×
Union Bank of the PhilippinesUnionBank
Integration Project Plan · Confidential

eKYC Integration
Union Bank of the Philippines

Dual-vendor architecture with PowerCred as primary eKYC provider. Phased integration plan for software architects.

ClientUnion Bank of the Philippines
Prepared byPowerCred
Total Timeline~14 Weeks
Version1.0 · Draft
Background

Strategic Context & Architecture Goals

🏢
Union Bank’s Position
Union Bank has evaluated multiple eKYC vendors and selected PowerCred as the preferred primary provider, citing superior performance across all evaluation parameters including pricing, accuracy, and developer experience.
🔀
Dual-Vendor Derisking Strategy
To maintain operational resilience, Union Bank intends to run a switchable dual-vendor architecture. PowerCred serves all traffic by default. A secondary vendor absorbs fallback traffic only when configurable SLA thresholds are breached.
⚙️
Switch Mechanism
A vendor routing layer in Union Bank’s backend will monitor real-time SLA metrics: latency, error rate, uptime. When PowerCred breaches a threshold, the session is routed to the secondary vendor seamlessly with no user-facing disruption.
🎯
Integration Objective
Integrate PowerCred’s full eKYC stack into Union Bank’s existing cross-device journey: active liveness and selfie capture on mobile via QR handoff, ID capture on mobile, followed by OCR (the first API call), with UB’s internal rules determining which subsequent checks to trigger. No vendor branding visible to applicants at any point.
🎨
UB-Owned UX: A Core Design Principle
Union Bank owns and builds every screen in the KYC journey. PowerCred operates as a pure API/SDK layer underneath: OCR, fraud signals, face match, and liveness intelligence, with no vendor UI embedded in the applicant flow. No PowerCred or secondary vendor branding is visible to applicants at any point. This gives UB full brand control, compliance ownership, and the freedom to switch or add vendors with zero user-facing impact. See Slide 4 for the full ownership model.
User Flow

The KYC Journey: Cross-Device Architecture

🖥️ Desktop — Origination & Completion— (Optional)
01
QR Code Display
Desktop shows a session-linked QR code. The applicant must scan this to continue the full eKYC journey on mobile. No biometric capture on desktop.
Origination
05
Application Review & Submission
Desktop resumes after mobile completes. Applicant reviews the pre-filled form extracted on mobile and submits the application. No document processing on desktop.
Form Review
06
Journey Complete
Applicant sees confirmation on desktop. All intelligence checks (fraud, deepfake, dedup, govt verify) run asynchronously in the background.
Webhook
📱 Mobile — All Biometric Capture
02
Selfie & Active Liveness
User scans QR and opens the mobile journey. PowerCred Liveness SDK renders the challenge on mobile. Selfie captured here. Returns a signed liveness token.
SDK + Mobile
03
ID Card Front Capture
UB’s mobile camera UI captures the front of the Philippine ID. Quality gate via /id/analyze/quality. First API call is OCR only (/id/analyze). UB rules determine subsequent checks.
Mobile API
04
ID Card Back Capture (where applicable)
For dual-sided IDs (e.g. UMID), user captures the rear face. API detects card type from the front and conditionally requests the back.
Mobile API
Session Continuity
The QR code carries a session token that ties the mobile capture back to the desktop session. Images are uploaded directly from mobile to PowerCred’s secure endpoint. The desktop polls for session completion before proceeding to step 05.
Strategic Recommendation

