SaaS Economics

Building vs. Buying Identity Verification: The Real Cost Comparison

Buying identity verification looks cheap at $0.30 a check. Building it looks expensive at six figures a year. The comparison only makes sense once you price in what happens when the vendor gets breached.

At a glance
  1. 01Buying identity verification costs $0.30 to $2.30 per check, while building runs up to $880,000 in year one.
  2. 02A 2026 breach at vendor IDScan exposed 153 million IDs, highlighting the severe risk of SaaS lock-in.
  3. 03The average US data breach costs $10.22 million, a hidden liability missing from per-check vendor pricing.
  4. 04Building in-house costs up to £3.36 million over three years due to compliance and opportunity costs.
A precise scanning kiosk module with a card token passing through an accented scan-slit, next to a smaller, rougher duplicate module, representing the choice between buying and building an identity-verification system.
Illustration generated by Remy for this story.

Building identity verification in-house costs roughly $300,000 to $880,000 in year one and a few hundred thousand a year after that. Buying it costs $0.30 to $2.30 per check.1234 On paper, buying wins easily. But that comparison leaves out the cost that only shows up when a vendor fails, and in 2026 that cost stopped being theoretical.

A breach that exposed the hidden cost of renting identity

In September 2026, a dark web service called Nexus began advertising scans of more than 153 million driver's licenses and IDs from the US and Canada, with roughly 500,000 new documents added every day.56 Security journalist Brian Krebs traced the breach to identity verification company IDScan, whose customers reportedly include multiple Fortune 500 companies.6 The exposure was broad enough to catch high-profile individuals, including U.S. Defense Secretary Pete Hegseth, and serious enough that the FBI's New Orleans field office opened an investigation.56

It wasn't isolated. Around the same period, researchers found an unprotected database tied to identity verification provider IDMerit exposing roughly 1 billion identity records across 26 countries, including more than 203 million in the US alone.7 Names, national ID numbers, addresses, and dates of birth used for KYC checks sat behind no password at all.7 When confronted, IDMerit said its own systems had never been compromised and pointed to independent third-party data sources as the origin. That's precisely the problem: in a multi-vendor identity supply chain, liability gets diffuse fast.7

These aren't edge cases. Identity verification has quietly become critical infrastructure, and critical infrastructure that lives entirely inside someone else's SaaS platform inherits that platform's failure modes.

What does buying identity verification actually cost?

The quoted price of buying is genuinely low. High-volume, low-cost vendors charge as little as $0.30 per core KYC verification covering ID document checks, liveness detection, and face match.3 Legacy incumbents charge more, typically $1.35 to $2.30 per verification, usually bundled with a monthly minimum and an annual contract.4 Juniper Research puts the global blended average around $0.20 per check in 2025, drifting down to roughly $0.17 by 2029 as the market matures, with North America falling from about 28 cents to 21 cents over the same stretch.8

Figure 1
Per-verification pricing across vendor tiers
Legacy incumbents (high end)$2.30Legacy incumbents (low end)$1.35High-volume/low-cost vendors$0.30Juniper global average (2025)$0.20Juniper global average (2029, projected)$0.17

At those per-check prices, buying looks like a rounding error. A company running 1,000 verifications a month pays somewhere between $300 and $2,300 monthly for the core service, plus platform fees. That's the number vendors put on their pricing pages, and it's the number most buyers compare against build estimates when they make the call.

It's also not the whole cost. It's the cost of the service working correctly. It says nothing about what happens when the vendor is compromised, and the vendor holds every document, every liveness scan, and every piece of PII you ever sent it.

What does building identity verification actually cost?

Building is more expensive up front, and it's worth being honest about that. A basic in-house AML or KYC system runs $50,000 to $150,000 to develop.1 A fully featured stack, one that handles ID verification, liveness detection, AML screening, and case management, realistically costs $300,000 to $880,000 in the first year once integration is included, and needs a team of five to seven engineers just to keep running.2

Zenoo's three-year total cost of ownership analysis for a mid-market company processing 1,000 verifications a month puts the fully loaded cost of building in-house at £1.35 million to £3.36 million over three years, once you include regulatory-change management, data-provider integration maintenance, security audits, and opportunity cost.9 Regulatory change management alone runs £80,000 to £200,000 a year, driven by the dozens of rule changes that hit KYC regimes in the UK and EU annually, each with a hard compliance deadline.9

The biggest hidden cost is opportunity cost. Firms that build in-house report that 20 to 30 percent of engineering capacity ends up permanently locked into maintaining compliance infrastructure instead of building product.9 That's not a one-time cost. It's a standing tax on the team, indefinitely.

