Identification and Verification
Identification and Verification (ID&V) is the process an organization uses to confirm that a person is genuinely who they claim to be, often by collecting and checking official documentation such as government-issued identification or other proof of identity. It is commonly applied when onboarding a new customer or opening an account, including in remote or digital channels. ID&V establishes identity at a point in time; it is distinct from ongoing authentication, which controls access on subsequent interactions.
ID&V is the process of confirming, at enrollment or onboarding, that an individual or entity corresponds to a claimed identity, typically by collecting and validating official documentation (for example government-issued identification or proof of identity) and, in remote contexts, by confirming that a digital user is the legitimate claimant. It is functionally separate from identity authentication (IDA): ID&V is focused on establishing and confirming identity, whereas authentication is focused on granting access on subsequent interactions. In payment and compliance contexts, ID&V supports customer onboarding and risk controls, and its rigor, evidence requirements, and acceptable methods depend on the applicable regulatory, program, or network rules governing a given use case rather than on the label alone. ID&V addresses identity assurance and should not be conflated with transaction-level controls such as EMV chip authentication, 3-D Secure, or multi-factor authentication, which mitigate different risks at different points in a transaction.
Why it matters
Identification and Verification (ID&V) establishes trust at the point where an organization first engages with a customer. If an identity is not confirmed correctly at onboarding, downstream controls inherit that weakness: an account opened under a false or stolen identity can become a vehicle for fraud, money laundering, or account takeover regardless of how strong later authentication controls are. Because ID&V confirms identity at a point in time rather than on every interaction, it is foundational to, but not a substitute for, ongoing authentication.
In payment and compliance contexts, ID&V is where the strength of an organization's fraud and risk posture is largely set. The rigor required, the evidence that is acceptable, and the methods that satisfy the process depend on the applicable regulatory, program, or network rules governing a given use case rather than on the label "ID&V" alone. This matters especially in remote and digital channels, where the organization cannot physically inspect a person or document and must instead confirm that a digital user is the legitimate claimant.
ID&V should not be treated as a control that eliminates fraud on its own. It is intended to reduce the risk of fictitious, stolen, or synthetic identities entering a system at onboarding, but it does not address transaction-level risks handled by controls such as EMV chip authentication, 3-D Secure, or multi-factor authentication. Its effectiveness also depends on the quality of the documentation and verification methods used, which carry their own trade-offs between friction and assurance.
Who it's relevant to
Inside ID&V
Common questions
Answers to the questions practitioners most commonly ask about ID&V.