Trust asked before it was earned.
A background-verification platform asks new hires to hand over their PAN, credit history, and five years of address history — before ever explaining why. This is an audit, redesign, and 90-day plan for fixing that.
A routine form, carrying the weight of a job offer.
TrustLayer is a background-verification platform used by enterprise clients to onboard new hires. When a company initiates a background check (BGV) for a candidate, the candidate receives a link and completes their KYC independently — no recruiter in the room, no one to ask questions.
This is a high-stakes moment disguised as a routine form. The candidate is anxious about a job offer that hasn't closed yet. The data being collected — PAN, salary history, credit pull, police and court records — is some of the most sensitive information a person will hand over online. And every incomplete submission isn't just a UX metric — it's a missed SLA with the hiring company and a delayed offer for the candidate.
Strip away the KYC labels and this is an 11-step conversion funnel — every screen a chance to lose a candidate who was ready to accept the job. The audit and redesign that follow use the same lens a CRO team would: where does the funnel leak, which step accounts for the most loss, and what's the smallest change with the biggest recovery.
I was given 15 screenshots covering the complete candidate journey across 11 steps: Welcome, LOA signing, Personal Details, Identity Details, Address Details, Address Interim, Education, Employment, References, CIBIL (with OTP), Police Verification, Court Verification, Global Database, and Submission Confirmation.
Three deliverables. 72 hours.
- UX Audit — structured findings covering abandonment risk, unexpected or alarming asks, cognitive load, missing reassurance, consistency problems, and copy issues. Prioritized, not a flat list.
- Redesign — pick the one section with the highest friction, redesign it for desktop. Show the thinking — low-fi exploration, decisions, rationale — not just a polished final screen.
- 90-Day Strategy Note — a Design Lead's first-90-days plan for owning this flow: what to measure, who to talk to, what to fix first, what success looks like.
Evaluation criteria were explicit: problem framing, prioritization judgment, whether the redesign actually solves the audited problem — not just looks cleaner — and strategic thinking.
Read it once as a candidate would. Then again as a designer.
I read the flow start to finish, no notes, timing myself. Then I went back screen by screen with one question at each step: if I were moderately anxious about this job offer and had limited time, what would make me stop here?
I tagged every friction point against six lenses — abandonment risk, unexpected or alarming asks, cognitive load, missing reassurance, consistency, and copy — then grouped what surfaced into tiers by how much each one actually moves the outcome, not by how easy each was to fix.
Trust asked before earned. Scope disclosed too late.
Four different brand names appear across the flow with no explanation of who holds the data. The full scope of what's being collected — PAN, CIBIL pull, five years of address history, salary, four reference contacts — is never disclosed upfront; candidates discover it one step at a time. "Police Verification" and "Court Verification" appear as step labels from step one, with zero context, reading as suspicion rather than routine process.
None of these are visual problems. They're sequencing and disclosure problems — the flow asks for sensitive data before it has told the candidate who's asking, why, or what happens to it.
14 findings. 3 tiers.
Not a flat list — ranked by how much each one actually moves abandonment, not by how easy each was to fix.
Brand identity crisis
Four brand names appear with no explanation. Candidates don't know who holds their data.
Scope shock — full ask never disclosed upfront
Welcome says "submit related information." Candidates discover PAN, CIBIL, police check, 5-year address history, salary, and 4 references only step-by-step. Likely moves completion rate by 15–20%.
CIBIL credit pull — biggest abandonment cliff
Treated as a routine field entry with no soft-pull reassurance, no "why we need this." An OTP modal adds friction at the highest-anxiety moment.
"Police" & "Court Verification" labels cause panic
Visible from step one with zero context. Reads as suspicion of wrongdoing; qualified candidates self-disqualify out of fear.
No save & resume for a 30–45 min form
No autosave indicator. Every interruption becomes an abandonment risk — multi-session completion is the norm for forms this size.
"Address Interim": broken IA + misspelling
Two address steps presented as separate, without warning. Candidates believe address is done after step 3, then hit step 4 with a 5-year history requirement.
LOA modal: wall of legal text, no plain-language summary
Sensitive terms buried in dense paragraphs. The signature box has no instructions.
