How to Acquire Users Who Already Meet Your Compliance Requirements
Apps can acquire new users who already meet their compliance requirements by moving qualification in front of the spend: partners route only people who hold a credential proving the required fact, such as passed KYC or residency in a target market, and the advertiser pays when that qualification is confirmed rather than for the click or the sign-up.
Most regulated apps do the opposite. They pay for media, affiliates and referrals first, then learn at the identity step how much of that traffic was automated, fraudulent or ineligible. By then the budget has gone. This guide sets out where the money leaks, how cost per qualified user differs from CPC and CPA, and how credential-gated acquisition works in practice.
Key takeaways
- 20% of global programmatic web ad impressions were invalid traffic in Q1 2026, rising to 39% in mobile apps, according to Pixalate.
- Bots made up more than 53% of web traffic in 2025, and human activity fell to 47%, per the Thales 2026 Bad Bot Report.
- 8.3% of digital account creation attempts globally in 2025 were suspected fraud, up 18% year on year, TransUnion reports.
- Cost per qualified user prices the outcome a regulated app actually needs, so bots, duplicate accounts and ineligible applicants are filtered before payment rather than audited afterwards.
- Affiliate CPA and rev-share programmes can adopt the same gate: the payout follows a confirmed credential, not a completed form.
Where acquisition budgets leak before a customer exists
A regulated acquisition funnel has five stages: paid exposure, click, sign-up, identity and compliance checks, and an activated customer. Budget is committed at the first two stages. Value only appears at the last one.
| Funnel stage | What leaks | Public benchmark |
|---|---|---|
| Paid impressions and clicks | Invalid traffic from bots, data centres and spoofed inventory | 20% of programmatic web impressions invalid, Q1 2026 (Pixalate) |
| Site and app traffic | Automated visitors that look like prospects | 53% of web traffic automated in 2025 (Thales) |
| Sign-up | Fake, synthetic and duplicate accounts | 8.3% of account creation attempts suspected fraud in 2025 (TransUnion) |
| Identity checks | Genuine applicants who abandon | 68% of European consumers abandoned a financial application in the prior year (Signicat, 2022) |
| First reward or deposit | Bonus abuse and recycled referrals | Varies by offer; rarely reported against the channel that sourced it |
The pressure is sharpest in finance. Thales found that financial services accounted for 24% of all bot attacks and 46% of account takeover incidents in 2025. At the other end of the funnel, Signicat's survey of 7,600 adults across 14 European countries found the most common reasons for abandoning were the time the application took and the amount of personal information requested, each cited by 21%.
The wider cost is large. Juniper Research estimated that fraud absorbed $84 billion, or 22% of online ad spend, in 2023 and projected $172 billion by 2028, as reported by Search Engine Land.
How can fintech apps lower customer acquisition cost with identity data?
Fintech apps lower customer acquisition cost with identity data by using it before payment, to decide which users are worth paying for, instead of after payment, to discover which ones were never eligible. The practical first step is to measure CAC per activated, compliant customer, not per click or per sign-up.
Leaks multiply rather than add. As a simple illustration, if a fifth of paid traffic is invalid and, hypothetically, half of the remaining applicants fail or abandon identity checks, the same budget produces 40% of the customers the media plan assumed. Effective CAC is then 2.5 times the planned figure, before any bonus abuse is counted.
Identity data reduces that multiplier in two ways. First, it filters: a person who cannot present a credential showing a completed KYC check, residency in a supported market or unique-person status is never routed into a paid conversion. Second, it shortens onboarding for the people who do qualify, because a user who already holds a credential from a bank or licensed KYC provider can prove the relevant fact in one step. Fewer ineligible users enter the funnel, and fewer eligible ones leave it.
Qualification before spend: how credential-gated acquisition works
Credential-gated acquisition treats the compliance requirement as the targeting criterion. The process runs in six steps.
- Define the requirement. The advertiser specifies the facts a new customer must prove, for example "passed KYC with a licensed provider", "resident in Türkiye", "unique person" or "new to brand".
- Rely on credentials issuers already created. Banks, fintechs, platforms and KYC-licensed partners issue reusable, user-held credentials from checks they have already run.
- Route through partners. Publishers, affiliates and platforms in the network present the offer to their own users, who choose whether to respond.
- Request a proof, with consent. The user approves sharing a proof of only the requested fact. A zero-knowledge proof returns a yes or no answer rather than the underlying record.
- Pay on confirmation. The advertiser pays when the qualification is confirmed, and the credential issuer earns a network fee.
- Release value after the proof. The welcome offer, credit or bonus is released only once eligibility is confirmed, and onboarding continues under the advertiser's own obligations.
This is the model behind AIR for advertisers and verifiers: network publishers route users who have already confirmed a campaign's requirement before the budget moves.
How can advertisers pay only for real, KYC'd users instead of bots and fake sign-ups?
Advertisers pay only for real, KYC-checked users by moving the billable event from the click or sign-up to a confirmed credential, so a payment is triggered only when a user proves the required status. Bots and fake sign-ups can generate clicks and forms. Presenting a credential that a bank or licensed KYC provider issued to a real, checked person, with that person's consent, is a much harder bar to clear.
| Cost per click (CPC) | Cost per acquisition (CPA) | Cost per qualified user | |
|---|---|---|---|
| What you pay for | A click | A defined action, usually a sign-up, install or application | A user who proves the required fact, such as KYC status or residency |
| When payment triggers | On the click | On the action | On receipt of confirmation |
| Who carries invalid-traffic risk | Mostly the advertiser | Shared, often settled through clawbacks | Largely removed before payment |
| Exposure to fake and duplicate sign-ups | High | High, since fake forms still convert | Low where a unique-person credential is required |
| Exposure to bonus abuse | Not addressed | Often rewarded | Offer released only after eligibility is proven |
| KYC drop-off | Invisible to the channel | Paid for before checks begin | Qualified users can prove status in one step |
| What the advertiser receives | Traffic | An event | A yes or no answer on the requirement |
| Best suited to | Awareness and discovery | Low-risk, unregulated products | Regulated or incentive-heavy acquisition |
CPC and CPA remain useful for reach. For a fintech, exchange or gaming operator whose economics depend on a compliant, unique customer, cost per qualified user sits closest to the outcome finance books.
