Read Time
Categories
Share
What Indonesian regulation makes mandatory at each of six digital onboarding steps under POJK 8/2023, what is only a product choice, and where KYC verification fails.

KYC in Indonesia is a financial institution's duty to identify, verify and monitor its customers. The rule in force for institutions supervised by OJK, the Financial Services Authority, calls it customer due diligence (CDD): POJK 8/2023, enacted and promulgated on 14 June 2023. The word "KYC" doesn't appear once in its 117 pages. For digital onboarding, Article 21 opens three routes for KYC verification, and only the non-face-to-face route requires population data plus two authentication factors. The words "liveness", "OCR" and "e-KYC" aren't in the regulation either.

This piece is for the Head of Digital or CIO who owns the onboarding funnel at a bank, insurer, securities firm or multifinance company, and for the compliance and internal audit (SKAI) teams who have to defend each screen in front of an OJK examiner. That includes regional teams holding an Indonesian subsidiary to a group standard. WEBARQ doesn't sell identity verification. We build the websites and apps those services plug into, so we have no e-KYC product to defend here. "Article" translates Pasal, an "elucidation" is a regulation's official explanatory note, and translations are ours.

The legal name is CDD, and 6 of 14 pages still cite a revoked rule

The anti-money-laundering law, UU 8/2010 (22 October 2010), Article 18, calls the duty prinsip mengenali Pengguna Jasa, the principle of knowing the service user. Its elucidation equates that principle with CDD and enhanced due diligence (EDD) as meant in FATF Recommendation 5. POJK 8/2023, Article 1 point 12, defines CDD, under its English name, as identification, verification and monitoring. The only "know your" in the POJK is "know your employee".

On 7 October 2026 we read 14 Indonesian-language pages that Google showed for "kyc adalah" ("KYC is"). Nine are among the 11 web pages its AI Overview cited while we pulled the results page 25 times, between 23:55 on 6 October and 00:33 on 7 October, Jakarta time. Five are the Indonesian-language articles among the other organic results of the first pull. We counted article bodies only, not navigation or footers.

  • 7 of the 14 name an OJK, Bank Indonesia or Ministry of Finance regulation by number. Six of those cite POJK 12/POJK.01/2017, which Article 89 of POJK 8/2023 revoked on 14 June 2023. One, an insurer's page, cites POJK 8/2023.
  • None cites an article of any regulation, and none states a rupiah amount. One mentions Dukcapil, the population registry.
  • 4 belong to identity-verification vendors. Not one of those names an Indonesian regulation. One lists GDPR, ISO 27001 and PDPA as the regulations that require KYC.

The count stops at those 14 because the organic results wouldn't hold still. Of the 24 later pulls, one reproduced the first organic set. Sixteen returned a thin set of eight results and seven a third set, and neither shared a single URL with the first. Not counted: a page from PPATK, the financial intelligence unit, that we couldn't open; a LoanPro glossary page the AI Overview cited through Google Translate; a journal PDF; three machine-translated foreign pages; and the Instagram and YouTube results. We searched each article body by pattern, and "cites an article" means the word Pasal followed by a number.

An AI Overview appeared on every pull. We saved its text on 18 of them. It never printed a regulation number, and on 14 it listed liveness detection among the stages of KYC.

Three routes for KYC verification in Article 21

Article 21(2) requires verification through at least one of three mechanisms.

  1. Face to face, in person. A member of staff meets the applicant physically (Article 21(3)).
  2. Face to face, electronically. Staff meet the applicant online in real time, and the elucidation's example is a video call (Article 21(4)). This paragraph doesn't mention population data or biometrics.
  3. Non-face-to-face, electronically. An app or website with no video call, the route usually sold as e-KYC. Article 21(5)(c) requires population data and at least two authentication factors: "something you are" (face, fingerprint, or retina or iris pattern) and "something you have". For the second, the elucidation names the KTP, the national ID card, which "must be accompanied" by something else such as a one-time password (OTP) or a digital signature. A KTP alone isn't enough, and a password or PIN is only an optional third factor (Article 21(6)).