11-step stepper with no grouping, %, or time estimate
Unexplained status icons appear before any interaction has happened.
Salary disclosure — invasive, unjustified mandatory field
BGV verifies dates and designation, not pay. Combined with 4 verifier contacts per employer, this is the most data-heavy section with the least justification.
Mandatory 2-record minimum breaks for real candidates
Freshers must duplicate entries; candidates with 4+ employers can't add enough records.
Verifier rejection comments shown without context
Candidate sees a name, a "Reject" badge, and a comment mid-form with no framing for what to do next.
Copy & labelling errors throughout
Inconsistent capitalization, awkward phrasing. Signals no copy audit has been done.
Pincode doesn't auto-populate city/state
Address fields repeat across 9 steps. A free pincode API would remove this friction almost everywhere at once.
Confirmation screen gives no next-step clarity
No timeline, no support contact, no download. Candidate finishes 45 minutes of disclosure and gets silence in return.
Why Welcome + LOA — over every other step
Fixing individual steps treats symptoms. The Welcome screen and LOA are the only two moments in the entire flow that happen before any sensitive data is collected — the only place where trust can be built proactively instead of repaired after the fact. This single redesign addresses F1, F2, and F4 simultaneously: brand confusion, scope shock, and the panic caused by scary-sounding labels. Everything downstream — CIBIL anxiety, police/court dread, mid-flow abandonment — is easier to solve once the candidate has already decided, on page one, that this process is legitimate and worth their time.
Three structural approaches. Two rejected on paper.
Before touching high-fidelity screens, I sketched three ways the Welcome + LOA experience could work.
Concept 1 — Linear walkthrough
RejectedThree swipeable screens before the LOA: Hi → What we check → Time. Modeled on consumer-app onboarding tutorials.
Why it didn't work: works for apps like Instagram or Spotify, where tapping through onboarding for a low-stakes experience is fine. This is a 25-minute, high-stakes form for someone joining a job. Forcing three intro screens before the candidate can even start feels disrespectful of their time — people who came prepared just want to begin.
Concept 2 — Single long page
RejectedEverything on one scrollable page: context, scope, documents, LOA, signature. Scroll to sign.
Why it didn't work: sketching it out revealed the page was doing two unrelated jobs at once. The top half builds trust; the bottom half asks for legal consent. When both jobs share one page, neither gets enough space — the candidate either skims past the context to reach the sign button, or gets lost in legal text and forgets the reassurance meant to calm them.
Concept 3 — Two-screen split
SelectedWelcome (full context, scope, documents) → Consent (plain-language LOA + signature). Each screen does exactly one job.
Why this one: screen one is purely about building trust — no legal text, no signature pressure. Screen two is purely about consent — plain language, a deliberate signature moment. Yes, it's one extra click compared to Concept 2. But that click is the right kind of friction. Signing should feel like a moment you choose, not a button you bump into at the bottom of a page.
The Welcome screen
From a single blind paragraph to a full trust brief — before a single byte of sensitive data is asked for.
- Who's involved & what they do — a three-step trust chain, spelled out before any data is asked for: the employer requested the check → TrustLayer runs it → you submit details. One sentence underneath states plainly that data is collected only for this verification and isn't sold or repurposed.
- Three at-a-glance stats — time needed (~25 min), what you'll need (PAN + 3 docs), and confirmation that sessions can be saved and resumed.
- Full scope, upfront — all 6 sections listed with time estimates each, each with a one-line plain-English explanation of why it's being asked.
- "Have these ready before starting" — a document checklist, so candidates aren't scrambling for Aadhaar or salary slips mid-flow.
- "How your data is protected" — encrypted end-to-end, used only for this verification, right to decline.
Every element on this screen maps back to a Tier 1 finding — nothing here is decorative.
The Consent / LOA screen
From a wall of legal text to a six-point plain-language summary — with the full legal text still there for anyone who wants it.
- "In plain language" panel — the LOA reduced to 6 numbered points a candidate can read in under a minute, including a clear note that the CIBIL pull is soft and won't affect their credit score.
