Identity verification confirms that a real-world identity belongs to the person registering or transacting, typically using a government-issued document, a biometric liveness check, or knowledge-based questions. It is distinct from authentication: verification establishes who someone is in the real world, while authentication later confirms that the same person is present in a specific session.
Frequently asked questions
Is identity verification a one-time step or ongoing?
It's most commonly done once at registration or at a high-risk transaction, though policies can require re-verification if new risk signals appear.
Why can't authentication alone prove who someone is?
Authentication proves the same person is returning to the same account; it can't establish that the original registrant is who they claimed to be in the real world.
Does identity verification slow down sign-up?
It adds friction, which is why most implementations reserve it for higher-risk actions rather than requiring it universally at registration.
.avif)