Opening one Finom business account quietly sets a large machine in motion: identity
checks, company-registry look-ups, risk scoring and document signing. This map shows the systems and
outside providers that cooperate to do it — and why the work is spread across several engineering
teams. It's meant to make the scope and complexity tangible, not to be read line by line.
15+
internal & external systems involved
5
engineering domains cooperating
11
applicant steps to complete
6
points where an application can be declined
★
The Onboarding team (Growth domain) builds and runs five of these systems —
bankonboarding, bprocess, idcheck, csearch, aibridge, highlighted throughout. The rest are owned
by neighbouring teams. No single team can open an account alone, which is part of why the flow touches
so many systems.
Legend
How systems talkDirect request (REST)Workflow engine (Camunda)Async event (queue)Data sync (Kafka)Analytics feed (DWH)External providerLive push to screen
Each box is a system; each arrow is one system asking another to do something. The detail
of the wiring matters less than the picture as a whole — opening an account touches this many moving
parts, owned by five different teams. bankonboarding in the centre is the conductor.
Who owns what
No single team can open an account on its own — the flow deliberately spans five
domains. Ownership is taken from the domains registry (which records a team lead per service rather
than a named domain); the Growth attribution for the onboarding cluster is per your input.
Growth · Onboarding YOUR TEAM
Owns the flow & the applicant experience
bankonboarding
bprocess
idcheck
csearch
aibridge
Risk & Compliance
Checks, decisioning & the customer record
customerdossier
auth
riskengine
screening
FCRM/*
docsrecognition
tasks
signature
Data & Integrations
Company data from external registries
bizdatasources
externalgateway
eventsproxy
reporting
dwhfilesync
Banking & Payments
The account, card & pricing
bank
tariffs
finom
banklimits
reward
Platform & BackOffice
Shared plumbing & internal tools
cometpush
tooling
cstools
thepipe
backoffice
notify
What happens, in six moves
01
Getting started
A few pre-onboarding screens (phone, turnover) tailored by country and business type.
"Open Account" kicks off the automated process.
Company look-up (csearch → Creditsafe) pre-fills what we already know.
02
Company check (KYB)
We confirm the company against official registries (via bizdatasources).
customerdossier builds the file and maps who really owns the business.
If registry and applicant data disagree, it goes to manual review.
03
Identity check (KYC)
The system decides who must be verified.
The person verifies through Sumsub (via idcheck).
Results flow back automatically; a mismatch triggers a review.
04
Risk & questions
riskengine scores the application and returns a decision.
Anything still missing becomes additional questions for the applicant.
05
Signing
The account agreement is signed with a qualified e-signature via InfoCert.
In some markets an in-app signature (Sumsub) is used instead.
06
Open & after
On approval, bank creates the wallet, card and plan.
Some accounts open with limits first, then upgrade once extra data arrives.
Later, post-opening data (tax, VAT, documents) is collected.
The account-opening process
How an account actually gets opened, end to end. Behind the screens the applicant sees, an
automated process (the fast-track flow) runs the compliance checks in a fixed order and only opens
the account once every gate passes. Any gate can send an application down the
red decline path. Technical names are kept as a reference for
engineers; the shape of the flow is what matters.
Automated stepSub-process (zoomed out)Decision pointStartEndsvc= system involved
Simplified for clarity: the parallel freelancer fast-track and the
inner detail of each sub-process (building the company file, verifying people, risk scoring, compliance
review) are collapsed into single boxes here.
What the applicant fills in
The screens a business owner actually sees, in order. Most run inside the "Applicant fills
in details" box above. waits = the screen
pauses until a background check finishes; optional
= shown only when that information is still missing.
1
Company registration number waits
The applicant enters the company number. This is what kicks off the whole automated process behind the scenes.
registriescustomer recordauth
1a
Upload registration documents waitsoptional
Only if we can't find the company automatically — the applicant uploads the paperwork.
customer record
2
Business details, activity & address waitsoptional
Company details, what the business does, and its address — each shown only if not already known.
customer record
3
Are you a legal representative? waitscan end here
Confirms the applicant is authorised to open the account. If not authorised, the application can stop here.
customer record
4
Declare representatives & ownership waits
List the legal representatives and confirm the ownership picture.
customer record
5
Personal details
Personal information for the applicant and representatives.
customer record
6
Beneficial owners (UBO)
Who ultimately owns the business — may include an ownership questionnaire or an org-chart upload.
customer recordrisk check
7
Identity verification
The representative proves their identity through Sumsub (document + selfie, or a video/e-signature flow depending on the market).
Sumsub / idcheck
8
Verification status
The applicant sees the verification progress for everyone who needs to be checked.
