Intel · 2026-06-05
The African Mobile Identity Leap: Carrier-First Identity in Markets Without Legacy IAM
By J. W. Bouckaert
Most identity infrastructure outside the West was built backwards from how the textbooks teach it. There was no legacy IAM stack to migrate from. There was no national PKI to defer to. There was, in many cases, no comprehensive civil registry to anchor against. What there was, almost universally, was a SIM card.
That single fact reshaped the architecture of identity across Sub-Saharan Africa. The result is not a deficit version of what Europe or North America built. What emerged is different in kind: a carrier-first identity stack in which the mobile network operator is the trust anchor, the SIM is the credential, and the mobile-money wallet is the de facto KYC record. For a Western architect arriving in Nairobi, Lagos, or Johannesburg, the disorientation is real. You are looking at production identity systems that skipped the step you assumed was foundational.
This is an account of how that happened, where it is live in 2026, and what the rest of the industry should be learning from it.
The penetration asymmetry that forced the architecture
Identity systems get designed around whichever credential the largest number of users already hold. In the United States, that has historically been a driver's license or a Social Security Number. In the European Union, it is increasingly a national eID. In Sub-Saharan Africa, it is a SIM.
The GSMA's Mobile Economy Sub-Saharan Africa 2024 report counts approximately 489 million unique mobile subscribers at end-2023, with the figure projected to reach about 692 million by 2030. The World Bank's Global Findex 2021 records that 55% of adults in Sub-Saharan Africa hold a financial account, with mobile-money accounts (33% of adults) doing most of the lifting and conventional bank accounts trailing far behind.
The asymmetry is not subtle.
| Coverage proxy (Sub-Saharan Africa, latest available) | Approximate reach | Source |
|---|---|---|
| Unique mobile subscribers (end-2023) | ~489M | GSMA Intelligence |
| Adults with a mobile-money account | ~33% | World Bank Findex 2021 |
| Adults with any financial account | ~55% | World Bank Findex 2021 |
| Registered mobile-money accounts (2023) | ~835M | GSMA State of Mobile Money 2024 |
| Mobile-money transaction value (2023) | ~$912B | GSMA State of Mobile Money 2024 |
When the credential most of your users hold is a SIM, the rational architectural decision is to make the SIM the trust anchor. Markets without legacy IAM made that decision a decade ago and have been compounding on it ever since.
Kenya: M-Pesa as identity layer, not just payment rail
Kenya is the canonical case study. Safaricom's M-Pesa, launched in 2007, was designed as a peer-to-peer payments product. It became something larger almost immediately: an identity attestation service operating at national scale.
A merchant accepting an M-Pesa payment is implicitly accepting a chain of trust: the MSISDN is registered under the Kenya Information and Communications (Registration of SIM-cards) Regulations, the wallet is bound to a KYC record held by Safaricom, and the transaction is authenticated by the SIM-bound PIN. No bank is in the loop. No government PKI is in the loop. The carrier is the identity register.
Safaricom's most recent disclosures show M-Pesa serving tens of millions of active customers in Kenya and a substantially larger footprint across the seven markets where M-Pesa operates. The Central Bank of Kenya publishes monthly mobile money statistics that put the asset class on a regulatory footing more rigorous than most informal-economy observers assume.
The downstream effect on identity is structural. Kenyan fintechs onboarding new users routinely use an M-Pesa name match as a primary KYC signal. The Safaricom carrier API tier exposes verification primitives (number verification, SIM-status checks) that compress what would be a multi-week bank-account-verification workflow into a sub-second response. The carrier is the identity stack, not a supporting actor in it.
Nigeria: NIN-bound SIMs as a national identity backplane
Nigeria took a different route to the same architectural endpoint. In December 2020, the Nigerian Communications Commission (NCC) and the National Identity Management Commission (NIMC) issued a directive requiring every active SIM to be linked to a National Identification Number (NIN) issued by NIMC. After multiple deadline extensions, the linkage is now operationally enforced across the major operators.
