Compliance and vulnerable activities
Identify the foreign client, and record how you did it
A passport is the document a foreign client identifies themselves with. Read it once, feed the fields into the identification file, and keep the evidence that the read was verified against the document itself.
What gets reviewed is the file, not the formality
When the client is foreign, identification stops being a form with the national ID pre-filled. Someone types a name in another alphabet, a nine-character passport number and a nationality by hand, and that typing becomes the data the identification file is built on, screened against lists and reported with.
A capture error does not show up on the day of onboarding. It shows up months later, when the name in the file does not match the scanned document, or when a review asks why the file carries one date of birth and the passport another. By then the problem is not the lost minute: it is that the file does not hold up.
And there is a second question almost no flow answers: how do you know the read was correct? A typed field proves nothing. A field read off the document, with the standard check digits recomputed and the outcome recorded with a timestamp, does.
How it fits the onboarding you already run
It does not replace your identification procedure or your risk matrix. It replaces the manual capture of the document, and adds a record that the read was verified.
- 1
The client or your agent uploads the data page
From your own onboarding, your app or the counter. It is one API call carrying the image: there is no separate portal to send the client to, and no interface of ours appears in your flow.
- 2
The document fields come back
Given names, surname, nationality, issuing country, passport number, sex, date of birth and expiry date, each in its own field and ready to join the identification file without retyping.
- 3
The read is checked against the standard
A machine-readable zone carries check digits defined by ICAO 9303. They are recomputed field by field: when the passport number or a date does not agree, the response says so instead of handing back wrong data that looks right.
- 4
You keep the evidence beside the file
The response carries the outcome of that verification, with a timestamp and the id of the operation in your account. That is what you retain: not only what the passport said, but that the read agreed with the document, and when it happened.
What changes for a compliance team
A file that survives review
The foreign client data comes off the document, not off what the onboarding agent heard. When an audit compares the file against the passport copy, they match because they came from the same place.
Evidence of the read, not just the data
Every extraction reports whether the document check digits agreed. Retaining that result turns "we captured the passport" into something demonstrable with a date — the difference between asserting the control and evidencing it.
Less friction at onboarding
Identifying a foreign client stops taking twice as long as identifying a domestic one, so onboarding moves at the speed of the rest of the process and sales stops asking for exceptions.
The document is not stored on our side
The image is processed and discarded. What you retain about the client is your decision, in your systems, under your retention policy and your privacy notice.
Does this replace my customer identification procedure?
No. It replaces the capture of the document. Due diligence, risk scoring, list screening and building the file remain yours; what changes is that the data feeding them is read off the passport and arrives verified.
Does it serve the vulnerable activities regime?
It serves the step where a regulated party identifies a foreign client and takes the data off their identity document. What the identification file must contain and how long it is retained is set by the rules for your activity; we return the passport fields and the evidence that the read was verified.
What evidence is left of the read?
The check-digit outcome for the machine-readable zone, with the timestamp of the extraction and the id of the operation in your account. That is what you can retain alongside the file and produce in an audit.
Do you store the client data?
No. A successful extraction retains none of the document personal data on our side; only the usage record for billing remains. The image is discarded once processed.
What if the passport is expired or close to it?
The expiry date comes back as a field, so your own rule decides what to do with it. If you also need the six-month rule, our validity checker computes it and it is free.
What about Mexican clients?
Their voter credential is read by our INE service, which returns CURP, elector key and address. It is a separate account on the same integration model, and that site is in Spanish.