Commercial banks carry a stricter rule. POJK 21/2023 on digital services by commercial banks (enacted 19 December 2023, promulgated 22 December 2023) requires at least two authentication factors in verification (Article 5(6)), and "something you are" has to be one of them on both electronic routes, the video call included (Article 5(7)). Securities firms have their own guidance, SEOJK 6/SEOJK.04/2019 (20 March 2019), which still cites POJK 12/POJK.01/2017. Confirm with OJK how it applies.

Six KYC onboarding steps: legal basis, status, failure point

Articles with no regulation named are from POJK 8/2023. The order of the screens is a product decision. What the rule fixes is that verification finishes before the business relationship opens (Article 30(5)).

No.StepWhat happensLegal basisMandatory or product choiceWhere applicants fail
1Identity document and data entryThe applicant photographs an e-KTP, the electronic KTP, or uses Digital Population Identity (IKD), then fills in 10 identity items, source of funds, income or net worth, and the purpose of the business relationship.Article 25(1)(a); Article 26(1) and (2)Mandatory. OCR is a product choice. Simplified CDD for low-risk customers cuts the identity fields to four or five (Article 45(4)) and must be notified to OJK (Article 45(6)). Article 21 isn't among the articles it simplifies.The document photo can't be read.
2NIK check with DukcapilThe institution sends the NIK (national identity number), name, and place and date of birth as typed. Under verification access the reply is match or no match, not data.Article 21(5)(c); Article 30(1); Permendagri 102/2019 Article 29Using population data is mandatory on the non-face-to-face route; the form of the check isn't specified. On the other routes, other reliable and independent sources are allowed.A name typed differently from the population record, even with the right NIK and date of birth.
3Face match and livenessA selfie is matched against a reference photo. The applicant passes if the score clears a threshold.Article 21(5)(c)(1); POJK 21/2023 Article 5(7)A biometric factor is mandatory on the non-face-to-face route, and for banks on the video-call route too. Neither POJK mentions liveness. On what the supervisor expects, see the last section.Unreadable selfie; e-KTP biometrics never recorded; score below the threshold.
4CDD risk ratingThe applicant is grouped by risk level on eight factors, including the delivery channel used.Article 20(1) and (2); Article 35(3); Article 37(1)(c)Mandatory. EDD is mandatory for high risk. A politically exposed person (PEP) needs a senior officer's approval before the relationship opens.Not a failure, but the applicant leaves the automated flow.
5SignatureThe applicant signs on the screen or uses an electronic signature.Article 26(1) and (3); POJK 21/2023 Article 22(1)A specimen signature is mandatory. An electronic signature "may" replace it: a product choice.No public figure.
6Account openingThe business relationship opens once verification is complete, or earlier under risk-management procedures with verification finished afterwards.Article 30(4) to (7); Article 49(1) and (4)Mandatory. Refusal is mandatory when the requirements of Articles 21, 25 or 26 aren't met, and it must be documented.Identity in doubt: more than one identity document must be requested, and an interview may be added.

The table follows an individual Indonesian citizen. For a foreign national the document is a passport plus an immigration document such as a stay permit card (Article 26(2)(b)), and companies have their own document list (Article 27).

Two notes on step 5. The elucidation to Article 26(1) counts a signature drawn directly on the device screen as a specimen. Against that, Article 17(2a) of the ITE Law (the Electronic Information and Transactions Law), inserted by UU 1/2024 (2 January 2024), says electronic transactions that carry high risk for the parties use an electronic signature secured by an electronic certificate. Its elucidation gives financial transactions not conducted physically face to face as an example. Compliance needs to settle the institution's position on that paragraph before the signature type is chosen.

