Know your customer in 90 seconds: how eKYC became the baseline in the Gulf and Egypt — Nafath, liveness and document AI
Three years ago “opening an account” meant a branch, a form and a signature. Today, any financial, real-estate or even crowd-investing product that cannot verify a customer’s identity within two minutes on a phone loses …

Three years ago “opening an account” meant a branch, a form and a signature. Today, any financial, real-estate or even crowd-investing product that cannot verify a customer’s identity within two minutes on a phone loses half its customers on the first screen. This article is a practical map for anyone building eKYC in Saudi Arabia, Egypt and the Gulf in 2026: what changed, what gets built, and where the expensive mistakes are.
What actually changed
- National digital identity became an API: Nafath in Saudi Arabia hands you a government-authenticated identity with one tap on the customer’s phone. You no longer build “identity verification”; you build the integration.
- Regulation became explicit: SAMA and CMA e-KYC guidance and the Personal Data Protection Law (PDPL) turned “best practice” into requirements.
- AI solved Arabic documents: invoices, ID cards, residence permits, commercial registrations — read and verified automatically, more accurately than manual entry.
The flow we build (and reuse)
- Mobile first: phone number + OTP on WhatsApp or SMS. That is the real “username” in the region.
- Government identity: Nafath for Saudis and residents (Absher for data checks); in Egypt, the national ID card read automatically and matched.
- Liveness: a short selfie with spoof detection that distinguishes a live face from a photo or replayed video.
- Documents: with an engine like SLT OCR: reading the ID, commercial registration and proof of address, with a confidence score per field and a human review path for grey cases.
- Screening: sanctions lists, politically exposed persons (PEP), eligibility checks.
- Signature: the customer agreement is e-signed through a platform like Tawqe3k, with a timestamp and an audit trail.
The rule: every step either completes verification or hands off to a human with a written reason. Nothing “passes silently”.
Where people lose money
- Drop-off: a screen asking for three photos at once loses 30% of users. Ask for one document per step and show progress.
- Quality: an ID photo with the owner’s hand shadow cannot be read. Guide the user at capture time (“retry — reflection”) instead of rejecting later.
- Retention: storing ID images “just in case” is legal liability with no benefit. Keep the result and minimal evidence, for a declared period.
- Foreign vendors: an eKYC provider outside the Kingdom means a cross-border transfer of sensitive data — check PDPL before signing.
eKYC beyond banks
The biggest demand did not come from banks but from businesses that need fast trust: the fractional real-estate platform Mashrouk verifies an investor’s identity before a single riyal is committed; booking and rental platforms verify tenants and owners; even digital contests and earnings need to know who is being paid.
Bottom line
Good eKYC is invisible. The customer taps Nafath, smiles at the camera, photographs their card, and is inside the product in 90 seconds — while six verification layers and a full audit trail run behind the screen. That is the baseline now, and anything less is measured in customers who never finished signing up.


