Issuance with Credence · Identity Verification

Six checks. One to two minutes. One verified identity.

IDV is the identity proofing engine inside Issuance with Credence. Document authentication, biometric match, liveness, OCR, registry validation, and fraud screening - all running in parallel, all surfaced in one reviewer view, all before a single digital ID gets signed and issued

A phone capturing a live selfie beside an identity card, feeding six checks - OCR, biometric match, liveness, document authentication, registry check and fraud screen - which all converge on a single verified identity record. A badge reads "1-2 minutes, in parallel".
From capture to verified identity record
1,500+
document types
200+
countries and territories
1-2 min
end-to-end pipeline
iBeta Level 2
certified liveness

Signing a credential is easy. Being sure who you signed it for is the hard part.

  • Manual review does not scale to millions
  • Document-only checks miss face substitution
  • Selfie-only checks miss forged documents
  • On-device matching can be spoofed
  • Audit gaps surface at exactly the wrong moment

What IDV is

IDV sits between enrollment and issuance. An applicant submits their identity document and a live selfie from the Credence Wallet app or the IDV Browser; IDV runs six automated checks in parallel, assembles every result into a single submission record, routes the exceptions to a reviewer, and hands a verified identity record to Issuance with Credence to sign against. It does not retain raw identity data permanently, does not issue credentials itself, and does not replace your enrollment front end. It does one job: establish, with evidence you can audit five years later, that the person applying is who they claim to be.

Six checks. All at once. No shortcuts.

Every submission runs the full battery. The pipeline does not stop at the first failure - a forged document does not cancel the biometric match, and a liveness miss does not skip the registry lookup. Reviewers see the complete picture, not the first thing that went wrong.

A submission of document plus selfie fans out to six numbered checks running side by side - OCR and data extraction, biometric match, liveness detection, document authentication, System of Record check, and fraud check. Five pass and one is flagged; all six results assemble into one submission record. A note reads "No short-circuit: one failing check never cancels the other five".
Six automated checks running in parallel

OCR & Data Extraction

Reads every field the document carries, and scores its own confidence in each one.

  • Visual Inspection Zone extraction
  • MRZ parsing to ICAO 9303
  • Per-field confidence scoring
  • Document-aware template matching

Biometric Match

Compares the document portrait against the live enrollment selfie.

  • 0–100 similarity scoring
  • Per-issuer pass thresholds
  • Robust to ageing, glasses, lighting
  • Demographic fairness benchmarked to NIST FRVT

Liveness Detection

Confirms a live human, not a photo, screen, mask, or deepfake.

  • Passive liveness, zero user effort
  • Optional active challenge-response
  • Randomised challenges block replay
  • ISO/IEC 30107-3 iBeta Level 2 certified

Document Authentication

Four forensic layers establishing that the document itself is real.

  • Hologram, microprint, and OVI inspection
  • Tamper and face-substitution detection
  • VIZ, MRZ, and NFC chip cross-validation
  • 1,500+ document types, 200+ countries

System of Record Check

Reconciles extracted attributes against your authoritative registry.

  • Fuzzy matching across scripts and formats
  • Per-field, per-programme thresholds
  • Multiple registry integrations
  • Canonical attribute enrichment

Fraud Check

Catches the applicant who already enrolled - under a different name.

  • 1:N biometric deduplication
  • Flagged and revoked document screening
  • Machine learning fraud pattern models
  • AML and sanctions screening

Liveness Detection

Four panels. A live person is accepted. A printed photo is rejected for no depth cues, a screen replay for its reflection pattern, and a mask by texture analysis. Below, passive mode uses texture, depth, reflection and micro-movement at a 70–85 threshold, while active mode uses randomised blink, turn or smile challenges. A badge reads ISO/IEC 30107-3, iBeta Level 2 certified.
Liveness detection: live person accepted, presentation attacks rejected

Document Authentication

An identity document exploded into four stacked layers under a magnifier: visual and forensic inspection of holograms, microprint and OVI; data extraction from VIZ templates, MRZ to ICAO 9303 and the NFC chip; cross-data validation where chip data wins every tie; and document consistency across layout, typography, colour profile and dimensions. Anomalies are ranked minor, moderate or definitive by a weighted risk model.
Document authentication: four forensic layers

Four steps, one of them optional

Four steps along a rail. Capture: document and live selfie from an app or mobile browser, under 10 minutes. Verify: six checks fire in parallel and assemble as one record, one to two minutes. Review: clean submissions auto-clear and exceptions go to a reviewer, optional by policy. Issue: signed in the HSM and delivered to the wallet over OpenID4VCI, FIPS 140-3 Level 3.
How IDV works: capture, verify, review, issue
  1. Capture

    The applicant photographs their document and takes a live selfie, guided by real-time feedback on lighting, framing, and glare. Native app or mobile browser. Under 2 minutes, typically far less.