By Zenoo's own comparison, an equivalent third-party platform at that same volume costs £300,000 to £750,000 over three years, well under half the low end of building.9 Read only this far, and buy wins clearly. The real argument starts with what that number leaves out.

Figure 2
Three-year cost of ownership: build vs. buy (1,000 verifications/month)
Low estimateHigh estimate
three-year total cost of ownership (GBP)
£0£2.5M£5MBuyingBuilding
Approach
Source: Zenoo

The cost buy-side pricing doesn't show

Per-check pricing prices a transaction. It doesn't price a breach. The global average cost of a data breach in 2025 was $4.44 million, and the average cost of a breach in the United States was $10.22 million, a figure driven up by regulatory fines, notification costs, litigation, and customer churn.10 Those are averages across all breach types. A breach at an identity verification vendor is structurally worse than most, because the stolen asset isn't a password that can be reset. It's a scanned driver's license, a face, a date of birth. Once it leaks, it stays leaked.

Figure 3
The hidden cost breach headlines put on the table
153M
Driver's licenses/IDs exposed in the IDScan-linked Nexus breach
$10.2M
Average cost of a US data breach (2025)
1B
Identity records exposed in the IDMerit database leak

Security researchers have started naming this explicitly as a concentration risk. When an organization relies on a single cloud-based identity provider, it inherits that provider's single point of failure, and a compromise cascades across every downstream customer that leaned on it for authentication or KYC.11 The same dynamic played out with the AWS outage, which showed how dependencies on a handful of cloud regions could disrupt operations even for companies that never signed a contract with AWS directly, simply because a vendor two layers removed relied on it.12 Analysts increasingly recommend a "+1 strategy": keep enough identity infrastructure in-house or under direct control that a single vendor's failure doesn't become your failure.11 That's the same instinct driving companies to rethink SaaS lock-in across their broader software stack, not just identity.

The IDScan and IDMerit incidents make the concentration risk concrete. One vendor's breach exposed 153 million documents across an unknown number of downstream Fortune 500 customers, none of whom had a breach at their own company, and all of whom now have to answer to regulators and customers about data they never directly held.56 That liability doesn't show up on any vendor's pricing page.

Side-by-side: three-year cost, breach risk included

Line up the honest numbers and the comparison changes shape.

  • Buying, quoted price: $300 to $2,300 a month at 1,000 verifications, or roughly £300,000 to £750,000 over three years including platform fees.349
  • Building, quoted price: £1.35 million to £3.36 million over three years, fully loaded with regulatory maintenance and opportunity cost.9
  • Buying, with breach risk priced in: add a probability-weighted share of a $4.44 million average breach cost, or $10.22 million in the US, concentrated in a vendor you don't control and can't audit at will.10
  • Building, with breach risk priced in: the same breach exposure exists, but the blast radius is your own systems, your own incident response, and a security posture you set the standard for rather than inherit.

On quoted price alone, buying wins by a wide margin. Weight in the tail risk of a catastrophic third-party breach, and the gap narrows considerably. For companies with real regulatory exposure or high-value identity data, it can flip entirely. This is the same logic that shows up whenever infrastructure gets rented instead of owned: the sticker price looks cheap until the bill comes due in a form nobody budgeted for.

When does buying still win, and when does it become a liability you can't outsource?

Buying is still the right default for most companies. If you're early-stage, running modest verification volumes, or verifying identity as a compliance checkbox rather than a core product function, the math from Zenoo and Didit isn't close: build costs multiples more than buy, and most companies don't have the compliance-engineering headcount to justify it.129

Building or owning a hybrid stack starts to make sense in a narrower set of cases:

  1. You run very high, steady verification volumes. At scale, per-check pricing stops looking cheap and the fixed cost of an in-house system amortizes down, similar to the break-even math that shows up when comparing rented cloud compute against owned hardware.
  2. Your compliance workflows are genuinely unusual. Off-the-shelf KYC platforms are built for common regulatory regimes. If your business sits in an unusual jurisdiction or vertical, customization costs on the buy side erode the price advantage.
  3. Identity verification is a competitive differentiator, not a cost center. If speed, accuracy, or a distinctive onboarding experience is part of your product, owning the stack gives you control a shared vendor can't.
  4. You've already been burned once. After a breach at a vendor, the calculus changes permanently. Companies that lived through an incident tend to adopt the "+1 strategy" and bring at least a slice of identity infrastructure back under direct control, even if the full stack stays outsourced.11

For everyone else, buy remains the sound default, but not blindly. A verification vendor isn't a commodity utility. It's a repository of the most sensitive data a company holds about its customers, and the IDScan and IDMerit incidents show what happens when that repository fails.567 Teams evaluating this trade-off are increasingly building or assembling their own compliance and verification tooling with AI-assisted development, using platforms like Remy to stand up internal workflows without committing to a full custom build or a single vendor's blast radius.

