Read Time
Categories
Share
Of eleven digital onboarding steps, only four are mandatory for every institution. Each step mapped to its article in POJK 8/2023.

KYC (Know Your Customer) in Indonesia is the duty of a financial services institution to identify and verify a prospective customer before opening a business relationship, then monitor that customer for as long as the relationship lasts. For the financial services sector the legal basis is OJK Regulation (POJK) No. 8 of 2023, issued and effective 14 June 2023. What rarely gets said: of the eleven steps in a typical digital onboarding flow, only four are mandatory for every institution, three are mandatory only if you choose an electronic channel with no face-to-face contact, and the regulation never uses the word "liveness".

This piece is written for the Head of Digital or CIO of a bank, insurer, securities firm or multifinance company that owns an onboarding funnel, with a compliance officer reading over their shoulder. The definition of KYC fits in the paragraph above. The rest is about decisions: which steps can't be removed, which ones you chose yourselves, and where the legally permitted levers on the funnel are. Throughout, "POJK 8/2023" is the regulation on implementing the anti-money laundering, counter-terrorist financing and counter-proliferation financing programme (APU-PPT-PPSPM) in the financial services sector. Quotations from it are our translation of the Indonesian text.

KYC and CDD in two sentences

KYC is the whole sequence of identifying and verifying a prospective customer. CDD (customer due diligence) is the part of KYC that assesses risk: Article 1 point 12 of POJK 8/2023 defines it as identification, verification and monitoring to confirm that transactions match the customer's profile, characteristics and transaction pattern, and Article 1 point 14 defines EDD (enhanced due diligence) as deeper CDD for high-risk customers, including politically exposed persons (PEPs).

One finding that changes how you read the funnel

The order almost every app uses (national ID number check, liveness and face match, documents, CDD risk rating, e-signature, active account) is a product design, not a legal sequence. Article 21 paragraph (2) of POJK 8/2023 gives the institution three verification mechanisms, to be used singly or in combination: "face-to-face meeting in person", "face-to-face meeting by electronic means", and/or "non-face-to-face by electronic means". The only ordering the law fixes is that verification must be finished before the business relationship is opened, with one exception covered below.

Our view: product teams too often answer an examiner with "that's the flow our vendor ships". It isn't an answer. The examiner wants the reason you chose that order, and the reason has to point either at an article or at your own risk policy.

The legal basis of each step, numbered

The table maps eleven steps to their articles. "Mandatory" means the law requires it; "product choice" means you decide. All references are to POJK 8/2023 unless stated otherwise. NIK is the 16-digit national identity number; Dukcapil is the Ministry of Home Affairs' population and civil registry directorate.

#Funnel stepMandatory or choiceBasis
1Collect identity data and identity documentsMandatory. For Indonesian citizens: KTP (national ID card) or digital population identityArt. 21(1)(a); Art. 25(1)(a) (including the "biological mother's maiden name"); Art. 26(2)(a)
2Check the NIK against population data (Dukcapil)Mandatory if you choose the non-face-to-face electronic channel. The text for the video-call channel does not include itArt. 21(5)(c)
3Biometric factor, the customer's "distinguishing characteristic" (face match)Mandatory as a factor class in the same channel. The specific technique, including passive or active liveness, is a product choiceArt. 21(5)(c) item 1 and its Elucidation
4Second factor, "something the customer holds": KTP plus OTP, digital signature or equivalentMandatory in the same channelArt. 21(5)(c) item 2 and its Elucidation
5Use a third party (vendor) for verificationA choice, but the conditions are mandatory: written cooperation agreement; vendor is a registered limited liability company or cooperative licensed or approved by OJK; vendor holds its own agreement with the ministry responsible for population affairs; the financial institution stays responsible for the resultArt. 22(1), (2)(a)-(b), (4)
6Complete verification before opening the business relationshipMandatory. The relationship may open first if risk-management procedures are in place, and verification must then finish within 3 working days at mostArt. 30(5), (6), (7)
7Risk rating (CDD)Mandatory: customers are grouped by money laundering, terrorist financing and proliferation financing riskArt. 20(1)-(2)
8Simplified CDD for low riskProduct choice. If you use your own criteria, OJK must be notifiedArt. 45(1), (6)
9EDD for high risk and PEPsMandatory when the customer is high risk or a PEP. A PEP needs senior-official approvalArt. 35(3); Art. 37(1)(c)
10Electronic signature in place of a wet-ink specimenProduct choice, provided it meets the electronic-signature regulationsArt. 26(3)
11Document retentionMandatory: at least 5 years, and available to OJK within 3 working days of a requestArt. 63(1)(a), (4)

The count: steps 1, 6, 7 and 11 are mandatory for everyone. Steps 2, 3 and 4 are mandatory if the channel is electronic without face-to-face contact. Steps 5 and 9 carry conditional obligations, applying when a vendor is used or when the customer is high risk or a PEP. Steps 8 and 10 are pure product choices. Four, three, two, two: eleven.

Four things in the table that get misread

1. No rule requires liveness

Article 21(5)(c) calls for using population data and at least two authenticity factors: something that is a distinguishing characteristic of the prospective customer, and something the customer holds. The Elucidation gives biometric examples: the face (facial recognition), fingerprint and retina pattern. "Liveness" doesn't appear as a legal term. It's a vendor-side control that stops a photo or a recorded video from passing. We'd still deploy it, because spoofing is a real risk. But the basis is your own risk policy, and that determines what you'll have to explain to an examiner.

