Skip to content
Moataz Mustapha
Objective
Chapter 1 of 2

Take a business account application that already worked on the web and make it work on mobile. A company should be able to complete onboarding in about ten minutes, with owners anywhere, and without a bank employee ever meeting anyone.

Context

NEO BIZ was a new product when I joined. The original journey served companies with layered ownership structures, companies owning companies, and verification happened the traditional way: a Relationship Manager visited the partners, or the partners came to a branch.

Then the bank decided to build NEO BIZ Express: a faster journey for the simpler case, companies owned by individuals. That journey was designed and shipped on web first. My brief was to bring it to mobile. I owned that end to end, as sole designer, including the customer portal that shipped alongside it. On mobile the two are one: customers apply and track their application from the same app.

A note on naming: the product is NEO BIZ Express on web and NEO BIZ Mobile on the app; the original layered-ownership journey remains a separate web product. A merge of the two systems is coming.

And the ground here is completely different from Egypt.

In the UAE, an Emirates ID does not need a human to verify it. The bank checks it against the official government gateway it is connected to: valid or not, expired or not. Sighting an original document in person is simply not a problem this journey has to solve.

So the constraint moved somewhere else. Dubai is largely expatriate, which means the bank needs more than the ID: it needs the passport, and it needed the visa. That is the problem this journey actually solves.

A consent sheet raised over a dimmed screen, headed "Consent for identity verification", stating that the bank may collect, store and share the customer's facial data with approved third-party providers including Emirates Face Recognition L.L.C, with an Accept and submit button beneath it
Consent, asked before anything is retrieved. The face is checked so the passport does not have to be uploaded.
Screen headed "Identity verification couldn't be completed", followed by the line "That's okay, you can still upload the required documents and continue with your application", a face-scan illustration overlaid with a dark red cross, and a single Continue button at the foot
A dead end, drawn as a step. Below the red cross there is one button, and it does not say try again.
Screen headed with the requirement to verify the key individual's identity using electronic Emirates Facial Recognition, an amber notice that the verification link has been generated and stays valid for a set number of hours, and two option cards beneath it: facial recognition on this device, or an email verification link sent to the key individual so they can complete recognition and sign remotely
Two ways to reach the same person: hand them the phone, or send the link. The second one is the decision — the person no longer has to be in the room.
Key individuals list under a green confirmation that the identity verification link has been sent, holding two entries: an Owner marked Verified with a green tick, and a PoA marked Verification initiated with the hours and minutes remaining. Confirm and continue is greyed out
One applicant, two people who have to sign. The second one's state sits in the list — initiated, counting down, and nowhere near a branch.
Account application dashboard headed "Complete all sections to submit", with five stacked cards: Business plan Lite and Company details both marked Completed, Ownership details open and highlighted with a Continue button and a note that it needs an Emirates ID and a passport for non-UAE residents, then Financial details and Regulatory declaration greyed out
The stepper, taken apart. Five cards, each carrying its own state, and the one still open says what it will ask for before it is opened.
Registration step asking for the company's ownership structure, with two illustrated cards side by side, Single owner and Partnership, and the progress bar near the start of the journey
One tap, two journeys. The question is asked once, at registration, and every section after it is shaped by the answer.

Decision

Face recognition as a data shortcut, not a security gate

Emirates Face Recognition (EFR) is the mechanism. The customer uploads their Emirates ID and verifies against their own face; with their explicit consent, the bank retrieves the rest — passport and supporting details — automatically. This is worth naming precisely, because it is usually misread. EFR here is not a security checkpoint bolted onto the journey. It is a way to avoid asking the customer to upload documents they shouldn't have to upload. The identity check is already handled by the government gateway; EFR is what stops the customer from typing and scanning. Two things follow from that framing. The failure path is trivial by design. Liveness fails most often for ordinary reasons like glasses or poor lighting. So there are instructions before the attempt, and live guidance during it (move somewhere brighter). After three attempts, the journey stops trying: the customer uploads their passport and continues exactly as if EFR had succeeded. No slower queue, no manual review, no handoff to a human. Three tries with help, then a door, not a rejection. And the visa requirement was removed entirely. It was in the original scope. It came out once it was established that the passport alone confirms visa validity. A required document deleted is worth more than any screen improvement.

