Identity Verification
Identity verification is the process of confirming that a person is who they claim to be, using evidence that’s been checked against a reliable, independent source rather than simply taken at face value. What counts as “verified” isn’t one fixed standard. In the US, NIST’s Identity Assurance Levels define three tiers of rigour. In the UK, the Good Practice Guide 45 framework, now on a statutory footing since December 2025, defines a comparable scale.
Key takeaways
- Identity verification confirms a claimed identity against independent evidence; it’s distinct from identification, which just collects the claim.
- NIST SP 800-63A defines three US Identity Assurance Levels: IAL1 (unverified), IAL2 (evidence-based), IAL3 (in-person/supervised, biometric mandatory).
- The UK’s GPG45 framework, Low/Medium/High/Very High confidence, became statutory under the Data (Use and Access) Act 2025, in force since 1 December 2025.
- No single verification method proves everything; document checks, database checks, and biometrics each confirm a different piece of the puzzle.
- FATF Recommendation 10’s “reliable, independent source” requirement is exactly what these assurance-level frameworks make concrete and auditable.
- Identity verification is the second of CDD’s four core elements, and usually the first point fraud actually gets caught.
- Synthetic identities and deepfake/injection attacks are specifically designed to defeat modern verification methods.
On this page
What identity verification actually meansIdentification vs verification: a distinction most content skipsNIST’s Identity Assurance Levels: the US standardThe UK’s GPG45 framework, and why it just became lawThe core methods, and what each actually provesBiometrics and liveness: what they add that documents alone don’tWhy identity verification standards exist at allWhat “reliable, independent source” actually means in AML lawWhere identity verification fits inside CDDFraud that’s specifically designed to beat verificationChoosing the right assurance level for the jobFAQsRead more
1 Dec 2025
Date the UK’s GPG45/DIATF framework became statutory under the Data (Use and Access) Act 2025
What identity verification actually means
Identity verification is the process of confirming that a person is who they claim to be, using evidence checked against a reliable, independent source rather than simply taken at face value. A name and date of birth typed into a form is a claim. Verification is what turns that claim into something a firm can actually rely on.
The term covers a wide range of methods, document checks, biometric matching, database lookups, and increasingly reusable digital identity credentials, but the underlying requirement is consistent across all of them: evidence has to be independently checked, not just collected.
Identification vs verification: a distinction most content skips
Identification and verification get used interchangeably, and that’s a genuine source of confusion. Identification is the act of collecting a claimed identity: a name, a date of birth, an address. Verification is the separate step of confirming that claim is actually true, against evidence the person providing it doesn’t control.
A firm that collects a name and address but never checks either against an independent source has identified a customer, not verified one. Regulatory requirements, under FATF Recommendation 10 and its domestic implementations, specifically require verification, not just identification, which is a distinction worth being precise about.
NIST’s Identity Assurance Levels: the US standard
In the US, the reference standard for how rigorous identity verification needs to be is NIST Special Publication 800-63A, which defines three Identity Assurance Levels. IAL1 involves no identity proofing at all; any attributes a person provides are self-asserted and unverified, the level typical of creating a basic social media account. IAL2 requires evidence supporting the real-world existence of the claimed identity, with the applicant verified as genuinely associated with it, achievable remotely or in person. IAL3 requires physical presence, in person or supervised remotely with specialised equipment, with identifying attributes verified by an authorised, trained representative and biometric comparison mandatory.
Most AML-regulated identity verification for opening a financial account sits at IAL2 or above; IAL1 doesn’t meet the “verification” bar at all.
The UK’s GPG45 framework, and why it just became law
The UK runs a parallel but structurally different framework. Good Practice Guide 45, GPG45, defines identity confidence levels, Low, Medium, High, and Very High, based on the strength and validity of evidence combined and the level of identity verification and fraud checking applied.
Until recently, GPG45 and the wider Digital Identity and Attributes Trust Framework, DIATF, were voluntary guidance. That changed with the Data (Use and Access) Act 2025, which received Royal Assent on 19 June 2025. Its provisions putting the DIATF on a statutory footing came into force on 1 December 2025, and version 1.0 of the framework, introducing the UK’s official CertifID trust mark, was published on 6 March 2026. Identity verification providers previously certified under earlier framework versions had to migrate: all Beta 0.3 certifications expired on 31 March 2026.
The core methods, and what each actually proves
Different verification methods prove different things, and understanding which is important. Document verification confirms a government-issued ID is genuine and internally consistent, checking security features, format, and issuing authority against known standards. Database verification cross-checks claimed identity details, name, date of birth, address, against government, credit bureau, or other authoritative records that exist independently of the document itself. Knowledge-based authentication asks questions only the real person should be able to answer, drawn from historical records, though this method has become significantly less reliable as personal data breaches have made much of that information available to fraudsters. Biometric verification confirms the person presenting the identity is physically the same person the identity document belongs to.
No single method proves everything on its own. A genuine, unaltered document proves the document is real; it doesn’t prove the person holding it is who the document says they are. That’s what biometric matching and liveness detection are specifically for.
Biometrics and liveness: what they add that documents alone don’t
Biometric verification, typically facial matching between a live selfie and a document photo, adds something document checks alone can’t: confirmation that the person presenting the identity right now is physically the same person the document was issued to. Liveness detection adds a further layer, confirming the face being captured belongs to a real, present person rather than a photo, video replay, or increasingly, an AI-generated deepfake.
