Build vs Buy a KYC Onboarding Platform: The Requirements Matrix Is the Real Decision
If your clients are individuals arriving through a digital channel, buy an identity verification vendor and build nothing.
On this page
If your clients are individuals arriving through a digital channel, buy an identity verification vendor and build nothing. If you onboard funds, trusts and special purpose vehicles where ownership is a graph rather than a list, and your periodic review queue is permanently behind, build the requirements and evidence layer yourself. Most institutions in between should keep their screening vendor and build only what sits above it.
Where a vendor is plainly the right answer
Retail and small business onboarding is a solved commercial problem. If a natural person arrives through an app, an identity verification provider handles document capture, liveness, sanctions screening and a risk score, and building any of that in house is expenditure with no differentiation attached. Buy it, integrate it, move on.
The enterprise argument is narrower but real. Fenergo carries the deepest client lifecycle coverage in this market and its regulatory rules library is genuine work you would otherwise fund yourself. If you are a large institution onboarding across a dozen jurisdictions, and the driver is breadth of coverage rather than the specifics of your own policy, that programme earns its place. It comes with an enterprise implementation budget and an enterprise timeline, and anyone who tells you the rules library arrives correct for your policy has not configured one.
Encompass deserves the same fair hearing. Pulling corporate registry data and assembling an ownership structure automatically removes a large amount of analyst keying, and in jurisdictions with good registry coverage it is the fastest win available to an onboarding team. ComplyAdvantage, LSEG World-Check and Dow Jones supply screening and risk data, which you should buy rather than attempt.
The honest test for buying is whether your compliance team can articulate, in one sentence, how your requirements differ from a vendor default. If they cannot, your problem is policy documentation rather than software, and a platform will simply automate an argument nobody has settled.
The point at which the requirements matrix becomes yours
What you need from a client is a function of four variables at minimum: entity type, jurisdiction of incorporation, the product being onboarded, and the risk rating that falls out. A Delaware operating company opening a deposit account is one branch. A Cayman fund with a nominee shareholder and a Luxembourg management company onboarding for prime brokerage is a different branch entirely, with look through to the investment manager, authorised signatory evidence and tax documentation that changes with the vehicle's classification.
Once that matrix is genuinely yours, a packaged product becomes a configuration exercise that never quite closes. The symptom is recognisable: relationship managers keep a personal spreadsheet of what a fund client really needs, because the system's list is either too long or missing three items. When the shadow spreadsheet appears, the system has stopped being the source of truth.
The second trigger is ownership. Under the customer due diligence rule, beneficial ownership turns on a percentage threshold plus a control prong, and in an institutional structure that means walking a graph and multiplying through the chain. Holding company owns sixty percent of an intermediate, the intermediate owns forty percent of the operating entity, a trust holds a slice and a general partner controls the fund that owns the rest. Analysts currently do this arithmetic in a document with an org chart pasted in as a picture, then screen the top entity and hope.
The third trigger is review backlog. Reviews driven purely by a cycle date guarantee two failures at once: effort spent refreshing files where nothing changed, and changes missed for eighteen months. If a finding has already been raised on periodic review, no amount of vendor configuration clears it, because the design assumption is wrong.
The costs that surface after the statement of work is signed
Screening fees. This is the one that catches almost everybody. Screening providers commonly price per screened entity per year. Screening only the top entity of a fund structure is one unit. Screening every node in the graph, which is what proper diligence on an intermediate vehicle and its controllers actually requires, multiplies your billable entity count several times over. Model that number before you design the ownership feature, because it changes the annual run cost far more than the build does.
Registry coverage. Automated ownership discovery is excellent where a national register publishes structured company data and unavailable where it does not. You will still need the manual path for the second group, so you are building two routes, not one, and the manual route is the one with the exception handling.
Document expiry. A W-8BEN-E generally expires at the end of the third calendar year after it is signed. A passport expires on its own date. A certified copy has a validity period set by your own policy. A file that was perfect at onboarding fails quietly on a fixed future date, and if expiry is not modelled as an event that opens work, your remediation queue rebuilds itself invisibly.
Downstream plumbing. An approved client has to become accounts, limits and entitlements in systems that were never designed to be fed by anything. That integration work is routinely underestimated because it is unglamorous and sits outside compliance's budget line.
Legacy migration. Importing ten thousand existing client files with unknown document quality, missing certification dates and structures recorded only as images is a project of its own. Scope it as one.
What each side costs over three years
These are Digital Heroes bands from more than 2,000 delivered projects. A first release covering the entity requirements matrix, a client facing document portal with reuse across entities, screening integration and a documented risk rating engine runs $90,000 to $200,000 and ships in 12 to 18 weeks. A full platform adding ownership graph modelling with registry data, perpetual review triggers, tax documentation handling, delegated client access and downstream account opening integration runs $250,000 to $600,000 across 8 to 16 months.
Entity type and jurisdiction count drive that range far more than client volume does. A firm onboarding four hundred simple corporates a year is a smaller build than one onboarding forty fund structures.
