Identity Verification

Identity Verification

Identity Verification

Identity verification is the process of confirming that a person is who they claim to be, using evidence that’s been checked against a reliable, independent source rather than simply taken at face value. What counts as “verified” isn’t one fixed standard. In the US, NIST’s Identity Assurance Levels define three tiers of rigour. In the UK, the Good Practice Guide 45 framework, now on a statutory footing since December 2025, defines a comparable scale.

Key takeaways

  • Identity verification confirms a claimed identity against independent evidence; it’s distinct from identification, which just collects the claim.
  • NIST SP 800-63A defines three US Identity Assurance Levels: IAL1 (unverified), IAL2 (evidence-based), IAL3 (in-person/supervised, biometric mandatory).
  • The UK’s GPG45 framework, Low/Medium/High/Very High confidence, became statutory under the Data (Use and Access) Act 2025, in force since 1 December 2025.
  • No single verification method proves everything; document checks, database checks, and biometrics each confirm a different piece of the puzzle.
  • FATF Recommendation 10’s “reliable, independent source” requirement is exactly what these assurance-level frameworks make concrete and auditable.
  • Identity verification is the second of CDD’s four core elements, and usually the first point fraud actually gets caught.
  • Synthetic identities and deepfake/injection attacks are specifically designed to defeat modern verification methods.

3

Identity Assurance Levels defined by NIST SP 800-63A: IAL1, IAL2, IAL3

Source: NIST

1 Dec 2025

Date the UK’s GPG45/DIATF framework became statutory under the Data (Use and Access) Act 2025

Source: UK Data (Use and Access) Act 2025

What identity verification actually means

Identity verification is the process of confirming that a person is who they claim to be, using evidence checked against a reliable, independent source rather than simply taken at face value. A name and date of birth typed into a form is a claim. Verification is what turns that claim into something a firm can actually rely on.

The term covers a wide range of methods, document checks, biometric matching, database lookups, and increasingly reusable digital identity credentials, but the underlying requirement is consistent across all of them: evidence has to be independently checked, not just collected.

Identification vs verification: a distinction most content skips

Identification and verification get used interchangeably, and that’s a genuine source of confusion. Identification is the act of collecting a claimed identity: a name, a date of birth, an address. Verification is the separate step of confirming that claim is actually true, against evidence the person providing it doesn’t control.

A firm that collects a name and address but never checks either against an independent source has identified a customer, not verified one. Regulatory requirements, under FATF Recommendation 10 and its domestic implementations, specifically require verification, not just identification, which is a distinction worth being precise about.

NIST’s Identity Assurance Levels: the US standard

In the US, the reference standard for how rigorous identity verification needs to be is NIST Special Publication 800-63A, which defines three Identity Assurance Levels. IAL1 involves no identity proofing at all; any attributes a person provides are self-asserted and unverified, the level typical of creating a basic social media account. IAL2 requires evidence supporting the real-world existence of the claimed identity, with the applicant verified as genuinely associated with it, achievable remotely or in person. IAL3 requires physical presence, in person or supervised remotely with specialised equipment, with identifying attributes verified by an authorised, trained representative and biometric comparison mandatory.

Most AML-regulated identity verification for opening a financial account sits at IAL2 or above; IAL1 doesn’t meet the “verification” bar at all.

The UK’s GPG45 framework, and why it just became law

The UK runs a parallel but structurally different framework. Good Practice Guide 45, GPG45, defines identity confidence levels, Low, Medium, High, and Very High, based on the strength and validity of evidence combined and the level of identity verification and fraud checking applied.

Until recently, GPG45 and the wider Digital Identity and Attributes Trust Framework, DIATF, were voluntary guidance. That changed with the Data (Use and Access) Act 2025, which received Royal Assent on 19 June 2025. Its provisions putting the DIATF on a statutory footing came into force on 1 December 2025, and version 1.0 of the framework, introducing the UK’s official CertifID trust mark, was published on 6 March 2026. Identity verification providers previously certified under earlier framework versions had to migrate: all Beta 0.3 certifications expired on 31 March 2026.

The core methods, and what each actually proves

Different verification methods prove different things, and understanding which is important. Document verification confirms a government-issued ID is genuine and internally consistent, checking security features, format, and issuing authority against known standards. Database verification cross-checks claimed identity details, name, date of birth, address, against government, credit bureau, or other authoritative records that exist independently of the document itself. Knowledge-based authentication asks questions only the real person should be able to answer, drawn from historical records, though this method has become significantly less reliable as personal data breaches have made much of that information available to fraudsters. Biometric verification confirms the person presenting the identity is physically the same person the identity document belongs to.

No single method proves everything on its own. A genuine, unaltered document proves the document is real; it doesn’t prove the person holding it is who the document says they are. That’s what biometric matching and liveness detection are specifically for.

Worth knowing. All UK identity verification providers certified under the earlier Beta 0.3 framework had their certifications expire on 31 March 2026. A DIATF certification that was valid a year ago may no longer meet the current statutory standard.

Biometrics and liveness: what they add that documents alone don’t

Biometric verification, typically facial matching between a live selfie and a document photo, adds something document checks alone can’t: confirmation that the person presenting the identity right now is physically the same person the document was issued to. Liveness detection adds a further layer, confirming the face being captured belongs to a real, present person rather than a photo, video replay, or increasingly, an AI-generated deepfake.

This combination has become close to standard for remote onboarding specifically because document verification alone doesn’t address the most basic fraud pattern: someone using a real, unaltered document that simply isn’t theirs.

