Gambling in your blood

KYC passport checks stall 41% when selfie uploads hit 3 attempts

· 5 min read
KYC passport checks stall 41% when selfie uploads hit 3 attempts

Internal data from three UK-licensed operators, covering roughly 214,000 verification attempts between January and March 2025, puts a hard number on something compliance teams have suspected for a while: when a customer fails a selfie-based liveness check three times, 41% of those accounts never complete KYC at all. They don't fail outright — they simply stop. The application sits in a pending state until it's eventually closed for inactivity, usually somewhere between day 14 and day 30. Two attempts is survivable, with a drop-off rate closer to 12%. The third attempt is where the funnel breaks.

That 41% figure matters more than it looks, because selfie verification is now the default second step at most UK operators, layered on top of the document upload that used to be the whole process. Under the Gambling Commission's licence conditions and codes of practice, operators must verify age and identity before allowing a customer to gamble or deposit — but the methods used to do that are a commercial and technical choice, and the industry has quietly converged on facial biometrics as the cheapest way to satisfy both the regulator and their own fraud teams. The problem is that the technology's failure modes are not evenly distributed, and the people who hit attempt three are disproportionately the ones operators can least afford to lose.

Why the third attempt is the cliff edge

The mechanics are straightforward. Most liveness providers allow three attempts before locking the session and forcing a manual review or a fresh start. Attempt one fails for mundane reasons: bad lighting, a hat, a phone held at the wrong angle, a face that doesn't match the document photo because the document is eight years old. Attempt two fails for the same reasons plus frustration. By attempt three, the customer has spent four to six minutes on a process they didn't ask for, on a phone, usually in a hurry, and the emotional cost of continuing has overtaken the rational benefit of finishing.

The drop-off isn't linear, and that's the part operators keep getting wrong when they model it. Attempt one to two loses about 12% of the cohort. Attempt two to three loses another 19%. Attempt three to abandonment loses 41% of whoever's left. The curve steepens because the marginal customer at attempt three is not a random sample — they're the subset with older documents, darker skin tones, weaker cameras, or non-standard names, which is to say the subset most likely to already be underserved by mainstream financial and gambling services.

The demographic skew nobody publishes

Of the abandoned applications in the sample, 58% came from devices more than four years old, and 34% came from customers whose document photo was issued before 2019. Both figures are well above the operator average. There's a temptation to read this as a technology problem that better cameras will solve. It isn't. It's a sequencing problem: operators are running the hardest check first because it's the cheapest to automate, then discovering that the customers who fail it are the ones who'd have passed a manual review in ninety seconds.

What the 41% actually costs

Take a mid-sized UK operator doing 40,000 sign-ups a month. If 30% of those reach the selfie stage — plausible, since many are pre-verified via credit reference or open banking — that's 12,000 selfie sessions. A 3% three-attempt rate gives you 360 customers hitting the cliff edge monthly, of which 148 abandon. At an average first-deposit value of £62 and a twelve-month LTV of £340 for the ones who stick, that's roughly £50,000 in foregone annual revenue per month of cohort, before you count the acquisition cost already sunk into getting them to the sign-up page.

The compliance cost runs the other way. Every abandoned application still needs to be logged, retained, and explained if the Commission asks. Under the Money Laundering Regulations 2017, you're required to keep records of verification attempts and the reasons for non-completion for five years. A 41% abandonment rate at the final stage generates a lot of paperwork for customers who never placed a bet.

The regulatory backdrop is tightening, not loosening

This is happening against a backdrop of the Commission's ongoing focus on customer interaction and affordability, and the April 2024 changes to remote customer interaction requirements, which pushed operators toward earlier and more frequent checks. There's a real tension here: the regulator wants more verification, earlier; the technology used to deliver it fails hardest on the customers the regulator also wants protected from over-restriction. Nobody has resolved that tension, and the 41% figure suggests most operators haven't even noticed it exists.

The July 2024 statutory levy consultation and the subsequent fee structure changes have also shifted the economics. Operators are now paying more per licence and per premises, which makes every abandoned sign-up marginally more expensive to absorb. That doesn't change the compliance obligation, but it does change the internal business case for fixing the funnel.

What actually works

The operators in the sample that reduced three-attempt abandonment below 20% did three things, in this order. First, they moved the selfie check after an initial low-friction identity match — usually a credit reference agency check or open banking confirmation — so that only genuinely ambiguous cases reach biometrics. Second, they introduced a hard pause at attempt two, offering a live video call with a human agent instead of a third automated attempt. Third, they stopped treating a failed selfie as a fraud signal and started treating it as a data quality signal, which changed which team owned the problem.

None of that is technically difficult. It's a routing decision. The reason it hasn't happened broadly is that selfie verification vendors price per attempt, not per successful verification, and the internal metrics that matter to the vendor are completion rates on their own product, not the operator's overall KYC funnel. That misalignment is the actual root cause.

The question operators aren't asking

If 41% of customers who reach three selfie attempts never complete KYC, and those customers skew toward older devices and older documents, the obvious question is whether the industry has quietly built a filter that excludes a specific slice of the adult UK population from gambling — not by policy, but by friction. The Commission has spent five years telling operators to identify vulnerable customers and intervene early. It has spent considerably less time asking whether the verification stack itself is doing the intervening, badly, on the wrong people, and without anyone recording it as an intervention.

The next time a compliance team reports a healthy 94% KYC completion rate, it's worth asking what the rate looks like specifically for the cohort that hit three attempts. That number is almost certainly not 94%, and until it's on a dashboard somewhere, the 41% will keep being invisible.