21 Jan 2026

Reading vendor attestations without over-trusting the seal

An IDV provider’s letter can support a story about their factory. It cannot tick your overrides, your cut-off, or your fee join.

Handshake standing in for a vendor relationship

When people financially audit KYC verification applications, a thick vendor pack arrives early: ISO-something, a SOC-shaped report, a penetration-test summary, a marketing one-pager with a hologram. The pack is not useless. It is just the wrong grain for most assertions you will sign.

Read the opinion or independent report for period, system name, and complementary user entity controls. Those last words are where your application lives. If the letter assumes you disable generic admin accounts and you have not, the seal does not travel. If the period ends six months before your sample month, you have a bridge to design, not a free pass.

What the letter can carry

It can reduce (not eliminate) work on the vendor’s change management, access into their production, and certain processing integrity claims about their matching engine. It cannot tell you whether your application stored the callback, whether an operator overrode a fail, or whether a cleared screen happened before a payout. Those are your events. Module 03 of the Audit Lab makes trainees highlight, in yellow, every sentence they wanted to treat as a sample of the customer’s journey. The yellow usually covers too much.

Certificates that mention “KYC”

Product certificates that say a camera liveness feature meets a biometric threshold are still product claims. They may inform inherent risk. They are not operating-effectiveness evidence for your control “we do not fund until liveness passes,” unless you also show that your application required that feature to be on, that it was on in the period, and that failures blocked the financial event. Many GB stacks let a desk skip liveness on “supported customers.” If that skip exists, the certificate is describing a path you might not have used.

Ask for configuration evidence from your application: feature flags, journey versions, and who can waive. That is closer to a financial-audit artefact than a vendor seal in a PDF.

Subprocessors and silence

IDV vendors subcontract. Your application may call vendor A while a document forensic tool is vendor C. If the attestation pack never names C, your trace map should show a blank. Blank is allowed. Filling the blank with “they are certified” is not. Write the unnamed subprocess as a limitation or as a follow-up request. Do not hide it in an appendix nobody reads.

None of this is an argument for ignoring vendors. It is an argument for putting the letter in the right folder: inherent risk and vendor due diligence, not the sample of your KYC application’s financial joins. If you want a public one-page version of that folder logic, use the control ledger.

← Field notes