- Full legal text still present — collapsed under "Read the full legal authorisation," accessible without being the first thing a candidate has to parse.
- A visible decline path — stated plainly, not buried. Counterintuitively, showing the exit clearly builds more trust than hiding it.
- Signature panel — name, date, place, and who the verification is for, pre-filled and clearly separated from legal content, with draw / type / upload options.
What each finding drove
| Finding | What changed |
|---|---|
| F1 | Single consistent brand identity; trust-chain card explicitly names who's involved and what each party does |
| F2 | Full 6-section scope + time-per-section shown before the flow begins, not discovered mid-flow |
| F4 | Reframed as "Address-based checks" with a plain-English explanation, removing alarming standalone labels from the first screen |
| F5 | Explicitly stated as a stat on the Welcome screen, before any data entry — not discovered only after losing progress |
| F7 | Plain-language summary leads; full legal text present but collapsed, not the default view |
F3 (CIBIL panic) and F6 (Address Interim IA) sit downstream of this screen and are addressed structurally in the 90-day plan, since fixing them fully requires touching later steps outside this assignment's scope.
If I owned this flow past the deliverable
The KYC flow has been built like a back-office form. Treat it like a customer-facing product. The audit found 14 problems — fixing them is the easy part. The harder part is making sure the team never ships another screen without asking what the candidate actually needs.
Understand before fixing
Turn the audit's educated guesses into facts. Six numbers on a weekly dashboard: step-level drop-off, time to complete, multi-session resumption rate, verification rejection reasons, support ticket categories, client-side SLA breach rate. That dashboard is the funnel report — it tells us which step to fix first, and gives the team hypotheses worth testing rather than opinions worth debating. In parallel — 5 completers, 5 non-completers, 3 ops team members, 2 enterprise clients, all behavioural questions, not opinion questions.
Fix what hurts most, first
Three "Fix Now" items: Welcome + LOA redesign, visible save state across all steps, and a one-sentence CIBIL explainer. Three deliberately deferred: visual rebrand, mobile-first redesign, and a from-scratch design system — all lower-leverage until structural fixes are proven.
Build the system
A continuous voice-of-candidate research cadence, design system foundations built from what actually shipped, and a weekly design review anchored to evidence, not taste. One additional flow redesign — proof the team can ship without the Lead personally driving every screen.
These are the goals I'd set going in, not numbers I've measured — nothing here has shipped yet.
Candidate completion rate improves measurably against the Day-30 baseline established in Phase 1
Welcome→CIBIL and CIBIL→Submission are the two biggest hypothesised leak points — first candidates for step-level CVR tracking once baselined
Candidates finish faster once they trust and understand what's coming — direction to prove, not a fixed number
Research and design rituals running without being chased
What I'd push further
This assignment asked for more than a redesign — it asked whether I could think like someone who'd own this problem past the deliverable. The hardest part wasn't the audit or the screens; it was resisting the pull to jump straight into "fix now" mode and instead write a 90-day plan that starts with measuring, not shipping.
If I revisited this today, I'd push the redesign one layer further — the CIBIL step (F3) is the single biggest abandonment cliff in the whole flow, and it didn't make it into this round's scope. It's first on the list in the 90-day plan for a reason.
This assignment was accepted, and I advanced to the final round of interviews. I didn't get the offer. I'm sharing this work as a design challenge — not a shipped product, not a client engagement — because the thinking behind it is the part I stand by regardless of the outcome.
I make data-heavy decisions clear and trustworthy.
I'm Ankur Bhatt — a product designer with 13 years across logistics, pricing, and AI-driven B2B tools. Today I'm Senior Product Designer at Shipway, designing the courier-intelligence, failed-delivery, and support tools that 3,000+ D2C brands lean on under pressure.
I started in graphics, moved through web and three years of production frontend, then into product — so I read a decision from four sides at once: what to build, how it's built, what's right for the user, and what the business needs. That's what lets me turn dense, high-stakes screens into decisions people trust.
If you're building something data-heavy and want it to feel clear — let's talk.
Open to Senior / Lead Product Design roles — Delhi NCR, Remote, or Hybrid.