  2. Verify

    Six checks fire in parallel. The pipeline completes in one to two minutes and assembles every score, flag, and anomaly into a single submission record.

  3. Review

    Clean submissions clear automatically. Flagged ones land in a reviewer queue with the evidence attached - side-by-side portraits, severity-ranked anomalies, and the raw document images at full resolution. Hard fraud signals always go to a human.

  4. Issue

    On approval, the verified record passes to Issuance with Credence. This verified record can be used to issue digital IDs directly into the holder's wallet app.

Give reviewers evidence, not verdicts

A match score of 74 means nothing on its own. The Review Dashboard shows the score, the threshold it was measured against, the two portraits side by side at equal scale, and every anomaly ranked minor, moderate, or definitive - so the decision belongs to a named person who can explain it.

  • Applicant Information, extracted fields with confidence scores
  • Document Trust Factors, security features and consistency results
  • Biometric Trust Factors, match, liveness, and portrait comparison
  • Approve, reject with reason code, or escalate
  • Role-based access - Reviewer, Senior Reviewer, Administrator
  • Overrides require written justification
  • Append-only action log, no operator can edit it
  • Five-year retention, JSON and CSV export
A reviewer screen for submission #48219, marked needs review. The left column compares the document portrait and enrollment selfie at equal scale, with document images and extracted fields carrying per-field confidence scores. The right column shows a face match of 91 and passive liveness of 88 against a threshold of 75, a document trust score of 68 below that threshold, and three anomalies ranked moderate, minor and minor, with Approve, Reject and Escalate actions. A footer strip notes an append-only action log, written justification for overrides, five-year retention, and JSON and CSV export.
Review Dashboard: evidence, not verdicts

Your policy. Not our defaults.

Every check is a toggle, every threshold a setting. Run fully automated for low-risk credentials, mandatory manual review for high-assurance national ID, and something different again for a third programme - all on one platform, all without custom development. Configuration is per issuer and editable after go-live.

What you control
  • Which of the six checks run
  • Match and liveness thresholds
  • Automated clearance vs mandatory manual review
  • Accepted document types per programme
  • Supporting document requirements
  • Consent capture and Terms & Conditions content
  • ABIS, AML, and registry integrations
  • Retry limits and lockout behaviour
A matrix of eight settings against three programmes. National ID runs every check except AML screening and mandates manual review, at a match threshold of 88. Bank KYC runs AML screening but not 1:N deduplication and does not mandate manual review, at 78. Employee badge skips deduplication, AML screening and mandatory review, at 70. A footer reads "One platform. Three pipelines. Zero custom development."
Configurability: three programmes, one platform, different pipelines

Certified where it counts

StandardApplies to
ISO/IEC 30107-3 (iBeta Level 2)Presentation attack detection
NIST FRVTFace recognition accuracy benchmarking
ICAO 9303MRZ parsing, check digits, ePassport chip data
ISO/IEC 18013-5mDoc credential assembly after approval
W3C VC 2.0Verifiable Credential data model
OpenID4VCICredential delivery to the wallet
FIPS 140-3 Level 3HSM-backed signing

Built for programmes where identity is the product

Government

National ID, mobile driving licences, and resident credentials at population scale. Registry integration, biometric deduplication across the enrolled population, and maker-checker review with a five-year audit trail.

Banking & Financial Services

KYC-compliant onboarding without the branch visit. AML and sanctions screening in the same pipeline, document authentication across 200+ countries for cross-border customers, and reason-coded rejections your compliance team can defend.

Healthcare

Patient and practitioner identity established once and reusable across every point of care. Liveness at every credential presentation, not just at enrollment.

Enterprise & Workforce

Employee and contractor credentials issued remotely on day one. Right-to-work document checks, deduplication against your existing workforce, and instant revocation on exit.

Education

Student and alumni credentials issued at graduation scale. Batch-friendly automated clearance with exception routing for the cases that need a human.

One component of a complete credential platform

IDV produces the verified identity. Issuance with Credence signs it into an ISO 18013-5 mDoc or W3C Verifiable Credential inside a FIPS 140-3 Level 3 HSM. The Credence ID Wallet and Wallet SDK hold it on the holder's device under hardware-backed keys. Verify with Credence checks it in person or online, anywhere in the world. Issuer, holder, verifier - the full Trust Triangle, from one vendor, with one integration.

A trust triangle. Issuance with Credence at the issuer corner signs into mDoc or W3C VC and issues the credential to the holder, the Credence ID Wallet, which stores it under hardware-backed keys and presents it to the verifier, Verify with Credence, in person, online or offline. The verifier trusts the signature back to the issuer. A callout marks Identity Verification as upstream of everything: six checks produce the verified record the issuer signs against.
Where IDV fits: feeding the issuer corner of the Trust Triangle

See it verify a real document

Fifteen minutes, your document, our sandbox. Watch the six checks run and the reviewer view assemble in real time.

Let's issue digital IDs to your users.
Tell us your requirements & we'll setup a demo for you.