Decision

Remote verification, so nobody has to travel

This is the decision I am proudest of in this journey, and it was mine. The Express journey had a structural gap that survived into the mobile build: one person applies, but every Key Individual must verify and sign. On web that gap was still being closed the old way — by a Relationship Manager. I noticed it while working on mobile. So I proposed pushing verification to the person instead of asking that person to come in. The applicant generates a link; each Key Individual receives it, completes their own liveness check, and signs from wherever they are. This took the in-person meeting out of the journey, which was the point. The Relationship Manager still owns the relationship and still advises the customer. What went away was the appointment that had to be arranged around several people's calendars and locations before an account could move. Key Individual is the bank's unified term, chosen by the business and CX teams, and it covers two roles: Owner and PoA, the authorised signatory. Both must verify. Both do it remotely. And I lost half of this argument. I proposed the native share sheet: it's a phone, so send the link by WhatsApp, by message, by anything the person actually uses. Stakeholders liked the mechanism but not the channel. Communication had to stay official, so email. I still see no problem with share, and it is the first thing I would change.

Decision

The dashboard, and the two paths

The web journey is a stepper with four modules: Company, Ownership, Financial, Regulatory. On mobile it became a task dashboard: each module a card with its own state, business plan first. This is the pattern I later carried into the Egypt mobile design. It started here. Sole proprietorship and partnership run as two full paths, and the difference is not the product, it's the questions. In the regulatory section, "are you…?" becomes "is any of the partners…?", and a yes opens the details of that specific partner. Same screens, different interrogation. And where the journey can't serve you, it redirects rather than rejects. NEO BIZ Mobile covers companies owned by individuals. If an applicant declares that one of the owners is itself a company, which is layered ownership, the app doesn't say you are not eligible. It sends them to the web journey built for that structure. They can still return to the app afterwards to track that application and act on it. Only account opening for that case is absent from mobile, not the relationship.

Tracking and exceptions

NEO BIZ dashboard carrying the application number and creation date, a red banner reading "5 exceptions raised, please resolve the exceptions to continue processing your application", and an application status list of five stages with Application submitted complete and Document check in progress
Five stages, and what is holding them up named above them. The exceptions are not a verdict on the application, they are the list of what is still being asked.

The customer portal lives inside the same app: track the application through its stages, see pending and submitted queries, open an exception and answer it. Upload a memorandum of association, respond to a buyer declaration, replace a file that came back too large. Withdrawal is here too, with reasons and a confirmation.

An exception here is a structured, answerable question rather than a rejection, and it arrives on the same device that made the application.

The argument I lost, in two countries

I proposed cutting the regulatory section down — screening questions that would let the overwhelming majority skip what doesn't apply to them.

Regulatory declaration screen, Sanction declaration Question 1, asking whether any of the entity's connected parties, meaning shareholders, signatories, subsidiaries, affiliates or branch, are currently targeted by sanctions administered by the UN, EU, UKHMT, OFAC or the UAE regulatory authorities, with Yes and No as the only two answers and Continue greyed out below
The first of the sanction questions. Seven lines of question and two buttons of answer — and the screening I proposed would have let most applicants past the whole section without reading one of them.

I lost that argument in the UAE, and I lost the same argument in Egypt.

What did change came from elsewhere: the bank's own regulatory requirements were revised, and FATCA questions were reduced. But reduction wasn't improvement. Fewer questions carrying the same weight in the same language don't make the section easier, and my observation was that the experience didn't measurably improve. The change served compliance, not comprehension.

Sanctions and FATCA get revised periodically across the bank; several versions in the design file are that, not post-launch redesigns.

I don't cite drop-off figures for this section. I didn't measure them and I don't own that instrumentation, so they aren't mine to claim.

Result

Live in production for more than a year and a half.

ClaimBasis
~10 minutes to complete an applicationReal, observed journey time in production; up to 25–30 minutes for complex cases with many partners
Under one business day to open the account, sometimes same dayObserved production behaviour rather than a target. The app has been live for over a year and a half
Thousands of new business accounts achieved through the digital journeyThe figure covers web and mobile together, so no single number is attributed to mobile alone

And the comparison that matters most is with the sibling case file.

Egypt and the UAE had the same regulatory requirement: every qualifying owner must be verified and must sign. Egypt has no verifiable digital identity, so that requirement produced six systems and a dedicated field team travelling with a tablet. The UAE has the infrastructure, so the same requirement produced a link in an inbox.

Same designer, same requirement, two outcomes that look nothing alike. The difference isn't design ambition, it's what the country's identity infrastructure will let a design assume.

What I'd change

Send the verification link through anything. Native share: WhatsApp, messages, email, whatever that person actually opens. It's a phone. The official-channel argument won; I'd reopen it.

UAE Pass. It was rejected on cost, because it charges per interaction. But for the customer it removes the upload entirely: no ID capture, no document handling, nothing. From a pure experience standpoint it is the strongest option available in this market, and cost is the only reason it isn't in the journey.

And the regulatory section, again. I'd make the same proposal I've now made twice.