, on the same ID number, and compares the selfie against the latest photograph Home Affairs holds for it; the Liveness Test runs together with both.

Which verifications use biometric data?

Facial Match and Liveness Test. Both require camera access, and both process biometric data, which POPIA treats as special personal information. How long records are kept is up to you: see retention and deletion.

What does bank account verification confirm in South Africa?

It verifies whether the bank account details provided exist and are registered to the customer’s name and South African ID number (or, for a business account, a company registration number) against participating banks. It also answers whether the account has been open for more than three months, whether it accepts debits and credits, and whether the mobile number you were given matches the number the bank holds.

Which verifications are available through the API?

All of them. Every verification is available through the API, with a sandbox to build against (credentials on request). The portal runs the same set for ops, compliance and credit teams without code.

See these verifications run against your own requirements.

Book a quick demo. We’ll walk through the verifications your process actually needs, build the flow, and show you what comes back.

Veriflow (Pty) Ltd · Reg. no. 2023/584644/07
51 Ingersol Road, Lynnwood Glen, Pretoria, 0081, South Africa
+27 83 209 0827 · support@veriflow.co.za