identity.org.au

Guides · Verification methods

Identity verification solutions compared

Choosing an identity verification solution? Compare the approaches — document checks, authoritative checks, biometrics, video and reusable credentials — by strength, friction and what you end up storing.

Identity.org.au editorial · Last updated 25 September 2026

An identity verification solution is any product or service that establishes, for a relying party, that a user is who they claim to be. The market offers many; they differ less in whether they check and more in what evidence they demand, how they behave when fake evidence arrives, and what they leave you holding afterwards.

This guide compares approaches, not vendors. Vendor rankings age badly and depend on data no evergreen page can honestly carry; the structural properties of each method do not age, because they follow from what the method actually does. One disclosure up front: this site documents one such solution, so the bias of the author is real — which is exactly why the comparison is framed by properties you can check yourself.

The five approaches

Real deployments combine rows rather than choosing one: a document check bound to a live face, backed by device attestation, is the shape most serious onboarding flows converge on. The combination matters because each layer's weakness is another's strength — see what document verification can and cannot do.

Identity verification approaches compared by mechanism, strength and what the verifier retains
ApproachHow it worksStrongest againstWhat you retain
Document verificationCapture an identity document in-session, parse and inspect it, match the portrait to the presenterCasual fraud; well-established and universally understoodDocument data and images, unless you deliberately discard them
Authoritative-source checks (“direct” verification)Check the person's details directly against a trusted record rather than against a picture of a cardForged documents — there is no image to fake; the record is the evidenceQuery logs and results; coverage depends on the records available
Biometric liveness and face matchChallenge a live person — blink, turn, speak — and match them to a referenceStolen documents and static photos; replayed mediaBiometric material, unless matching happens on-device with only a verdict retained
Video or assisted verificationA human interviews the applicant and inspects evidence in real timeNovel cases and edge situations a model handles poorlyRecordings and notes — the heaviest privacy footprint of the five
Reusable credentials and proofsVerify once under hard conditions, then present a signed result or zero-knowledge proofRepeated collection; every downstream copy that never happensThe answer itself — a tier, a pass/fail, a proof — and nothing beneath it

Compare on two axes, not one

The common mistake is scoring solutions on check strength alone. There are two independent axes, and a solution strong on the first can be dangerous on the second:

  • Strength against fraud. Can the method be passed with generated images, replayed video, or a borrowed document? In the synthetic era, methods that inspect static media score poorly here — the arms race is described in AI-generated fraud and fake IDs.
  • Exposure after the check. What exists in your systems tomorrow, and what happens when that is breached? A method that retains document images converts every successful check into future liability — the honeypot problem again.

Match the solution to the risk

The proportionality principle decides the rest: match assurance to the actual risk of the action. As a shape, not a rule:

  • Low-risk actions — gating content, light participation — need little beyond proof a person is present; a threshold proof may answer the question outright.
  • Account opening and transactions need a full check: document, live face match, device attestation, scored together.
  • Sensitive roles and high-value operations justify the deepest tier — hardware-backed biometrics, sustained history, and re-checking on a schedule rather than once.

The wallet's four verification levels express exactly this ladder, and the for-services pages map each level to appropriate use.

Australian considerations

Beyond fraud and friction, an Australian buyer is bound by privacy law's minimisation duty — collect only what you need, secure it, dispose of it when finished — and, in regulated sectors, by accreditation expectations for digital identity providers. Two practical consequences follow. Retention plans should be written before integration, not after. And accessibility is not optional: a solution that excludes people without particular documents or devices shifts the problem onto your support team.

The wider context — who checks identity here and which rules bind them — is mapped in digital identity in Australia.

A shortlist you can actually use

  • What does the relying service receive — a result, or raw evidence? Prefer answers you do not have to store.
  • How is capture controlled? In-session guided capture resists injection; open file upload does not.
  • Is liveness active and challenge-based, or a single passive frame?
  • Does the device attest its integrity, closing the emulator and virtual-camera routes?
  • What is retained, where, for how long — and what happens at the end of that period?
  • Can consent be seen, scoped and revoked by the person, with an auditable record?
  • Is the method inspectable? Published specifications and open code let your security team verify claims instead of trusting them.

Where this service sits

The Identity Wallet documented here is primarily approach five, executed with approach three at enrolment: verification produces signed results and proofs; services receive a tier, a pass/fail answer or a zero-knowledge proof — never documents, never biometrics — because no interface for receiving them exists. It is free, open-source reference infrastructure stewarded by a not-for-profit foundation, independent of government and claiming no accreditation.

If that shape fits your risk, the next step is become a verifier; if you are still architecting, start with the integration overview. Terms used above are defined in the definitions section.

Quick answers

What is the best identity verification method?

The one whose assurance matches your actual risk without retaining more evidence than you need. For most services that means a document check bound to a live face under challenge, scored with device attestation — and a threshold proof where the question is a simple yes/no.

What is the difference between a document verification system and an identity verification solution?

A document verification system is a component: it checks that a document is genuine and coherent. An identity verification solution is the whole flow — evidence, liveness, scoring and result — of which document verification is usually one layer.

What is “direct” identity verification?

Checking a person's details directly against an authoritative record — a trusted source of truth — instead of inspecting a document image. There is no picture to forge, which is its strength; its limits are coverage of the record and whether the data behind it is current.