The Death Loop

Written by Liam Chennells, CEO

Why the data your customer gives you is the real bottleneck in merchant onboarding - and what it's costing you...

The email nobody answers

Somewhere in your business there is a person whose entire job is sending emails that don't get replied to.

They're good at their job. They're diligent. They have a spreadsheet, or a Salesforce view, or if things have got really bad, a shared inbox with colour-coded flags. And every day they write some version of the same email:

Hi Maria, thanks for your application. To complete our review we'll need: a copy of your certificate of incorporation, proof of address for the registered office dated within the last three months, photo ID for both directors, and confirmation of any individuals holding more than 25% of the shares. Please reply to this email with the attachments.

Maria runs a nine-person business. She applied on a Tuesday because she wants to take card payments. She got this email on the Thursday. She'll open it on her phone on the Sunday, think "I'll do that Monday", and then not do it Monday. Eleven days later somebody sends a chaser. Fourteen days after that she uploads a bank statement that's four months old and a driving licence photo taken at an angle that makes it unreadable. Your analyst rejects both. Another email goes out.

Maria signs up with your competitor in week six.

Here's the part that should bother you: nothing in that story was a compliance failure. Every single step was performed correctly by capable people following an approved policy. The risk decision was sound. The controls worked.

And you still lost the customer, burned about forty hours of salaried time across the business, and have nothing to show for it.

This is the forgotten half of onboarding. Not the data you look up. The data you have to ask for and the Death Loop needed to get it.

What we're actually talking about

When the industry says "KYB", most people picture a lookup. You take a company name, you hit a registry, you get back a company number, a status, a list of officers, maybe a filing history. It feels like technology. It's fast, it's automated, it scales, and it's the bit every vendor demos.

That's not the hard part. That's never been the hard part.

The hard part is everything that has to come from the customer:

  • Director and officer verification. Not "this name appears on a filing" - an actual human, proving they are who they say they are, with a document and a face.
  • Ultimate beneficial ownership. Who really owns and controls this business? Declared by someone with authority to declare it, and evidenced.
  • Proof of address. A utility bill, a bank statement, a lease. For the entity, and often for the individuals.
  • Proof of trading. Bank statements, processing history, invoices, and a website that actually works.
  • Licences and permissions. FCA authorisation, MSB registration, gambling licences, alcohol licences, whatever the vertical demands.
  • Source of funds and source of wealth. The enhanced due diligence questions that no registry on earth will ever answer for you.
  • Attestations and declarations. Signed statements about business model, expected volumes, jurisdictions served, and prohibited activity.

Every one of these has the same three properties. It can only come from the customer. It has to be verified, not just collected. And in most organisations today, it is requested by a human being, via email, after the fact.

We call this customer-supplied data. It is somewhere between 40% and 70% of the evidence file on a typical merchant, depending on risk tier. And in almost all cases it is not automated.

How an entire industry ended up solving the easy half

I don't think anyone decided this. It happened by accident, for a reason that made sense at the time.

The data aggregation problem was solvable with money. You could buy registry feeds, license a sanctions list, plug in a credit bureau, and build an orchestration layer that stitched them together. It's a hard engineering problem, but it's a bounded one. So that's where the vendors went, and that's where the funding went.

The customer-supplied data problem wasn't solvable with money, because it isn't really a data problem at all. It's an experience problem wearing a compliance costume. And experience problems get solved by e-commerce people, not by compliance people - and until recently, nobody thought to put e-commerce people anywhere near a KYB flow.

So we ended up with an industry that has genuinely brilliant technology for the 50% of the file that's sitting in a public database, and an inbox for the other 50%.

There's a second reason, and it's more uncomfortable. In most organisations, onboarding is owned by compliance. Compliance is measured on the quality of the decisions it makes - not on how many applicants never got as far as a decision. If 30% of your applicants abandon before submission, that number appears nowhere on the compliance dashboard. It's not that anyone is hiding it. It's that nobody's job description includes looking at it.

Ask a compliance leader their false positive rate and they'll tell you to two decimal places. Ask them their drop-off rate at the document upload step and there is very often a pause.

What it's actually costing

For years this was an argument you had to make on instinct. It isn't any more. The 2025 data is unusually blunt.

