News

Identy.io’s mobile-first biometrics designed to tackle Nigeria’s KYC, fraud challenges

Identy.io’s mobile-first biometrics designed to tackle Nigeria’s KYC, fraud challenges

By Enitan Abdultawab

The Regional Head for Africa at Identy.io, Ola Olasiyan has said the company’s mobile-first biometric solution is designed to tackle persistent Know Your Customer (KYC) challenges and rising fraud cases in Nigeria’s banking and fintech sectors by simplifying and securing customer onboarding.

Speaking at the unveiling, Olasiyan, said the platform was designed to simplify and strengthen customer onboarding across financial institutions.

He explained that the solution helps organisations accurately identify users during onboarding processes.

“Identy.io comes in KYC — Know Your Customer — and a lot of Nigerians have KYC issues that we’ve been trying to solve. Onboarding in banking, onboarding with companies, onboarding with fintech companies and payment companies — they need to know who that person is that’s coming to visit with them. And that’s where we come in, to help them identify who that person is,” he said.

Olasiyan noted that the system combines biometrics with mobile devices, eliminating the need for bulky verification hardware.

“Not just biometrics, but biometrics and mobile devices. So making it seamless to do, instead of using those bulky hardware systems to capture data on the internet,” he added.

He stressed that fraud prevention is central to the company’s model, noting that data is sourced directly rather than relying on third-party datasets.

“What we do is that we are more focused on fraud prevention. What that means is that we fetch data directly from the source and use proper metrics to verify the data,” he said.

According to him, the platform internalises its own verification metrics to improve security and reliability.

“So, everything we do around fraud metrics is not dependent on recycled third-party data. We become the source of the data ourselves and then internalise it into the metrics we want to save and secure. That’s the difference,” he explained.

He added that the idea emerged after identifying gaps in existing identity systems.

“That was actually one of the key things that made me realise there was a need to do this. I had already seen gaps in the system and that inspired the idea behind it,” he said.

Olasiyan further said the system improves both security and user experience by operating directly on mobile devices.

“With this system, it becomes more secure and more comfortable for users. That’s the technical aspect of it. It creates an extra security layer for the tool and improves protection beyond what currently exists,” he said.

He added that the platform does not require access to personal data to function.

“We do not need your personal data to carry out what we do,” he said.

Also speaking, Identy.io chief executive officer, Jesus Aragon, said traditional authentication systems are no longer effective against modern fraud tactics.

“This is why we are here. Traditional authentication methods like passwords, OTPs and SMS no longer work effectively. It has become very easy for fraudsters to use social engineering to commit fraud,” he said.

He added that properly implemented biometrics can significantly reduce fraud incidents.

“But once you introduce biometrics properly, fraud can drop drastically. For example, when fingerprint verification is introduced for transactions, fraud levels can fall almost immediately,” he said.

Aragon warned that identity verification must be properly executed to avoid new risks.

“Our approach is that biometrics remains the best way to verify identity, but it has to be done properly. You must ensure that when you are capturing a face or fingerprint, it is a real face or real fingerprint — not a mask, photocopy, scanned image or fake identity,” he said.

He noted that fraud tactics have evolved from physical impersonation to deepfake-based attacks.

“That was the old method of attack. A year or two ago, people were using masks and similar tricks. But now, everything is about deepfakes,” he said.

Aragon explained that attackers can now generate synthetic identities using publicly available images.

“Someone can go to LinkedIn, download my face, create a deepfake and inject it directly into the system. They can bypass the camera entirely and use an artificial image instead,” he said.

He added that such attacks scale quickly due to low production costs compared to physical impersonation methods.

“These attacks scale very quickly because unlike creating physical masks, which takes time and money, deepfakes can be produced rapidly and used repeatedly at scale,” he said.

He emphasised that mobile-based biometric systems are critical to addressing these risks.

“Our approach is that biometrics is necessary for identity verification, but if it is implemented wrongly, it can create even bigger problems,” he said.

“That is why we believe it has to be done through mobile phones, because almost everyone already has a smartphone. Our tools run entirely on the phone, meaning the process is not dependent on a central server.”

He added that the system prioritises privacy and convenience.

“The system is designed with privacy in mind because everything happens directly on the user’s device,” he said.

“So, you do biometrics on the phone because it improves usability. People no longer need to go physically to a bank branch or office before they can verify their identity.

“At the same time, it has to be done securely, because biometrics without proper security creates a major risk,” he added.