SardineCon SF/2026

Learn More

What is Identity verification (IDV)?

SUBSCRIBE

Identity verification confirms a claimed identity is real and that the person presenting it is its rightful owner, usually by combining document, biometric, and data checks. It is the gate that keeps fake and stolen identities out at onboarding, so getting its strength right sets the tone for everything downstream.

What is identity verification, in plain English?

Identity verification, usually shortened to IDV, answers two questions at once: is this a real identity, and is the person presenting it its rightful owner. It does that by combining checks, typically a document to prove the identity is genuine, a biometric like a selfie with liveness to tie it to a live person, and data checks against authoritative sources to confirm the details line up.

It is the gate at onboarding. Get it right and fake and stolen identities are stopped before they ever fund an account or move money; get it wrong and everything downstream inherits the problem. The important framing is that IDV is not one check but a stack, tuned to the risk of what the customer is about to do.

In fraud and AML, IDV is where two separate failure modes have to be handled: a made-up or synthetic identity that does not correspond to a real person, and a real identity used by an impostor. They need different controls, so treating them as one problem is where a lot of onboarding fraud gets through.

Two failure modes, two controls

What changes

Synthetic identity

Impostor on a real identity

The problem

The identity is fabricated or stitched together.

The identity is real but stolen.

What catches it

Data and document checks, entity resolution.

Face match with liveness.

The tell

Details that do not cohere or lack history.

A selfie that does not match the ID photo.

If you skip it

Synthetic accounts onboard and age.

Takeover and impostor accounts pass.

Who is involved?

Who

Their role

The applicant

Presents an identity to be confirmed as real and their own.

The IDV vendor

Runs the document, biometric, and data checks and returns a combined result.

The risk owner

Matches the depth of verification to the risk of the product and action.

The fraudster

Brings either a synthetic identity or a real, stolen one to slip through the gate.

What it looks like in practice

In practice

A fintech offers a basic wallet and a high-limit credit line. For the wallet it runs a light data check, which keeps friction low and conversion high. For the credit line it steps up to a document, a live selfie, and source checks, because the risk is far higher.

A synthetic identity, real number and fabricated name, clears the light wallet check but fails the credit-line step when the details do not cohere and there is no genuine face behind them. Meanwhile an impostor with a stolen but real passport passes the document check yet fails the face match. Two different attacks, each stopped by the control matched to it.

Why it matters to operators

IDV is the single decision that shapes your whole fraud picture. Everything downstream, from transaction monitoring to takeover defense, is easier when the front door is sound and harder when it is not. The two failure modes need different controls, so a flow that only checks documents will miss impostors, and one that only checks faces will miss synthetics.

The other half of the craft is calibration. Over-verifying adds friction and drives good customers away; under-verifying opens the door to takeover and synthetic onboarding. The answer is not one setting for everyone but matching the checks to the risk, so a low-risk action stays smooth while a high-risk one earns a stronger gate.

What to watch in the data

  • Document without biometric. A genuine document that never faced a live selfie leaves the impostor path wide open.
  • Incoherent details. A real identifier paired with a name or history that does not fit points to a synthetic identity.
  • Risk-value mismatch. A high-value product cleared on a light check is under-verified for the exposure it carries.
  • Friction-driven drop-off. Good customers abandoning at verification can mean the gate is heavier than the risk requires.
  • Reused verification evidence. The same document or selfie appearing across accounts signals reuse rather than genuine new customers.

Quick questions

What are the two failure modes IDV must handle?

A synthetic or made-up identity that does not correspond to a real person, and a real identity used by an impostor. They need different controls, so a strong IDV flow covers both rather than assuming one.

Is IDV the same as KYC?

They overlap but are not identical. KYC is the broader regulatory obligation to know your customer, including ongoing checks. IDV is the specific act of confirming an identity is real and belongs to the person presenting it, often the first step of KYC.

Why not just verify everyone to the maximum?

Because over-verifying adds friction that drives good customers away. The goal is to match the depth of checks to the risk, keeping low-risk actions smooth while reserving stronger verification for high-risk or high-value ones.

What makes an IDV flow strong?

Layering document, biometric, and data checks so both failure modes are covered, tying the identity to a live person, and calibrating depth to risk. A single-signal flow leaves one door open for fraudsters to walk through.

Does IDV stop account takeover?

It helps at onboarding by tying the identity to its owner, but takeover happens later at login. Defending against it also needs authentication controls and monitoring, since a genuine account can still be seized after a clean IDV pass.

Go deeper

  • NIST Digital Identity Guidelines (SP 800-63) ↗ — The US standard for identity proofing and authentication assurance levels.
  • FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.

What to know alongside Identity verification (IDV)