โ† All work
Buy vs build KYB / verification Platform strategy

Knowing when
to stop building

Our KYB tooling ran on a backoffice that couldn't scale; every new market, check and rule became engineering work. I led the buy-vs-build analysis and landed on neither extreme: buy the commoditised verification automations, build the case management that actually differentiates us.

My role
Product Lead, owned the analysis & the decision
Where
B2B spend-management scale-up
Team
Product ยท Eng ยท Risk & Compliance ยท Ops
75%
of KYB checks covered by pre-built vendor automations in the proposed model
4
core KYB capabilities mapped: identification, verification, risk assessment, monitoring
2
clean halves of the decision: buy the plumbing, build the workbench

01Situation

KYB is four jobs, and we hand-built all of them

Know Your Business verification underpins regulated onboarding: identify the customer, verify them (CDD/EDD, PEP & sanctions screening, ownership structures and UBOs), assess risk, and monitor continuously, because it never ends at onboarding. All four ran through a home-grown backoffice tool that nobody owned as a product.

What KYB actually is: four capabilities, not one check
01
Customer identification
Who is this business, and who is on the other side of the screen? Verified against reliable sources.
02
Verification (CDD / EDD)
Due diligence, PEP & sanctions screening, ownership & control structures, ultimate beneficial owners.
03
Risk assessment
Entity type, industry, country, product, transparency, combined into a risk profile that drives treatment.
04
Ongoing monitoring
KYB is not a one-time event: data, risk and transactions must be monitored continuously.

02Problem

The backoffice was the bottleneck

The home-grown tool couldn't scale with verification volume: slow processing that delayed onboarding, manual workarounds that grew the maintenance burden, a clunky analyst experience that bred data-entry errors, failing integrations, data silos, and a rising compliance risk every time regulation moved faster than our roadmap. Every improvement competed with feature work for the same engineers.

03Goal

Scalable, compliant KYB, without betting the roadmap

Decide deliberately (buy, build, or something smarter) against explicit criteria, and get analysts a tool that scales with volume, keeps pace with regulation, and stops taxing engineering.

04My role

Product Lead. I framed the decision criteria, ran the market analysis across KYB vendors, built the buy-vs-build case, and drove the proposal through Risk, Compliance, Engineering and Ops.

05Team

Product & Engineering (integration and case-management build), Risk & Compliance (policy, regulatory surface), Operations (the analysts living in the tool daily).

06Diagnosis

Both pure options had structural flaws

Pure buy wins on time-to-market, vendor expertise, regulatory updates and support, but costs you customisation, creates vendor lock-in and data-sharing surface, and never fits your workflows exactly. Pure build wins on customisation, integration and agility, but demands scarce compliance expertise, high upfront cost, and a permanent regulatory maintenance burden. The real question became: which parts of KYB are commodity, and which parts are our competitive edge?

07Decision making

Five criteria, applied per-capability

We scored options against five explicit criteria: regulatory compliance, cost-benefit, time-to-market, core competencies (risk engine, data collection, tool integrations) and long-term vision. Applied per-capability instead of wholesale, the answer split cleanly: verification data and checks are commoditising; vendors do them better, faster, and keep them current. But the case management and risk workbench, how analysts work, how decisions flow, how our risk logic evolves, is where differentiation and agility live.

The split decision: per capability, not wholesale
Verification checks & data Case management & risk logic
โ† Build in-houseBuy / partner โ†’
Differentiation
Regulatory surface
Time-to-market
Cost of ownership
Checks and data pointed to buy on every axis; the analyst workbench pointed to build. So we did both, deliberately.

08Solution

Buy the plumbing, build the workbench

1
~75% of KYB checks via pre-built automations
Vendor-powered verification (identification, screening, registry data) integrated into the backoffice instead of hand-built and hand-maintained.
2
A custom case-management system
Built in-house around our analysts, our risk logic and our audit needs. Transparent, streamlined KYB casework where differentiation actually lives.
3
Risk-assessment redesign
The risk engine and its inputs redesigned as the durable, owned core, fed by bought data rather than bought wholesale.
4
Market analysis with named criteria
KYB vendors evaluated against the five criteria, so the recommendation read as evidence, not preference.

09Trade-offs

What the hybrid costs

The hybrid keeps build effort on the case-management side: time, resources and ongoing maintenance we consciously accepted because that's where our leverage is. On the buy side we accepted vendor dependence and data-sharing surface, managed through vetting and integration design rather than avoided. And we said no to the comfortable default, which was to keep patching the old backoffice, because "no decision" was quietly the most expensive option on the table.

10Impact

Verification stopped being a roadmap tax

New checks and markets became configuration on bought automations instead of engineering projects; analysts got a workbench designed for their casework instead of a strained backoffice; and the regulatory-update treadmill moved to the vendor, while risk logic, the part regulators and customers actually feel, stayed ours.

11Learning

Buy-vs-build is rarely the right question

The right question is per capability: what's commodity, what's core? Verification data is commoditising; the way your analysts and risk logic work is not. Split the decision and you stop paying build costs for commodity, and stop renting your differentiation.

"Buy the plumbing. Build the workbench."