UB Owns the UX: PowerCred Powers the Intelligence

The Recommendation
Union Bank builds and owns every screen in the KYC journey. PowerCred — and any future vendor — is a pure API layer underneath.
🏢
UB owns
UI / UX / Brand
PC powers
AI / APIs / Data
🔀
Vendor-agnostic
Swap anytime
🏢Union Bank Owns & Builds
📷
Selfie capture screen Mobile only
Camera permission, selfie frame UI, capture button — all in UB’s design language. Biometric capture is mobile-only; no camera access required on desktop.
📱
QR handoff screen
QR code display, instructions, countdown timer. UB generates the QR using the session token returned by PowerCred’s API.
🔜
ID capture screens (mobile)
Card framing guides, flip prompts for dual-sided IDs, capture confirmation. UB calls /id/analyze/quality to validate before submitting.
Application review & data submission
Desktop displays pre-filled form from PowerCred’s /id/analyze response. User reviews and submits. Edits trigger PUT /id/update. No document processing on desktop.
⚠️
Error states & retry flows
Blur/glare rejection messaging, liveness retry, timeout handling — all written in UB’s tone of voice.
📋
Consent & data privacy language
Biometric consent screens, NPC-compliant disclosure copy — drafted and owned by UB Legal/Compliance, not a vendor template.
PowerCred Provides (API / SDK)
🎥
Active Liveness SDK Mobile SDK only
The one exception — liveness challenge rendering is SDK-driven on mobile. UB embeds it as a component; the challenge UI is PowerCred’s. Everything else is pure API.
🔬
OCR intelligence (first API call)
Structured field extraction from ID images. /id/analyze is the first and primary API call. UB applies internal rules to determine which subsequent checks to trigger.
👱
Fraud detection signals
Template, font, photocopy, screenshot, AI-generated, photo substitution — returned as flags + risk level. Called per UB’s internal rules.
🤳
Face match, deepfake & deduplication
Similarity score, deepfake boolean, duplicate applicant flag — all returned as JSON for UB to handle. Called per UB’s internal rules.
🏛
Government database verification
Async verification against PH government records. Backend retrigger mechanism for govt API downtime. Subject to Legal/NPC/BSP clearance.
📊
Session management & audit trail
Every KYC session is stored with full revision history, fraud status workflow, and analyst correction audit trail — accessible via dashboard and API.
🎨
Full Brand Control
Applicants see UnionBank throughout — no vendor splash screens, no third-party branding.
🔀
Vendor-Agnostic UX
Swapping or adding a vendor requires zero UX changes. The dual-vendor switch is invisible to users.
⚖️
Compliance Ownership
UB Legal owns consent copy and NPC disclosure language. No dependency on a vendor’s template.
🚀
Faster Iteration
UB’s product team can update flows, copy, and error handling on their own release cycle.
Architecture

System Architecture: Vendor Routing Layer

UB Desktop App
QR display · Form review · Confirmation
UB Mobile App
Liveness · Selfie · ID capture
Union Bank Frontend Layer
UB Backend API
Session mgmt · QR generation · UB rules engine
Vendor Router
SLA monitor · Failover logic · Volume control
⚡ SLA-triggered switch
Union Bank Orchestration Layer. Built by UB. Integrates PowerCred Liveness SDK + both vendor REST APIs
Primary Vendor
PowerCred eKYC
Liveness · OCR · Fraud · Face Match
Deepfake · Dedup · Govt Verify
100% of traffic by default
Default route
Secondary Vendor
Secondary eKYC
Fallback only
SLA breach triggers
Fallback only
eKYC Vendor Layer
UB Core Banking / CRM
Webhook receiver · KYC result store
Project Phases

Integration Roadmap: 4 Phases

01
Phase 1 · Weeks 1–2
Foundation & Onboarding
2 weeks
  • API credentials provisioning and environment setup (sandbox + UAT)
  • SDK delivery: PowerCred Liveness SDK for mobile active liveness; all other capabilities consumed via REST API: ID capture, OCR, face match, face deduplication, fraud indicators, deepfake detection, and government database verification
  • Shared session token schema definition: session ID, expiry, state machine
  • Webhook endpoint contract alignment (event types, payload schema, retry policy)
  • ID document type matrix for the Philippines (PhilSys, UMID, DL, Passport, SSS, PRC, TIN)
  • Security review: data residency, PII handling, BSP data localisation requirements
Foundation
02
Phase 2 · Weeks 3–7
Core Journey Integration
5 weeks
  • Mobile: implement QR deep link handler; embed PowerCred Liveness SDK on mobile for selfie capture and active liveness challenge
  • Backend: initiate eKYC session via PowerCred API, receive session token, generate QR code linking session to mobile flow
  • Mobile: ID card front/back capture with auto-detection of dual-sided cards; quality gate before submission
  • OCR via /id/analyze is the first API call. UB’s internal rules engine determines which subsequent checks to trigger: face match, deepfake detection, fraud indicators, face deduplication, and government database verification
  • Desktop: poll for mobile completion; render pre-filled form for applicant review and submission
  • Receive consolidated verification result via webhook; store decision, flags, and confidence scores in UB’s KYC record
Core Integration
03
Phase 3 · Weeks 8–11
Vendor Router & Resilience
4 weeks
  • Vendor abstraction layer: define a unified interface contract that both PowerCred and secondary vendor must satisfy
  • SLA monitoring: instrument PowerCred API calls with latency, error rate, and timeout metrics. Push to UB’s observability stack
  • Manual volume control: UB ops can dial the traffic split between vendors at any ratio without code changes
  • Failover logic: rule engine to evaluate SLA breaches and select vendor per session (not per request) to avoid mid-journey switches
  • Session-level vendor affinity: once a session starts with a vendor, it must complete with the same vendor
  • Secondary vendor API integration (+ their liveness SDK if applicable) using the same unified interface contract
  • Chaos testing: simulate PowerCred degradation to validate fallback routing
Resilience
04
Phase 4 · Weeks 12–14
UAT, Security & Go-Live
3 weeks
  • End-to-end UAT across all journey permutations: all Philippine ID types, primary vendor path, failover path
  • Verification stack testing: face match accuracy, deepfake detection (spoofed selfie test cases), fraud indicator triggers (photocopy, screenshot, AI-generated ID test samples), dedup collision detection, govt verification response handling
  • Penetration testing on session token handling, QR code security, and webhook authentication (HMAC signature verification)
  • BSP MORB compliance review: biometric data handling, consent capture, audit log retention
  • Performance benchmarking: full 18–20s journey latency under concurrent load; regression check against PoC baseline
  • Runbook documentation: incident response, SLA threshold tuning, vendor weighting adjustments
  • Phased production rollout: 5% → 25% → 100% traffic ramp with rollback gate at each stage
Go-Live
People & Departments