2. Paragraph (5)(c) is cumulative

Population data and two factors, not one of them. An app that only matches a NIK to a name hasn't met item (c), whatever the vendor says.

3. Verification may follow, but only by 3 working days

Article 30(5) requires verification to be complete before the business relationship opens. Paragraphs (6) and (7) make an exception: where risk-management procedures are in place, the relationship may start first, and verification must finish "at the latest 3 (three) working days from the occurrence of the business relationship". It's the one legal lever a funnel owner has for cutting friction at the front, and the price is operational risk for up to 3 working days. Article 23(2)(b) closes the other side: a business relationship may not be opened where identity or document completeness is in doubt.

4. A vendor does not move the liability

Article 22(2)(b) requires the vendor to hold its own cooperation agreement with the ministry responsible for population affairs, and paragraph (4) states that the financial institution "must be responsible for the verification result" and for the confidentiality of the data. When choosing a vendor, the committee's first question isn't accuracy. It's whether that agreement with Dukcapil exists, and in whose name.

What a Dukcapil verification returns

Access to population data is governed by Minister of Home Affairs Regulation (Permendagri) No. 102 of 2019 on granting access rights to, and use of, population data. Permendagri No. 17 of 2023 amends it; the BPK regulation database entry for Permendagri 17/2023 lists its status as amending 102/2019. We haven't read the article text of either regulation for this piece, so we cite no article numbers from them and don't say which provisions the 2023 amendment changed. The authority for your design is your own cooperation agreement with Dukcapil and the current consolidated text, which counsel should read before the integration is specified.

The one published example of a response comes from a Dukcapil press release dated 15 June 2020. A partner sends the NIK, name and date of birth, and the result is "SESUAI" (match) or "TIDAK SESUAI" (no match). In that example, a name that differs from the one registered under the NIK doesn't return a match even when the date of birth is the same. Dukcapil's stated position is that partners receive an access right to verify, not the data itself.

Two limits to note. First, that press release was written about peer-to-peer lending partners in 2020, so we don't generalise it to all institutions: the response format in your bank's agreement may be richer. Second, per-institution technical specifications (response fields, per-call fees, face-match scores or thresholds) aren't published, and we found no primary source for them. Per-call prices that circulate in third-party articles aren't quoted here.

Data protection: biometrics are specific personal data

Law No. 27 of 2022 on Personal Data Protection (the PDP Law, promulgated 17 October 2022) classes biometric data as specific personal data (Article 4(2)(b)), and Article 34 requires an impact assessment when processing is high risk, including processing of specific data. Our reading of the text, not a regulator's statement: Article 20(2)(c) makes a controller's legal obligation a lawful basis for processing, so a mandatory KYC step doesn't depend on consent. An automatic rejection by a face-match engine may fall into the automated-decision category in Article 34, but that's also our inference. We didn't check the PDP Law's implementing regulations for this article.

E-signatures: valid, with conditions

Article 26(3) of POJK 8/2023 only requires an electronic signature that satisfies the applicable laws. Government Regulation (PP) No. 71 of 2019 (issued 4 October 2019) gives legal force to electronic signatures that meet six requirements (Article 59(3)), and distinguishes certified signatures, which use an Indonesian electronic certification provider (PSrE), from uncertified ones. The POJK doesn't require the certified type for onboarding. Particular documents, such as credit agreements or anything needing an electronic stamp duty (e-meterai), may carry additional requirements under the Electronic Information and Transactions (ITE) Law. That's the subject of this series' Friday article and we haven't checked it here.

Drop-off per step: what we can't show

The question a funnel owner most wants answered is what percentage of applicants disappear at each step. We searched OJK, Bank Indonesia, Dukcapil, PPATK and Komdigi, and no primary source publishes conversion or drop-off figures per onboarding step. Numbers from vendor blogs aren't used here as fact. That's why the table has no percentage column.

What the legal text does show is where the levers are, not how big they are. Three steps add friction and can't be removed if an electronic channel is chosen (2, 3, 4). One design decision reduces friction up front: Article 30(6)-(7), at the price of operational risk for up to 3 working days. Two decisions are pure choice: simplified CDD (step 8) and the electronic signature (step 10). Measure your own drop-off per step from application logs, separate risk rejections from technical failures, and use that to compare channels.

What this means for your committee

  • Head of Digital / CIO: choose the verification channel first (Article 21(2)); that choice decides whether steps 2-4 are mandatory. The on-screen order is yours to set, except that verification comes before the relationship opens.
  • Compliance / internal audit (SKAI): document why a particular liveness technique was chosen as a risk decision, because the POJK doesn't require it. Keep an archive that can reach OJK within 3 working days.
  • CISO: classify face photos and biometric results as specific data under the PDP Law, and make sure the vendor's agreement with the population ministry can be produced on request.

WEBARQ's position and the limits of our evidence

WEBARQ doesn't sell identity services. We have no e-KYC, liveness or PSrE product, so no vendor in the table above benefits us. Our experience is building the front end of apps for regulated institutions, among them Mirae Asset Sekuritas, Forsa UKME Eximbank, Sequis Apps Online, the PT Bank Mandiri web app, PT Asuransi FPG Indonesia and MNC Leasing. On those projects the KYC logic sat in the client's own systems. We don't claim first-hand experience building Dukcapil or KSEI integrations in this article. Everything here rests on the regulation text cited, and the article was prepared with AI assistance. POJK 8/2023 is the version we saw in force as of 5 October 2026; we found no amendment, which is not proof that none exists.

To build an onboarding flow that survives an examination, see our mobile app development and website development services for financial institutions.

Back to List