Reducing investor onboarding friction without compromising compliance.
40% faster onboarding · 35% higher KYC pass rate · 5× customer engagement
Regulated investor onboarding is where good customers give up. KYC requirements are non-negotiable — but the experience of completing them does not have to feel like a compliance audit. Most onboarding flows treat KYC as a form to fill rather than a process to design, and the result is abandonment at exactly the moment you need commitment.
This is an anonymized reconstruction of real product work. The workflow UI, data, names, and examples are synthetic; the stated outcomes reflect the original programme.
Compliance is the product. The experience does not have to be compliance-shaped.
Investor onboarding for alternative investments involves KYC document collection, PEP screening, source-of-funds verification, and accreditation checks — all before anyone can invest.
The default approach — a long form, a document upload, a wait — produces:
- High abandonment at document upload (investors do not have files ready)
- Low KYC pass rates because investors misunderstand the requirements
- High re-submission rates because the form does not explain what is needed
- Compliance teams spending time chasing information instead of reviewing applications
The product opportunity was to treat KYC not as a compliance gate but as a guided workflow — where every step is explained, the path is clear, and AI assists compliance officers without replacing them.
Investor KYC Onboarding Flow
Complete the 4-step intake and see the AI risk classification on step 5. Try entering "yes" for the PEP question or "crypto" as source of funds to see how risk factors change the output.
Step 1 of 5 — Basic information
Four decisions that shaped the flow.
- 01
Show the compliance reason, not just the requirement.
Investors who understand why they're being asked for something complete the step. Investors who see a form field with no context abandon. Every compliance step includes a plain-English explanation of what it is and why it's required.
- 02
AI classifies risk, compliance officer approves.
Automated KYC decisions in a regulated environment carry liability the product cannot absorb. AI surfaces the risk classification and the factors behind it; a compliance officer makes the final call. The system speeds up the review — it doesn't replace it.
- 03
Progressive disclosure over a single long form.
A 20-field form on page one creates abandonment before the investor starts. A five-step flow with contextual explanation at each step reduced perceived complexity and drop-off significantly.
- 04
Make the PEP question unavoidable but not alarming.
PEP self-declaration is legally required but badly worded questions cause both false positives and deliberate omissions. The question design — clear definition, three specific options — improved accuracy and pass rates.
Where I drew the automation boundary.
In regulated products, the wrong automation is worse than no automation.
- 01
No automated KYC approval
Automated approval in a regulated environment creates regulatory risk and audit exposure. The system classifies; humans decide. Removing the human step would have required a regulatory opinion we didn't have.
- 02
No third-party PEP database lookup in v1
External PEP database integration was scoped for v2. In v1, self-declaration plus compliance review provided sufficient coverage while we evaluated vendor options. Launching without it got the product to market six weeks earlier.
- 03
No investor-facing risk score display
Showing the investor their risk classification would have created incentives to answer questions strategically. The classification is internal — visible to compliance, not the applicant.
What the product has to get right.
Potential risks
- False PEP negative — investor omits disclosure intentionally
- Document verification delay blocking onboarding funnel
- Risk classification error on borderline cases
- Data privacy exposure for sensitive compliance documents
- Compliance officer bottleneck under high application volume
- Regulatory change invalidating current screening logic
Controls
- Self-declaration logged and timestamped — creates legal record
- Document verification SLA tracked with escalation for delays
- Borderline risk cases flagged for senior compliance review, not auto-classified
- Compliance documents stored in isolated, encrypted storage with access logging
- Queue management tools for compliance team — priority scoring by risk level
- Screening logic versioned and auditable — changes require compliance sign-off
The measurement definitions we used.
Each metric below is defined by its measurement method — what was counted, how, and against what baseline.
- Onboarding completion rate — funnel tracked step-by-step from intake start to compliance decision submission
- Time to decision — median hours from application start to compliance officer approve or decline
- First-submission KYC pass rate — proportion of applications approved without requesting additional information
- Document rejection rate — proportion of uploaded documents rejected, segmented by document type
- PEP flag rate — proportion of applicants self-declaring as PEP, and subsequent approve or decline split
- Compliance officer review time — median minutes per application from queue entry to decision
- Re-submission rate — proportion of applications requiring at least one request for more information
Earn regulatory trust before adding automation.
- Phase 1
Structured onboarding flow
- — 5-step investor intake
- — Document upload
- — PEP self-declaration
- — Compliance review queue
- Phase 2
AI-assisted classification
- — Automated risk scoring
- — Evidence-backed classification
- — Compliance officer briefing card
- Phase 3
Continuous monitoring
- — Post-onboarding PEP re-screening
- — Adverse media alerts
- — SAR/STR workflow integration
Where I was involved.
- Led end-to-end product discovery with investors, compliance officers, and operations teams to map the current onboarding failure points
- Designed the five-step onboarding flow, progressive disclosure model, and PEP question architecture
- Defined the AI risk classification model — scoring logic, risk factors, and the boundary between automated classification and human review
- Owned the compliance audit trail specification and data-permission model for sensitive documents
- Partnered with engineering, design, legal, and compliance to deliver 40% faster onboarding and a 35% improvement in KYC pass rates
- Drove 5x improvement in customer engagement through reducing friction at high-abandonment steps
Cross-functional collaboration
- Product
- Engineering
- Design
- Compliance
- Legal
- Operations
What I would do differently.
- 01I would have instrumented step-level abandonment tracking from day one. We added funnel analytics in iteration 3 and discovered that step 2 (document upload) had much higher drop-off than expected — something earlier data would have let us address in v1.
- 02The compliance officer review queue was designed without enough input from the compliance team on how they actually triage applications. We built a time-ordered queue; they needed a risk-prioritised one. A two-hour shadowing session earlier would have caught this.
- 03I'd define the re-submission rate metric upfront and set a target before launch. It turned out to be the most sensitive indicator of form clarity — but we only started tracking it after we noticed the compliance team spending a lot of time requesting more information.