The Dukcapil NIK check answers match or no match

Dukcapil is the Home Affairs Ministry's Directorate General of Population and Civil Registration. By its own account, verification access doesn't hand over population data. Its press release of 15 June 2020 explains that the user institution sends the NIK, name, and place and date of birth the applicant entered, and gets back a notification reading SESUAI (match) or TIDAK SESUAI (no match). Its example: same NIK and date of birth, different name, and the reply is "Data Tidak ditemukan" (data not found). That's a 2020 explanation, not today's API specification. Ask Dukcapil or your vendor for the current interface contract.

Access is governed by Permendagri 102/2019, a Home Affairs ministerial regulation (enacted 6 December 2019), as amended by Permendagri 17/2023 (enacted 20 October 2023). Article 29(4) limits Indonesian legal entities with majority foreign ownership to verification access with a match or no-match confirmation. So a majority foreign-owned subsidiary can't ask for more than that reply. Article 38A bars users of population data from charging the public a fee. On our reading, the cost of the check can't be billed to the applicant.

The fees are in the annex to PP 10/2023, a government regulation promulgated on 27 February 2023:

  • NIK verification by web service: Rp1,000 per NIK;
  • face recognition biometrics by web service: Rp3,000 per biometric;
  • fingerprint biometrics by web service: Rp2,000 per biometric.

Those are tariff ceilings (elucidation to Article 1(2)) and exclude any vendor fee. Article 4 sets the fee at zero for government agencies, social security agencies, cooperatives, and micro and small enterprises. Banks, insurers, securities firms and multifinance companies aren't on that list. If the NIK check and the face match are billed separately, the ceiling is Rp4,000 per attempt, or Rp400 million for 100,000 attempts. We couldn't find an official source saying whether a face call already includes the NIK check.

Dukcapil administrative data as of September 2022, printed in a World Bank project appraisal document (PAD5112, 21 April 2023), show the 26 financial-sector organisations among its 50 largest institutional users running 2,588,689,049 demographic authentications and 41,018,797 biometric ones. The biometric share, on our arithmetic: 1.56%. The same document calls demographic matching error-prone. Those figures predate the PP 10/2023 fees. Dukcapil's later count: its face recognition service was accessed 667,348,734 times up to 30 June 2026, 299,642,054 of them by banking (Dukcapil, 7 August 2026). The two counts aren't comparable, so we haven't recomputed the share.

Why does KYC verification fail?

From the institution's side, failure comes from four sources that can be pinned to an article or a number.

  • The typed fields don't match. A demographic check answers yes or no to what the applicant typed. A different name is enough to fail.
  • The photo can't be read. PAD5112, paragraph 18, records fintech providers reporting that as many as 60% of customers send selfies holding an e-KTP that are unreadable or need manual handling such as a video call. No sample size is given. Treat it as a rough upper bound.
  • No biometric record yet. Dukcapil's clean population data for the first half of 2026, released on 3 August 2026 (Dukcapil, 4 August 2026): 208.53 million of the 214.35 million residents required to hold an e-KTP have recorded their biometrics, or 97.28%. The difference is 5.82 million people. In the 2025 results it was 5.36 million (206.46 million of 211.82 million, 97.47%). Both differences are our subtraction. The remainder is an administrative count, not a queue of applicants: reporting the same statistic in February 2022, Dukcapil's then Director General said the unrecorded may have died, changed citizenship or be recorded under another identity.
  • The regulation itself stops the flow. A doubtful identity triggers a request for a second document such as a passport or driving licence (Article 30(4)). High risk triggers EDD. Unmet requirements trigger mandatory refusal (Article 49(1)).

We found no regulator that publishes drop-off per step, and we have no figures of our own to share. Measure your funnel against each row of the table. The record already has to exist: Article 49(4) requires the institution to document the applicants it refuses.

How long does KYC verification take?

