Consumer Identity and Access Management (CIAM) is growing within IAM due to accelerating digital transformation, rising expectations for smooth and secure digital experiences, and expanding regulations around consumer data protection. The pandemic intensified digitization even in historically slower sectors like retail, healthcare, and insurance, raising the stakes: secure, low-friction identity journeys drive repeat engagement and revenue, while frustrating or risky interactions push consumers to competitors. CIAM innovation is concentrated in passwordless authenticators, risk analytics and continuous authentication, fraud detection intelligence, IoT device identity integration, API-centric interoperability, and privacy/consent management.
OneWelcome is an Identity-as-a-Service provider formed by the 2021 merger of iWelcome and Onegini (both founded in 2011, Netherlands). The combined platform targets European market needs, especially regulated industries, and supports deployments at scales of tens of millions of consumer identities per customer. Its offering consists of an IDaaS Core (directory, APIs, federation, SSO) plus modules for Customer Journey orchestration, Delegation & Relations, Consent Management, and Mobile (MFA, app, SDK). It is hosted in EU public-cloud data centers with ISO 27001 and SOC 2 Type 2 certifications, and is licensed per active or registered user over various time periods.
The platform supports white-labeled experiences, social logins, OIDC/OAuth2/SAML federation, bulk provisioning via SCIM, and integration with AD/Azure AD. It has strong coverage of EU eIDs (including eIDAS and multiple national schemes) and integrates with identity proofing providers (e.g., Onfido, iProov, Signicat) to reduce fraud and meet AML/KYC needs. Authentication options include OTP, mobile push/OOB verification, biometrics, QR-based flows, and FIDO support (not certified). Risk-adaptive authentication uses contextual signals and can invoke step-up methods. Consent management is fine-grained and metadata-rich, enabling transparency, traceability, data export/deletion, retention policies, and family management via delegated administration. Strengths center on GDPR-ready consent, relationship management, APIs, and mobile SDK flexibility; challenges include limited FRIP connectors, richer device intelligence collection, non-certified FIDO, and EU-centric go-to-market.
See All Locations
See All Locations