Stakeholders Required for Go-Live

Union Bank of the Philippines
🏗️
Software / Platform Engineering
Primary integration owners. Responsible for SDK embed, API wiring, session management, QR handoff logic, and vendor router implementation.
Phase 1–4Core Owner
🔒
Information Security
Reviews API credential handling, data encryption in transit, biometric PII storage, webhook HMAC validation, and pen test sign-off.
Phase 1, 4
⚖️
Compliance & Legal
BSP MORB alignment, NPC registration for biometric data processing, DPA obligations, vendor contract review, and consent language approval.
Phase 1, 4
🎨
Product & UX
Owns the cross-device journey UX, QR handoff screen design, application review UI, error state copy, and user-facing consent flow.
Phase 2, 4
📊
Risk & Fraud Operations
Defines thresholds for fraud indicator flags, deduplication match scores, and deepfake confidence scores. Reviews alert workflows and case escalation rules.
Phase 2, 4
🔧
Infrastructure & DevOps
Provisions environments (sandbox, UAT, prod), sets up observability for vendor router SLA monitoring, manages rollout pipeline and rollback gates.
Phase 3, 4
PowerCred
🤝
Solutions Engineering
Dedicated integration engineer embedded with UB’s team. Owns API onboarding, SDK delivery, troubleshooting, and phase sign-off.
Phase 1–4Core Owner
🧪
Product & QA
Provides test ID samples for all Philippine document types, spoofed selfie sets for deepfake UAT, and fraud indicator test cases (photocopy, screenshot, AI-generated).
Phase 2, 4
🔐
Security & Compliance
Responds to UB InfoSec queries, provides data processing agreements, ISO/SOC documentation, and supports NPC biometric data registration requirements.
Phase 1, 4
📈
Account Management
Commercial point of contact. Manages SLA review cadence, escalation paths, vendor router threshold agreements, and go-live approval.
Phase 1, 4
Note on Governance
A formal RACI matrix will be produced at Phase 1 kickoff. Each department maps to at least one Responsible or Accountable owner per phase gate. Go-live sign-off requires explicit approval from UB Engineering, InfoSec, Compliance, and PowerCred Account Management.
API Reference

