Skip to main content

Overview

This guide covers FrankieOne’s KYC solution for Buy Now Pay Later (BNPL) providers, designed to support identity verification, fraud prevention, and responsible lending obligations while maintaining the low-friction experience BNPL customers expect.

Summary

Available Workflows

Tiered Verification Approach

Tier Definitions

Quick Implementation Flow

Decision Outcomes

Key Fraud Signals

Support


Expanded Details

Regulatory Context

Disclaimer: The information in this section is provided for general guidance only and does not constitute legal or compliance advice. Customers must seek independent legal and regulatory advice to ensure their implementation meets their specific regulatory obligations. FrankieOne is not responsible for customers’ compliance decisions or outcomes.
Regulatory Updates: BNPL regulation in Australia is evolving. The Australian Government has announced reforms to bring BNPL under the National Consumer Credit Protection Act. Customers should monitor updates from ASIC and Treasury to ensure ongoing compliance.

Australian BNPL Regulatory Framework

BNPL providers operate under an evolving regulatory framework. FrankieOne’s BNPL workflows can support these obligations:

Upcoming BNPL Reforms

The Australian Government has announced BNPL will be regulated as a credit product. Key changes may include:

Workflow Configuration Details

Design Principles for BNPL

BNPL verification must balance:
  • Low friction: Customers expect instant approval
  • Fraud prevention: BNPL is a target for fraud due to instant credit
  • Regulatory compliance: Meeting current and upcoming obligations
  • Scalability: High volume, variable transaction values

Primary Workflow: AUS-Basic2V-LowFriction

Optimised for BNPL’s low-friction requirements while maintaining verification integrity. Core Checks:

Step-Up Workflow: AUS-Basic3V-Standard

Triggered for higher-risk scenarios or higher credit limits. Step-Up Triggers:

Fraud Detection: AUS-Risk-CDD-Email-Phone-Device

BNPL is particularly vulnerable to fraud. This workflow assesses fraud signals. Risk Signals Evaluated:

Step-by-Step Implementation

Note: This section describes the conceptual implementation flow. For actual API endpoints and schemas, refer to the FrankieOne API Documentation.

Step 1: Collect Customer Details

Collect minimal required information for frictionless experience:
  • Full name
  • Date of birth
  • Residential address
  • Email address
  • Mobile phone number
UX Consideration: Pre-fill where possible, minimise form fields, support autofill.

Step 2: Identity Verification

Verify customer identity against authoritative sources. For BNPL, speed is critical. Verification Approach by Scenario:

Step 3: Fraud Assessment

Evaluate fraud risk signals to protect against BNPL-specific fraud patterns. Common BNPL Fraud Patterns:

Step 4: Risk Decision

Combine identity and fraud signals into a risk decision.

Step 5: Handle Outcomes

APPROVE:
  • Proceed with transaction
  • Set appropriate credit limit
  • Enable repeat purchase capability
STEP-UP:
  • Request additional verification
  • May include document upload
  • Time-limited to maintain conversion
DECLINE:
  • Display compliant decline message
  • Do not disclose specific reasons
  • Log for review if borderline

Risk Tier Examples

Tier 1: Low Risk - Instant Approve

Customer Profile:
  • Australian resident, 28 years old
  • Name and DOB verified
  • Email aged 3+ years
  • Device not flagged
  • First purchase $80
Example Scenario:
Sarah Testone, 28, makes her first BNPL purchase for $80 at an online retailer. Identity verified instantly against electoral roll and credit bureau. Email is 5 years old, device shows no risk signals. Approved in 3 seconds.

Tier 2: Medium Risk - Step-Up Required

Customer Profile:
  • Identity verified but address mismatch
  • New email address (14 days)
  • Higher value purchase ($450)
Example Scenario:
Michael Testtwo, 24, attempts a 450purchase.NameandDOBverifiedbutaddressdoesntmatch(recentlymoved).Emailcreated14daysago.Systemtriggersstepupverification.Customeruploadsdriverlicence,documentverified.Approvedwith450 purchase. Name and DOB verified but address doesn't match (recently moved). Email created 14 days ago. System triggers step-up verification. Customer uploads driver licence, document verified. Approved with 500 initial limit.

Tier 3: High Risk - Decline

Customer Profile:
  • Multiple identity inconsistencies
  • Disposable email domain
  • Device associated with previous fraud
  • Synthetic identity indicators
Example Scenario:
Application received with name “David Testthree”. Identity check shows inconsistencies across sources. Email is from disposable domain. Device fingerprint matches 3 previously declined applications. Synthetic identity patterns detected. Application declined.

Edge Cases and Special Handling

Young Adults (18-21)

Young adults may have limited credit history, making verification challenging.

Address Verification Challenges

Returning Customers

Merchant Risk Considerations

Some merchants/categories carry higher fraud risk:

Fraud Prevention

BNPL-Specific Fraud Vectors

Device Intelligence

Device signals are critical for BNPL fraud prevention:

Velocity Controls


Compliance Reporting

Audit Trail Requirements

Responsible Lending Support

For upcoming responsible lending obligations, FrankieOne verification data can support:
  • Customer identification for affordability assessments
  • Consistent identity across credit applications
  • Fraud indicators that may affect creditworthiness assessment

Conversion Optimisation Tips


Troubleshooting