Reusable KYC in Emerging Markets: SIM Mandates and the Consent Problem
Reusable KYC is a model in which a completed identity verification is presented to subsequent institutions as a verifiable credential, rather than being performed again from scratch. In emerging markets it is arriving faster than in mature ones, because the alternative is not an inconvenience but an exclusion: a population that cannot complete a verification cannot open an account.
The last week of August 2026 produced two developments that show both the opportunity and the fault line. One national telecoms regulator mandated biometric identification for every mobile SIM connection, with a three-month compliance deadline. One central bank approved regulations for a digital financial identity platform enabling remote onboarding. In a third market, a remote biometric telecom verification pilot drew a formal petition from human rights groups seeking its withdrawal.
The same technology, deployed under different consent conditions, produces very different outcomes.
Key takeaways
- Telecoms is becoming the highest-volume identity verification channel in many markets, ahead of banking.
- Central bank approval of digital financial identity platforms moves e-KYC from pilot to regulated infrastructure.
- Mandatory biometric enrolment tied to an essential service creates a consent problem that technical controls alone cannot resolve.
- Reusable credentials reduce total collection events, which is the single most effective mitigation available.
- Emerging markets are likely to reach reusable-credential architectures before mature markets, not after.
Why telecoms became the identity chokepoint
A mobile connection is the entry point to the digital economy in most emerging markets. It is the authentication factor for banking, the delivery channel for government services, and often the wallet itself. Regulators have responded by treating SIM registration as an identity control, typically requiring one of:
- National ID e-KYC lookup against a central register
- Live facial matching against the ID photograph on file
- In-person document presentation at an accredited outlet
The volumes are extraordinary. National SIM registration campaigns process tens of millions of verifications in months. That makes telecoms, not banking, the largest single generator of verified identity records in these economies.
Which raises the obvious question: if a citizen has completed a live-face verification against a national register in order to obtain a SIM, why must they repeat the entire process to open a bank account the following week?
What central bank e-KYC approval actually unlocks
Regulatory approval of a digital financial identity platform is not primarily a technology decision. It is a liability allocation decision. Approval establishes:
- Which verification methods are acceptable for remote onboarding
- What assurance level each method carries
- Which institution bears the loss when a verification later proves wrong
- Whether a verification performed by one regulated entity may be relied upon by another
The fourth point is where reusable KYC lives or dies. Without explicit reliance provisions, every institution must repeat every check regardless of what has already been established, because it cannot transfer the liability. With them, verification becomes a shared asset.
Markets writing these frameworks in 2026 have the advantage of writing reliance in from the start. Mature markets are retrofitting it into regimes drafted when remote onboarding did not exist.
The consent problem
Here the picture darkens, and it should be stated directly.
When biometric enrolment is mandatory for an essential service, consent is nominal. A citizen who cannot obtain a mobile connection without submitting a facial scan has not meaningfully consented to biometric processing. They have complied. Human rights objections to remote biometric telecom verification rest on exactly this point, and they are not resolved by improving the technology.
Three risks follow, and they compound:
- Centralisation. Mandatory enrolment concentrates biometric records for an entire population in a small number of systems. The consequences of compromise are national and permanent, because a biometric cannot be reissued.
- Function creep. A database built for SIM registration becomes available for purposes never disclosed at enrolment. The original consent, already thin, covers none of them.
- Exclusion. Every biometric system has a failure population: worn fingerprints, disability, poor capture conditions, ageing reference photographs. Where enrolment is a precondition for connectivity, system failure becomes civic exclusion.
None of these are arguments against digital identity. They are arguments about architecture, and specifically about how many copies of a biometric exist and who holds them.
Minimising collection is the available mitigation
The most effective control is also the least discussed: reduce the number of times the biometric is collected and stored at all.
A reusable credential architecture does this structurally. The verification happens once, with a qualified issuer, under conditions that can be audited. What propagates afterwards is not the biometric but a cryptographic assertion about it. A bank confirming that a customer completed verification at a given assurance level receives a proof, not a facial template. The bank cannot leak what it never held.
This inverts the usual sequencing assumption. Emerging markets are often expected to adopt mature-market patterns late. In identity the opposite is likely, for the same reason mobile payments arrived there first: there is less legacy infrastructure to defend, the volumes force the issue, and the frameworks are being drafted now rather than amended.
AIR Identity is built for that architecture. Partners issue reusable credentials from verifications they have already performed, and relying partners confirm assertions through zero-knowledge proofs without receiving raw personal data. Paired with AIR Money for cross-border settlement and payouts, a verified user can transact across markets without repeating enrolment in each one.
We have been building this in exactly these conditions. Our work in Türkiye across gaming, ticketing and regulated digital assets runs on the same principle: verify once with a qualified partner, then let the credential travel instead of the data.
Frequently asked questions
What is reusable KYC?
Reusable KYC is a model where an identity verification performed once by a qualified institution is presented to other institutions as a verifiable credential. The relying institution receives a cryptographic assertion of the result, including issuer and assurance level, rather than collecting and storing the underlying documents and biometrics again.
Is reusable KYC allowed by regulators?
It depends on the regime. The determining factor is whether the framework contains explicit reliance provisions allowing one regulated entity to rely on another's verification, and how liability is allocated when it does. Several markets writing digital financial identity regulations in 2026 are including these provisions from the outset.
Why is biometric SIM registration controversial?
Because consent is nominal when enrolment is a precondition for an essential service. Citizens who cannot obtain connectivity without submitting biometrics have complied rather than consented. The objections centre on centralised storage of population-scale biometric records, use of those records for purposes beyond the original enrolment, and exclusion of people the system fails to capture.
How does reusable KYC reduce data breach risk?
By reducing the number of institutions that hold sensitive data. In a repeated-verification model every institution stores its own copy of the documents and biometrics. In a reusable model, one qualified issuer holds the verification record and every relying party holds only a cryptographic assertion, which is of no value to an attacker.
Can KYC be reused across borders?
Technically yes, and this is where credential portability is most valuable. Whether it is permitted depends on the receiving jurisdiction's reliance rules and its recognition of the issuing party's assurance framework. Credentials built on open standards such as W3C Verifiable Credentials and decentralised identifiers are designed to make the technical layer portable so that only the legal layer needs negotiating.
Related reading
- Biometric data retention is a liability
- What is a QEAA? Qualified attestations explained
- Why biometrics alone are no longer enough
More from AIR: AIR Money, industry solutions, or browse the full AIR blog.
Operating in markets where verification cost and exclusion are both high? See how AIR Identity makes a single verification reusable, or talk to our team.




.png)