Kyc Interoperability Barriers .
KYC Interoperability Barriers
1. Introduction
KYC interoperability barriers arise when banks, payment institutions, fintech platforms, wallets, exchanges, insurers, or other regulated financial entities cannot effectively reuse, verify, transfer, or authenticate a customer's Know Your Customer (KYC) information across different systems.
The issue has two competing dimensions:
- Financial-crime compliance: KYC/AML rules require reliable identification, beneficial-owner verification, risk assessment, and ongoing monitoring.
- Competition and interoperability: Requiring every new provider to repeat the entire KYC process can increase switching costs, customer-acquisition costs, and entry barriers, particularly where incumbent institutions control important identity or customer-data infrastructure.
The European Commission has specifically examined cross-border KYC portability and interoperability, including the possibility of portable KYC/CDD solutions. Similarly, EU financial-data policy identifies non-standardised data and technical interfaces as barriers to data sharing and competition.
In India, the RBI's framework has also connected KYC-compliant wallets and interoperability, requiring phased interoperability among wallets and subsequently between wallets and bank accounts through UPI.
2. Meaning of KYC Interoperability
KYC interoperability means that a customer's verified identity and relevant due-diligence information can, subject to legal safeguards, be used across multiple regulated institutions without requiring an entirely new onboarding process each time.
It may involve:
- identity verification;
- beneficial-owner information;
- customer address;
- tax information;
- risk classification;
- sanctions screening;
- politically exposed person screening;
- source-of-funds information;
- verification timestamps;
- digital signatures;
- electronic identification;
- CKYCR/KYC-registry information;
- API-based authentication;
- portable KYC credentials.
Example
Suppose a customer has already completed full KYC with Bank A.
The customer then wants to open an account with Fintech B.
If Fintech B cannot access or rely upon the relevant verified information, the customer may have to submit:
- identity documents again;
- address proof again;
- photographs again;
- beneficial-owner information again;
- verification information again.
Where this happens repeatedly across financial institutions, KYC becomes a switching-cost and entry-barrier issue.
3. What Constitutes an Interoperability Barrier?
A. Technical barriers
Different institutions may use:
- incompatible databases;
- different API standards;
- incompatible identity formats;
- proprietary authentication systems;
- different data fields;
- different verification protocols.
The European Commission has recognised that non-standardised financial data and technical infrastructure can make data sharing significantly more costly.
B. Regulatory barriers
A financial institution may argue that it cannot rely upon another institution's KYC because:
- its own AML obligations remain;
- verification standards differ;
- liability for inaccurate information is uncertain;
- beneficial ownership has changed;
- the customer-risk profile has changed.
Therefore, interoperability does not necessarily mean automatic acceptance of another institution's KYC.
C. Commercial barriers
An incumbent institution may have an economic incentive to prevent competitors from easily accessing:
- customer identity information;
- verified customer credentials;
- transaction histories;
- risk profiles;
- account information.
This can make KYC infrastructure strategically important.
D. Data-protection barriers
KYC information is highly sensitive financial and personal information. Sharing therefore raises issues concerning:
- purpose limitation;
- consent;
- data minimisation;
- security;
- retention;
- cross-border transfers;
- unauthorised secondary use.
The EU's proposed financial-data framework expressly combines data access with customer control and data-protection safeguards.
4. Competition-Law Concerns
A. Barriers to entry
If an incumbent controls an important KYC or identity-verification infrastructure and competitors cannot obtain access on reasonable terms, new firms may face significantly higher onboarding costs.
This is particularly important for:
- fintechs;
- payment institutions;
- digital banks;
- remittance providers;
- crypto/virtual-asset businesses;
- insurance technology;
- lending platforms.
B. Raising rivals' costs
A dominant financial institution could theoretically increase competitors' costs by:
- refusing technical access;
- imposing discriminatory access requirements;
- requiring unnecessary duplicate verification;
- withholding standardised KYC information;
- imposing excessive API charges;
- deliberately maintaining incompatible technical formats.
Competition authorities would normally need to establish the relevant market, dominance or market power, and the competitive effect of the conduct rather than treating every interoperability disagreement as anticompetitive.
C. Customer lock-in
Repeated KYC requirements can make customers reluctant to change providers.
