Identity Verification API: A Buyer's Guide for African Banks and Fintechs
ByVictoria okere
•5mins Read
Key Takeaways
An identity verification API lets your app check a customer's identity against authoritative sources in real time, without building those connections yourself.
In Nigeria, the sources that matter most are the National Identity Management Commission (NIMC) database for the National Identification Number (NIN) and the Nigeria Inter-Bank Settlement System (NIBSS) for the Bank Verification Number (BVN).
Government databases go down. A third-party status tracker reported a NIN lookup outage of about six hours on 31 January 2026, so your provider's fallback plan matters as much as its happy path.
A standard integration with a well-documented provider can take days, not months. Data mapping, testing and compliance sign-off usually take longer than the code.
Ask for a contractual uptime commitment, a public status page and a clear remedy. A marketing claim of "99.9% uptime" is not a Service Level Agreement (SLA).
What is an identity verification API?
An identity verification API is a software interface that lets a business confirm a person's identity programmatically. Your application sends identity data, such as a NIN, BVN, ID document image or selfie. The API checks it against trusted sources and returns a structured result your system can act on immediately.
For banks, fintechs, payment companies and gaming operators in Africa, that result decides whether a customer is onboarded, sent for review or declined. It also becomes part of the record an examiner from the Central Bank of Nigeria (CBN) or the Nigerian Financial Intelligence Unit (NFIU) may ask to see.
Most guides to identity verification APIs are written for developers. This one is written for the people who sign the contract. It answers the questions compliance officers, heads of risk and CTOs actually ask vendors before they integrate.
How does an identity verification API work?
Every identity verification API follows the same basic loop. Your app collects the customer's details, sends them to the provider and receives a decision it can act on.
The request carries whatever your onboarding flow captured. In Nigeria that is usually a NIN or BVN, a selfie for face match and liveness detection, and sometimes an ID document image. The provider routes each item to a source. NIN checks are normally answered from NIMC records and BVN checks from NIBSS, though the exact route varies by provider. The selfie is compared with the photo held on the record.
The response comes back as structured data, typically JSON, with a match status and the fields that were confirmed. Checks that need manual review return later through a webhook, a server-to-server callback that delivers the result when it is ready. Your system then applies your own rules: approve, review or decline.
The part most buyers never ask about is the failure path. What happens when NIMC is slow, a selfie is too dark or a name is spelt differently on two records decides your real conversion rate and your audit trail.
How long does it take to integrate an identity verification API?
The code is rarely the slow part. Youverify'sKYC API integration guide estimates three to seven days for a backend developer, when the provider offers a production-like sandbox, SDKs and clear error codes. Providers with poor documentation can stretch that to several weeks.
The full project takes longer because of the work around the code. Your team must map which checks apply to which customer tier, design the review queue and test failure cases. Compliance must also sign off the flow, and your data protection officer may need to assess it under theNigeria Data Protection Act 2023 (NDPA).
Ask each vendor three things before you commit. Does the sandbox return realistic NIN and BVN test responses, including failures? Are SDKs available for web, iOS and Android? Do asynchronous results arrive by webhook, or must your team poll for them?
Can one API cover KYC, KYB and AML across multiple African countries?
It can, but only if the coverage is real in every country you need. Africa is not one identity market. Nigeria uses the NIN and BVN, Ghana uses the Ghana Card, and South Africa verifies against the Department of Home Affairs.
Regulators differ as well. A fintech in Nigeria answers to the CBN and NFIU, while one in South Africa answers to the Financial Intelligence Centre (FIC). A single integration saves engineering time only if the provider maps each country's checks to that country's rules.
Ask for a country-by-country list showing which checks are live registry lookups and which are document checks only. Then ask whether Know Your Business (KYB) checks against company registries, such as Nigeria's Corporate Affairs Commission (CAC), and Anti-Money Laundering (AML) screening run on the same customer record.
Which ID databases does the API check, and does it connect directly?
This question separates strong providers from resellers. A provider can query a government source directly, go through an aggregator, or match against a cached copy of past results.
Each extra hop adds a failure point and a delay. A cached match may also miss a record that changed yesterday. For BVN and NIN checks, Youverify's own integration guide advises confirming whether the lookup is a live registry query or a cached database match.
Ask the vendor to name the source behind every check, not just the check itself. "NIN verification" tells you little. "Live query to NIMC, with a second route if the first fails" tells you what you are buying.
During an earlier maintenance outage of its NIN Verification Service, TheCable reported that NIMCdirected users to its alternative tokenisation platform. Once NIN checks sit inside your onboarding flow, NIMC's uptime effectively becomes your uptime.
A good provider plans for this instead of returning a generic error. It should tell your system the source is unavailable, retry automatically and push the final result by webhook. It may also offer a second route, such as tokenised NIN verification or a BVN check.
What your business does during the outage is a compliance decision, not an engineering one. Some institutions pause onboarding. Others open restricted accounts and verify later, which must stay within CBN tier limits. Agree that policy in writing before you need it.