Enterprise API: Pipeline Endpoints

Sandboxhttps://mock.powercred.io/kyc
Productionhttps://dev.powercred.io/kyc
Auth?apikey=YOUR_API_KEY on every request
Pipeline Orderquality check → analyze (OCR, first call) → [UB rules determine] → fraud-detection → selfie → session poll / callback
MethodEndpointPhaseDescription
SDKLivenessSDK.init()Ph 2Active Liveness (SDK only). Mobile Web SDK. Renders the liveness challenge in-browser on mobile. On completion, emits a signed liveness token. All other pipeline steps are REST API calls.
POST/id/analyzePh 2OCR + Session creation. The primary pipeline entry point and first API call. Submits ID card images with user_id and document_type. Runs OCR immediately and returns structured fields plus a session_id. UB applies internal rules to determine which subsequent checks to trigger. Supports all 7 PH ID types: DL, Passport, PhilSys, UMID, SSS, PRC, TIN.
POST/id/analyze/qualityPh 2Image quality gate. Assesses brightness, blur, DPI, taken-from-screen, and bright-spot text on the captured ID image. Used as a pre-submission gate on the mobile capture step. Run before invoking /id/analyze.
POST/id/fraud-detectionPh 2ID fraud indicators. Template invalidity, font inconsistency, photo substitution, photocopy, taken-from-screen, AI-generated ID, security feature compromise. Returns per-check boolean flags, confidence scores, aggregate fraud_detected boolean, and risk_level: low / medium / high / critical. Called per UB’s internal rules.
POST/id/selfiePh 2Face match + deepfake + deduplication. Submit the applicant’s selfie. Returns: matched (boolean), score (0–100 similarity %), deepfake (boolean), live (liveness signal), and exists (boolean: duplicate applicant flag). Default face match threshold: 55%, configurable per account. Called per UB’s internal rules.
GET/id/session/{id}Ph 2Full session retrieval. Returns the complete session document: OCR fields, image quality results, fraud detection results, selfie match score, deepfake result, dedup result, and government verification status. Used by the desktop to poll for mobile completion and to render the application review screen. completion_status flags indicate which pipeline steps have finished.
PUT/id/updatePh 2OCR field correction. Allows the applicant to correct OCR-misread fields on the desktop application review screen. Deep-merges the corrected fields into the session. Every correction creates an immutable revision history entry with edited_by and a description.
PUT/id/sessions/{id}/rerun-verificationPh 2Re-run government verification. Re-triggers PH government database check using the session’s current (corrected) OCR data. Also used as the backend retrigger mechanism for govt API downtime. Subject to Legal/NPC/BSP clearance. Returns updated is_verified and failure_reason.
POST/id/session/{id}/callbackPh 1Journey callback (webhook). Register a webhook URL on a session. PowerCred fires a POST to UB’s callback endpoint when all triggered pipeline steps are complete. Retries up to 3× with exponential backoff on non-2xx responses.
PUT/id/session/{id}/fraud-statusPh 3Analyst fraud decision. Sets the manual review outcome: Verified, Fraud, or In Review. Used by UB’s fraud ops team. Each status change creates a revision history entry.
GET/id/sessionsPh 3Session list. Filterable by from_date, to_date, and user_id. Returns session summaries with fraud status, completion flags, and timestamps. Used by UB’s operations and fraud review dashboard.
SLA & Resilience

SLA Commitments & Failover Design

< 5s
Liveness SDK Latency
p95 time from SDK initialisation to liveness result token. Measured on mobile; failover threshold configurable.
📄
< 7s
OCR Processing Time
p95 end-to-end time from image upload submission to structured OCR result availability.
🔎
18–20s
Full Journey Latency
End-to-end time from session initiation to final verified result: liveness, ID capture, OCR, face match, deepfake, fraud checks, dedup, and govt verify combined. Validated in PoC.
🟢
99.9%
Uptime SLA
Monthly uptime commitment with error budget tracking. Excludes planned maintenance windows communicated 48h in advance.
Failover Sequence: Session-Level Routing
New KYC
Session
Route to
PowerCred
(Primary)
SLA Monitor
checks each
API call
Threshold
breached?
No → continue
on PowerCred
Yes (next session)
→ Secondary vendor
Log vendor
selection +
SLA metrics
Key design principle: Vendor switches happen at session boundaries, never mid-session. A session that begins on PowerCred completes on PowerCred regardless of transient latency spikes. SLA thresholds (e.g. p95 latency > 8s, error rate > 2%) are configurable by Union Bank’s ops team. UB ops can also manually dial the traffic split between vendors without code changes.
Timeline

14-Week Delivery Schedule

Phase 1
Wks 1–2
Phase 2
Wks 3–7
Phase 3
Wks 8–11
Phase 4
Wks 12–14
Phase 1 Exit · Week 2
API credentials live, session contract signed off, webhook test passing in sandbox
Phase 2 Exit · Week 7
Full cross-device KYC journey functional in UAT environment, all PH ID types covered
Phase 3 Exit · Week 11
Vendor Router live in staging; chaos test passes; secondary vendor fallback verified
Phase 4 Exit · Week 14
Production go-live; BSP compliance sign-off; runbook complete
Dependencies & Assumptions
!Union Bank to provide dedicated integration engineer(s) from Week 1
!Secondary vendor SDK available and documented by Phase 3 start
!BSP / NPC compliance review initiated by UB in parallel with Phase 2
!PowerCred to provide dedicated solutions engineer for Phase 2–3 duration
1 / 11