Everything you need to know about GBG

Last updated: May 2, 2026

On Dotfile, GBG powers the eKYC Check. Unlike document-based IDV checks (which verify a physical ID), eKYC is a passive, data-driven check: the user does not need to photograph a document or complete a liveness challenge. Instead, identity data collected from the user (name, address, date of birth, and optionally a national ID number, social security number or phone number) is matched against GBG's data sources. 

image.png

How does GBG matching work? 1-source vs 2-source

The most important concept to understand about GBG eKYC is the distinction between 1-source matching (ID1) and 2-source matching (ID2). This determines how many independent data sources must confirm a user's identity for the check to pass.

image.png

💡 ID1 and ID2 are thresholds, not separate data sets

The check names in our contract (e.g. "Italy ID 1", "Italy ID 2") refer to matching thresholds — not two different sets of data sources. Italy ID 2, for instance, queries 12–13 sources internally, but requires matches from at least two of them to return a pass. You use either ID1 or ID2 for a given country — never both. A single check generates a single charge.

What counts as a match

A source counts as a match when it successfully verifies a combination of identity fields. GBG uses a numerical scoring system to weight each field:

image.png

Scores are summed across all matching sources. The total score is then mapped to a decision band (see section 3). A name + address match on one source scores 111; a name + DOB match on another scores 1,110 — giving a combined score of 1,221, which qualifies as a 2 SOURCE PASS.

Waterfall / escalation logic (select countries)

For some countries where ID2 (multiple sources in one dataset - ability to have 2 sources match with only one dataset) is not available (UK, USA, Germany, Netherlands, Denmark), GBG uses a waterfall logic:

  • 2 datasets: Both are always queried (e.g. Denmark, USA). No early exit — both are needed for a 2-source pass.

  • 3+ datasets: The first two datasets are checked. If a pass is found, the remaining datasets are not queried. If not, GBG escalates to the next dataset. This continues until a pass is found or all datasets are exhausted (e.g. Germany, Netherlands).

Billing implication of waterfall logic

For countries with waterfall logic, you are billed for each dataset that is actually queried. In the worst case — where no pass is found on early datasets — all datasets in the profile may be queried. For pricing purposes, always assume worst case = sum of all dataset costs in the profile. See section 4 for full billing details.

Decision bands and scoring

GBG maps the total score from all matching sources to one of four decision bands. The band returned determines the outcome of the eKYC check on Dotfile.

image.pngimage.png

How is GBG eKYC billed?

GBG charges per completed check — that is, per API call that is processed and returns a result. Billing is not conditional on whether the check passed or failed.

image.png

Pricing structure

Waterfall countries: budget for worst-case billing

For countries that use GBG's waterfall/escalation logic (UK, USA, Germany, Netherlands, Denmark), billing is per dataset queried — not per check. If the first datasets do not return a pass, GBG escalates to additional datasets, each generating an additional charge. When budgeting for these countries, always assume the worst case: all datasets in the profile are queried. Contact your Dotfile Solutions Consultant for the dataset-level pricing for waterfall countries.

Profile modification costs

Clients can request modifications to their country profile for example, excluding a specific data source from a country check or adjusting mandatory field matching requirements. Profile modifications are charged at a flat rate per change. Contact your Dotfile Solutions Consultant to request a modification.

Country coverage and required data fields

GBG provides eKYC coverage across 50+ countries. Not all countries support 2-source matching — some have only 1-source (ID1) coverage due to limited data source availability. Dotfile applies the best available profile for each country.

2-source (ID2) available countries — key markets

The following countries support 2-source matching on Dotfile: UK, USA, France, Germany, Italy, Spain, Belgium, Austria, Switzerland, Netherlands, Poland, Portugal, Finland, Denmark, Brazil, Mexico, Indonesia, Nigeria, Philippines, South Africa, Vietnam, and others.

1-source only (ID1) countries — key markets

The following countries support 1-source matching only: Ireland, Sweden, Argentina, Chile, Colombia, UAE, Saudi Arabia, Kuwait, Oman, Jordan, Romania, and others. For regulated clients requiring 2-source assurance in these markets, the recommendation is to supplement the eKYC check with document verification (ID scan or proof of address).

Custom 2-source profiles cannot be created for ID1-only countries

It is not possible to create a 2-source profile for a country that is classified as ID1-only — there are simply not enough overlapping data sources to support it. The only exceptions are Chile and Colombia. If a regulated client requires 2-source assurance in an ID1-only country, the solution is to layer a document verification check alongside the eKYC check.

Required and recommended data fields by country

The general rule is: always collect first name, last name, address, and date of birth. Collecting national ID and phone number where applicable significantly improves match rates. Below are the key markets:

💡 National ID and phone number improve pass rates significantly

Providing a national ID number (Codice Fiscale, DNI, CPF, SSN, etc.) or a verified phone number unlocks additional data sources in GBG's profile and can meaningfully increase match rates, particularly in markets where credit bureau data is restricted (e.g. France). Always collect these fields where the user can reasonably be expected to provide them.

image.png

Country specific notes on key markets

image.png