
Jumio, which sells identity verification software, says it has completed the independent electronic know-your-customer assessment required by Bank Negara Malaysia with no findings. The assessment was carried out by a Malaysian cybersecurity and testing firm, and the release says Jumio's system met 100 per cent of the criteria it examined.
The product checks that a person opening an account is who they claim to be, using a photograph of a document, a facial scan, and a test that the face belongs to a living person rather than a photograph or a screen. Jumio says it has processed more than a billion such transactions across more than two hundred countries.
What a passed assessment certifies
An independent assessment of this kind is worth having, and it is more than many vendors can show. It is also a snapshot with boundaries. Passing it means the system met a defined checklist on the day it was tested, judged by an assessor working to that checklist. It does not mean the system resists the attack that has not been invented yet.
That gap matters most in identity work, because the fraud changes faster than the standards do. A liveness check that frustrates last year's deepfake can be defeated by this year's, and a certificate issued after a successful test says nothing about the model's performance on faces it has not seen. The result also tells a reader nothing about false rejections, which are the other half of the cost, since a system that blocks genuine customers is failing in a way the checklist may not capture. Ee Khoon Oon, who leads Jumio's Asia Pacific business, called zero findings a strong validation. It is a validation of the process. Whether it predicts real-world fraud outcomes is the question the assessment was never designed to answer.