Sumsub / idcheckcustomer record
9
Choose a plan instant
Pricing / plan selection.
tariffscustomer record
10
Additional questions instantoptional
Extra compliance questions, shown only when the checks ask for more information.
customer record
11
Sign the documents instant
A final completeness check, then the account agreement is signed (InfoCert e-signature, or an in-app signature via Sumsub in some markets).
InfoCertSumsub e-sign
German companies — the most complex path
Germany is the heaviest onboarding we run. A registered German company (e.g. a
GmbH) is matched against the commercial register (Handelsregister), needs its exact
registering court, and — when the ownership is layered (companies owning companies) — every
representative traced through that chain has to be verified. On top of the normal business-details
collection it adds a business-activity questionnaire and extra documents. This branch expands
"what the applicant fills in" above for the complex German case.
🇩🇪
A German company flagged corporate / complex stays on the German registration-number & court
journey (it is not simplified into a single business-details screen, because Germany has a full
registry) and branches into the deeper ownership and activity checks below.
Handelsregister number + court
The registration number plus the exact registering court (Amtsgericht) — auto-suggested from the registry and stored as the company's registration issuer. Germany-only.
Legal form sets the path
GmbH / UG / AG / e.K. take the registered path; a GbR partnership and not-yet-registered companies follow their own document journeys.
Register pull & pre-fill
Company data is fetched from the German commercial register (CompanyInfo / Handelsregister) and pre-fills the form. Retrieval runs in the background.
Ownership traced end to end
When companies own companies, the whole chain is resolved and every required representative along it must be verified — not just the applicant.
Business-activity questionnaire
Complex companies answer a tailored questionnaire — holding / investment / services / sale of goods — then provide payment info and supporting documents.
Identity & signing
Verification by video-ident or an in-app penny-drop e-signature (A/B). Joint setups may need a second representative to verify and co-sign.
1
Company number & registering court DE-onlywaits
The applicant enters the Handelsregister number and the registering court (Amtsgericht, auto-suggested from the register), the German legal form, business name, activity and registration date. The legal form decides the journey (registered company, GbR, or not-yet-registered). This kicks off the background register look-up.
Uploaded when the register doesn't give us everything. A GbR provides the partnership agreement (Gesellschaftsvertrag) and trade licence (Gewerbeschein); not-yet-registered companies have their own document set.
customer record
3
Business details & activity waits
Company details and the type of activity (NACE) — largely pre-filled from the register, with known fields locked.
customer record
4
Company address waits
Registered / business address.
customer record
5
Representatives & ownership waits
Confirm the applicant's authority, declare the legal representatives, and confirm the ownership picture.
customer record
6
Personal details
Personal information for the applicant and representatives.
Who ultimately owns the business — an ownership questionnaire and, where needed, an org-chart upload. For layered structures the full chain of companies is resolved here to work out exactly who must be verified.
customer recordrisk check
8
Verify all required people DE video-ident / QES
Each required representative proves their identity through Sumsub — Germany uses video-ident or an in-app penny-drop e-signature (A/B test). Complex ownership means everyone traced in step 7, and joint setups add a second signer.
A tailored questionnaire based on what the company does — holding, investment, services, or sale of goods — followed by payment information and any supporting documents. This is the extra layer complex companies carry over a simple company.
customer record
10
Plan → questions → signing final
Choose a plan, answer any remaining compliance questions, then sign the agreement (InfoCert e-signature, or the in-app signature). A second representative co-signs where required.
tariffsInfoCertSumsub e-sign
Every system-to-system call
The full list of interactions behind the map above — a reference for engineers.
The domains registry records a team lead per system rather than a named domain, so the domain grouping is derived from those leads; the Growth label for the onboarding cluster is per your input.
riskengine / screening are being gradually phased out in favour of the financial-crime (FCRM) workflows, but they are still called during onboarding today.
The AI onboarding chat appears under two names in the code (aibridge → casper, and "AI CFO" / aiassistant) — likely one subsystem. The AI assist is non-decisioning: it never makes the approve/reject call.
This is the standard company fast-track. Freelancers, complex ownership structures and some countries follow variants that add or reorder steps.
German nuance: because Germany has a full commercial register, even a complex German company keeps the registration-number & court journey. The single-screen "business details" shortcut is only used for complex companies in countries without a usable registry.
The intent that a GbR partnership must verify everyone (a stricter list than "the owner + one representative") is described in the spec, but in the current code every path prepares the lighter list — worth confirming with Compliance before relying on it.
Compiled from source code and internal documentation; interactions reflect actual calls between systems.