Jumio vs Trulioo vs deepidv: AUSTRAC Tranche 2 Readiness
Jumio, Trulioo, and deepidv compared for AUSTRAC Tranche 2 compliance: enrolment-to-examination readiness, SMR quality, and AML programs that match practice.
Sumsub, 1Kosmos, and deepidv compared for GENIUS Act stablecoin CIP compliance: bank-grade identification, watchlist screening, and the 12-month build window.
An operational engineering analysis evaluating deepidv, Sumsub, and 1Kosmos against the proposed customer identification program requirements for permitted payment stablecoin issuers under the GENIUS Act.
Stablecoin issuers are about to inherit bank-grade identity obligations, and the extended comment window closing October 23 is the last quiet stretch before the build. The five-agency proposal requires each permitted payment stablecoin issuer to run a written CIP: collecting name, date of birth or formation, address, and identification number; verifying through risk-based documentary or non-documentary procedures; screening against terrorist watchlists; and retaining records for five years, with compliance due 12 months after the final rule. Issuers comparing Sumsub, 1Kosmos, and deepidv for the build-out are comparing three different distances from that finish line.
| Requirement | deepidv | Sumsub | 1Kosmos |
|---|---|---|---|
| Bank-grade CIP collection and verification | Native single-session flow | Configurable KYC workflows | Wallet enrolment flow |
| Watchlist and sanctions screening | Luna, continuous and event-driven | Integrated screening module | Via integration |
| Institutional and entity onboarding (KYB) | Arc-routed entity credentials and registry proof | KYB product line | Workforce-identity heritage |
| Evidence retention and audit trail | Five-year decision-trail architecture | Case management records | Credential event logs |
| Verifiable credential and wallet ingestion | Arc: eIDAS 2.0, mDLs, ZKP tokens | Roadmap-stage support | Native wallet, proprietary format |
| Regulatory change tracking | Luna maps rulemaking to program gaps | Compliance content resources | Not a product focus |
deepidv's verification engine and agentic compliance suite treats the CIP list as its native workload. The platform collects and verifies the four required data elements in one session, with document forensics, NFC chip validation, and deepeye liveness underneath the verification verdict. Luna runs watchlist screening continuously rather than at onboarding only, tracks the rulemaking docket itself, and maintains the five-year evidence trail examiners will request. For issuers whose customers arrive holding credentials, Arc ingests eIDAS 2.0 attestations, mobile driver's licenses, and ZKP tokens. The deepidv vs Sumsub comparison details the head-to-head.
Sumsub offers one of the widest KYC/KYB toolkits in the market, and crypto-native firms know it well. For GENIUS Act CIP specifically, the questions are around the edges: continuous screening cadence, credential ingestion for institutional counterparties, and how much program logic the issuer's team must configure and maintain themselves. A capable compliance team can assemble a conforming program on Sumsub; the twelve-month clock makes the assembly cost a real line item.
1Kosmos brings hardened credential binding and passwordless authentication from its workforce heritage, valuable for securing issuer operations and repeat institutional access. As the primary CIP engine, its wallet-centric model aligns less directly with a rule written around collection, verification, screening, and retention for arbitrary new customers, including entities. Issuers drawn to its authentication strengths often pair it with a dedicated verification engine; the platform comparison hub covers where the boundary falls.
Suggested read: Stablecoin CIP comment window extended to October 23
The most underweighted line in the proposal is the compliance date: 12 months after the final rule. Subtract vendor selection, integration, testing, and examiner-ready documentation, and the effective build window is closer to two quarters. Issuers should therefore score vendors on time-to-conforming-program, not feature checklists. Three questions cut through demos. How much of the CIP obligation does the platform operate versus merely enable? What does the evidence trail look like on day one of an examination? And when the final rule moves the perimeter, who reconciles the program: the vendor's agent or the issuer's staff?
Primary-market scope is the wildcard. Commenters are pressing the agencies to redraw the primary/secondary boundary, and a final rule that moves it will reward platforms that can extend verification outward without re-architecture.
The comment window's extension gives issuers one more quarter of leverage: vendors answer harder questions before contracts are signed than after. Five belong in every evaluation. Show the evidence file an examiner would receive for one contested onboarding decision, produced live, not mocked. Demonstrate watchlist screening propagation time from a list update to an alert on an existing customer. Walk through exactly what changes in the platform, and who performs the change, if the final rule extends obligations beyond the primary market. Produce latency distributions for the full CIP collection-and-verification flow on real mobile traffic. And name the red-team cadence: when the platform's own defenses were last attacked with current fraud tooling, and what was found.
The proposal requires permitted payment stablecoin issuers to maintain a written customer identification program: collecting name, date of birth or formation, address, and ID number before account opening; verifying identity through risk-based procedures; screening against terrorist watchlists; providing customer notice; and retaining CIP records for five years. Compliance is due 12 months after the final rule.
Issuers with large compliance teams can assemble conforming programs on configurable toolkits like Sumsub. Issuers that need the platform to operate the program, continuous screening, evidence trails, rulemaking tracking, and credential ingestion included, are the profile deepidv was built for. 1Kosmos fits best as an authentication and credential layer alongside a verification engine.
Not under the current proposal, which limits CIP to primary-market relationships between the issuer and its direct customers. Commenters have asked the agencies to reconsider that boundary, so issuers should prefer architectures that can extend verification scope without rebuilding.
A customer identification program, or CIP, is the Bank Secrecy Act requirement that a financial institution collect and verify identifying information, name, date of birth or formation, address, and ID number, before opening an account, screen against terrorist watchlists, and retain records. The GENIUS Act rulemaking extends this banking obligation to permitted payment stablecoin issuers.
The extended comment period closes October 23, 2026. A final rule in 2027 would make compliance mandatory 12 months later, putting live, examinable CIP programs in the 2028 timeframe, with the practical build window considerably shorter once selection and integration are subtracted.
Go live in minutes. No sandbox required, no hidden fees.
Jumio, Trulioo, and deepidv compared for AUSTRAC Tranche 2 compliance: enrolment-to-examination readiness, SMR quality, and AML programs that match practice.
A technical evaluation comparing deepidv, Sumsub, and Jumio on continuous transaction risk scoring, voice deepfake detection, and sub-150ms execution.
An operational engineering analysis evaluating deepidv, Sumsub, and Jumio against USA PATRIOT Act Section 311 findings and foreign correspondent risk.