Glossary
Identity verification (IDV) is the process of confirming that a person is who they claim to be, typically by checking a government-issued ID document and matching it to a live selfie of the person presenting it. It’s how a business establishes, at onboarding, that a real and specific human is behind a new account: before granting access, opening an account, or extending credit.
IDV answers a different question than authentication. Authentication confirms a returning user is the same person who set up the account; verification establishes who that person is in the first place. Get verification wrong and everything downstream is protecting an account that never should have existed.
A typical IDV flow runs in seconds on a phone:
For regulated institutions, IDV is both a compliance requirement and a fraud control. It underpins KYC and AML obligations, and it’s the front line against new-account fraud and synthetic identities, the fabricated or stolen identities used to open fraudulent accounts. The tension is familiar: verification has to be rigorous enough to stop fraud yet smooth enough not to sink onboarding conversion.
Modern IDV is AI-driven and built for both accuracy and experience. Transmit Security’s Identity Verification, for example, supports 10,000+ ID document templates, analyzes 150+ features (biometrics, NFC chips, machine-readable zones, barcodes), uses guided capture to reach roughly a 90% first-attempt pass rate, and includes deepfake detection, covering digital and in-person verification and automating KYC/AML. The strategic advantage comes when IDV isn’t a standalone step but feeds the same platform as authentication and fraud detection, so a verification outcome informs later risk decisions across the customer lifecycle.
Onboarding is the obvious use case, but IDV increasingly shows up across the lifecycle. It’s used to re-establish identity during high-risk account recovery, a far stronger approach than knowledge-based questions an attacker can look up. It gates high-value or unusual actions, where a fresh biometric check against the enrolled identity confirms the person before a large transfer or a sensitive change. And it supports step-up verification whenever risk signals suggest the account may not be in the right hands. Treating verification as something you can invoke at any point, not just at signup, is what makes it a lifecycle control rather than a one-time gate.
The biggest shift in IDV is the attack side. Generative AI has made convincing fake faces and documents cheap, and attackers increasingly use injection attacks, feeding synthetic video directly into the capture pipeline to bypass the camera entirely. This has moved the bar from "can we read this document and match this face?" to "can we prove this is a genuine, live capture of a real person and an authentic document, not an AI-generated forgery?" Modern IDV answers that with strong liveness and presentation-attack detection, deepfake detection, and analysis of many document features, which is why the depth of a provider’s anti-spoofing now largely determines its real-world security.
The perennial tension in IDV is rigor against drop-off. Every added step and every failed capture costs completions, and onboarding abandonment is often the single biggest metric a digital leader watches. The resolution is twofold: make the verification itself smooth (guided capture that helps users get a usable image on the first attempt lifts pass rates dramatically), and apply verification proportionately through a risk-based flow, escalating to a full check only when signals warrant. Done well, IDV can raise both assurance and conversion at once, the opposite of the trade-off it’s often assumed to be.
What does IDV stand for?
Identity verification.
What’s the difference between identity verification and authentication?
Verification establishes who a person is (usually at onboarding); authentication confirms a returning user is that same person.
What documents are used for identity verification?
Government-issued IDs such as passports, driver’s licenses, and national ID cards.
How does IDV prevent fraud?
By confirming a real, specific person is behind a new account, blocking synthetic identities and new-account fraud.
Can identity verification be used after onboarding?
Yes, it’s increasingly used for high-risk account recovery, sensitive actions, and step-up verification across the lifecycle, not just at signup.
How does IDV handle deepfakes?
Through liveness and presentation-attack detection, deepfake detection, and injection-attack defenses that confirm a genuine, live capture rather than synthetic media.
Related: Identity Proofing · Document Verification · Liveness Detection · Know Your Customer (KYC) · Synthetic Identity Fraud · Digital Onboarding