Skip to main content
Category: Customer Due Diligence

Verification of Identity

Also known as: IDV, Identity Verification, ID Verification
Simply put

Verification of identity is the process an organization uses to confirm that a person is genuinely who they claim to be, typically by checking their identifying information or documents against reliable evidence. It is a common step when opening a bank account, applying for a loan, or otherwise seeking to do business with a regulated firm. In broad terms, it involves comparing the credentials a person presents with information that has already been proven or established.

Formal definition

Verification of identity is the process of confirming or denying that a claimed identity is correct by comparing the credentials or identifying information a person presents (such as an ID card or other documents) with information previously proven or established. In an AML compliance context it forms part of customer due diligence, whereby an obliged entity confirms that an individual seeking to do business with it is who they claim to be, though the specific documentary and non-documentary standards, thresholds, and acceptable evidence vary by jurisdiction and regulatory regime and should be confirmed against the applicable rules. As presented in the evidence, the term is defined operationally and technically rather than by reference to any single binding legal standard; note that identity verification is distinct from broader concepts such as full customer identification and ongoing due diligence, which may impose additional requirements.

Why it matters

Verification of identity sits at the foundation of customer due diligence, because nearly every subsequent control depends on knowing who the customer actually is. If an obliged entity cannot confirm that a person is genuinely who they claim to be, it cannot meaningfully assess the risk that customer poses, screen them against sanctions or PEP lists with confidence, or attribute transactions to a real, accountable individual. In this sense, IDV is less a standalone safeguard than the anchor point on which the reliability of an AML program rests.

Weak or absent identity verification exposes firms to the risk that accounts and services are opened under false, stolen, or synthetic identities, which can facilitate the placement and layering of illicit funds and frustrate later investigation. It is important to stress, however, that verifying a person's identity confirms only that the claimed identity is correct; it does not by itself establish the legitimacy of their source of funds, their beneficial ownership arrangements, or the absence of criminal intent. IDV is one measure to detect and deter misuse, not a guarantee against it.

Because the specific documentary and non-documentary standards, acceptable evidence, and applicable thresholds vary by jurisdiction and regulatory regime, the operational adequacy of an identity verification process is judged against the rules that apply to a given entity rather than a single global benchmark. Compliance teams should therefore treat IDV as a jurisdiction-sensitive obligation and confirm expected standards against the applicable regulation.

Who it's relevant to

Compliance and Onboarding Officers
Staff responsible for customer onboarding rely on identity verification as an early step in customer due diligence, confirming that an applicant is who they claim to be before establishing a business relationship. They must apply the documentary and non-documentary standards required in their jurisdiction and confirm those standards against the applicable rules.
Financial Institutions and Other Obliged Entities
Banks and other regulated firms perform identity verification when individuals seek to open accounts, apply for loans, or otherwise do business with them. For these entities, IDV is a component of their wider CDD obligations, distinct from full customer identification and ongoing due diligence, which may impose additional requirements.
Financial Crime Investigators and Analysts
Investigators depend on reliable identity verification to attribute accounts and transactions to identifiable individuals. Where identity has not been robustly confirmed, their ability to trace activity and assess risk is undermined, though a confirmed identity alone does not establish wrongdoing.
Risk and Technology Teams
Teams designing and maintaining IDV processes must ensure the methods used to compare presented credentials against previously established information are fit for the risks and regulatory expectations they face, treating verification as a measure to mitigate risk rather than eliminate it.

Inside IDV

Identification
The collection of identifying information about a customer, such as name, date of birth, address, and identification number. Identification is the gathering of claimed identity data and is a distinct step that precedes verification; the two are frequently conflated but should be treated separately.
Verification
The process of confirming that the identifying information collected is accurate and that the customer is who they claim to be, typically using reliable, independent source documents, data, or information. Verification tests the validity of the identity claim rather than merely recording it.
Reliable, Independent Source Material
The documents or data used to substantiate a customer's identity, which may include government-issued documents, electronic data sources, or other information not supplied solely by the customer. What qualifies as 'reliable and independent' generally depends on the applicable regime and the entity's risk-based approach, and exact acceptable sources should be confirmed against the relevant regulation.
Documentary Verification
Confirmation of identity using physical or scanned documents such as passports or national identity cards. This is one common method; its acceptability and required standards vary by jurisdiction and by the risk profile of the customer.
Non-Documentary / Electronic Verification
Confirmation of identity using electronic data sources, database checks, or other non-document methods, which may be used alone or to supplement documentary verification depending on the applicable regime and assessed risk.
Relationship to CDD
Verification of identity is a component of Customer Due Diligence (CDD), which itself is broader than KYC and encompasses identifying and verifying the customer, understanding the purpose of the relationship, and ongoing monitoring. Verification generally addresses the identity-confirmation element of CDD rather than the whole of it.
Beneficial Owner Verification
Where applicable, verification extends to identifying and taking reasonable measures to verify the identity of beneficial owners, which is distinct from verifying the legal owner or the customer of record. The extent of measures required typically depends on the entity type, risk, and applicable regime.
Timing of Verification
Verification is generally expected before or during the establishment of a business relationship, though some regimes permit verification to be completed during the course of establishing the relationship subject to risk controls. Exact timing rules should be confirmed against the applicable regulation.