This combination has become close to standard for remote onboarding specifically because document verification alone doesn’t address the most basic fraud pattern: someone using a real, unaltered document that simply isn’t theirs.
Why identity verification standards exist at all
Assurance-level frameworks exist because identity verification needs are genuinely different depending on what’s at stake. Opening a basic account with tight transaction limits carries different risk than opening a private banking relationship or accessing government benefits, and applying the same verification intensity to both wastes resources on the low-risk case while potentially under-protecting the high-risk one.
NIST and GPG45 both formalise this logic into defined, auditable tiers specifically so that a firm or regulator can point to a named standard, rather than a subjective sense of “thorough enough,” when explaining why a given verification process was considered adequate for a given use case.
What “reliable, independent source” actually means in AML law
FATF Recommendation 10 requires verifying customer identity using reliable, independent source documents, data, or information, a phrase that shows up in nearly every jurisdiction’s implementing regulation but rarely gets defined precisely. In practice, “reliable and independent” means the source wasn’t provided or controlled by the customer being verified: a government identity document checked against the issuing authority’s own records, rather than simply photographed and accepted at face value.
This is exactly the gap NIST’s IALs and the UK’s GPG45 levels exist to close: turning a vague standard, “reliable, independent source,” into a specific, auditable set of technical and procedural requirements.
Where identity verification fits inside CDD
Identity verification is the second of the four elements that make up customer due diligence: identify the customer, then verify that identity, understand the relationship’s purpose, and monitor ongoing activity. It’s the step where a claimed identity either gets confirmed against real evidence or doesn’t, and it’s usually the first point in an onboarding flow where a fraudulent application actually gets caught, before any funds move.
A CDD programme with weak verification at this stage undermines everything built on top of it: risk scoring, sanctions screening, and ongoing monitoring are all working from a customer identity that was never properly confirmed in the first place.
Fraud that’s specifically designed to beat verification
Fraud specifically designed to defeat identity verification has evolved considerably. Synthetic identities combine real and fabricated information into a persona that doesn’t correspond to any single real person, designed specifically to pass document and database checks that verify pieces of information in isolation rather than the whole identity as a coherent unit. Deepfake and injection attacks target the biometric layer directly, presenting AI-generated or manipulated video specifically to defeat liveness detection rather than fooling a human reviewer.
This is part of why verification standards keep evolving rather than settling on a fixed method: a technique considered sufficiently rigorous a few years ago can be specifically targeted once it becomes the default everyone relies on.
Choosing the right assurance level for the job
Choosing the right assurance level means matching verification rigour to actual risk and consequence, not defaulting to the maximum for everything or the minimum to reduce friction. A firm should be able to state, for any given product or customer segment, which specific assurance level, an IAL tier, a GPG45 confidence level, or an equivalent, it’s targeting, and why that level is appropriate for what’s actually at stake if the verification is wrong.
Frequently asked questions
What is identity verification?
Identity verification is the process of confirming a person is who they claim to be, using evidence checked against a reliable, independent source, distinct from simply collecting a claimed identity without checking it.
What is the difference between identification and verification?
Identification is collecting a claimed identity, a name and date of birth, for example. Verification is the separate step of confirming that claim is actually true against independent evidence.
What are NIST’s Identity Assurance Levels?
NIST SP 800-63A defines three levels: IAL1 (no proofing, self-asserted), IAL2 (evidence-based, remote or in-person), and IAL3 (in-person or supervised remote, with mandatory biometric comparison).
What is GPG45 in the UK?
GPG45 (Good Practice Guide 45) defines UK identity confidence levels, Low, Medium, High, and Very High. It’s now on a statutory footing under the Data (Use and Access) Act 2025, as of 1 December 2025.
What identity verification methods are commonly used?
Document verification, database verification against government or credit bureau records, knowledge-based authentication, and biometric verification with liveness detection, each proving a different aspect of a claimed identity.
Why isn’t document verification alone enough?
A genuine, unaltered document proves the document is real; it doesn’t prove the person presenting it is who the document says they are. Biometric matching and liveness detection close that specific gap.
What does “reliable, independent source” mean under FATF’s standard?
It means the evidence wasn’t provided or controlled by the customer being verified, such as a government document checked against the issuing authority’s own records rather than accepted at face value.
How does identity verification fit into customer due diligence?
It’s the second of CDD’s four core elements: identify the customer, verify that identity, understand the relationship’s purpose, and monitor ongoing activity.
What kind of fraud specifically targets identity verification?
Synthetic identities combine real and fabricated data to pass fragmented checks, while deepfake and injection attacks target the biometric layer directly to defeat liveness detection.
Read more: our ultimate guides, whitepapers and templates
Related guides and resources to help you act on what you just read.
Last reviewed July 19, 2026 · 11 min read · Written for compliance and risk professionals · By the WhoWiki editorial team
Key takeaway: Identity verification is the process of confirming that a person is who they claim to be, using evidence that’s been checked against a reliable, independent source rather than simply taken at face value. What counts as “verified” isn’t one fixed standard. In the US, NIST’s Identity Assurance Levels define three tiers of rigour. In the UK, the Good Practice Guide 45 framework, now on a statutory footing since December 2025, defines a comparable scale.