The architectural consequence is unusual: every active SIM in Nigeria is, by regulatory construction, bound to a government-issued identity number. The MSISDN inherits the assurance level of the NIN registration. Carriers can answer "is this SIM the one we issued to this number?" and, indirectly, "is the underlying identity record one NIMC has enrolled?"
That is a stronger guarantee than most high-income markets can offer at the network layer. It is also a model with real operational scars. The enrollment process has been criticized for queues, data-quality issues, and exclusion of populations without other supporting documents. Those criticisms are accurate. They do not change the fact that, for the population that is enrolled, Nigeria has built a SIM-bound identity backplane at a scale and depth that the EU's eIDAS 2.0 wallet program is still working toward.
Fintech onboarding in Nigeria reflects this. Platforms verify a customer by submitting the NIN and MSISDN together; the carrier and NIMC respond with a match decision. The same primitive is consumed by banks under Central Bank of Nigeria KYC tiering, by lenders running credit decisions, and by remittance platforms meeting AML obligations.
South Africa: RICA, mobile money, and cross-border KYC
South Africa's regulatory baseline is the Regulation of Interception of Communications and Provision of Communication-Related Information Act 70 of 2002 (RICA), which has required SIM registration since its commencement. Every MSISDN in active service is, by statute, linked to a registered identity.
The mobile-money story in South Africa is less clear-cut than the Kenyan one because formal banking penetration is higher and product competition is fiercer. Vodacom's VodaPay, MTN MoMo South Africa, and a long tail of bank-led wallets all compete for the same identity-attestation real estate. The architectural pattern, however, is the same: the SIM-bound, RICA-verified identity is the substrate. The wallet is the surface.
South Africa is also the regional hub for cross-border KYC-as-a-service providers serving the rest of the continent. Smile ID, among others, builds composite identity products that combine carrier signals, mobile-money records, and document verification across multiple African markets. The architecture is explicitly carrier-first; document verification is a supplement to it.
The CAMARA convergence
Until recently, every African carrier exposed identity primitives through proprietary APIs with bespoke contracts. That fragmented the integration surface and capped the addressable market at carriers individually willing to invest in developer relations.
The GSMA Open Gateway initiative, built on CAMARA (a Linux Foundation project standardizing telecom network APIs), is collapsing that fragmentation. As of 2026, GSMA reports that more than 80 operator groups, representing the majority of global mobile connections, are aligned around CAMARA. African operators including Orange, MTN, Vodacom, and Safaricom are participants. Orange in particular exposes SIM Swap and Number Verification primitives through Orange Developer across multiple African markets.
For a global identity platform, the consequence is concrete. A SIM Swap check executed against an Orange Côte d'Ivoire subscriber now uses the same CAMARA contract as a check against Telefónica España. The cost of building multi-market African identity coverage has moved from months of per-carrier work to days of standardized onboarding. That is what makes African carrier signals consumable inside global fraud-prevention pipelines for the first time at meaningful scale.
We have written elsewhere about how this convergence reshapes carrier economics globally; see Carrier Monetization of Identity Signals. The African case is the same dynamic with sharper edges, because there is no existing IAM stack for the carrier signal to augment: the carrier signal is the stack.
The failure modes a carrier-first stack must defend against
Treating the SIM as the primary trust anchor concentrates risk on a small number of attack surfaces. The serious ones:
SIM-swap fraud. An attacker socially engineers, bribes, or coerces a carrier agent to port the MSISDN to a SIM the attacker controls. Account takeover follows directly. We have written extensively about this class of attack and why detection latency is the deciding metric; see Detect SIM Swap in the Next 50 Milliseconds and SIM Swap Detection Latency: The Blind Spot.