Document collection is now the single biggest cause of abandonment. In Celent'sGlobal Commercial Banking Onboarding Survey 2025- 409 banking professionals across North America, EMEA and Asia-Pacific, at institutions from $10bn to $500bn+ in assets - document collection ranked as the number one point of customer abandonment, cited by 79% of respondents. KYC/KYB processes ranked second at 65%, and were named as a top frustration by relationship managers as well as customers.

Read that again. Not risk appetite. Not pricing. Not the credit decision. Asking people for documents.

Roughly one in thirteen applicants walks. Celent puts average abandonment at 7.7%, rising above 10% at Tier 1 institutions. Fenergo's 2025Financial Crime Industry Trends Report- 600 senior decision-makers across banks, asset managers and fund administrators - independently lands at around 10%. In my experience, the true number is likely in the 30%-40% range. Vendor research across the wider funnel consistently puts the large majority of onboarding drop-off at the KYC/KYB stage rather than anywhere else.

The unit economics are brutal. Celent puts the average cost of onboarding a commercial customer at $14,700, and average annual spend on commercial onboarding at $15.9m per bank - with 67% saying it costs them more this year than last. At 1,000 customers a year, abandonment alone represents over $1m of pure waste: money spent acquiring, reviewing and partially processing customers who then leave. That's before you count the revenue they would have generated.

The work is still being done by hand. 31% of banks describe their onboarding workflows as mostly to fully manual. For related party identification and ongoing monitoring - which is to say, beneficial ownership - that figure is 51%. Half the industry is mapping who really owns a business using human beings and email.

It takes far too long. Celent found average onboarding time of 49 days. Not 49 days of work - 49 days of elapsed calendar time, most of it spent waiting for a reply to an email. Nearly two months of delayed revenue per customer.

And the plumbing is broken underneath. 73% of Celent respondents said they do not have a single source of data supporting the entire onboarding process. Which is a polite way of saying: the documents are in an inbox, the decision is in a case management tool, the company data is in a third system, and the audit trail is whatever somebody remembered to paste into a comment field.

The market is punishing it. Fenergo found 70% of financial institutions globally lost clients in the past year due to slow onboarding - the highest figure they've ever recorded, up from 67% in 2024 and 48% in 2023. That's not a plateau. That's a trend line going the wrong way, fast.

Meanwhile the cost of getting it wrong keeps climbing. Average annual AML/KYC operational spend now sits at $72.9m per firm (UK institutions highest at $78.4m). Global AML, KYC and sanctions fines hit $1.23bn in the first half of 2025 alone.

So the picture is: you're spending more than ever, taking longer than ever, losing more customers than ever, and getting fined more than ever. Every one of those four numbers is influenced by how well you collect data from your customer.

One more figure, because it tells you the industry already knows. When Celent asked where banks intend to invest over the next 18 months, the number one priority - 43% ranked it first, more than double anything else - was self-service digital portals. Giving the customer a way to submit documentation proactively and see where they stand, instead of waiting on the back-and-forth. The market has worked out what's broken. Most of it just hasn't fixed it yet.

The Death Loop

Here's the process almost everyone is running, drawn honestly:

  1. Customer arrives and fills in a catch-all web form. It asks for everything, because nobody wanted to build conditional logic, so a low-risk sole trader gets the same twenty-eight questions as a complex multi-jurisdiction group.
  2. A record is created in a CRM.
  3. An analyst picks it up - hours or days later - and looks at what's available.
  4. The analyst identifies what's missing.
  5. The analyst writes an email.
  6. Nothing happens.
  7. The analyst writes another email.
  8. The customer replies with the wrong thing, or the right thing in the wrong format, or the right thing four months out of date.
  9. Go to step 4.

The loop is the product. Not the decision - the loop. And it has three costs that almost never make it onto a business case.

The salary cost. Large teams exist purely to run steps 4 through 9. They are not making risk decisions. They are chasing attachments. When a business tells me they need to "hire more analysts to keep up with volume", what they usually need is to stop generating work that shouldn't exist.

The quality cost. This one matters more and gets discussed less. Evidence that arrives by email is evidence of unknown provenance. A PDF bank statement in an inbox has no verification, no liveness, no tamper check, no timestamp you can trust, and no link between the document and the person who supposedly owns it. In a world where a convincing forged utility bill costs about the price of a coffee and generative tooling has made document fraud trivially cheap, "the customer emailed it to us" is not a control. It's a filing convention.