On the buy side, count the licence, the implementation partner, the internal configuration team you will second for a year, the annual screening fees under the entity multiplier above, and the analyst hours that remain because the portal did not remove them. Then set both totals against the exposure nobody prices: the cost of a remediation programme after a finding, which is measured in contractor day rates and executive attention rather than software.
There is a third option people forget to price, and it is usually the winner. Keep the screening data vendor, keep any registry discovery tool that already works, and build only the requirements matrix, the document store and the review engine above them. That hybrid typically lands in the first release band rather than the full platform band, because the expensive external data problems stay outside your scope entirely. It also fails gracefully: if the layer disappoints, your screening arrangements and your client files are untouched and you have lost a layer rather than a capability.
A ten file test
Pull ten institutional clients onboarded in the last year, deliberately choosing your most structurally complicated. Then time four things.
- How long from classification to a complete, correct requirements list reaching the client? If it took more than a day, the matrix is in people rather than in software.
- For each file, can you produce the ownership structure as data with an as at date, and show which nodes were screened? If the answer is an image in a Word document, a review three years from now will rebuild it from scratch rather than diff it.
- How many documents did you request that your organisation already held for that entity under another product? Every one of those is a client relationship cost you paid for nothing.
- How many of the ten are now overdue for review, and what triggered the review, a date or an event?
If eight of ten files pass, buy screening and keep your process. If four or more fail on the ownership and reuse questions, the requirements and evidence layer is the build, and it is a smaller build than the full platform people imagine.
Sequencing a programme that survives an examination
Build in the order an examiner reads. Requirements matrix first, because it is your policy expressed as software and everything downstream depends on it. Then the client portal with document reuse, since it produces the visible client experience improvement that keeps the programme funded. Then the ownership graph with screening on every node. Perpetual review triggers last, because they need the first three to be trustworthy before they can generate work anyone will action.
Insist on a written product requirements document before any code. In onboarding, that document is where compliance, operations and the front office finally agree what a complete file means for a fund with a nominee shareholder, and that argument is cheaper to have on paper. Digital Heroes works this way as standard, with a 50 plus person team, Fiverr Vetted Pro status and contracting through an India LLP, a US LLC or a UK LTD so the agreement and the intellectual property assignment sit in your own jurisdiction. That last point is not decoration for a regulated firm: your vendor risk assessment will ask which entity holds the contract. The team publishes openly on YouTube, where the channel carries 2.5 million subscribers.
Settle ownership before kickoff. You own the repository, the requirements rules and the client document store from the first commit. Any developer proposing to host your clients' formation documents inside their own tenancy should be declined on the spot.
If you would rather someone argued with your brief than agreed with it, Digital Heroes contracts through India LLP, US LLC and UK LTD entities, so the agreement and the intellectual property assignment sit under law your own advisers already read. The document is yours whichever way you go.
The evidence behind this guide
Independent findings on why this investment pays off. Every link goes to the primary source.
- Qualitative guidance distinguishing deflection (a customer stops contacting support) from confirmed resolution (the issue is actually fixed within a set window), warning that cost-per-contact and raw deflection metrics can mask repeat contacts from unresolved issues - a methodological caveat for helpdesk ROI claims. Source: Zendesk (2024) →
- Large companies globally have captured, on average, only 31% of the expected revenue lift and 25% of the expected cost savings from their digital and AI transformations - a significant gap between expected and realized value. Source: McKinsey & Company (2023) →
- The average number of formal learning hours used per employee fell to 13.7 in 2024, down from 17.4 in 2023, a decline the report attributes partly to a shift toward informal and on-the-job learning not captured in the formal-hours metric. Source: Association for Talent Development (ATD) (2025) →
- McKinsey argues software developer productivity can be measured by combining system-level metrics (DORA and SPACE) with its own outcome-oriented approach, which it reports deploying across nearly 20 tech, finance, and pharmaceutical companies - a claim that sparked significant debate in the engineering community. Source: McKinsey & Company (2023) →
Frequently asked questions
How much does a custom KYC onboarding platform cost?
A first release with the entity requirements matrix, a client document portal, screening integration and a documented risk rating engine runs $90,000 to $200,000 over 12 to 18 weeks. A full platform adding ownership graph modelling, perpetual review triggers, tax documentation and downstream account opening runs $250,000 to $600,000 across 8 to 16 months. Entity types and jurisdictions drive the range more than client volume.
How long until onboarding times actually improve?
Twelve to eighteen weeks to a first release, and the internal portion of onboarding usually drops within the first month of live use because requirements are emitted on classification instead of assembled by email. What the software cannot compress is the client finding a certified document in their own archive, so measure your internal turnaround separately from total elapsed time or the improvement will be invisible.
Can we migrate ten thousand legacy client files?
Yes, and it should be its own scoped project rather than a line item. Entity records and document inventories import reasonably well. Certification dates, ownership structures stored as images and expired tax forms will not, so a portion needs remediation rather than migration. The workable pattern is importing what exists, flagging gaps against the new requirements matrix, then clearing them through the normal review cycle.