What uptime SLA should you expect from an identity verification API provider?
Ask for a contractual commitment, not a figure on a sales page. A Service Level Agreement (SLA) should define how uptime is measured, what counts as a breach and what you receive when one happens.
The percentages sound similar but are not. Over a 30-day month, 99.9% uptime allows about 43 minutes of downtime. 99.5% allows about 3.6 hours, which is roughly one NIMC outage.
Read the exclusions closely. Many SLAs exclude failures in third-party sources such as government databases. That may be fair, but you need to know it before signing. Also ask whether the provider runs a public status page and how quickly it notifies you of an incident.
Does the API support the CBN's tiered KYC requirements?
It should let you build a different flow for each tier, but the tier rules themselves are your responsibility. The CBN introduced itsthree-tiered KYC requirements in a circular dated 18 January 2013. They allow lighter checks for low-value accounts, with transaction and balance caps that rise by tier.
The documentation differs by tier. For example, a 2017 CBN circular on mobile money made the BVN mandatory for wallet holders on tiers 2 and 3, but not tier 1,as reported by InvestData.
Ask whether the API supports step-up verification. When a tier 1 customer reaches their limit, they should complete the extra checks without starting again. For the full rules, see our guides to theCBN three-tiered KYC requirements andCBN KYC/AML requirements for 2026.
How to evaluate an identity verification API provider
Use the same questions with every vendor, and judge the answers rather than the features list. The table shows what a strong answer sounds like and what should worry you.
Question to ask
A strong answer
A red flag
Which source sits behind each check?
Names NIMC, NIBSS or the registry, and says whether the query is live
"We cover NIN verification" with no source named
What happens when NIMC is down?
Clear status code, automatic retry, webhook result, a second route
A generic error your team must handle
What uptime do you commit to in the contract?
A defined SLA, breach terms, service credits and a status page
A marketing uptime figure with no remedy
How long does integration take?
A realistic sandbox, SDKs and a named technical contact
"A few lines of code" with no test data for failures
Can one integration cover KYC, KYB and AML?
Checks attach to one customer record you can audit
Separate products, separate reports, separate IDs
Where is our customers' data stored and processed?
Named locations, sub-processors and retention periods
No clear answer until after signing
How Youverify's identity verification API answers these questions
Youverify Cowork runs KYC, KYB, AML screening, transaction monitoring and case management onone platform with one set of credentials. Every check attaches to a single customer record, so an examiner sees one history rather than four reports.
According to its developer documentation, Youverify holds SOC 2 Type II, ISO 27001, ISO 27018 and ISO 42001 certifications. It also complies with data protection laws in Nigeria, Côte d'Ivoire, Kenya, South Africa and the UK, among others. See ourcountry coverage for supported checks by market.
An identity verification API is easy to buy and hard to replace. The vendor you choose shapes your onboarding speed, your audit trail and how your business behaves when a government database goes offline.
Ask where each check comes from, what happens when it fails and what the contract promises. The answers will tell you more than any demo.
About the Author
Victoria Okere is a compliance content writer at Youverify, specializing in AML compliance, financial crime risk, regulatory technology, and emerging trends in financial services.
FAQs
Frequently Asked Questions
A verification API is an interface that lets software confirm whether information is true by checking it against a trusted source. Identity verification APIs confirm a person's identity using data such as a national ID number, document image or selfie. They return a structured result your system can act on in real time.
Yes. Some identity verification APIs verify driver's licences, but capability varies by country and method. They work either by reading the document and checking its security features or by querying the issuing authority's records. In Nigeria, ask whether the provider checks the Federal Road Safety Corps (FRSC) record or only reads the card. The difference changes how much assurance you get.
An identity verification API confirms that a person is who they claim to be. A KYC API usually does more. It combines identity checks with AML screening, risk scoring and record keeping to meet Know Your Customer rules. Many providers use the terms interchangeably, so ask exactly which checks each call runs.
Most Nigeria-focused providers verify both. NIN checks are normally run against NIMC records and BVN checks against NIBSS, but the route varies by provider. Confirm whether each lookup is a live registry query or a cached match, because a cached match can miss recent changes to a record. Also ask how the API behaves when either source is unavailable.
A backend developer can complete a standard integration in three to seven days with a well-documented provider, according to Youverify's integration guide. The full project usually takes longer. Mapping checks to CBN KYC tiers, testing failure cases and getting compliance sign-off often take more time than the code.
NIN checks fail or slow down until service returns. A third-party status tracker reported two NIN lookup outages in early 2026, each lasting about six hours. A strong provider returns a clear status, retries automatically, delivers the result by webhook and may offer a second route. Decide in advance whether to pause onboarding or open restricted accounts.
There is no standard figure. Ask for the contractual availability definition, measurement window, exclusions, service credits and incident-notification commitments. For scale, 99.9% availability allows about 43 minutes of downtime in a 30-day month. A marketing uptime figure is not an SLA.