For example:
Bank A → completed KYC
↓
Customer considers Fintech B
↓
New KYC + documents + verification
↓
Higher switching cost
↓
Customer remains with Bank A
This can reinforce incumbent market power.
D. Refusal of access
A refusal to provide access to an essential identity/KYC infrastructure could potentially raise essential-facility/refusal-to-deal questions.
However, the fact that an infrastructure is useful does not automatically make it an essential facility. Competition-law analysis normally considers factors such as:
- indispensability;
- absence of realistic alternatives;
- ability to duplicate the facility;
- effect on competition;
- objective justification;
- proportionality.
5. KYC Interoperability and Open Banking
KYC interoperability should be distinguished from ordinary open-banking data interoperability.
Open banking primarily concerns access to:
- account information;
- transaction information;
- payment initiation.
KYC interoperability concerns:
- identity;
- customer due diligence;
- beneficial ownership;
- risk information.
Nevertheless, the two systems can interact.
The EU's PSD2 framework requires mechanisms facilitating third-party access to payment-account information, while the EBA has treated certain bank-imposed obstacles to account-information services as regulatory problems.
The broader lesson is that technical interoperability can be a prerequisite for effective competition even where formal access rights exist.
6. KYC Interoperability and India
India provides a particularly important example because the regulatory system contains mechanisms designed to reduce repeated KYC procedures.
The RBI's KYC framework imposes customer-identification and due-diligence obligations on regulated entities.
At the same time, RBI's payment-system framework has promoted interoperability. Its PPI framework contemplated interoperability first among KYC-compliant wallets and subsequently between wallets and bank accounts through UPI.
The competition-law significance is that interoperability becomes less useful if the underlying KYC requirements make participation prohibitively expensive.
This tension has been expressly discussed in scholarship concerning Indian payment systems: enhanced KYC requirements can increase customer-acquisition costs and potentially reduce some of the competitive benefits expected from wallet interoperability.
7. Six Important Case Laws
Because direct reported judgments specifically titled "KYC interoperability" remain relatively limited, the following cases are important as analogous authorities on KYC, access, interoperability, payment systems, data sharing, and competition.
1. Safe Interenvíos SA v. Liberbank SA and Others, C-235/14
Court: Court of Justice of the European Union
Year: 2016
This is one of the most directly relevant authorities.
The case concerned a money-transfer/payment institution and banks' KYC/AML requirements. The banks requested information concerning customers and applied enhanced due-diligence measures.
The CJEU recognised the importance of AML controls but held that financial institutions cannot simply assume the supervisory role belonging to competent authorities. Due-diligence measures must be appropriately connected to the relevant money-laundering and terrorist-financing risk.
Relevance
The case demonstrates the boundary between:
legitimate KYC/AML requirements
and
potentially excessive or unjustified requirements imposed on competitors.
For interoperability disputes, it supports a risk-based rather than automatically duplicative approach.
2. Financial Software and Systems Pvt. Ltd. v. ACI Worldwide Solutions Pvt. Ltd.
Forum: Competition Commission of India
The dispute concerned technology and payment-processing infrastructure. The CCI considered the relevant market for electronic financial transactions and the role of different transaction-processing systems, including bank systems and international card networks.
Relevance
The case illustrates the importance of defining the relevant market around technological infrastructure.
For KYC interoperability disputes, analogous questions include:
- Is the relevant market KYC services?
- Digital identity verification?
- Banking authentication?
- KYC-registry access?
- Financial onboarding infrastructure?
Market definition can determine whether an interoperability refusal is capable of constituting an abuse of dominance.
3. XYZ v. Alphabet Inc. and Others
Forum: Competition Commission of India
Cases: 07 of 2020, 14 of 2021 and 35 of 2021
The CCI examined Google's position in digital ecosystems and discussed the role of UPI and interoperability in digital payments.
The record specifically identifies UPI's interoperability across platforms and its ability to link multiple bank accounts to a digital identity as important features of the payment ecosystem.
Relevance
This is significant for the proposition that interoperability can reduce ecosystem dependence.
For KYC systems, interoperable identity credentials could similarly allow users to move among financial providers without repeatedly rebuilding their identity profile.