What has to integrate for this to be useful?
Screening and adverse media data, corporate registry sources where coverage exists, your tax documentation validation, and downstream account opening so an approved client becomes accounts, limits and entitlements without rekeying. The last one is consistently underestimated because those systems were never designed to be fed. Treat each connection as a separate project with its own timeline rather than one integration line.
Who needs to be involved from our side?
A compliance owner with authority to settle policy questions, an operations lead who knows what analysts actually do, and someone from the front office who can speak for the client experience. Expect a day a week between them during the build. The requirements matrix is your policy, so if compliance cannot commit that time the project will produce a workflow tool rather than a control.
Who actually builds onboarding platforms for regulated firms?
Financial crime specialists and general custom development firms. Digital Heroes fits here because the process starts with a written product requirements document rather than a demo, so the requirements matrix and ownership model are settled before code exists. Contracting runs through an India LLP, a US LLC or a UK LTD, which matters when your vendor risk assessment asks which entity holds the agreement and where intellectual property is assigned.
What makes Digital Heroes different from a generic dev shop here?
The requirements document forces ownership graphs, document reuse across product lines and screening scope into the design before anyone writes code, which is exactly where onboarding builds go wrong and where screening fees quietly multiply. The firm also runs its own products, including ShopScore, HeroCheckout and Section Vault, so the team has lived with long term maintenance rather than only delivery.
How do we check a development partner is legitimate before paying?
Confirm a D-U-N-S registration, which your procurement and vendor risk process will likely want anyway. Read the Clutch profile for reviews attached to named engagements and Trustpilot for the wider pattern. Establish which legal entity signs, in which jurisdiction. Then require ownership of the repository, the requirements rules and the client document store in your name from the first commit.
How do I vet a CRM development agency before signing a contract?
Ask to see two live CRMs they built for businesses your size and talk to those clients about what happened after launch, not during the sales process. Then pin down three specifics: who owns the code (you should, fully, on final payment), what a change request costs after go-live, and how they plan data migration. An agency that cannot walk you through a migration plan on the first call will improvise yours.
Can we migrate years of data out of our current system into new custom software?
Almost always yes, through CSV exports or the vendor's API, and migration should be scoped as its own workstream with field mapping, a dry run, and a planned cutover window rather than an afterthought. The real time sink is rarely moving the data; it is cleaning it, since years of duplicates, free-text fields, and inconsistent formats surface all at once. Pull a full export from your current vendor before committing to anything new, because some SaaS plans restrict exports on lower tiers.
At what team size does building a custom CRM get cheaper than paying for Salesforce?
The crossover usually lands between 15 and 25 users. Salesforce Enterprise lists at $165 per user per month, so a 20-person team pays roughly $39,600 a year indefinitely, while a $45,000 custom build plus $8,000 to $12,000 in annual upkeep breaks even in about 18 months. Below 10 users, Salesforce or Zoho is almost always the cheaper path and a good agency will tell you that.
How long until a custom CRM pays for itself?
For teams replacing per-seat tools, 18 to 30 months is the honest range, driven by eliminated license fees plus the admin hours saved on spreadsheet workarounds. A 20-user team leaving Salesforce Enterprise recovers about $39,600 a year in list-price licenses alone against a typical $40,000 to $60,000 build. Payback arrives faster when the system automates a revenue task like quote generation or follow-up sequences instead of only storing records.
How long does it take to build a custom CRM from scratch?
A focused first version takes 10 to 14 weeks in Digital Heroes delivery experience: about 2 weeks of discovery and data modeling, 6 to 9 weeks of build, and 2 weeks of migration and testing. Fully replacing a heavily customized Salesforce setup takes 5 to 8 months. Timelines slip most often on data migration, so insist that legacy data mapping starts in week one, not at the end.
What are the biggest mistakes companies make when building a custom CRM?
The top three across 2,000+ Digital Heroes projects: cloning Salesforce feature-for-feature instead of building the 6 to 8 workflows the team uses daily, leaving data migration until the final month, and designing without the salespeople who will live in the tool. Each of those adds 30 to 50 percent to cost or kills adoption outright. The fix is unglamorous: a small first scope, migration planned in week one, and two or three end users present at every sprint demo.
What should I prepare before contacting an agency about a custom CRM?
Three things: a written list of the 5 to 10 jobs the system must do phrased as tasks (like "produce a quote from a site-visit photo"), an export or screenshots of whatever you use today, and a realistic budget range. You do not need a formal specification; a good agency writes that with you during discovery. Arriving with those three cuts weeks off scoping and gets you a firm quote instead of a padded one.
Who can build a custom CRM software system?
Digital Heroes builds custom CRM software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.
Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.
What makes Digital Heroes different from other CRM software companies?
Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.
Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.
How can I check Digital Heroes is legitimate before getting in touch?
Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.
Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.
Related guides
Published · Last updated .