Agent-assisted registration fraud. A SIM is registered at the point of sale against a stolen, borrowed, or synthetic identity document. In jurisdictions with high registration-channel volume and low agent oversight, this is the dominant fraud vector at enrollment.
Silent number recycling. When an MSISDN is decommissioned and reissued to a new subscriber, services that bound an account to that number can be inherited by the new holder unless the carrier signals the recycling event. See Silent Number Recycling as a Carrier Signal Entropy Source.
Single-provider failure. A single carrier's SIM Swap response is a single point of trust. If the carrier's HLR data is stale, the response is incorrect, and the fraud succeeds. The mitigation is signal fusion across multiple carriers and signal classes; see When One Carrier Lies: Signal Fusion Against Single-Provider Failure.
The architectural response is to stay carrier-first and refuse to trust any single carrier signal in isolation. SIM-Swap freshness, Number Verify, mobile-money KYC cross-check, and a device-bound passkey assertion fused together produce a composite trust score that no single signal class can replicate.
A reference fusion architecture
The minimum viable carrier-first identity decision in a high-stakes African transaction looks something like this in production:
+-----------------------------+
| Composite Trust Decision |
| (PQC-signed attestation) |
+--------------+--------------+
|
+----------------------------------+----------------------------------+
| | | |
SIM Swap (TTL) Number Verify Mobile-money KYC Device-bound passkey
via CAMARA via CAMARA (M-Pesa / MoMo / assertion (FIDO2,
(Orange / MTN / (Orange / MTN / Orange Money name + WebAuthn) bound to
Vodacom / Safari) Vodacom / Safari) MSISDN match) user agent
| | | |
+----------------------------------+----------------------------------+
|
Signal weighting + freshness
evaluation in-request
Each input is independently weak. The SIM Swap signal can be stale; the Number Verify signal proves SIM possession but not subscriber identity; the mobile-money name match can be defeated by a colluding agent; the passkey proves device possession but not subscriber identity. The composite decision is strong because the failure modes are independent. An attacker has to defeat all four classes simultaneously, in real time, to forge a decision.
This is the same architectural pattern we apply globally, with one important difference: in carrier-first markets, the mobile-money KYC signal is materially stronger than its closest Western analogue (a bank-account name match), because the wallet KYC is held directly by the carrier and is updated continuously through transaction activity.
Lessons for the rest of the industry
The temptation, reading the above from a Western perspective, is to file it under "interesting context for emerging markets." That misreads the situation. What is happening in Sub-Saharan Africa is a forward-looking architectural pattern.
Three lessons travel:
The credential users actually hold is the credential to design around. Most high-income markets are now confronting their own version of the African problem in the form of underbanked, undocumented, or unbanked populations who cannot present a driver's license at a KYC checkpoint. The carrier-first pattern is the most production-tested response to that problem on the planet.
Mobile-money KYC is a globally underused identity primitive. GSMA's 2024 mobile-money totals indicate that the dataset is large enough, fresh enough, and regulated enough to underwrite high-assurance identity decisions. The interoperability work to make it consumable globally is still nascent. The opportunity is real.
Carrier signals must be treated as first-class credentials rather than metadata. This is the architectural shift the rest of the industry is in the middle of, often without naming it. African operators have been operating this way for years, with the regulatory and commercial scars to prove it works.
The African mobile identity leap was less a leap than the natural result of building identity infrastructure for the credential users actually hold, on the network they actually carry, in a regulatory regime that already names the carrier as the registrar. The rest of the industry is catching up.
---
PasskeyBridge consumes CAMARA-standardized carrier signals from Orange, MTN, Vodacom, Safaricom and global Tier-1 operators, fuses them with device-bound passkey assertions and Verifiable Credential evidence, and emits PQC-signed composite trust decisions inside the request. For the architectural backplane, see our work on carrier signal fusion, edge-first verification, and SIM-signal cross-referencing with Verifiable Credentials. Developer-facing documentation lives at docs.passkeybridge.io.