4. Banco Santander / Visa and payment-system interoperability jurisprudence
EU payment-system competition jurisprudence provides an important analogy for KYC interoperability.
Payment systems can become more competitive when merchants, banks and service providers are not locked into a single vertically integrated infrastructure. The OECD's review of fintech and open-banking competition records enforcement experience concerning exclusionary arrangements and interoperability in payment systems.
Relevance
The principle applicable by analogy is:
A privately controlled infrastructure can become a competition concern where its rules materially restrict access by competing providers.
For KYC, the equivalent infrastructure could be:
- a KYC utility;
- digital identity network;
- customer-verification API;
- industry-wide KYC database.
5. Safe Interenvíos — data-sharing aspect
A second important aspect of Safe Interenvíos concerns the relationship between KYC information and data protection.
The CJEU considered whether payment institutions could be required to provide customer information to banks and how AML obligations interact with data-protection requirements.
Relevance
This is especially important because a competition remedy requiring KYC interoperability cannot simply order unrestricted disclosure of customer information.
A legally sustainable interoperability system must address:
- customer's consent;
- purpose limitation;
- security;
- data minimisation;
- liability;
- accuracy;
- retention.
Thus, competition law cannot be separated from financial regulation and privacy law.
6. OTP Bank — C-81/24
Court: CJEU
Year: 2026
The Court considered customer due-diligence requirements under the EU AML framework and the consequences of relying upon sanctions-list information.
The Court emphasised that AML compliance operates through a risk-based assessment, rather than automatic exclusion solely because a customer appears on a third-country list.
Relevance
This supports an important interoperability principle:
KYC portability cannot mean blind reliance, but neither should a regulated institution impose automatic additional restrictions without an appropriate risk assessment.
8. Additional Relevant Authority — RBI KYC/Interoperability Framework
Although not a judicial case, the RBI regulatory framework is highly relevant to an Indian competition-law analysis.
The RBI framework specifically contemplated interoperability for KYC-compliant wallets and subsequent interoperability with bank accounts through UPI.
This demonstrates that interoperability and KYC are not inherently conflicting concepts.
The regulatory challenge is to create a system in which:
KYC integrity + interoperability + competition + privacy
operate simultaneously.
9. Essential-Facility Analysis
Where KYC infrastructure is controlled by a dominant firm, an essential-facility analysis may proceed through the following questions:
Step 1 — Relevant market
Determine whether the relevant market is:
- KYC verification;
- digital identity;
- financial onboarding;
- customer due-diligence services;
- payment authentication;
- KYC-registry services.
Step 2 — Dominance
Determine whether the entity controls a substantial portion of the relevant infrastructure.
Step 3 — Indispensability
Is the KYC infrastructure genuinely indispensable?
Could competitors use:
- alternative KYC providers;
- government identity systems;
- CKYCR;
- independent verification agencies;
- alternative APIs?
Step 4 — Refusal
Has access been:
- completely denied;
- technically obstructed;
- delayed;
- made discriminatory;
- made commercially unreasonable?
Step 5 — Competitive harm
Has the conduct:
- excluded competitors;
- increased rivals' costs;
- reduced innovation;
- increased switching costs;
- protected an incumbent ecosystem?
Step 6 — Objective justification
The provider may rely on:
- AML requirements;
- fraud prevention;
- cybersecurity;
- data protection;
- operational resilience;
- customer consent;
- liability concerns.
The crucial question is whether the restriction is necessary and proportionate to those legitimate objectives.
10. Forms of Anticompetitive KYC Interoperability Conduct
| Conduct | Possible competition concern |
|---|---|
| Refusal to provide KYC API access | Foreclosure |
| Excessive KYC re-verification | Raising rivals' costs |
| Discriminatory access | Discriminatory abuse |
| Proprietary identity format | Interoperability foreclosure |
| Excessive API fees | Exploitative/exclusionary access terms |
| Deliberate technical incompatibility | Technical foreclosure |
| Restrictive data portability | Customer lock-in |
| Exclusive KYC arrangements | Input foreclosure |
| Bundling KYC with banking services | Tying/bundling |
| Self-preferencing own KYC service | Leveraging |
| Restricting third-party verification | Entry barrier |
| Refusing portability after customer consent | Switching-cost enhancement |
11. Difference Between Legitimate KYC Restriction and Anticompetitive Barrier
Not every interoperability restriction violates competition law.