The audit cost. When the regulator askswhyyou approved a merchant in March 2024, the answer needs to be reconstructable. If the reasoning lives across an email thread, a Slack message, a CRM note and an analyst who left the business, you don't have an audit trail. You have an archaeology project.

Where it gets worse: the EDD cliff edge

Everything above describes standard due diligence. Enhanced due diligence is where the model really falls over.

EDD is, almost by definition, made up of customer-supplied data. Source of wealth. Source of funds. Ownership structures that don't appear in any registry because they route through jurisdictions that don't publish one. Explanations of unusual trading patterns. Evidence of the commercial rationale behind a complex structure.

None of that can be looked up. All of it has to be asked for, and asked forwell- because the questions are sensitive, the answers are nuanced, and the customer is now several weeks into a process they thought would take an afternoon.

And here's the thing about EDD: the customers who trigger it are frequently your most valuable ones. Higher volumes, more complex businesses, bigger revenue. The current model punishes them the hardest. The better the customer, the worse the experience.

There's also a structural trap worth naming. In the UK, Companies House data is still, for the most part, self-reported by the company that filed it. The Economic Crime and Corporate Transparency Act 2023 is fixing this - identity verification becomes compulsory for new directors and PSCs from autumn 2025, with existing directors and PSCs required to verify by autumn 2026 - but until that transition completes, treating registry ownership data as independent verification is a control gap, not a control. The structures built to exploit that gap are well documented and depressingly simple: shell companies, nominee directors, offshore holdings, layered just deep enough that nobody with an email inbox and a deadline is going to unpick them.

And remember the Celent number: 51% of institutions are still doing related party identification mostly or entirely by hand. The one part of the file that a registry genuinely cannot answer for you is the part that's least automated anywhere.

The only reliable way to close it is to go to the human being and make them prove it. Which brings us straight back to the forgotten half.

The reframe: stop asking afterwards

The fix isn't a better email template. It isn't a bigger team. It isn't an AI that writes chasers more persuasively - that's automating the death loop, not removing it.

The fix is a change in sequence.

Do the asking at the front, in the flow, dynamically - not at the back, by email, after the fact.

That single move changes the economics of the whole process, because it changeswhenthe customer is paying attention. A business owner signing up for a payments account is engaged for a window of maybe fifteen minutes. Right now we spend that window collecting a company number we could have looked up ourselves, and then we go and ask for the hard stuff three days later when they've moved on.

Invert it. Use the window. Ask the director to verify their identity while they're sat there. Ask them to declare the UBOs while they're in the mindset of describing their business. Ask for the bank statement while their banking app is open on the phone in their hand.

And - this is the part people miss - askonlywhat you actually need, based on who this specific customer is.

Because the other reason flows are so painful is scar tissue. Every onboarding form I've ever reviewed contains questions nobody can justify. A field added for a product that was discontinued. An IDV step applied to every applicant because of one incident in 2019. A document request that exists because a previous MLRO liked having it. Nobody removes anything, because removing a compliance question feels risky and adding one feels safe.

So before you automate anything, do the spring clean. What do youactuallyhave to know to onboard this business, for this product, in this country, at this risk level? Usually the honest answer is materially less than what you're asking for - and the things you should be asking for instead are the things you're currently getting by email.

What good looks like

Here's the test. Run your current process against these ten questions and count the yeses.

  1. Is the ask dynamic? Does the flow change based on jurisdiction, entity type, product, risk tier and company age - or does everyone get the same form?
  2. Is verification happening at the point of capture? Is the ID document checked for authenticity and matched to a live human at the moment it's submitted, or is it an attachment somebody eyeballs later?
  3. Can the customer self-certify in-flow where data isn't publicly available? Or does missing registry data automatically trigger a manual email?
  4. Is UBO declared and evidenced by someone with authority in the flow? Or is it a name typed into a free-text box?
  5. Do you know your drop-off rate, by step? Not your approval rate. Your drop-off rate. Per page.
  6. Is every document tied to the person who supplied it, with a tamper-evident record? Would it survive a challenge?
  7. Is the whole evidence file in one place? Company data, customer-supplied documents, verification results, decision reasoning, timestamps - one record, one audit trail.
  8. Does the customer always know what's outstanding and why? Or do they have to email and ask?
  9. When something changes post-onboarding, does the system go back and ask the customer for updated information automatically, or does it wait for a periodic review?
  10. Is time-to-onboard measured from the customer's first arrival, or from application submission? Because if it's the latter, you're not measuring the bit that's broken. You're measuring the bit that works.

