stile
Compliance

What Is Identity Verification, and When Do You Need It?

Identity verification confirms that a person is who they claim to be. Learn what the check involves, when compliance or fraud risk calls for one, and how to add it to a workflow.

A
Alex MarinovCo-founder & CEOSeptember 28, 20266 min read
Illustration of a person presenting an identity card, with a verification result flowing into a decision path.

A customer opens an account. A seller changes their payout details. Someone calls support to regain access to a locked account. Each action is different, but each raises the same question: is the person taking this action the person they claim to be?

Identity verification is the process of confirming that a person is who they claim to be by checking their claim against trusted evidence, such as a government-issued ID or a digital credential. For a business, the practical question is where a verification result would change a decision. Two common reasons to add a check are a compliance requirement and a fraud risk tied to a specific action.

How does identity verification work?

Most identity checks answer two separate questions:

  1. Is the evidence genuine? The check assesses whether an ID document or digital credential is authentic, valid, and accurate. NIST calls this evidence validation.
  2. Does the evidence belong to this person? The check links the person presenting the evidence to its owner. NIST defines identity verification as confirming that the applicant is “the genuine owner of the presented evidence and attributes.” NIST SP 800-63A

In one common online flow, a person scans a government ID and takes a live selfie. The system checks the document, assesses whether a live person is present, and compares the selfie with the ID portrait. Other flows use a digital credential and may require different steps.

The result is evidence for a decision. A passed check does not establish that someone is authorized to act for a company, entitled to a payment, or safe to transact with. Your team still compares the result with its own records, permissions, and policies.

Common identity verification methods

  • Document verification checks a passport, driver’s license, or ID card and reads relevant data from it.
  • Biometric checks may use a selfie. Liveness detection assesses whether a live person is present; face matching separately compares that person with a trusted portrait.
  • Digital IDs, including supported mobile driver’s licenses, can carry a signature from the issuing authority that a verifier checks. Learn more about digital ID verification.
  • Data checks compare details a person provides with authoritative or third-party records. They can help validate a claim, but matching details alone may not establish that the person submitting them owns the identity.

The methods you need depend on the question the result must answer.

Identity verification vs. authentication

Authentication checks whether someone controls an account credential, such as a password, passkey, or one-time code. Identity verification checks a claim about who the person is.

A correct password shows that someone has the credential. It does not establish who is using it now. That is why a sensitive request can call for a fresh identity check even when it comes from a logged-in account.

Trigger 1: A compliance requirement

Some businesses must check identity or age as part of a regulated process. The requirement depends on the activity and jurisdiction.

  • Banking: FinCEN says a bank’s Customer Identification Program must include “risk-based procedures for verifying the identity of each customer.” It also says a CIP “is only one part of a bank’s BSA/AML compliance program.” FinCEN CIP guidance
  • Age-restricted services and products: Certain US state laws require an age check for specified online content or transactions. An age check may establish only that someone meets a threshold, without revealing or verifying their full identity. Requirements vary by state and use case. See the guide to US state age verification laws.

If compliance is your trigger, identify the rule that applies to your organization, product, customers, and jurisdiction. Determine whose identity or age must be checked, when the check must happen, what evidence is acceptable, and which records you must keep. Then design the flow around those requirements.

Do not treat “KYC” as a synonym for an ID check. Identity verification can be one part of a Know Your Customer program, which may also include due diligence, screening, and ongoing monitoring. A passed identity check does not complete those obligations on its own.

Trigger 2: A fraud risk at a specific action

Even when no rule requires a check, some actions carry enough risk to justify one:

Timing matters. Verifying someone at signup tells you who completed onboarding. It does not establish who is requesting a change months later, after account credentials may have been stolen. A check at the moment of the action gives your team current evidence about the person making the request.

Take a request to change bank details. The FBI advises businesses to “use secondary channels or two-factor authentication to verify requests for changes in account information.” An identity check can add evidence about who is in the workflow. It should complement confirmation through a trusted contact method, not replace it. FBI IC3 guidance

The aim is to put friction where the decision warrants it. A low-risk action may need no identity check. A disputed account recovery or payout change may warrant a stronger check and a manual review path when the evidence is unclear. Read more about identity verification for fraud prevention.

How to add identity verification to a workflow

Start with one decision, such as “may this person change the payout account?” Then work backward:

  1. Name the trigger. Decide exactly which action starts the check.
  2. Choose the evidence. Select the document, digital credential, and presenter checks that fit that decision.
  3. Link the result to the request. Tie the verification session to the account and action under review.
  4. Define your decision paths. Decide what your application does when verification succeeds, expires, or cannot establish enough confidence. A hold or manual review is your workflow’s response.
  5. Keep the decision in your hands. Combine the result with your own records and approval rules, and retain the audit evidence your process requires.

With Stile, your server creates a verification session, the person completes the check, and Stile sends a signed result to your server. Your application verifies the webhook signature, matches the result to the original request, and decides whether to continue, hold, or review. See how identity verification software fits into your workflow, or follow the quickstart.

The takeaway

Identity verification is most useful when its result answers a defined question at a defined moment. Start with the compliance obligation or fraud risk, choose evidence that fits, and decide in advance how your team will act on the result.

Frequently asked questions

Is identity verification required by law?

For some businesses and activities, yes. Banks have customer identification requirements, and certain age-restricted activities are subject to state age-check rules. Other businesses add identity checks to address fraud risk. The applicable requirement depends on the activity and jurisdiction.

What is the difference between identity verification and KYC?

Identity verification checks a person’s identity claim. KYC is a broader customer due diligence program that can include identity verification, screening, and ongoing monitoring.

What documents are used for identity verification?

Common evidence includes a passport, driver’s license, or national ID card. Some flows accept a supported digital credential, such as a mobile driver’s license. The evidence required depends on the workflow.

Share this article