Identity verification

Checking that a person is who they say they are, before granting access or a product. What it checks in practice, how it differs from authentication and KYC, and where the rule requires it.

In short

Identity verification is the set of checks with which an organization establishes that a person is who they say they are. It brings together different things in a single moment: a document that gets validated, a face that gets compared against that document, and a signal that there's a real person in front of the camera. Its result isn't just a yes or a no, but the preserved evidence of how that yes was reached.

What an identity verification checks

Behind the term there are concrete checks, and each one answers a question the others don't.

  • Document authenticity — that the document presented is genuine, corresponds to a real issuance, and hasn't been altered or reproduced.
  • Biometric match — that the face of the person being verified is the same as the one on the document.
  • Presence — that there's a real person at the moment of capture, and not a photograph, a screen, or a generated face.
  • Data consistency — that the declared data matches internally and against the source that issued it, when that lookup is available in the country.
  • Watchlist screening — that the person doesn't appear on watchlists or qualify as a politically exposed person, when the activity requires it.

None replaces the previous one. An authentic document doesn't say who is presenting it. A face that matches the document doesn't say whether anyone is there.

Verifying is not authenticating, and it's not the same as KYC either

The three terms show up mixed together in project conversations and they name different things.

  • Identity verification — establishes for the first time that someone is who they say they are. It happens at sign-up and when something substantial about the relationship changes.
  • Authentication — checks that whoever is coming back is the same person who was verified. It happens at every access.
  • [KYC](/glosario/kyc) — the regulatory obligation to know the customer and keep that information current. Identity verification is the operation that meets that obligation, but not every verification stems from a KYC: a platform that verifies age to comply with its license also verifies identity.

An organization can have strong authentication over an identity it verified poorly. The second factor protects an account. It says nothing about who opened it.

Where identity verification is required

It's not an optional best practice. There are activities where a rule imposes it and sectors that no longer operate without it.

  • Anti-money laundering — the region's regimes require identifying the customer before onboarding them and keeping the evidence. It's the regulatory origin of most of the processes that exist today. In Colombia it's SARLAFT; in Mexico, the anti-money-laundering law.
  • Financial services — account opening, product sign-up, and access recovery.
  • Betting and gaming — age and identity verification as a licensing condition.
  • Background screening — identity accreditation within hiring processes.
  • Government — access to procedures and benefits in one's own name.

A verification is judged by two errors, not one

Every verification system errs in two opposite directions, and improving one worsens the other.

A false rejection leaves out a legitimate person: the document was worn out, the light was bad, the face changed. A false positive lets through someone who shouldn't have gotten in: an altered document that wasn't detected, a face that resembled enough.

Between the two there's a threshold, and that threshold is a business decision before it's a technical one. A bank that opens accounts and a platform that validates age don't carry the same cost per error, and they shouldn't operate with the same configuration.

That's why it's worth distrusting any evaluation that shows a single number. An acceptance rate without its counterpart of rejections doesn't describe the system's behavior — it describes the half that's convenient to show.

How VU solves identity verification

VU's capability for identity verification and biometric onboarding is Verify: it reads the document, compares the face against it, and checks presence within the same flow, without the user having to complete a separate step for each control.

The liveness detection applied in that flow is certified by iBeta at Level 2 of its testing program, which applies the ISO/IEC 30107-3 standard's methodology to evaluate presentation attack detection. It's a measurement made by a third party, not a claim from the provider.

Frequently asked questions

It's the set of checks with which an organization establishes that a person is who they say they are before granting access or a product. In a digital process it brings together three controls that answer different questions: whether the document is authentic, whether the face of whoever is presenting themselves matches the one on the document, and whether there's a real person at the moment of capture. The process also produces the evidence of how the result was reached, which is what later allows it to be audited.

Verification establishes for the first time who someone is and happens at sign-up. Authentication checks that whoever is coming back is the same person who was verified, and it happens at every access. The practical difference is that authentication inherits the quality of the initial verification: a system with flawless two-factor authentication over a poorly verified identity is rigorously protecting an impostor's account.

No. KYC is the regulatory obligation to know the customer and keep that information current; identity verification is one of the operations that meets that obligation. A complete KYC also includes watchlist screening, risk profiling, and periodic data updates. And conversely, there are identity verifications that don't respond to a KYC, like the age validation a gaming license requires.

Yes, and that's exactly the problem digital verification solves. What replaces physical presence isn't trust in the document, but the combination of three checks: that the document is genuine, that the face matches, and that there's a real person in front of the camera at that moment. Without the third one, the process works just as well for the actual holder as for whoever has a photo of them.

One identity, one SDK

VU ONE brings identity verification, authentication and fraud protection together on a single identity graph.

The verification you run at signup stays available to authentication and to your fraud rules, with no repeated processes and no duplicated data.

Verify, Authenticate and Protect, consolidated in one place.

Request a demo