Common questions

Answers to the questions practitioners most commonly ask about IDV.

Is verification of identity the same thing as identification?
No. Identification generally refers to obtaining identity information from a customer (such as name, date of birth, and address), while verification is the separate step of confirming that information against reliable, independent source documents, data, or information. Many frameworks, including the FATF Recommendations and jurisdiction-specific rules such as the UK Money Laundering Regulations, treat these as distinct components of customer due diligence. Collecting identity data alone does not satisfy the verification obligation.
Does verifying a customer's identity confirm that the customer is not involved in money laundering?
No. Verification of identity is a control to confirm that a customer is who they claim to be; it is not a determination of criminality or legitimacy. A successfully verified identity does not establish that funds are clean or that the customer poses no risk. Verification is one measure among several (alongside ongoing monitoring, screening, and other due diligence) that helps a firm detect, deter, and manage financial crime risk, but no single control eliminates that risk.
What types of sources can be used to verify identity?
Verification generally relies on reliable and independent sources, which may include government-issued documents, data from credible databases, or electronic verification methods, depending on the jurisdiction and the firm's risk-based approach. Acceptable sources and whether documentary, non-documentary, or electronic methods are permitted vary by regime and by the risk profile of the customer, so firms should confirm requirements against the applicable regulation and their own policies.
At what point in the customer relationship must identity be verified?
Verification is typically required before or during the establishment of a business relationship or before carrying out certain transactions, though many regimes permit verification to be completed shortly after establishing the relationship where this is necessary not to interrupt normal business and where risks are effectively managed. The precise timing rules and any permitted exceptions vary by jurisdiction and should be confirmed against the applicable law.
How does verification of identity differ for legal persons compared with individuals?
For individuals, verification generally focuses on confirming attributes such as name, date of birth, and address against reliable sources. For legal persons, verification typically extends to confirming the entity's existence, legal form, and status, and often requires identifying and taking reasonable measures to verify beneficial owners, which is a distinct concept from legal ownership. The scope and expected evidence differ, and enhanced measures may apply to higher-risk structures.
Can identity verification be performed remotely or by a third party?
In many jurisdictions, remote and electronic verification is permitted, and firms may in some cases rely on verification performed by qualifying third parties or introducers, subject to conditions. However, the acceptability of remote onboarding, the standards for electronic verification, and the extent of permitted reliance vary by regime, and the obliged entity generally retains responsibility for meeting its obligations. Applicable rules and any additional safeguards should be confirmed against the relevant regulation.

Common misconceptions

Collecting a customer's identity details satisfies the verification requirement.
Identification (collecting the information) and verification (confirming it against reliable, independent sources) are distinct steps. Recording a customer's stated details without independently confirming them generally does not meet a verification obligation.
Verification of identity is the same as KYC or CDD.
Verification is one element within CDD, which is broader and typically also includes understanding the nature and purpose of the relationship and conducting ongoing monitoring. KYC is often used loosely to describe onboarding processes, but verification specifically addresses confirming identity.
Verifying the named customer also verifies the beneficial owner.
Verifying the legal or account-holding customer is not the same as identifying and taking reasonable measures to verify a beneficial owner. Beneficial ownership and legal ownership are distinct concepts, and separate measures may be required depending on the entity and applicable regime.

Best practices

Treat identification and verification as separate steps, and ensure procedures clearly require confirming collected identity data against reliable, independent sources rather than simply recording customer-supplied details.
Apply a risk-based approach to the depth and method of verification, allocating more robust documentary or electronic checks to higher-risk customers while confirming acceptable methods against the applicable regime.
Where beneficial owners are relevant, take reasonable measures to verify their identity separately from verifying the legal or account-holding customer, distinguishing beneficial ownership from legal ownership.
Confirm the acceptable timing of verification (before or during establishment of the relationship) against the applicable regulation, and apply appropriate controls where verification is completed after onboarding begins.
Document the sources, methods, and rationale used to verify each customer's identity so that the basis for the verification decision is auditable and supports ongoing due diligence.
Verify exact acceptable source types, thresholds, and timing requirements against the specific regime that applies to the obliged entity, since these vary by jurisdiction and are not defined identically everywhere.