Explainer

How Online Identity Verification Works, Step by Step

Online identity verification combines document analysis, biometric checks and screening data to decide whether a person is likely genuine and eligible for a service. The exact steps vary by provider, country, risk level and the document presented.

Online identity verification, often called IDV, is the process a business uses to establish that a customer is a real person and that the identity they claim is credible. Banks, marketplaces, employers, travel platforms and age-restricted services use it to meet legal duties, prevent fraud or control access.

A typical check takes place in a mobile app or web browser and may finish in seconds, although some cases need human review. It does not prove identity with absolute certainty. Instead, it combines signals from a document, a live person and relevant data sources to reach a risk-based decision.

1. Capturing an identity document

The user is asked to photograph or scan an accepted government-issued document, such as a passport, driving licence or national identity card. The service normally guides them to capture the front and back where relevant, with enough light and without glare, blur, fingers or cropped edges.

The verification software first assesses image quality. It checks whether text is readable, the document is fully visible and the image appears to be of a physical document rather than a screen or a low-quality copy. Some journeys use the phone camera directly, while others accept an uploaded image. Direct capture can provide more information about how the image was created, but it is not foolproof.

2. Capturing a selfie and performing liveness detection

The user then takes a selfie or a short video. This supplies a facial image for comparison with the portrait on the identity document. Many services also run a liveness check, which assesses whether the camera is seeing a present, live person rather than a printed photograph, a replayed video, a digital face image or a synthetic media attack.

Liveness may be passive, meaning it operates in the background from a selfie or video, or active, meaning the user is asked to turn their head, blink or follow an on-screen prompt. Active prompts can deter simple replay attempts but may add friction and are not automatically more accurate. Systems should account for camera quality, lighting, disability and accessibility needs, since these factors can affect completion rates.

3. Reading document data with OCR and NFC

Optical character recognition, or OCR, converts visible document text into digital fields. It can extract a name, date of birth, document number, expiry date, address and the machine-readable zone, the standardized lines of characters found on passports and some other documents. The service may also compare OCR results with data the user entered earlier to identify discrepancies.

Some passports and national ID cards contain a near-field communication, or NFC, chip. If the user has an NFC-capable phone, they can hold it against the document to read the chip. A properly read chip can provide signed identity data and, in many travel documents, a higher-quality facial image. Cryptographic checks can help establish that the chip data was issued by the document authority and has not been altered. NFC is not available for every document or every device, so it is usually an additional route rather than a universal requirement.

4. Checking whether the document is genuine

Document verification examines whether the credential matches the expected design and security features for its type, country and version. Automated checks can evaluate layout, fonts, portrait placement, barcode structure, machine-readable zone checksums, hologram-like optical behavior where supported, and consistency between the visible data and encoded data.

Tamper detection looks for signs that fields or images have been edited, replaced or obscured. Examples include inconsistent compression patterns, altered background textures, mismatched fonts, irregular edges around a portrait, or conflict between the front and back. These checks are probabilistic. A clean result means the system found no material warning sign, not that it can guarantee the document is authentic.

5. Matching the face to the document

A 1:1 face match compares the selfie with the portrait from the submitted document, or with the portrait read from an NFC chip. It is different from 1:N facial identification, which searches one face against a large database. In a 1:1 match, the question is narrower: is the person completing this session likely to be the person depicted on this credential?

The software generates biometric templates, mathematical representations of facial features, and calculates a similarity score. A score above a configured threshold can pass, while a low score may fail or be sent to review. Performance can be affected by age differences between photos, facial hair, glasses, pose, lighting and image quality. Providers should test for unequal error rates across demographic groups and offer alternatives when biometrics are unsuitable.

6. Screening databases, sanctions and watchlists

Depending on the service and its legal obligations, the business may screen the extracted name, date of birth and other identifiers against sanctions lists, politically exposed person lists and adverse-media sources. Sanctions lists identify people and entities subject to legal restrictions. A politically exposed person, or PEP, is someone entrusted with a prominent public function, as well as certain relatives and close associates in many regimes. PEP status is not evidence of wrongdoing, but it can require enhanced due diligence.

  • Name screening is prone to false matches, especially for common names, transliterations and incomplete records.
  • A possible match generally requires additional identifiers and human assessment before a business treats it as a true match.
  • Some checks also validate document numbers, address data or phone and email risk signals, subject to the business purpose and applicable privacy rules.

7. Making a risk decision and handling manual review

The verification provider or the business combines the results into a decision policy. A strong document, successful liveness result and high face-match score may produce an automatic pass. A failed security check, expired document or confirmed sanctions match may produce a decline. Borderline cases can be routed to trained reviewers, who inspect the images and evidence under documented procedures.

Manual review can reduce some automated errors, but it introduces its own risks, including inconsistency and unnecessary access to sensitive personal data. In the United States and European Union, organizations also need a lawful basis for processing, clear notices, security controls, retention limits and a process for contesting or correcting certain decisions. Requirements differ by sector and jurisdiction.

8. What the user sees

Most users see a simple result: verified, unable to verify, or under review. A well-designed service explains the next step, such as retaking a photo, using a different document or waiting for a review outcome. It should avoid revealing detailed anti-fraud rules that could help attackers evade them.

A verification result is usually limited to the purpose for which it was collected. Passing a platform's IDV process does not make a document universally valid, eliminate future checks or establish a permanent guarantee that every transaction is legitimate.