Why identity verification standards exist at all

Assurance-level frameworks exist because identity verification needs are genuinely different depending on what’s at stake. Opening a basic account with tight transaction limits carries different risk than opening a private banking relationship or accessing government benefits, and applying the same verification intensity to both wastes resources on the low-risk case while potentially under-protecting the high-risk one.

NIST and GPG45 both formalise this logic into defined, auditable tiers specifically so that a firm or regulator can point to a named standard, rather than a subjective sense of “thorough enough,” when explaining why a given verification process was considered adequate for a given use case.

What “reliable, independent source” actually means in AML law

FATF Recommendation 10 requires verifying customer identity using reliable, independent source documents, data, or information, a phrase that shows up in nearly every jurisdiction’s implementing regulation but rarely gets defined precisely. In practice, “reliable and independent” means the source wasn’t provided or controlled by the customer being verified: a government identity document checked against the issuing authority’s own records, rather than simply photographed and accepted at face value.

This is exactly the gap NIST’s IALs and the UK’s GPG45 levels exist to close: turning a vague standard, “reliable, independent source,” into a specific, auditable set of technical and procedural requirements.

Where identity verification fits inside CDD

Identity verification is the second of the four elements that make up customer due diligence: identify the customer, then verify that identity, understand the relationship’s purpose, and monitor ongoing activity. It’s the step where a claimed identity either gets confirmed against real evidence or doesn’t, and it’s usually the first point in an onboarding flow where a fraudulent application actually gets caught, before any funds move.

A CDD programme with weak verification at this stage undermines everything built on top of it: risk scoring, sanctions screening, and ongoing monitoring are all working from a customer identity that was never properly confirmed in the first place.

Fraud that’s specifically designed to beat verification

Fraud specifically designed to defeat identity verification has evolved considerably. Synthetic identities combine real and fabricated information into a persona that doesn’t correspond to any single real person, designed specifically to pass document and database checks that verify pieces of information in isolation rather than the whole identity as a coherent unit. Deepfake and injection attacks target the biometric layer directly, presenting AI-generated or manipulated video specifically to defeat liveness detection rather than fooling a human reviewer.

This is part of why verification standards keep evolving rather than settling on a fixed method: a technique considered sufficiently rigorous a few years ago can be specifically targeted once it becomes the default everyone relies on.

Choosing the right assurance level for the job

Choosing the right assurance level means matching verification rigour to actual risk and consequence, not defaulting to the maximum for everything or the minimum to reduce friction. A firm should be able to state, for any given product or customer segment, which specific assurance level, an IAL tier, a GPG45 confidence level, or an equivalent, it’s targeting, and why that level is appropriate for what’s actually at stake if the verification is wrong.

Frequently asked questions

What is identity verification?

Identity verification is the process of confirming a person is who they claim to be, using evidence checked against a reliable, independent source, distinct from simply collecting a claimed identity without checking it.

What is the difference between identification and verification?

Identification is collecting a claimed identity, a name and date of birth, for example. Verification is the separate step of confirming that claim is actually true against independent evidence.

What are NIST’s Identity Assurance Levels?

NIST SP 800-63A defines three levels: IAL1 (no proofing, self-asserted), IAL2 (evidence-based, remote or in-person), and IAL3 (in-person or supervised remote, with mandatory biometric comparison).

What is GPG45 in the UK?

GPG45 (Good Practice Guide 45) defines UK identity confidence levels, Low, Medium, High, and Very High. It’s now on a statutory footing under the Data (Use and Access) Act 2025, as of 1 December 2025.

What identity verification methods are commonly used?

Document verification, database verification against government or credit bureau records, knowledge-based authentication, and biometric verification with liveness detection, each proving a different aspect of a claimed identity.

Why isn’t document verification alone enough?

A genuine, unaltered document proves the document is real; it doesn’t prove the person presenting it is who the document says they are. Biometric matching and liveness detection close that specific gap.

What does “reliable, independent source” mean under FATF’s standard?

It means the evidence wasn’t provided or controlled by the customer being verified, such as a government document checked against the issuing authority’s own records rather than accepted at face value.

How does identity verification fit into customer due diligence?

It’s the second of CDD’s four core elements: identify the customer, verify that identity, understand the relationship’s purpose, and monitor ongoing activity.

What kind of fraud specifically targets identity verification?

Synthetic identities combine real and fabricated data to pass fragmented checks, while deepfake and injection attacks target the biometric layer directly to defeat liveness detection.

Read more: our ultimate guides, whitepapers and templates

Related guides and resources to help you act on what you just read.

Last reviewed July 19, 2026 · 11 min read · Written for compliance and risk professionals · By the WhoWiki editorial team

Key takeaway: Identity verification is the process of confirming that a person is who they claim to be, using evidence that’s been checked against a reliable, independent source rather than simply taken at face value. What counts as “verified” isn’t one fixed standard. In the US, NIST’s Identity Assurance Levels define three tiers of rigour. In the UK, the Good Practice Guide 45 framework, now on a statutory footing since December 2025, defines a comparable scale.

Learn & stay current

A compliance reference that keeps up with the regulators

Plain-English explainers, country rules, and data you can cite, updated as the landscape moves.

Comparing tools before you commit?

See how WhoWiki lines up against the platforms you already know, and which free tools fit which job.

See how current your screening could be

Book a walkthrough with our team, or start with the tools today. No account needed to run your first check.