Identity theft is more common than most organisations assume. When the CEO of a major security company had his digital identity stolen, including fraudulent loans taken out in his name, it served as a stark reminder that even sophisticated, security-conscious professionals are vulnerable. For companies managing digital customer relationships, verifying identity accurately and robustly is not optional. It is a fundamental business requirement with direct implications for legal compliance, fraud risk, and customer trust.
At Namirial, we provide identity verification solutions to financial institutions, insurance companies, healthcare providers, and other regulated organisations across Europe. This article explains how digital identity verification works, the key distinction between identification and authentication, the methods available, and how to choose the right approach for each context.
Identification vs Authentication: A Key Distinction
These two terms are often confused, but the difference is fundamental, and has direct implications for what your verification system needs to achieve.
Identification means stating who you are: providing your name, username, ID number, or email address. It is the equivalent of knocking on a door and shouting your name through the letterbox. It tells the system who the person claims to be, but provides no evidence that the claim is true.
Authentication means proving that you are who you claim to be: allowing the system to verify your identity with a reasonable level of confidence. It is the equivalent of the neighbour opening the door, looking at your face, and recognising you. The system checks the claim against evidence.
A secure digital onboarding process needs to cover both aspects: the customer declares their identity (identification), and the system verifies that declaration with appropriate rigour for the risk level involved (authentication). Skipping authentication, accepting identification alone, is how fraudsters obtain services, open accounts, and take out loans in other people’s names.
The Three Factors of Authentication
Authentication systems are traditionally categorised by what they verify. There are three fundamental factors:
Something you know: passwords, PINs, security questions, secret phrases. This is the oldest and most widespread authentication factor. Its weakness is that knowledge can be shared, stolen, guessed, or socially engineered. In high-risk contexts, “something you know” is rarely sufficient on its own.
Something you have: smart cards, hardware tokens, mobile phones receiving OTP codes. This factor is harder to steal than knowledge, but not impossible: phones can be lost or stolen, SIM cards can be swapped, tokens can be cloned. It is a significant improvement over knowledge alone, but has its own vulnerabilities.
Something you are: biometric features such as fingerprints, face, voice, iris, or the dynamics of handwriting. Biometric factors cannot be forgotten, cannot be shared (in the conventional sense), and are intrinsic to the individual’s physical person. Combined with liveness detection, they are the most robust authentication factor currently available.
When a system requires two of these factors simultaneously, it is called two-factor authentication (2FA). When it requires more than two, it is multi-factor authentication (MFA). The highest security contexts combine all three: something the customer knows (a PIN or passphrase), something they have (their phone or a smart card), and something they are (a biometric).
Modern Identity Verification Methods
Biometric Liveness Detection and Facial Recognition
AI-powered facial recognition combined with passive liveness detection verifies that the person presenting an identity document is the same person currently interacting with the system in real time. Modern systems analyse over 500 control points and detect deepfakes, masks, video replays, and other spoofing attempts, achieving fraud detection rates of 99.9%.
The process works as follows: the customer captures a brief video (typically 1–3 seconds) using their device camera. The liveness detection system analyses physiological micro-patterns (micro-movements, skin texture, blood flow indicators…) to confirm the person is genuinely present and alive, not a photograph or digital fabrication. The facial recognition system then compares the captured face against the photo on the submitted identity document.
If both checks pass, the system has strong evidence that the person submitting the document is the genuine holder of that identity, not someone who found or stole the document.
ID Document Verification with OCR
Document verification systems read the MRZ (Machine Readable Zone) code on identity documents, passports, national identity cards, driving licences, and verify that the data is internally consistent and has not been tampered with.
The MRZ contains a compact, machine-readable encoding of the document’s key data, including a set of check digits that mathematically verify the integrity of the data. If someone modifies any field on the document: the name, date of birth, expiry date, or nationality, the MRZ check digits will no longer match the modified content, and the system flags the discrepancy immediately.
Modern OCR systems also verify: the correct format and layout for the document type and issuing country, the authenticity of visible security features (holograms, microprinting, UV patterns where applicable), the dates (is the document expired? is the stated date of birth consistent with the stated age?), and the coherence between the visual inspection zone and the machine-readable zone.
Namirial’s document verification system covers identity documents from over 200 countries, with continuously updated templates for new document versions and security features.
OTP via SMS
A one-time password sent to the customer’s registered mobile phone number provides an additional layer of authentication during signing or account activation. The customer enters the six-digit code to proceed, confirming they have access to the phone number registered in their name.
OTP via SMS is straightforward to implement, works on any phone without app installation, and adds meaningful security, particularly as a second factor combined with document or biometric verification. Its limitations include vulnerability to SIM swapping attacks and the inability to confirm that the person holding the phone is the identity document holder. It is best used as one factor in a multi-factor framework rather than as standalone verification.
Video Identity Verification
For higher-assurance onboarding, such as opening bank accounts, contracting financial products, or accessing sensitive services, video-based identity verification allows a trained agent or an automated AI system to confirm the customer’s identity in real time, cross-referencing their face with the submitted identity document.
In France, the ANSSI PVID (Prestataire de Vérification d’Identité à Distance) certification sets the highest standard for remote identity verification, combining AI analysis with optional human review. Namirial (via Universign) is one of the few European providers holding PVID certification.
The response time for video verification varies by service level: under 5 minutes, under 15 minutes, or under 3 hours depending on the configuration chosen. For the highest-assurance regulated use cases, the combination of AI efficiency with human expertise provides robust coverage of edge cases that automated systems alone might miss.
Digital Identity Wallets (EUDI Wallet)
With the arrival of the EUDI Wallet under eIDAS 2.0, customers will be able to share verified identity attributes directly from a government-issued digital wallet. Instead of the business verifying the customer’s identity from scratch, the customer shares verified credentials from their wallet, credentials that have already been verified by a government authority.
This shifts the verification burden from the business to the state, dramatically reduces the time and cost of KYC processes, and eliminates the risk of document forgery (since the attributes come from official sources, not submitted documents). By July 2027, all regulated entities including financial institutions must accept the EUDI Wallet as a means of identification.
Namirial is actively building EUDI Wallet integration infrastructure, including the Namirial Wallet Gateway, to help organisations prepare for this transition.
Choosing the Right Method
The appropriate authentication level depends on three factors: the risk profile of the transaction or service, the regulatory requirements applicable to the sector (KYC, AML, eIDAS), and the user experience implications.
Lower-risk interactions (confirming a renewal, accessing a self-service portal, accepting standard terms) may require only OTP. Medium-risk contexts (signing commercial contracts, updating account details, accessing personal financial information) warrant advanced biometric verification with document validation. High-risk transactions (account opening, mortgage origination, accessing medical records, accessing regulated financial products) demand full biometric verification with document validation, liveness detection, and potentially video identification.
Namirial’s identity verification platform supports the full spectrum, from simple OTP and document checks to advanced biometric verification aligned with ETSI TS 119 461 v2.1.1. Our solutions are modular: organisations can configure the appropriate level for each type of transaction within a single integrated platform, presenting different verification flows to different customer segments based on risk assessment.
All solutions integrate via API into existing customer journey workflows, minimising disruption to current systems while significantly elevating the security and compliance of every customer interaction.







