deepidv
KYC ComplianceSeptember 18, 20265 min read
256

Sumsub vs Trulioo vs deepidv: UK CDD in the confusion era

Sumsub, Trulioo, and deepidv compared for UK customer due diligence as £500M of AML enforcement meets unresolved DVS certification guidance under MLR 28.

An operational engineering analysis evaluating deepidv, Sumsub, and Trulioo for UK customer due diligence, in the quarter where £500 million of new AML enforcement meets guidance that cannot decide which digital identity providers count.

UK compliance teams are buying CDD infrastructure inside a contradiction. The enforcement side is unambiguous: a 2026-2029 strategy funding 500 new officers against £100 billion of annual laundering, with CDD files the natural first evidence request. The guidance side is anything but: Treasury and OfDIA point to DVS-certified providers under Money Laundering Regulation 28, only 14 of 39 surveyed providers hold the certification, the FCA's own materials never mention DVS, and the same regulation recognizes EU eIDAS qualified providers. Vendor selection in that fog needs one organizing question: which stack produces CDD evidence that stands regardless of how the scheme politics settle? This analysis compares deepidv, Sumsub, and Trulioo on that question.

The UK CDD scorecard

CapabilitydeepidvSumsubTrulioo
Verification depth per customerNFC, forensics, structural liveness, telemetryDocument and selfie workflows, configurableGlobal data-source matching
Certified credential acceptance (DVS, eIDAS)Native via Arc, per-issuer policyConfigurable blocks, customer-maintainedData-network orientation, credential support limited
MLR 28 evidence mappingPer-decision records with regulation mapping via LunaCase records, mapping by customerMatch records, mapping by customer
Ongoing monitoring and event re-screeningLuna: perpetual KYC, event-drivenMonitoring modules, configuredRe-query on demand
Beneficial ownership / KYB depthEntity chains via Arc + registry corroborationKYB product lineRegistry data strength
Guidance-change absorptionPolicy layer re-mapped as configurationCustomer reconfigurationCustomer reconfiguration

Three vendors against one contradiction

deepidv: evidence that does not care which certificate wins

deepidv's design premise fits the moment: verify to evidence, treat schemes as routing. Where a customer presents a DVS-certified digital ID or an eIDAS qualified credential, Arc validates it cryptographically under per-issuer policy; where they present documents, the core engine runs chip, forensic, and structural liveness verification that no confidence-level interpretation undercuts; and Luna writes every CDD decision with its method, evidence, and MLR 28 mapping, then runs the ongoing side, event-driven re-screening, risk-rating upkeep, SAR-ready narratives, that the enforcement build-out will test hardest. When OfDIA and the FCA reconcile their positions, the program re-maps as configuration rather than re-procurement.

Sumsub: the configurable middle

Sumsub's toolkit breadth serves UK fintechs well, and its workflows can express certified-credential acceptance and document fallbacks. The confusion era sharpens its standing trade-off: which credentials to accept, how to map decisions to MLR 28's contested readings, and how monitoring cadence satisfies a newly aggressive investigator are all configuration the customer owns and must re-own at each guidance shift. Well-staffed compliance teams can carry that; the firms without them should price the carry honestly. The deepidv vs Sumsub comparison maps the recurring boundary.

Trulioo: data reach, program elsewhere

Trulioo's registry and data-source network answers the identification data question across borders, and UK firms with international books use it for exactly that. As the CDD answer under enforcement, it is one layer: data matching neither binds the person present, no liveness, no presenter forensics, nor operates the program around the result, risk ratings, monitoring, evidence assembly. In the UK's current climate, a match record without a program around it is the file an investigator picks apart, so Trulioo deployments pair with biometric verification and program tooling, or consolidate onto a platform carrying all three.

Suggested read: UK pairs a £500M AML crackdown with digital ID confusion

Ready to get started?

Start verifying identities in minutes. No sandbox, no waiting.

Get Started Free

The test that decides it: the investigator's file request

Simulate the letter every UK firm should expect more of: an investigator requests complete CDD files for ten customers tied to a laundering inquiry, identification evidence, screening timestamps, risk rationale, monitoring dispositions, EDD where triggered. Run the request against each candidate stack in the proof of concept and time the answer. Evidence assembled by the system in minutes is a defense; evidence reconstructed from exports and inboxes is a finding with a delivery date.

Add the guidance-shift scenario: assume OfDIA and the FCA settle the DVS question a year from now, in either direction. Ask each vendor precisely what changes in the deployed program and who performs the change. The honest answers separate platforms from toolkits faster than any feature list.

Frequently Asked Questions

Which vendor is best for UK customer due diligence?

Firms with strong internal compliance engineering can assemble UK CDD on Sumsub's toolkit; firms needing identification data reach add Trulioo's network. Firms that need the platform to operate the program, verification to examiner-grade evidence, certified-credential routing, event-driven monitoring, and MLR 28-mapped records, are the profile deepidv serves natively.

What is MLR 28 in UK AML regulation?

Regulation 28 of the UK's Money Laundering Regulations sets the customer due diligence duty, including how identity may be verified. Current guidance points to Digital Verification Service providers certified under the UK trust framework and recognizes EU eIDAS qualified trust services, a combination that has left firms without one settled rule.

Do UK firms have to use DVS-certified providers for CDD?

The Treasury and OfDIA guidance points that way, but only 14 of 39 surveyed providers are certified, the FCA's materials do not mention DVS, and eIDAS recognition offers an alternative path. Prudent programs accept certified credentials where presented while verifying to standalone forensic evidence everywhere, so compliance holds under any reading.

How should firms prepare for the £500M enforcement expansion?

Assume more CDD file requests and deeper challenge: confirm every customer file is reconstructable from system records, move screening to event cadence, close the gap between documented and actual practice, and rehearse the investigator's request internally before it arrives externally.

Does data-source matching satisfy UK CDD alone?

No. Matching a name to registries verifies data, not the person presenting it, and CDD also requires risk rating, ongoing monitoring, and retained evidence. Data networks like Trulioo serve as one layer inside a program, not as the program.

Start verifying identities today

Go live in minutes. No sandbox required, no hidden fees.

Related Articles

All articles

Jumio vs Sumsub vs deepidv: The Mobile Driver's License Era

Jumio, Sumsub, and deepidv compared on verifiable digital credential support after the five-agency CIP FAQ made mobile driver's licenses bank-grade ID.

Sep 11, 20265 min
Read more

Sumsub vs 1Kosmos vs deepidv: The Stablecoin CIP Build-Out

Sumsub, 1Kosmos, and deepidv compared for GENIUS Act stablecoin CIP compliance: bank-grade identification, watchlist screening, and the 12-month build window.

Sep 4, 20265 min
Read more

Jumio vs Trulioo vs deepidv: AUSTRAC Tranche 2 Readiness

Jumio, Trulioo, and deepidv compared for AUSTRAC Tranche 2 compliance: enrolment-to-examination readiness, SMR quality, and AML programs that match practice.

Sep 4, 20265 min
Read more