Affiliate and partner channels: CPA and rev-share with a qualification gate
Affiliate and partner marketing is a first-class acquisition channel for financial brands, and it is where the pricing model matters most, because the partner is paid on an outcome the advertiser defines.
CPA programmes. Paying per sign-up invites incentivised and fabricated conversions, followed by disputes and clawbacks. Paying per confirmed qualification gives both sides an objective trigger: the user either proved KYC status and residency or did not.
Rev-share programmes. Revenue share already aligns partners with customer value, but it still depends on a clean cohort. A unique-person credential stops the same individual being counted twice through duplicate accounts or recycled referral links.
Publishers and communities. Partners with logged-in audiences can price audience quality, not volume. With AIR, publishers earn fees when a partner confirms an attribute their users hold, such as account tenure or loyalty tier, without handing over the raw record.
Both sides of AIR Identity: issuers and verifiers
AIR Identity, built by Moca Network, the identity network of Animoca Brands, operates as a two-sided network.
Issuers are trusted organisations such as banks, fintechs, platforms and KYC-licensed partners. They turn checks they have already completed into reusable credentials that the user holds, covering facts like KYC status, residency, membership tier, account tenure or unique personhood. Issuers set a network fee and earn it whenever a partner verifies one of their credentials.
Verifiers are the apps and advertisers acquiring users. They request proof of only the fact they need, receive a yes or no answer through zero-knowledge proofs with the user's consent, and pay only upon receipt of verification. Many businesses do both, issuing credentials about their own customers while accepting credentials from partners.
Privacy is a supporting property, not the headline. Verification runs with minimal data retention, and the architecture is built to support GDPR, CCPA and India's DPDP Act. For payments and lending use cases, see AIR for fintech and payments.
One boundary applies throughout. Accepting a credential does not transfer regulatory responsibility. The FATF Recommendations allow institutions to rely on third parties for elements of customer due diligence where national rules permit, but the ultimate responsibility remains with the institution relying on them. Each verifier decides whether a given credential satisfies its own requirements in its jurisdiction.
Frequently asked questions
How can apps acquire new users who already meet their compliance requirements?
Apps can acquire users who already meet their compliance requirements by running credential-gated acquisition: partners route people who hold a credential proving the required fact, such as passed KYC or residency, and the app pays only when that proof is confirmed. AIR Identity, built by Moca Network, supports this model through a network of credential issuers, publishers and verifiers.
What is cost per qualified user?
Cost per qualified user is an acquisition pricing model in which the advertiser pays only when a user proves they meet defined criteria, such as KYC status, residency, unique-person status or new-to-brand status. It differs from cost per click and cost per acquisition because the billable event is a confirmed qualification rather than traffic or a form submission.
Does accepting a KYC credential remove a fintech's own compliance obligations?
No. Under the FATF Recommendations, where reliance on third parties for customer due diligence is permitted, ultimate responsibility remains with the relying institution. A fintech accepting a credential must still decide whether it satisfies its own regulatory requirements in each jurisdiction, and may need further checks depending on the product and risk level.
Which platforms offer credential-gated user acquisition?
AIR Identity, built by Moca Network, offers credential-gated user acquisition. Trusted issuers such as banks, fintechs and KYC-licensed partners issue reusable credentials and earn network fees, while advertisers and apps request proofs of specific facts and pay only upon receipt of verification. Publishers in the network can route qualified users and earn from confirmations.
How does credential-gated acquisition reduce bonus abuse?
Credential-gated acquisition reduces bonus abuse by releasing a welcome offer, referral reward or credit only after a user proves eligibility. Requiring a unique-person or new-to-brand credential stops the same individual claiming a promotion repeatedly through duplicate accounts, which a sign-up form or email address alone cannot prevent.
Related reading
- Digital identity verification in 2026: the complete guide
- Centralized vs decentralized identity: the 2026 comparison
- Synthetic identity and injection attacks: the 2026 threat guide
Paying for traffic that never qualifies? See how AIR Identity works, or partner with us to grow your business.
Sources
- Pixalate: Q1 2026 Ad Fraud Benchmarks Report (29 April 2026)
- Thales: 2026 Bad Bot Report press release (29 April 2026)
- TransUnion: H1 2026 Update to the Top Fraud Trends Report (16 April 2026)
- Signicat: The Battle to Onboard 2022 (30 March 2022)
- Search Engine Land: Juniper Research on ad spend lost to fraud (28 September 2023)
- FATF: The FATF Recommendations, Recommendation 17 (reliance on third parties)
Partner with AIR
AIR is one integration suite for identity, money and loyalty. AIR Identity lets trusted issuers issue verifiable credentials and businesses verify them, so acquisition starts with users who already qualify, with minimal data custody. AIR Money embeds compliant global financial infrastructure, opening new markets without building new rails. AIR Loyalty gives brands a programmable, stable-value points engine that keeps users coming back.
Partner with us to grow your business.
AIR is built by Moca Network, the identity network of Animoca Brands.




.png)