A user who registered, started KYC and vanished is the warmest lost revenue a broker has. They found you, clicked, created the account, got halfway through uploading a passport - then nothing. The acquisition dollars for that user are already spent. Most brokers spend exactly zero getting them back. A structured recovery sequence wins a meaningful share of these users back at near-zero marginal cost, because the trigger, the message and the send are all automated once.
Search anything with KYC in it and you get a wall of vendor content about verification technology: liveness checks, document OCR, fraud scoring. Almost nobody writes about what happens after a real, non-fraudulent user quits mid-flow - the recovery communications. That is the gap this article closes: why users abandon, the three-touch sequence that brings them back, how message logic changes with abandonment age, and the compliance lines those messages must never cross. It covers one stage of the bigger funnel we mapped in registration to FTD.
Why Users Abandon KYC Mid-Flow
First, the scale. Sardine, a KYC and fraud vendor, estimates that around 63% of potential new customers in financial services never finish signing up. On the institutional side, Fenergo's 2024 survey of over 450 C-level banking executives found 67% of banks lost clients due to inefficient KYC onboarding, up 19% on the prior year. Different populations, same lesson: abandonment is the default outcome of verification, not an edge case.
Why they quit falls into four buckets. These are pattern observations from running broker funnels, not survey data:
- Document friction. The upload fails. Glare on the ID, cropped corners, an expired document, a file type the system rejects. Every failed attempt multiplies the odds the user closes the tab and never reopens it.
- Mobile camera problems. Browser camera permissions denied, blurry captures, a desktop user with no webcam being asked for a selfie. The flow demands hardware cooperation it never checks for.
- The trust spike. Up to this point the user gave an email and a password. Now a screen wants a passport and a live selfie, and the question lands: why do they need my ID? Cisco's consumer privacy research, cited in Sardine's KYC writing, found 75% of consumers will not share data with a company they do not know and trust. A broker the user discovered forty minutes ago is exactly that company.
- Timing. Nothing went wrong at all. They started at work, the ID was in another room, they planned to finish tonight. No reminder ever came, so tonight never did.
Notice that three of the four have nothing to do with your verification vendor. They are communication problems. Which is why the fix is a marketing fix.
The Three-Touch Recovery Sequence
The architecture is three scheduled touches over 72 hours, each with its own job and its own copy rules. The trigger is a KYC-started event with no completion after a set window. The suppression is instant on approval.
Touch 1 - 2 hours: the helpful resume
No selling. No bonus. No countdown. The user's last memory of you is friction, and this message's only job is to make the next attempt feel like sixty seconds of work. Subject line lowercase and plain, six to ten words: something like your verification is one step from done. Body: acknowledge where they stopped, give one direct resume link that lands on the exact step they left, not the homepage. Add one line of reassurance about how documents are handled and a real support contact. That is the whole email.
Touch 2 - 24 hours: answer the trust objection
Whoever ignored touch 1 usually has the why-do-they-need-my-ID objection sitting unanswered. So answer it, explicitly. Identity verification is a regulatory requirement, not a company preference - say so. State your license or registration where you hold one. Explain how documents are stored, who can see them, and when they are deleted. If you track your median time from upload to approval, state the real number; if you do not track it, do not invent one. Close with a human offer: reply to this email and a person walks you through it. Trust language throughout, still zero pressure.
Touch 3 - 72 hours: deadline or incentive, if compliant
Where your rulebook allows it, the final touch adds urgency: a completion incentive, or an application expiry with a real date. Only real deadlines - if the application does not actually close, do not say it closes. In markets where the regulator restricts inducements, touch 3 is a last clean nudge plus the human offer, and then the sequence ends. It does not turn into a daily drip of the same ask. Three touches, then the user changes segments.
Channel Mix: Email, SMS, WhatsApp, Retargeting
Email is the backbone because every registrant gave you an address. Where the user opted in, add one SMS or WhatsApp message - short, first name, resume link, nothing else - timed between touch 1 and touch 2. Do not mirror the full sequence on messaging channels; a triple-channel barrage reads as desperation and burns the opt-in.
Third channel: retargeting. Sync the abandoned-KYC segment to your ad platforms as a custom audience and run low-frequency reassurance creative - regulation, security, finish in minutes - not offer creative. The user already chose you; the ad's job is removing doubt, not repeating the pitch. And the discipline that makes all three channels safe: the moment verification completes, the user leaves every recovery flow instantly. A please-finish-verifying message arriving after approval tells the user your systems do not talk to each other. The craft behind sender setup, deliverability and sequence copy is its own discipline - we covered it in email marketing for forex brokers.
How many registrations died at your KYC step last month?
Segmentation by Abandonment Age
One sequence for everyone is how these programs fail. The message logic changes with how long ago the user dropped:
- Fresh (0-7 days): resume logic. The ad, the brand and the intent are still in memory. These users get the full three-touch sequence exactly as above. This bucket carries most of the recoverable revenue, which is why the 2-hour trigger matters - speed is the strategy.
