Annex J translates P21 into the implementation profile for the current Being KYC upgrade. Technical values are implementation defaults and may be replaced by a regulator-approved or independently validated equivalent without changing the P21 control objective.
Control | Implementation profile v1 | Public / private | Regulatory gate |
|---|---|---|---|
Session binding | Fresh signed challenge/NIP-98; nonce/TTL/anti-replay; one active process; rate limits. | Private metadata | Mandatory before capture. |
Document capture | Direct raw upload; high-resolution MRZ/VIZ; no public media URL; TD1/TD3 v1. | Strictly private | Accepted document list + fallback required. |
MRZ/VIZ | Deterministic OCR/extraction + ICAO check digits + VIZ cross-check; LLM advisory only. | Private | Checksums are integrity, not authenticity. |
Document authenticity | Risk signals + certified/eID/vendor seam. | Private | Independent validation before CASP production. |
Face match | Local 1:1 embeddings; calibrated thresholds; grey zone retry/review. | Biometric private | DPIA + performance/bias testing. |
Liveness/PAD | Random challenge + server timing + optional low-risk illumination nonce; multi-signal PAD. | Biometric private | Do not claim replay-proof; test/deploy vendor seam. |
Screening | Sanctions + PEP local dataset; multilingual fuzzy/identifier matching; human candidate review. | Private | Commercial data licence + PEP/EDD workflow. |
Decision | Automatic IDENTITY-VERIFIED allowed; separate CDD-PENDING -> human safeguarded decision where required. | Private decision | AMLR Article 76(5) readiness / GDPR Article 22. |
Storage | Encrypted fields + sealed archive; no PII in logs; controlled break-glass retrieval. | Private | Article 77/current-law retention and retrievability. |
Document fingerprint | HMAC of normalized issuer/country/type/number; raw number encrypted. | Private | Duplicate detection without public/plain hash. |
Public attestation | 37105: person, verified/revoked, method, version, times, authority; no document/biometric/screening data. | Public minimal | Trusted authority signature + expiry/revocation. |
Public photo | Separate user-selected profile photo, not KYC selfie; separate consent. | Optional public | Not a condition of regulatory KYC. |
Ongoing KYC | Daily/event-driven screening update; expiry/review reminders; transaction-monitoring handoff. | Private | KYC is ongoing, not perpetual badge. |
Travel Rule | 37105 identity evidence + separate wallet ownership/control proof when TFR requires. | Mixed/minimal | P17/TFR implementation remains separate. |
KYB | Separate corporate/UBO/representative flow. | Private | HOLD for legal-person clients until implemented. |
UK deployment legal basis | Reuse technical identity pipeline only with UK-specific CDD decisioning and privacy mapping. | Private; public 37105 remains minimal | UK MLR/FCA + UK GDPR/DPA 2018 + DPIA + biometric Article 9 condition; CP-38 |
U.S. deployment identity/biometric | Reuse P21 pipeline only after state privacy/biometric + OFAC/tax/obliged-entity mapping; KYB for B2B. | Private; public attestation minimal | CP-48/49; state-specific consent/retention/human-review |