Legitimate restriction
A bank may legitimately require additional verification where:
- the customer's risk profile has materially changed;
- beneficial ownership is uncertain;
- information is outdated;
- fraud indicators exist;
- sanctions concerns arise;
- the receiving institution has independent statutory obligations.
Potential competition concern
The situation becomes more problematic where a dominant institution:
- possesses interoperable information capable of being safely transferred;
- receives a valid customer-authorised request;
- has no genuine AML/security justification for refusal;
- nevertheless prevents competitors from obtaining access;
- thereby materially increases switching costs or forecloses rivals.
12. Regulatory Design for KYC Interoperability
A workable system could use a portable KYC credential rather than unrestricted transfer of the customer's entire file.
Model
Customer
↓ consent
KYC Utility / Trusted Identity Provider
↓ authenticated API
Bank / Fintech / Payment Provider
↓ risk assessment
Account / Financial Service
The receiving institution should receive only the information necessary for its regulatory obligations.
13. Key Safeguards
A competitive KYC interoperability framework should include:
- Common technical standards
- Standardised data fields
- API interoperability
- Customer-controlled consent
- Strong authentication
- Data minimisation
- Purpose limitation
- Audit trails
- Liability allocation
- Real-time revocation
- Fraud and sanctions screening
- Non-discriminatory access
- Reasonable access pricing
- Independent dispute resolution
The EU's financial-data initiative similarly identifies standardised data and technical interfaces as important mechanisms for effective data sharing.
14. Competition-Law Test
A useful analytical framework is:
KYC infrastructure
↓
Is it commercially/technically important?
↓
Is the provider dominant?
↓
Is access refused or technically restricted?
↓
Is the restriction discriminatory or disproportionate?
↓
Does it raise rivals' costs or increase switching costs?
↓
Is there a legitimate AML/privacy/security justification?
↓
Can a less restrictive alternative achieve the same compliance objective?
↓
Assessment under applicable competition law
15. Key Legal Principles from the Case Law
The authorities collectively support several important propositions:
Principle 1
AML/KYC compliance is a legitimate regulatory objective, but financial institutions cannot automatically assume regulatory powers belonging to competent authorities.
— Safe Interenvíos
Principle 2
KYC measures should be connected to the actual AML/CTF risk rather than being unnecessarily duplicative.
— Safe Interenvíos
Principle 3
Interoperable infrastructure can materially affect competition in digital financial markets.
— Indian payment-system/UPI jurisprudence and CCI proceedings
Principle 4
Data access and interoperability must coexist with privacy and security safeguards.
Principle 5
A refusal to interoperate is not automatically an abuse of dominance; indispensability, dominance, foreclosure and justification must be examined.
Principle 6
Technical standards themselves can become competition-relevant when control over those standards gives an incumbent the ability to exclude competing providers.
16. Conclusion
KYC interoperability barriers sit at the intersection of competition law, AML regulation, financial regulation, data protection and digital-platform governance.
The central competition concern is not that every financial institution must automatically accept another institution's KYC. Rather, the concern arises when duplicative KYC requirements, proprietary technical systems, discriminatory access conditions, or refusal to provide interoperable verification infrastructure unnecessarily increase switching costs or prevent competitors from entering or expanding.
The strongest legal approach is therefore a risk-based interoperability model: preserve each institution's independent AML responsibility while allowing verified KYC information to be securely reused where legally permissible and authorised by the customer.
For India, the interaction between RBI KYC/AML requirements, CKYCR, UPI/payment interoperability and the Competition Act 2002 makes this particularly significant. The RBI's existing interoperability framework demonstrates that KYC compliance and interoperability can be designed together rather than treated as mutually exclusive objectives.
Core cases to remember: Safe Interenvíos v. Liberbank (C-235/14); Financial Software & Systems v. ACI Worldwide; XYZ v. Alphabet/Google (CCI); and OTP Bank (C-81/24), supplemented by payment-system interoperability jurisprudence and the RBI's regulatory framework.

comments