For the customer, digital identity verification is four steps. For the institution, it is five separate judgements that can each fail on their own.
Upload an ID, take a selfie, wait a moment, done. That is the journey a good eKYC flow should feel like. Underneath it, the system has to decide whether the document is genuine, whether its details were read correctly, whether the person holding the phone is the person on the card, and whether that person is actually present. A perfect answer to one of those questions says nothing about the others.
Four steps for the customer, five judgements for the system
The four steps the customer sees
| Step | What the customer does | What the system has to establish |
|---|---|---|
| 1. Upload ID | Photographs an Omani Resident ID or National ID, with guided framing | The image is usable, and it is a genuine card rather than a copy or an edit |
| 2. Selfie or video | Takes a short capture of their face | A live person is present, not a photo or a replayed video |
| 3. AI verification | Waits | Fields are extracted, the face is compared with the card, and fraud signals are checked |
| 4. Share verified data | Nothing further | The result reaches the institution's own system, carrying only what it needs |
Step one is harder than it looks. Omani cards carry Arabic and English side by side, and the fields that break extraction are rarely the ones anyone tests first.
Five judgements, not one
Behind step three sit five distinct checks. Extraction reads the card. Face match compares the selfie with the card's photograph. Liveness asks whether anyone was actually in front of the camera. Fraud and risk checks look for forgery, tampering and known bad identities. And decisioning combines the rest into a result.
They fail independently, which is the whole reason there are five. OCR will read a forged card as cleanly as a real one. A face match will pass a printed photograph of the cardholder. Each gap is covered by a different check, which is why the series that follows takes liveness and document fraud one at a time.
A confidence score, not a yes or no
A useful eKYC system does not return verified or rejected. It returns a result with a confidence attached, and the evidence behind it. That lets the institution set its own lines: high-confidence results with every check passed proceed automatically; anything uncertain goes to a person.
Where those lines sit is a policy decision for the institution, not a constant shipped with the software. They should be set against the institution's own risk appetite and tested on its own customers before anything is automated.
Where people stay in the loop
A worn card, a dim room, a face match just under the threshold, a fraud signal with an innocent explanation — these are the cases a reviewer should see, with every signal laid out rather than a single unexplained score. Automation should take the clear cases off the queue so that people spend their attention on the unclear ones.
The part that is not a feature
Reading an ID card is personal data processing. Comparing a face to it is biometric processing, and under Article 5 of Oman's Personal Data Protection Law, issued by Royal Decree 6/2022, processing biometric data is prohibited except after obtaining a permit from the Ministry. That belongs in the project plan before the pilot, not after it — the detail is in eKYC under the PDPL and in what ID capture obliges you to keep and delete.
ekyciq is Muscat Tech Solutions' identity verification product for Oman, built around exactly this journey. See how ekyciq works, or talk to us about verifying customers in your own onboarding.
Related posts
-
reKYC: Verification Is a Date, Not a Status
A customer verified three years ago was verified three years ago. That is all the record proves.
11 September 2026 -
10 Automated Checks Every Cheque Platform Should Perform
A single successful OCR result is not enough. Confidence has to be built across the whole document.
31 August 2026 -
Detecting Cheque Alterations and Fraud Indicators with AI
An unusual image characteristic is not proof of fraud. The system flags; authorised people decide.
31 August 2026