A framework for deciding: control, criticality, and concentration

The decision comes down to three questions, and they matter more than the per-check price on any vendor's homepage.

  1. How critical is identity verification to your regulatory exposure? If a breach at your vendor would trigger your own disclosure obligations and fines, treat that risk as part of the buy price, not a separate line item.
  2. How concentrated is your risk? If one vendor holds identity data for a meaningful share of your user base, you've recreated the exact single point of failure that turned a breach at IDScan into a 153-million-record incident.56
  3. How much does control actually matter to your business? If verification is a checkbox, rent it and negotiate hard on price. If it's core to trust with your customers, the multi-year cost of building starts to look like insurance rather than overhead.
Figure 4
Build vs. buy identity verification: a decision framework
Build vs. buy identity verification: a decision framework
Upfront CostOngoing CostControl Over Breach Blast RadiusCustomization for Unusual RegimesTime to Launch
RecommendedBuy (third-party vendor)early-stage or standard-compliance companiesLowMediumLowLowLow
Build (in-house stack)high-volume, high-control, or previously-breached companiesHighHighHighHighHigh
Ratings are relative across these two options, not absolute; based on figures cited in the article (Zenoo, Didit).
Source: Remy analysis

The published per-check price was never the real cost of buying identity verification. It was the cost of buying it correctly, every time, forever, from a vendor that never gets breached. Given what happened to IDScan and IDMerit in 2026, that assumption is no longer one any company should make for free.567

Frequently asked
Questions readers ask
Is it cheaper to build or buy identity verification?

On quoted price alone, buying is far cheaper: $0.30 to $2.30 per check versus $300,000 to $880,000 to build a full in-house stack in year one.3412 But once you factor in breach risk, concentration risk, and the three-year total cost of ownership, the gap narrows, and for high-volume or highly regulated companies it can favor building or a hybrid approach.910

What was the IDScan/Nexus breach and why does it matter for buy vs. build decisions?

Nexus was a dark web service that emerged in 2026 selling access to over 153 million driver's licenses and IDs, traced to a breach at identity verification vendor IDScan, whose customers reportedly include multiple Fortune 500 companies.56 It matters because it shows that renting identity verification concentrates catastrophic breach risk in a single third party that downstream customers cannot fully audit or control.

How much does a data breach cost on average, and does that change the buy vs. build math?

The global average cost of a data breach was $4.44 million in 2025, and the average U.S. breach cost was $10.22 million.10 Weighting that risk into a per-vendor SaaS relationship changes the effective cost of buying identity verification, even though it never appears on a vendor's pricing page.

What is the three-year cost of building KYC in-house versus buying it?

For a mid-market company running 1,000 verifications a month, building in-house costs roughly £1.35 million to £3.36 million over three years once regulatory maintenance and opportunity cost are included, versus roughly £300,000 to £750,000 for an equivalent third-party platform over the same period.9

When does it make sense to build identity verification instead of buying it?

Building makes more sense at very high steady verification volumes, when compliance workflows are unusual, when identity verification is a competitive differentiator rather than a cost center, or after a company has already experienced a vendor breach and wants to reduce concentration risk.911

Sources
  1. 1Cost of KYC Compliance: Build vs. Prebuilt SolutionsKitrum
  2. 2Build vs. Buy Identity Verification: A Deep DiveDidit
  3. 3Build vs. Buy Identity Verification: Cost AnalysisDidit
  4. 4Top KYC & Identity Verification Software in 2026: The Best Alternatives ComparedDidit
  5. 5It sure looks like hackers breached a major ID card verification serviceTechCrunch
  6. 6FBI Probes Service Selling 153M+ Drivers LicensesKrebs on Security
  7. 71 billion identity records exposed in ID verification data leakFox News (CyberGuy Report)
  8. 8Identity verification scale and maturity to push average cost downBiometric Update (citing Juniper Research)
  9. 9The real cost of building KYC in-houseZenoo
  10. 102025 Cost of a Data Breach Report: Navigating the AI rush without sidelining securityIBM Think (Cost of a Data Breach Report, with Ponemon Institute)
  11. 11The hidden risk in SaaS: Why companies need a digital identity exit strategyHelp Net Security
  12. 12AWS cloud outage reveals vendor concentration riskTechTarget
Portrait of Lena Ortiz
Lena Ortiz
Software Ownership
Lena makes the case for owning the software your company runs on.
More from Lena Ortiz
© 2026 The Official Remy BlogDrafted by AI authors, reviewed by human editors.