identity.org.au

Definitions · Verification and proofing

What is digital identity verification?

Digital identity verification is checking online that a person is who they claim to be. How it works, how it differs from a password check, and what a service should actually receive at the end.

Identity.org.au editorial · Last updated 25 September 2026

Digital identity verification is the process of confirming, online, that a person is who they claim to be. Instead of a human comparing a card to a face across a counter, software and evidence do the work: data is captured, checked against signals, and a result is issued that a service can rely on.

Three nearby terms are worth separating, because they are constantly confused. Identification asks who someone is. Authentication proves you control something — a password, a passkey, a device. Verification tests a claim about identity: this person really is the holder of this account, this age, this licence. Authentication happens every login; verification usually happens once, to a stated level of confidence.

What happens during a digital identity check

Most verification flows follow the same skeleton, whatever the brand on top of it:

  • Evidence is produced. A document is captured with the camera, a face is matched under a liveness challenge, or a credential is presented from a wallet.
  • Signals are assessed. The data is read and cross-checked: does the document parse, does the portrait match the live face, does the response arrive with human timing, does the device prove its integrity?
  • A result is issued. A tier, a score, a pass/fail answer or a proof — something a service can check and store without holding the underlying evidence.

The wallet's own flow is documented step by step in how it works, and each method above is compared, with its trade-offs, in identity verification solutions compared.

The methods, in brief

Four families of method cover almost everything on the market. Document verification reads and inspects an identity document. Authoritative checks query a trusted record directly — verifying details against a source of truth rather than against a piece of paper. Biometric checks confirm a live person matches a reference, usually with a liveness challenge (see biometric identity verification). Credential presentation reuses a result that was already verified once, delivered as a signature or a zero-knowledge proof.

Real-world systems combine them. The point of combination is that each method's weakness is another's strength: a stolen document fails a liveness check, a generated face fails device attestation, a replayed video fails an unpredictable challenge.

A good digital identity check ends in two things: an answer you can rely on, and no pile of identity data you now have to protect forever.

What the service should receive

The most consequential design decision in any verification system is not how the check is performed but what happens to the evidence afterwards. The conventional pattern collects document images and selfies into the service's own storage, which creates the exact archive attackers want — the honeypot problem.

The alternative is structural: verification produces results, not copies. The service receives a verification level, a pass/fail answer or a proof it can verify cryptographically. It never receives documents or biometric data — not because a policy forbids it, but because no such interface exists. That is the interface described in the integration overview, and what users see from their side is covered in who can see your data.

Verification is a level, not a single yes

Not every interaction deserves the same depth of check, so verification is expressed as levels of assurance — from a light check that a real person is present, up to hardware-backed biometrics for sensitive roles. The level a service demands should match the risk of the action: that is the proportionality principle set out in verification tiers and proportionality.

One well-chosen verification, performed under hard conditions, can then be reused everywhere through credentials and proofs — instead of every service re-running its own camera gauntlet and re-storing its own copy.

Quick answers

What is the difference between identity verification and authentication?

Verification tests a claim about who you are — that this person is the holder of this identity. Authentication proves you control something, such as a password, passkey or device. Verification usually happens once to a stated level; authentication happens every time you sign in.

What is a digital identity check?

A digital identity check is one run of the verification process: evidence is produced and assessed, and a result is issued. In practice the phrase means the same thing as digital identity verification — the online equivalent of showing ID, but with the outcome recorded as a result rather than a photocopy.

What should a service receive from a verification?

A result: the user's verification level, a pass/fail answer to a stated requirement, or a cryptographic proof — never document scans, photos or biometric data. Holding no evidence means having no identity archive to breach, which protects the service as much as its users.