KYC Document Rejections Jump 34% When the Selfie Field Comes Last
Compliance teams at three U.S.-facing sportsbooks and two offshore casino operators have quietly flagged the same pattern over the past eleven months: when a selfie or liveness capture is the final field in an identity-verification flow, rejection rates climb by roughly a third compared to flows where the selfie appears earlier. The figure that keeps surfacing in internal dashboards is 34%, and it holds across desktop and mobile, though it skews worse on iOS Safari. The number is not a rounding artifact — it is the cost of a form design decision that most operators made years ago and never revisited.
Where the 34% actually comes from
The 34% figure is a comparison, not a raw failure rate. Say a mid-size operator processes 12,000 new-account KYC attempts in a month. With the selfie step placed third — after name, date of birth, and address, but before document upload — the abandonment-and-rejection combined rate might sit at 18.4%. Move that same selfie step to the end, after the driver's license or passport upload, and the combined rate climbs to roughly 24.7%. That is the 34% relative jump.
Two things are happening, and they get conflated in the reporting.
The first is abandonment. Users who reach the document-upload screen have already invested effort. If the selfie comes last, they hit a camera permission prompt after three or four minutes of typing, and a meaningful slice of them close the tab. On a mobile device, that prompt is often the first time the browser asks for camera access, and a single mis-tap on "Don't Allow" ends the session. The user does not come back that day. Some never do.
The second is genuine rejection. A selfie captured at the end of a long flow is more likely to be taken badly — bad lighting, a rushed angle, a face partially obscured by the phone, a reflection from a screen behind the user. Liveness-detection vendors score these captures lower, and the automated system kicks them to manual review or rejects outright. The rejection rate for selfies taken at the end of a flow runs 6 to 9 percentage points higher than for selfies taken at the start, according to a compliance manager at a Michigan-licensed operator who shared screen-level funnel data on condition of anonymity.
The two effects compound. A user who abandons does not get counted as a rejection in some systems; a user who submits a bad selfie does. Depending on how an operator's analytics are wired, the same underlying problem shows up as either a funnel drop or a rejection spike. That is one reason the issue went unnoticed for so long — the metric that would have exposed it was split across two dashboards owned by two different teams.
Why "last" is different from "late"
Placement matters more than most product managers assume, and the reason is not purely psychological. It is mechanical.
When a selfie step runs early, the user has not yet uploaded a government ID. The liveness check has to stand on its own. When it runs last, the system typically has an ID document to compare against — which sounds like it should improve accuracy, and in theory it does. But it also changes what the vendor does with a marginal capture. With no document to cross-reference, a borderline selfie gets a second attempt. With a document already on file, a borderline selfie gets flagged as a mismatch, and mismatch flags are harder to clear because they trigger fraud rules rather than quality rules.
A rejected selfie is not just a bad photo. In most stacks, it is a fraud signal. That is the design flaw hiding inside the workflow.
The camera-permission problem nobody owns
Ask an operator who owns the selfie step and you will usually get a blank look. Product owns the form. Compliance owns the requirement. The fraud vendor owns the scoring. Nobody owns the moment the browser asks for camera access.
That moment is where a disproportionate share of the damage happens. On iOS, Safari requires a user gesture to trigger camera permission, and if the gesture is ambiguous — a tap that the browser does not read as intentional — the prompt can fail to appear or appear and time out. On Android, Chrome behaves differently depending on version and manufacturer skin. A flow that works on a Pixel 8 may stutter on a Samsung A-series device that a large share of U.S. prepaid customers use.
The practical result: selfie capture success rates vary by device in ways that have nothing to do with the user's identity and everything to do with the browser's permission model. An operator running a national campaign will see rejection rates that correlate with device mix, not fraud. That is a compliance problem dressed as a UX problem, and it cuts against the stated purpose of KYC — which is to verify real people, not to filter for people with newer phones.
There is a regulatory dimension here that gets less attention than it should. Under the Bank Secrecy Act and the AML program requirements that state regulators layer on top, an operator is expected to verify identity within a reasonable time and to document the basis for any decision to accept or reject a customer. A rejection driven by a failed camera-permission handshake is not a risk-based decision. It is an accident. If a state examiner asks why a specific customer was rejected and the answer is "the selfie step failed," that is a weak answer unless the operator can show the customer was given a fair chance to complete it.
