Document verification

Deciding whether an identity document is authentic and whether anyone modified it. What gets looked at in practice, how a document is forged, and why this check, alone, doesn't verify anyone.

In short

Document verification is the check that an identity document is genuine, current, and hasn't been altered. It relies on three things that get cross-checked against each other: the security features the issuer built into the document, the data the document holds in its different readable zones, and the signals that the captured image corresponds to a physical document and not a reproduction. It answers a single question, and it's important to know which one: whether the document is real, not whether it belongs to whoever is presenting it.

What a document verification looks at

An identity document holds the same information in several different places, and that redundancy is what allows an alteration to be detected.

  • Issuer security features — microprinting, security inks and backgrounds, holograms, die-cutting, and other resources the issuer built in that a home-made reproduction doesn't reproduce well.
  • Machine-readable zone — the MRZ, with its check digits. A modified data point in the visual part stops matching what the MRZ encodes.
  • Two-dimensional barcodes — the PDF417 carried by many documents in the region, which repeats the holder's data in encoded form.
  • NFC chip — when the document has one, it holds the data signed by the issuer. It's the strongest check available, because the signature is validated against the issuer, not against the look of the plastic.
  • Front-and-back cross-check — that both sides belong to the same document and say the same thing.
  • Reproduction and alteration signals — cut edges, screen moiré, reprinting, digital retouching over the photo or the fields.

The logic of the control is to cross-check each source against the others. Changing a piece of data on the visible face is easy; changing it consistently in the MRZ, the barcode, and the signed chip is not.

The three ways of presenting a document that doesn't match

The three cases are detected with different controls, and calling all of them "fake document" hides the problem.

  • Genuine document belonging to someone else — the document is authentic and passes any document control, because there's nothing wrong with it. The only thing that catches it is comparing the face and checking presence.
  • Genuine altered document — a real document whose photo, date of birth, or number was modified. It's what the cross-checks between zones look for.
  • Completely fake document — a reproduction built from scratch, of varying quality. It fails on security features and lack of internal consistency.

A fourth variant adds to those three, and it's about capture, not the document: a photograph of a photograph. A screen showing an authentic document looks, in the image, very similar to the real document.

Verifying the document is not verifying the person

It's the costliest confusion around the term, because it's the one that leaves incomplete processes feeling resolved.

An authentic document proves that a legitimate issuance with that data exists. It doesn't prove that whoever is presenting it is its holder. The question of who it belongs to is answered by the biometric comparison, and the question of whether a real person is presenting it is answered by liveness detection.

  • Document verification — the document is genuine and hasn't been altered.
  • Biometric match — the face of whoever is presenting themselves is the one on the document.
  • Liveness detection — there's a real person in front of the camera at that moment.

A process with flawless document verification and without the other two approves the actual holder and whoever found their document with equal ease. And against a deepfake, the authentic document offers no resistance: the attack doesn't touch the document, it touches the face.

The real difficulty is in coverage, not in the algorithm

Explaining how a document is read is the easy part. What decides whether a provider works in a country is something else.

Every identity document has versions: different issuances coexist on the street for years, they change format, add security features, move fields around. Each of those versions is a different template that has to be supported. A country isn't covered because a provider "supports" that country; it's covered when it supports the issuances people actually carry.

The practical consequence for whoever is evaluating: the useful question isn't how many countries a provider covers, but which documents and which issuances it covers in the countries where your operation will be, and what happens when an issuance shows up that it doesn't recognize.

How VU solves document verification

VU's capability for identity verification and biometric onboarding is Verify. It reads the document on both sides, cross-checks the readable zones against each other, compares the face on the document against the person's, and checks presence, all within the same flow.

The liveness detection applied in that flow is certified by iBeta at Level 2 of its testing program, which applies the ISO/IEC 30107-3 standard's methodology to evaluate presentation attack detection. That certification measures the presence control, not the document reading; they're two different checks and it's worth not crediting one with the other's backing.

Frequently asked questions

It's the check that an identity document is genuine, current, and hasn't been altered. It's done by cross-checking the different sources of information the document holds against each other: the visual part, the machine-readable zone, the barcode, and, when it exists, the chip with the data signed by the issuer, plus the security features the issuer built in. It answers whether the document is real, not whether it belongs to whoever is presenting it.

By inconsistency. An identity document repeats the holder's data in several places, and whoever modifies the visible data almost never manages to modify it consistently in the MRZ, the barcode, and the chip. Added to that are the signals of manipulation on the image itself: retouching over the photo or the fields, cut edges, reprinting, and the pattern a screen leaves when what was photographed wasn't the document but its reproduction.

No. An authentic document proves that a legitimate issuance with that data exists, not that whoever is presenting it is its holder. Two more checks are needed: comparing the person's face against the one on the document, and confirming with liveness detection that there's someone real in front of the camera. Without them, a genuine document that was lost or stolen works perfectly for whoever found it.

It works much less than it seems. An image sent through any channel has lost the context of the capture: there's no way to know when it was taken, with what, or whether what was in front of the lens was a document or a screen. Capture within the flow itself, with camera control and verification at the same moment, is what makes the rest of the process verifiable.

One identity, one SDK

VU ONE brings identity verification, authentication and fraud protection together on a single identity graph.

The verification you run at signup stays available to authentication and to your fraud rules, with no repeated processes and no duplicated data.

Verify, Authenticate and Protect, consolidated in one place.

Request a demo