Glossary
The language of identity verification, defined in plain English.
- AML
- AML, or Anti-Money Laundering, is the set of laws, controls and processes used to prevent criminals from disguising illegally obtained funds as legitimate money. In identity verification, AML checks help firms assess customer risk and meet compliance duties.
- Account takeover
- Account takeover, or ATO, is fraud in which an attacker gains unauthorized control of an existing user account. They use it to steal money or data, make purchases, change account details, or lock out the legitimate user.
- Biometric verification
- Biometric verification confirms that a person is present and matches a previously enrolled biometric, such as a face, fingerprint or voiceprint. It compares measurable physical or behavioral traits rather than relying only on passwords or identity documents.
- Decentralized identity
- Decentralized identity, or self-sovereign identity, is a model in which people or organizations hold and control reusable digital credentials rather than relying on a single platform to manage their identity data.
- Deepfake
- A deepfake is synthetic or altered audio, video, image, or text made with artificial intelligence to convincingly imitate a real person or event. In identity verification, deepfakes can be used to bypass selfie, voice, or document checks.
- Document verification
- Document verification is the process of checking whether an identity document, such as a passport or driver’s license, is genuine, valid and belongs to the person presenting it.
- Identity assurance level
- Identity assurance level, or IAL, measures the confidence that a person’s claimed identity is their real identity after an identity-proofing process. It describes the strength of evidence and verification, not the security of login authentication.
- Identity proofing
- Identity proofing is the process of establishing that a person is who they claim to be, usually by checking identity evidence and linking it to the person presenting it. It is a core step in digital identity verification.
- KYB
- KYB, or Know Your Business, is the process of verifying that a business is real, lawful and represented by authorized people. It typically includes checking company registration, ownership and sanctions or other financial-crime risks.
- KYC
- KYC, or Know Your Customer, is the process of identifying and verifying a customer before or during a financial or regulated service relationship. It helps organizations meet anti-money-laundering and fraud-prevention obligations.
- Knowledge-based authentication
- Knowledge-based authentication, or KBA, verifies a person by asking questions they are expected to answer from personal knowledge, such as past addresses or loan details. It may use static questions or data drawn from credit and public records.
- Liveness detection
- Liveness detection is an identity-verification check designed to determine whether a biometric sample, such as a face scan, comes from a live person present at the time of capture rather than a spoof or replay. It helps prevent presentation attacks using photos, videos, masks or synthetic media.
- Mobile driver's license
- A mobile driver’s license, or mDL, is a government-issued digital version of a driver’s license stored in a smartphone app or digital wallet. It lets a holder prove identity or eligibility, often by sharing only the required information.
- Presentation attack
- A presentation attack, often called spoofing, is an attempt to fool an identity-verification system by presenting a fake or altered biometric trait, such as a face image, voice recording, fingerprint or mask, as if it belonged to a real user.
- Synthetic identity fraud
- Synthetic identity fraud is the use of a wholly invented identity, or a fabricated profile built from real and false personal data, to open accounts or obtain credit. The fraudster controls the identity even when some details belong to a real person.
- Verifiable credential
- A verifiable credential, or VC, is a digital record of claims, such as a qualification or age attribute, that is issued by an organization and protected with cryptographic proofs. A verifier can check who issued it and whether it has been altered, often without contacting the issuer each time.