Skip to main content
Category: Customer Due Diligence

Electronic Identity Verification

Also known as: eIDV, Electronic ID Verification, EIDV, Digital Identity Verification
Simply put

Electronic Identity Verification (eIDV) is a digital process businesses use to confirm that a customer is who they claim to be, typically over a computer or online rather than through an in-person document check. It generally works by cross-checking the personal details a person provides against public and other information sources. It is often used to establish a customer's identity when onboarding them online.

Formal definition

Electronic Identity Verification (eIDV) is an operational method of establishing and confirming an individual's claimed identity through digital or electronic means, typically by matching submitted identity attributes against a combination of public and other information sources. It is commonly deployed by businesses to verify customer identity in online or remote channels, and is generally positioned as providing reliability comparable to an in-person identity check. eIDV is an operational and technological control that can support identity verification within a broader compliance process; the specific data sources, matching logic, and evidentiary standards vary by provider and by the requirements of the applicable jurisdiction and obliged-entity regime, which should be confirmed against the relevant regulation.

Why it matters

Identity verification is a foundational element of customer due diligence (CDD), and as onboarding has shifted to online and remote channels, obliged entities have increasingly relied on electronic methods to confirm that a customer is who they claim to be. eIDV addresses the practical challenge of establishing identity when a customer is not physically present to produce documents, and it is frequently positioned as offering reliability comparable to an in-person identity check. For compliance teams, verifying identity reliably at onboarding is important because subsequent controls, such as ongoing monitoring, sanctions and PEP screening, and risk profiling, depend on knowing who the customer actually is.

Who it's relevant to

Compliance and onboarding teams
Teams responsible for customer onboarding and CDD frequently deploy eIDV to establish and confirm identity in online or remote channels. They need to ensure that the chosen eIDV approach aligns with the identity-verification requirements applicable to their obliged-entity category and jurisdiction, and that it is integrated appropriately with other CDD steps.
Financial institutions and other obliged entities operating remotely
Businesses that acquire customers without in-person contact rely on eIDV as a practical means of establishing identity. For these firms, eIDV supports the verification element of their identity checks, but the acceptable standard and permitted data sources depend on the applicable regime and should be confirmed against the relevant regulation.
Risk and audit functions
Second- and third-line functions assessing the effectiveness of identity controls should understand that eIDV outcomes depend on the coverage and quality of underlying data sources and matching logic, which vary by provider. They should evaluate whether the control is calibrated to the firm's risk appetite and regulatory obligations, recognising it as a measure to detect and manage identity risk rather than a guarantee against fraud.
Technology and vendor management stakeholders
Those selecting or overseeing eIDV providers need to assess how a given solution's data sources, matching approach, and evidentiary standards map to the firm's jurisdictional requirements, since these elements differ across providers and regimes.

Inside eIDV

Attribute Verification
The process of confirming identity attributes such as name, date of birth, and address against independent and reliable electronic data sources rather than physically inspecting documents.
Data Source Reliability
eIDV depends on the quality, independence, and coverage of the underlying data sources (for example credit bureaus, government registers, and other reference databases), which vary significantly by jurisdiction and may leave certain populations underrepresented.
Verification vs. Identification
eIDV addresses the verification element of Customer Due Diligence, checking that claimed identity information is accurate, and is distinct from initial identification (obtaining the customer's identity information) and from ongoing monitoring.
Screening Integration
eIDV is typically deployed alongside, but is not a substitute for, sanctions screening, PEP screening, and adverse media checks, which serve different risk purposes.
Assurance Level
The degree of confidence an eIDV outcome provides can vary; some checks confirm a match against one or more data sources at differing levels of certainty, and higher-risk relationships may generally require additional or corroborating measures.
Regulatory Positioning
Where permitted, eIDV may satisfy the identity verification component of CDD obligations under applicable regimes (for example rules derived from the EU AML framework, the US BSA/FinCEN requirements, or the UK Money Laundering Regulations), but acceptability and conditions differ by jurisdiction and should be confirmed against the applicable rules.

Common questions

Answers to the questions practitioners most commonly ask about eIDV.

