Orkivanta
← All posts
7 min read

Video KYC in India: build vs buy, accuracy, DPDP

For most Indian fintechs, buying Video KYC from an established provider beats building it — the accuracy, liveness, and fraud-resistance that make VKYC work take specialist investment, and the compliance surface is not where you want to be debugging your own computer vision. You build only when the flow has to live so deep inside your systems, or handle such volume, that a platform's ceiling costs more than owning it. Either way, accuracy and straight-through-processing rates are the two numbers that matter, and whether the flow meets the RBI's Video KYC norms and DPDP is a question for your compliance and legal team. Here is how to weigh it honestly.

The build-versus-buy line

Buy for speed, for accuracy that someone else maintains, and for a vendor absorbing the model upkeep as fraud techniques change. Build when integration depth, data-path ownership, or volume economics force it — when the verification has to read and write your internal systems, when owning the data path is a hard requirement, or when per-verification pricing at scale outgrows the cost of running your own.

It is the same platform-versus-custom logic as any automation decision, but the stakes are higher because the errors here are regulatory, not cosmetic. A wrong answer in VKYC is not a bad row in a dashboard; it is a compliance event. That raises the bar for building your own, which is why 'buy' is the default for most teams and 'build' is the exception you justify.

The two numbers that matter

HyperVerge publicly reports that for IndMoney, an Indian wealth app, a Video KYC flow combining ID-OCR, face match, and liveness went from concept to go-live in about 9 days and reported roughly 99.5% verification accuracy and around 80% straight-through processing, alongside business-volume growth. Those are HyperVerge's reported figures for its client — third-party public evidence, not an Orkivanta benchmark.

What to take from it is the pair to interrogate for any VKYC vendor: accuracy and straight-through processing, together. A high accuracy claim with low STP means humans are quietly carrying the flow; high STP with soft accuracy means errors are slipping through unreviewed. One number without the other is half the picture, and the half that is missing is usually the one that costs you.

A non-India counterpoint

Jumio publicly reports that for Casumo, an online gaming operator, AI and computer-vision ID verification increased KYC handling capacity by about 80% and moved the operator off email-based KYC to secure in-account upload. That is Jumio's reported result for its client — third-party public evidence from a different market and a different regulator, cited here for the framing it raises, not as a number that transfers to India.

The framing is worth borrowing: 'capacity up 80%' is a different claim from 'time reduced by X.' A compliance workflow is judged on throughput under audit, not on speed alone, so when a vendor leads with one framing, ask what the other one looks like. Speed with a weak audit trail is not a win in a regulated flow.

The DPDP and RBI questions, and where Orkivanta fits

These stay open and human-owned. Does the VKYC flow meet the RBI's Video-based Customer Identification Process requirements for your licence and product? What does DPDP require for capturing, storing, and retaining video and biometric data, and who may access it? What must the audit log capture — the recording, the liveness result, the reviewer's action — to reconstruct a verification later? Where does human review sit for the cases that do not clear? A vendor can supply the capability and the logs; it cannot supply the certification that your use of it is compliant. That is your counsel's call.

Orkivanta does not sell a packaged VKYC product. The nearest thing we have run is the bespoke regulated verification build at /case-studies/regulated-verification-rails, with the productised agents at /products. What we bring is the auditability and the human-in-the-loop discipline, not a compliance badge.

When building it is the wrong call

When volume is low — buy, do not build; onboarding a few users a day never repays a custom VKYC stack.

When you want to build to dodge vendor cost but cannot staff the accuracy and fraud upkeep. You will ship something worse than what you could have bought, and in a regulated flow 'worse' has a legal edge.

And when the real goal is to remove human review entirely from identity in a regulated flow. That is the one thing neither building nor buying should do — the residual review is part of the design, not a cost to engineer to zero.

Before you talk to anyone

Score your workflow first.

One number, already counted in your systems, that should move — and a switch to stop the thing if it misbehaves. Our readiness test checks exactly that, in a few minutes, with the result shown immediately.

Take the readiness test