- Stale (8-30 days): re-sell, then resume. Intent has faded and the user may not remember why they registered. The message must restate the reason first - the offer, the platform, whatever pulled them in - and only then present the resume link. Two touches, slower spacing, no urgency theater.
- Cold (30+ days): reactivation logic, not recovery. Stop asking for documents. Move these users into the nurture list: value content on a monthly cadence with a standing finish-your-verification module, one clean re-ask per quarter, then a sunset policy so dead addresses stop dragging your deliverability down. One practical detail: after this long, old upload sessions and links are often expired, so the CTA must start a fresh verification session, not resurrect a dead link. The mechanics mirror what we documented in our dormant account reactivation case study.
Compliance Guardrails
Recovery messaging sits close to two sensitive zones - identity data and financial promotion - so the guardrails are not optional:
- No bonus-conditioned KYC pressure in regulated markets. Several major regulators restrict or prohibit deposit bonuses and inducements for retail trading. Conditioning a reward on submitting identity documents in those markets is a complaint waiting to be filed. Offshore and unregulated brands have more room; regulated ones should keep incentives out of the sequence entirely.
- No false urgency. If the account will not actually be deleted tomorrow, do not write that it will. Users screenshot, and regulators read screenshots.
- Respect opt-outs instantly, per channel. An email unsubscribe is not consent to switch the conversation to SMS. Each channel needs its own opt-in and its own kill switch.
- Mind the service-versus-marketing line. A message that helps a user complete an application they initiated is service communication in most frameworks. The moment promotional content enters it, marketing-consent rules apply. Keeping touches 1 and 2 purely functional is a compliance choice as much as a copy choice.
- Only security claims you can defend. Say how documents are actually stored and handled. Do not reach for phrases like bank-grade encryption unless your infrastructure team signs off on them.
KYC Events in the Marketing Layer
Here is why almost nobody runs this sequence: KYC status lives in the back office, and the marketing tools never see it. The ESP knows opens, the back office knows verification states, and no system knows both - so the trigger that should fire two hours after abandonment has nothing to fire from. The fix is instrumentation: stream KYC-stage events - started, document uploaded, verification failed, approved - into the marketing layer as first-class triggers, so sequences launch on abandonment and suppress on approval in real time.
This is exactly how we wire it. AIM (Advancements in Marketing) is the growth marketing partner for brokers and prop firms. On the back-office side we integrate with EXO - disclosure: EXO is AIM's back-office integration partner - which runs KYC through Sumsub and handles account management, payments and IB commissions. AIM's platform reads those verification events and runs the recovery sequences, the age-based segmentation and the reporting on top, so every recovered registration traces back to the touch that recovered it.
The delta between a recovery flow that works and one that gets ignored shows up in the send stats. Across AIM client accounts, campaigns run at 45%+ open rates vs ~20% industry average, and automations click at 5-6% vs 2-3% industry. Recovery sequences are automations - at double the click-through, the same abandoned-user pool returns roughly twice the completed verifications, from messages that cost nothing to send.
The play, compressed: instrument the KYC events, fire three touches in 72 hours, split by abandonment age, keep the copy helpful before urgent, and keep the incentives inside the rulebook. Your warmest lost users are sitting in a database column right now. Nobody else is writing to them.
Turn abandoned verifications into funded accounts.
Frequently Asked Questions
Why do users abandon KYC?
Four reasons repeat across broker funnels: document friction (failed uploads, expired IDs, unreadable photos), mobile camera problems, a trust spike the moment the flow asks for an ID and a selfie, and bad timing - the user started at work or in transit and never came back. Sardine estimates that around 63% of potential new customers in financial services never finish signing up, so abandonment is the default outcome, not the exception.
Can brokers email users who didn't finish KYC?
In most frameworks, yes. A user who created an account and started verification has an existing relationship with the broker, and a message helping them complete an application they initiated is service communication, not cold marketing. Two conditions: honor every opt-out immediately, and check your jurisdiction's rules before adding promotional content or incentives to those messages. When in doubt, keep the message purely about completing the step.
How do you recover abandoned registrations?
Run a three-touch sequence triggered by the abandonment event: a helpful resume message at 2 hours with a direct link back to the exact step, a trust-focused message at 24 hours that answers why the documents are required and how the data is protected, and a final nudge at 72 hours with a deadline or a compliant incentive. Support it with SMS or WhatsApp where the user opted in, plus a retargeting audience that suppresses the moment verification completes.
How many touches should a KYC recovery sequence have?
Three scheduled touches over roughly 72 hours: 2 hours, 24 hours, 72 hours. Fewer leaves recoverable users on the table; more hits diminishing returns and trains users to ignore the sender. After touch three, the user moves into the stale segment with a slower cadence instead of receiving the same ask again.
Should you offer an incentive to complete KYC?
Only on the final touch, and only where your regulator allows it. Several regulators restrict deposit bonuses and inducements for retail trading, and conditioning a reward on handing over identity documents reads badly even where it is technically legal. Unregulated and offshore brands have more room. The first two touches should carry no incentive at all - helpfulness and trust recover more users than pressure does.