Written by: Karol Sobieraj, Founder & CEO, Digital Colliers
Socure just closed $156M at a $5.2B valuation and bought Fravity, an agentic-AI startup focused on identity fraud workflows. Read that as a signal, not a headline. The identity verification vendors are moving up-stack into decisioning and case management, and they're doing it by absorbing the agent layer rather than building it. If your bank still runs a document verifier, a device intelligence tool, and a sanctions screener as three separate contracts with three separate data schemas, the ground is moving under you.
What the deal actually signals
KYC vendors used to sell a check. You sent them a passport image or an SSN, they sent back a score. That was the whole relationship. Fravity gives Socure the ability to run multi-step reasoning across a case: pull the applicant's history, cross-reference device signals, ask follow-up questions, draft the SAR narrative. The vendor is no longer a check. It's a decisioning surface that sits inside your onboarding and monitoring stack.
The competitors will do the same thing within eighteen months. Alloy, Persona, Onfido, LexisNexis, they all have the money and the motive. When four of your vendors all offer agent-based decisioning, the one who wins the wallet share is the one whose data model your bank can actually feed.
Why the three-tool stack is about to hurt
Most mid-market banks I look at have this shape:
- One vendor for document and biometric verification at onboarding
- One vendor for transaction monitoring and sanctions
- One vendor for fraud scoring on payments and logins
Each one has its own case object. Each one writes to its own audit log. Each one has a separate reviewer queue. When AML transaction-monitoring false positives already run 85 to 95 percent at typical mid-market banks, adding three agent layers on top of three disconnected data models doesn't reduce the noise. It multiplies the reviewer surface area and makes every case harder to defend to a regulator.
The banks who will get value from the next generation of KYC agents are the ones with a single customer risk object that all three tools read from and write to. Everyone else is going to be renting intelligence that can't see the full picture.
The data model you actually need
Think of it as three layers, and be honest about which ones you have.
- A canonical customer risk record. One ID, one lifecycle, every signal from every vendor attached to it with provenance.
- An event log that captures every decision, every human override, every model version, timestamped and immutable.
- A policy layer that sits above the vendors, not inside them. Your risk appetite lives here, not in a Socure config screen.
If that sounds like plumbing, it is. It's also the thing that lets you swap vendors, run two in parallel for a bake-off, or add an agent workflow without ripping out the case management system. Around 95 percent of enterprise AI projects never reach production or ROI, and the ones that fail in financial services usually fail here, at the integration and audit layer, not at the model.
The regulatory clock is already running
DORA has been in force across the EU since 17 January 2025, which means your third-party risk register needs to actually reflect what these vendors are doing inside your decisioning path. Agent-based KYC is not a SaaS subscription anymore, it's an operational dependency. Under the SCHUFA ruling from the CJEU in December 2023, automated credit and risk scoring already carries GDPR exposure when it materially drives a decision about a person. GDPR fines reach up to €20M or 4 percent of global turnover, so the audit trail question is not academic.
EU AI Act Article 50 transparency obligations kick in on 2 August 2026. High-risk obligations follow on 2 December 2027. If your KYC vendor's agent denies an account and you can't reconstruct why, in plain language, with the model version and the input data, you own that gap. The vendor doesn't.
What to build in the next twelve months
Stop buying more point tools. Spend the budget on the canonical risk record and the event log instead. Pick one vendor per layer and negotiate hard on data export, model versioning, and reasoning traces. Assume every KYC vendor you use in 2027 will be running agents, and design so you can plug them in without another integration project. The banks that do this quietly this year will be the ones setting the terms of the next vendor cycle. Everyone else will be integrating whatever their incumbent ships them.

