Overview
This guide covers FrankieOne’s KYC solution for Buy Now Pay Later (BNPL) providers, designed to support identity verification, fraud prevention, and responsible lending obligations while maintaining the low-friction experience BNPL customers expect.Summary
Available Workflows
Tiered Verification Approach
Tier Definitions
Quick Implementation Flow
Decision Outcomes
Key Fraud Signals
Support
- Documentation: docs.frankieone.com
- Support: Contact your FrankieOne representative
Expanded Details
Regulatory Context
Disclaimer: The information in this section is provided for general guidance only and does not constitute legal or compliance advice. Customers must seek independent legal and regulatory advice to ensure their implementation meets their specific regulatory obligations. FrankieOne is not responsible for customers’ compliance decisions or outcomes.
Regulatory Updates: BNPL regulation in Australia is evolving. The Australian Government has announced reforms to bring BNPL under the National Consumer Credit Protection Act. Customers should monitor updates from ASIC and Treasury to ensure ongoing compliance.
Australian BNPL Regulatory Framework
BNPL providers operate under an evolving regulatory framework. FrankieOne’s BNPL workflows can support these obligations:Upcoming BNPL Reforms
The Australian Government has announced BNPL will be regulated as a credit product. Key changes may include:Workflow Configuration Details
Design Principles for BNPL
BNPL verification must balance:- Low friction: Customers expect instant approval
- Fraud prevention: BNPL is a target for fraud due to instant credit
- Regulatory compliance: Meeting current and upcoming obligations
- Scalability: High volume, variable transaction values
Primary Workflow: AUS-Basic2V-LowFriction
Optimised for BNPL’s low-friction requirements while maintaining verification integrity.
Core Checks:
Step-Up Workflow: AUS-Basic3V-Standard
Triggered for higher-risk scenarios or higher credit limits.
Step-Up Triggers:
Fraud Detection: AUS-Risk-CDD-Email-Phone-Device
BNPL is particularly vulnerable to fraud. This workflow assesses fraud signals.
Risk Signals Evaluated:
Step-by-Step Implementation
Note: This section describes the conceptual implementation flow. For actual API endpoints and schemas, refer to the FrankieOne API Documentation.
Step 1: Collect Customer Details
Collect minimal required information for frictionless experience:- Full name
- Date of birth
- Residential address
- Email address
- Mobile phone number
UX Consideration: Pre-fill where possible, minimise form fields, support autofill.
Step 2: Identity Verification
Verify customer identity against authoritative sources. For BNPL, speed is critical. Verification Approach by Scenario:Step 3: Fraud Assessment
Evaluate fraud risk signals to protect against BNPL-specific fraud patterns. Common BNPL Fraud Patterns:Step 4: Risk Decision
Combine identity and fraud signals into a risk decision.Step 5: Handle Outcomes
APPROVE:- Proceed with transaction
- Set appropriate credit limit
- Enable repeat purchase capability
- Request additional verification
- May include document upload
- Time-limited to maintain conversion
- Display compliant decline message
- Do not disclose specific reasons
- Log for review if borderline
Risk Tier Examples
Tier 1: Low Risk - Instant Approve
Customer Profile:- Australian resident, 28 years old
- Name and DOB verified
- Email aged 3+ years
- Device not flagged
- First purchase $80
Sarah Testone, 28, makes her first BNPL purchase for $80 at an online retailer. Identity verified instantly against electoral roll and credit bureau. Email is 5 years old, device shows no risk signals. Approved in 3 seconds.
Tier 2: Medium Risk - Step-Up Required
Customer Profile:- Identity verified but address mismatch
- New email address (14 days)
- Higher value purchase ($450)
Michael Testtwo, 24, attempts a 500 initial limit.
Tier 3: High Risk - Decline
Customer Profile:- Multiple identity inconsistencies
- Disposable email domain
- Device associated with previous fraud
- Synthetic identity indicators
Application received with name “David Testthree”. Identity check shows inconsistencies across sources. Email is from disposable domain. Device fingerprint matches 3 previously declined applications. Synthetic identity patterns detected. Application declined.
Edge Cases and Special Handling
Young Adults (18-21)
Young adults may have limited credit history, making verification challenging.Address Verification Challenges
Returning Customers
Merchant Risk Considerations
Some merchants/categories carry higher fraud risk:Fraud Prevention
BNPL-Specific Fraud Vectors
Device Intelligence
Device signals are critical for BNPL fraud prevention:Velocity Controls
Compliance Reporting
Audit Trail Requirements
Responsible Lending Support
For upcoming responsible lending obligations, FrankieOne verification data can support:- Customer identification for affordability assessments
- Consistent identity across credit applications
- Fraud indicators that may affect creditworthiness assessment