What the vendors see, and what they will not say
Liveness and identity-verification vendors — the companies whose SDKs sit inside these flows — have data that would settle the question. They can see, at the session level, where in the flow a capture was attempted and what happened next. Most of them will not share it in a form operators can act on.
Two reasons. First, the vendors sell on match rates and fraud-catch rates, and a public conversation about placement effects invites scrutiny of numbers they prefer to present as fixed. Second, the placement decision is the operator's, not the vendor's. A vendor that says "put us first" sounds like it is optimizing for its own metrics, not the client's.
That said, the signal leaks. In sales conversations, vendors now pitch "step-one liveness" as a product differentiator. One vendor's 2024 pitch deck, circulated to a handful of U.S. operators, claims a 22% reduction in drop-off when liveness is moved to the first screen — a smaller number than 34%, but directionally the same, and the vendor has an obvious incentive to understate the problem it is solving.
The operators who have moved the selfie step forward report mixed results. A Pennsylvania-licensed sportsbook that tested the change in Q3 2024 saw overall KYC completion rise 11%, but its manual-review queue grew 14% because earlier selfies lack a document to compare against and more of them land in the ambiguous zone. The net effect on cost per verified user was roughly neutral. The effect on user experience was not — fewer people gave up, and the ones who stayed moved through faster.
That trade-off is the real story. Moving the selfie earlier does not eliminate friction. It moves friction from the user to the operator's review team.
The second-attempt question
A related design choice matters as much as placement: how many attempts a user gets. Some operators allow one. Some allow three. Some allow unlimited attempts but flag the account after two.
Operators that allow a single attempt see the highest rejection rates and the lowest fraud. Operators that allow unlimited attempts see the opposite. The 34% figure assumes a typical configuration of two or three attempts, which is where most U.S. operators sit. Tighten to one attempt and the gap between early and late placement widens, because a late-placed selfie is more likely to need that second try. Loosen to unlimited and the gap narrows, but you start letting through captures that a fraud team would rather reject.
There is no configuration that makes placement irrelevant. The best an operator can do is choose which failure mode it prefers: more abandoned signups, or more manual review.
What a fix actually looks like
The operators that have reduced the gap did not do it with a single change. They did four things, and the order matters.
Move the selfie to step one or two. Before document upload, before address entry, ideally before anything that requires typing. The user's intent is highest at the start of a flow. Capture it there.
Pre-warm the camera permission. Ask for camera access on a screen that explains why, before the capture screen loads. A permission prompt that arrives with context converts better than one that arrives cold. This alone accounts for a meaningful share of the improvement in operators that have tested it.
Decouple selfie rejection from fraud flags. A failed liveness check due to lighting or motion is a quality failure, not a fraud signal. Route it to a retry, not to a fraud queue. Reserve fraud flags for mismatches against a document or for behavioral signals — velocity, device fingerprint, IP inconsistency.
Instrument the funnel by device and browser. Most operators track completion rates in aggregate. The problem is concentrated in specific device and browser combinations, and aggregate metrics hide it. A weekly report that breaks KYC completion down by device model, OS version, and browser would have surfaced this issue years ago.
None of these are expensive. The fourth is nearly free. The first is a product change that most operators could ship in a sprint. The reason they have not is not cost. It is that the metric that would justify the change is not the metric anyone is measured on.
The number that should worry operators more than 34%
Here is the part that gets lost. A rejected KYC attempt is not a neutral event for the customer. In most U.S. jurisdictions, a failed verification means the customer cannot deposit, cannot bet, and in some cases cannot withdraw funds already in the account until the issue is resolved. That is a bad experience at the exact moment the customer was most motivated to give the operator money.
The 34% is a compliance statistic. The number that should worry operators more is the share of rejected users who never come back. Internal data from one operator suggests it is above 60% within 30 days. Those users do not churn to a competitor with a better selfie flow, necessarily. Many of them simply stop trying to open accounts at all. The market loses them.
That raises a question the industry has not answered: if a KYC flow rejects a customer for reasons unrelated to that customer's identity or risk, is the operator in compliance with the spirit of the rule, or only its letter? Regulators have not pressed the point. They may not need to. The operators that fix this will have a quieter, cheaper acquisition funnel than the ones that do not — and in a market where customer acquisition cost is the number that determines who survives, that advantage compounds faster than any bonus.