For verifying a new customer, POJK 8/2023 knows one time limit: 3 working days. Article 30(5) wants verification finished before the business relationship opens. If the institution opens it first under risk-management procedures, verification must be completed as soon as possible and within 3 working days (Article 30(6) and (7)). The elucidation's example is a stock-exchange trade that can't wait. There is no duration in minutes. For parties supervised by Bank Indonesia, PBI 10/2024 (enacted 30 December 2024), Article 22(5), sets the same 3 working days.

Four of the 14 pages we read promise completion in seconds or minutes. None mentions 3 working days. Minutes are a product promise, not a regulatory number. A PEP, who needs a senior officer's approval, and an applicant whose identity is in doubt can't finish automatically at all.

A vendor can verify; the institution stays responsible

Article 22 requires a written cooperation agreement whenever third-party software or hardware is used on either electronic route (Article 22(1)). The vendor must be a limited liability company or cooperative that is recorded, registered, licensed or approved by OJK, and must hold its own cooperation agreement with the ministry or agency that runs population and civil registration (Article 22(2)). The agreement has to cover at least ten items. Three worth guarding: the data from carrying out verification belongs wholly to the institution (Article 22(3)(d)), data is shared without a switch of application or device (Article 22(3)(f) and its elucidation), and subcontracting needs the institution's written approval (Article 22(3)(g)). The elucidation to Article 22(3)(b) adds a duty for the vendor: hand over records and data within 3 working days of an OJK request. Under Article 22(4) the institution stays responsible for the verification result.

Our reading of point (f): a flow that sends the applicant off to another app to be verified should be tested against it before the contract is signed.

One of our projects with a published case study touches this flow: the online registration system for CGS International, a securities firm. The case study describes a web form with OCR technology, backed by video call and self-verification, and links to banks, CGS-CIMB, KSEI (the central securities depository) and Dukcapil. That is all we claim. The page doesn't use the word KYC and doesn't mention liveness, face matching or electronic signatures.

What this means for the Head of Digital, compliance and SKAI

  • Head of Digital or CIO: set the route per product and risk level. The non-face-to-face route demands four things at once: the KTP, its companion such as an OTP, a biometric, and population data. An applicant who fails any one of them needs another route, so design the video call or the branch into the funnel.
  • Banks: the face-match threshold is your own number. Appendix I of POJK 21/2023 asks for the detailed specification of each authentication factor in the digital-service licence application, and its example for face recognition is the confidence threshold. Neither POJK sets the figure.
  • Compliance and SKAI: the risk assessment has to be finished before a new channel or technology is launched (Article 18(2)). A face photo is biometric data, which Article 4(2) of the Personal Data Protection Law, UU 27/2022 (17 October 2022), classes as specific personal data, so processing it triggers the data protection impact assessment in Article 34 of UU PDP. Read literally, Article 49(5) of POJK 8/2023 requires a refused applicant to be reported to PPATK as a suspicious financial transaction. We couldn't find it written how that applies to an applicant who only fails a selfie. Ask your OJK supervisor.

Our view: choosing a liveness vendor before choosing the route gets the order backwards. The route decides what's mandatory. And the two failure points that have a written source, a name typed differently and a photo that can't be read, are problems of the name field and the camera guidance. Liveness is still a sensible control against photo attacks and deepfakes. It isn't the answer to those two failures.

Don't read the silence of both POJKs on liveness as permission to skip it, though. On 12 May 2026 the head of OJK's Banking Regulation and Development Department said OJK expects financial institutions to treat strong liveness verification as a core operational need, and that it is committed to drafting regulatory guidance with the industry (reported by Katadata, 13 May 2026). That's a supervisor's expectation, given in a written statement at a forum the fintech association Aftech held with an identity-verification vendor. It isn't rule text yet.

If your onboarding funnel is being redesigned through mobile app development or website development, start from the table above: one row, one owner, one number.

Prepared by WEBARQ with AI assistance from primary texts retrieved on 7 October 2026. We checked the in-force status of the laws, the government regulation, the ministerial regulations and both POJKs in the BPK regulation database on the same day. Translations of Indonesian regulatory text are ours. This is not legal advice.

Back to List