Most organisations score three or four. If you scored above seven, you're genuinely ahead of the market.

How Detected does it

We built Detected around exactly this problem, and we built it from the wrong direction on purpose.

I didn't come from compliance. I came from e-commerce - eBay, Zalando, EasyPost - where you learn very quickly that the person on the other side of the screen is a consumer whether they're buying trainers or opening a merchant account. They have consumer expectations. If the experience is bad, they vote with their feet. KYC has largely caught up with this. The Monzos, Starlings and Revoluts made consumer onboarding feel like nothing at all. KYB has not caught up, and the businesses on the receiving end have noticed.

So the design principle is simple: put the work at the front, not after the fact.

Dynamic flows, not catch-all forms. The flow changes on the fly based on jurisdiction, entity type, product, risk level or even how old the business is. A six-month-old sole trader and a Chinese seller onboarding to a European marketplace get genuinely different journeys, because they genuinely present different questions.

In-flow self-certification where the data doesn't exist. Data availability varies enormously by country - it depends entirely on what that government required at incorporation and how often it demands a refresh. Then it changes again when regulations change. Rather than let a gap in registry data drop into a manual email queue, we let the customer certify it in the flow, against a specific request, with evidence attached. This is why we can say things like European marketplaces using us to onboard Chinese business sellers - not because we found a magic Chinese registry, but because we stopped depending on one.

Verification at the point of capture. Director IDV, document authenticity, liveness, and the link between the human, the document and the company – established in the moment, not reconstructed later from an inbox.

UBO declared and evidenced in the flow. Related entities declared, ownership structures pulled and mapped, and the whole picture pinned to the screening results so you have one coherent evidence file rather than a folder of PDFs.

Behavioural analytics on the front end. We can see which page people are dropping out of, and why. If your signposting on the proof-of-address step is unclear, we'll tell you and you'll fix it. You cannot improve what you don't measure, and almost nobody in this space is measuring the front end at all.

AI for what happens next. Onboarding isn't a moment, it's a relationship. Profiles are monitored continuously for screening hits and company data changes. If a credit rating drops, or accounts aren't filed, automation can automatically go back to the business owner and request supplementary information - the same in-flow, verified mechanism, triggered by a rule rather than by a human noticing.

Native in Salesforce. Because that's often where compliance teams already live, and asking them to work in yet another window is how good tooling dies.

The commitment we make to new customers is deliberately unglamorous and deliberately measurable: 25% improvement in month one, on three metrics.

  • Time to onboard, measured from the moment the business owner arrives - not from application submission. If you only measure post-submission, you're measuring compliance's homework, not the customer's experience.
  • Churn through the funnel. If a thousand businesses arrive, 25% fewer of them drop out.
  • Time to revenue. The whole point.

We typically go a lot further than 25%. We start there because the baseline in this industry is so poor that anything more ambitious sounds like marketing.

The conversation that changes everything

The moment this stops being a compliance discussion and starts being a board discussion is always the same. It's when the CFO runs the numbers.

You're spending marketing money to drive businesses to your site. A meaningful share of them arrive, start onboarding, hit a wall made of email attachments, and leave. You are paying to acquire customers for your competitors. And separately, you're paying a team of skilled people to spend their days chasing utility bills.

At $14,700 a customer and around 10% abandonment, a business onboarding 5,000 merchants a year is setting fire to roughly $7m before anyone's counted the lost revenue.

There's a comfortable belief in this industry that you have to trade compliance quality against customer experience - that a smooth onboarding flow must mean you're not asking enough. It's exactly backwards. The manual, email-based model doesn't produce better evidence. It produces later, weaker, less verifiable evidence from fewer customers at a higher cost. Everything about it is worse.

Better experience and better evidence are the same project. They always were. We just spent a decade building tooling for the half of the problem that was easier to solve.

The other half is sitting in The Death Loop

Sources

  • Celent, Global Commercial Banking Onboarding Survey 2025 (409 respondents, North America / EMEA / Asia-Pacific, institutions $10bn-$500bn+ AUM)
  • Fenergo, Financial Crime Industry Trends Report 2025
  • UK Economic Crime and Corporate Transparency Act 2023, Companies House identity verification phasing
  • Industry research and Detected data on KYC/KYB funnel drop-off rates