Does passing an electronic identity verification (eIDV) check confirm that a customer is not involved in money laundering or other financial crime?
No. eIDV is a tool used to verify that a claimed identity corresponds to a real person and that the customer is who they say they are; it does not assess whether that person is engaged in criminal conduct. Identity verification is one component of customer due diligence (CDD) and typically sits alongside separate processes such as sanctions screening, politically exposed person (PEP) screening, adverse media checks, and ongoing transaction monitoring. A successful eIDV result should not be treated as evidence that a customer poses no financial crime risk, and it does not establish or disprove wrongdoing.
Is electronic identity verification the same thing as Know Your Customer (KYC) or customer due diligence (CDD)?
No, and the terms should not be used interchangeably. eIDV is a method for electronically confirming identity data against reference sources. KYC and CDD are broader obligations that generally encompass identifying the customer, verifying their identity, understanding the nature and purpose of the relationship, identifying beneficial ownership where relevant, and conducting ongoing monitoring. eIDV can support the identity-verification element of these processes but does not by itself satisfy the full range of CDD or enhanced due diligence (EDD) expectations that may apply under the relevant regime.
Can electronic identity verification be used as the sole means of verifying a customer's identity, without any document-based checks?
Whether eIDV alone is sufficient depends on the applicable regime, the assessed risk of the relationship, and the reliability and independence of the data sources used. In many jurisdictions, guidance permits electronic verification where it draws on multiple reliable and independent sources, but higher-risk situations may call for additional or corroborating measures, which can include document verification. Obliged entities should confirm what their regulator or supervisory framework expects and document the basis on which they consider an electronic-only approach adequate.
What data sources are typically used in an eIDV process?
eIDV solutions generally draw on a combination of reference data sources, which may include credit reference data, electoral or population registers, government-issued identity databases, utility and telecommunications records, and other independent datasets, depending on the jurisdiction and provider. The availability and reliability of such sources vary significantly by country. Firms should assess whether the sources used are sufficiently reliable and independent for their risk profile, and recognise that data coverage may be limited for certain populations, such as younger customers or those new to a jurisdiction.
How should firms handle customers who cannot be verified electronically?
A failure to verify electronically does not necessarily indicate elevated risk; it may reflect thin data coverage or population characteristics rather than any concern about the individual. Firms typically maintain alternative or fallback verification procedures, such as document-based checks or additional corroborating evidence, for customers who cannot be verified through eIDV. The appropriate approach should be risk-based and consistent with the applicable regulatory expectations, and the reasons for using an alternative method should generally be recorded.
What record-keeping considerations apply to eIDV checks?
Firms are generally expected to retain records demonstrating what identity verification was performed, when, and on what basis, including the outcome of eIDV checks and the sources relied upon. Record-keeping obligations, including retention periods, derive from the applicable regime and vary between jurisdictions, so exact requirements should be confirmed against the relevant regulation. Maintaining a clear audit trail supports the firm's ability to evidence compliance and to explain how it satisfied the identity-verification element of its CDD obligations.

Common misconceptions

eIDV confirms that a person is who they claim to be.
eIDV generally confirms that the identity attributes provided match one or more independent data sources; it verifies data consistency rather than proving that the individual presenting the information is the genuine identity holder. Additional measures may be needed to address impersonation and synthetic identity risk.
eIDV satisfies all customer due diligence requirements on its own.
eIDV typically addresses only the identity verification element of CDD. It does not by itself deliver purpose-of-relationship understanding, beneficial ownership identification, risk assessment, sanctions or PEP screening, or ongoing monitoring, and it is not a form of enhanced due diligence.
eIDV works equally well everywhere and eliminates onboarding fraud risk.
The effectiveness of eIDV depends on the availability and quality of data sources, which vary by jurisdiction and customer segment. It is a measure to detect and mitigate identity risk, not a guarantee against fraud or financial crime.

Best practices

Assess the coverage, independence, and reliability of the underlying data sources for each relevant jurisdiction and customer population before relying on eIDV outcomes.
Adopt a risk-based approach that calibrates the required level of verification assurance to the assessed risk of the customer and relationship, applying additional or corroborating measures for higher-risk cases.
Treat eIDV as one component of a broader CDD framework, ensuring it is paired with sanctions screening, PEP screening, adverse media checks, and ongoing monitoring where required.
Establish documented fallback procedures for customers who cannot be verified electronically, avoiding unintended exclusion of underrepresented populations.
Retain records of eIDV checks, data sources used, and outcomes to support auditability and to evidence compliance with applicable verification obligations.
Confirm the acceptability and specific conditions for electronic verification against the applicable regulatory regime, as requirements differ across jurisdictions and obliged-entity types.