11 September 2026 FinTech By Vedhagiri Prakasam

eKYC in Oman: What Happens Between the ID Scan and a Verified Customer

For the customer, digital identity verification is four steps. For the institution, it is five separate judgements that can each fail on their own.

Upload an ID, take a selfie, wait a moment, done. That is the journey a good eKYC flow should feel like. Underneath it, the system has to decide whether the document is genuine, whether its details were read correctly, whether the person holding the phone is the person on the card, and whether that person is actually present. A perfect answer to one of those questions says nothing about the others.

Abstract illustration of form fields in rows, standing for an identity verification journey

Four steps for the customer, five judgements for the system

The four steps the customer sees

Step What the customer does What the system has to establish
1. Upload IDPhotographs an Omani Resident ID or National ID, with guided framingThe image is usable, and it is a genuine card rather than a copy or an edit
2. Selfie or videoTakes a short capture of their faceA live person is present, not a photo or a replayed video
3. AI verificationWaitsFields are extracted, the face is compared with the card, and fraud signals are checked
4. Share verified dataNothing furtherThe result reaches the institution's own system, carrying only what it needs

Step one is harder than it looks. Omani cards carry Arabic and English side by side, and the fields that break extraction are rarely the ones anyone tests first.

Five judgements, not one

Behind step three sit five distinct checks. Extraction reads the card. Face match compares the selfie with the card's photograph. Liveness asks whether anyone was actually in front of the camera. Fraud and risk checks look for forgery, tampering and known bad identities. And decisioning combines the rest into a result.

They fail independently, which is the whole reason there are five. OCR will read a forged card as cleanly as a real one. A face match will pass a printed photograph of the cardholder. Each gap is covered by a different check, which is why the series that follows takes liveness and document fraud one at a time.

A confidence score, not a yes or no

A useful eKYC system does not return verified or rejected. It returns a result with a confidence attached, and the evidence behind it. That lets the institution set its own lines: high-confidence results with every check passed proceed automatically; anything uncertain goes to a person.

Where those lines sit is a policy decision for the institution, not a constant shipped with the software. They should be set against the institution's own risk appetite and tested on its own customers before anything is automated.

Where people stay in the loop

A worn card, a dim room, a face match just under the threshold, a fraud signal with an innocent explanation — these are the cases a reviewer should see, with every signal laid out rather than a single unexplained score. Automation should take the clear cases off the queue so that people spend their attention on the unclear ones.

The part that is not a feature

Reading an ID card is personal data processing. Comparing a face to it is biometric processing, and under Article 5 of Oman's Personal Data Protection Law, issued by Royal Decree 6/2022, processing biometric data is prohibited except after obtaining a permit from the Ministry. That belongs in the project plan before the pilot, not after it — the detail is in eKYC under the PDPL and in what ID capture obliges you to keep and delete.

ekyciq is Muscat Tech Solutions' identity verification product for Oman, built around exactly this journey. See how ekyciq works, or talk to us about verifying customers in your own onboarding.

You may also like

Related posts