Identity Verification Compliance Suite
Establish high-assurance identities with checks tailored to risk and regulatory requirements. Entrust combines ETSI-certified identity verification, Device Intelligence, Workflow Studio, and QES to support regulated onboarding and IDV compliance while helping legitimate users move through the process efficiently.
Product Highlights
Year-over-year increase in injection attacks in 2026
[Source: 2026 Identity Fraud Report]
Users who prefer document and biometric identity verification
[Source: End-User Research Report]
Number of buyers more likely to say their IDV solutions provide a competitive advantage
[Source: IDV Competitive Advantage]
What Is IDV Compliance?
IDV compliance means designing and governing identity verification around the laws, standards, assurance levels, and policies that apply to a specific onboarding journey. It can involve identity evidence, digital and physical document and data checks, biometrics, fraud signals, workflow rules, signing, and recordkeeping.
Requirements vary by market, risk, and use case. A well-designed program applies the appropriate level of assurance while limiting unnecessary manual review and friction.
Inside the Compliance Suite
Entrust combines ETSI-certified identity verification, Device Intelligence, QES, and Workflow Studio for regulated onboarding.
ETSI-certified IDV and QES, orchestrated in Workflow Studio.
IDV Capabilities for Regulated Journeys
Document Verification
Use AI-powered document verification to confirm ID authenticity and detect altered, reused, or fraudulent documents during regulated onboarding.
Biometric Verification
Match a live applicant to verified identity evidence using facial biometrics and liveness checks designed to detect impersonation, spoofing, and deepfakes.
Biometric Authentication
Verify the person behind the identity with authentication that confirms who’s really there, not just the password, device, or access code.
Data Verification
Validate identity attributes against trusted sources and support checks such as ID record, proof of address, sanctions, and PEP screening.
Fraud Detection
Use AI-powered fraud detection alongside device, network, and repeat-attempt signals to identify suspicious activity, including deepfakes, synthetic identities, and injection attacks.
Workflow Studio
Orchestrate document, biometric, data, and fraud checks with configurable logic, automated decisions, and an audit trail of the IDV journey.
Digital Signing & QES
Use a verified identity in electronic signing workflows, including QES for transactions that require a qualified certificate and qualified signature creation device.
Extend Trust Beyond Onboarding
Use the identity established at onboarding for biometric authentication, account recovery, high-risk transactions, and account takeover prevention. Discover how to protect the moments that matter most in this Guide to Account Takeover Prevention.
What Is IAL2 Identity Verification?
IAL2 is an identity assurance level defined in NIST SP 800-63-3. It requires more identity evidence and more rigorous validation and verification than IAL1 to reduce impersonation and proofing errors.
For organizations evaluating IAL2 compliance, NIST requires sufficient evidence and core attributes, validation of that evidence, and verification that the applicant owns it. IAL2 identity verification can use non-biometric, biometric, or digital-evidence pathways.
Identity Proofing and Qualified Signing
ETSI Remote Identity Proofing
ETSI standards define auditable requirements for remote identity proofing under eIDAS. Entrust uses ETSI-certified identity verification in its IDV Compliance Suite.
eIDAS 2
The EU framework for electronic identification and trust services connects identity proofing, digital identity, signing, and trusted interactions across Member States.
Qualified Electronic Signature
QES is the highest-assurance e-signature level under eIDAS. It uses a qualified certificate and qualified signature creation device and has the same legal effect as a handwritten signature.
KYC
Customer due diligence commonly requires organizations to identify and verify customers, assess risk, and keep appropriate records during onboarding and ongoing review.
AMLR
Identity verification can support AML programs by strengthening customer identification and enabling risk-based workflows, sanctions checks, and ongoing monitoring.
GDPR
Identity verification in the EU can involve personal and biometric data subject to GDPR requirements for lawful processing, security, transparency, and data minimization.
HIPAA
Healthcare organizations may use identity verification to support secure digital onboarding and access to services involving protected health information.
UK DVS Trust Framework
The UK Digital Verification Services Trust Framework sets rules for digital verification services seeking certification under the UK framework.
Improve KYC Performance and Conversion
Lemonway combined a redesigned KYC workflow with Entrust Identity Verification to double identity-document validation rates, reduce manual work, and improve conversion while maintaining its regulatory obligations.
IDV Compliance Resources
Compliance Manager’s Guide to Identity Verification for KYC
Compare KYC and AML requirements across markets and review practical considerations for identity verification programs.
An Introduction to Digital Identity Verification
Review the core methods, benefits, and use cases behind digital identity verification.
2026 Identity Fraud Report
Explore current identity fraud trends, including deepfakes, injection attacks, and other threats affecting digital verification.
Find IDV Certifications
Review Entrust identity-related certifications and supporting assurance documentation.
IDV Compliance FAQs
Answers about IDV compliance, IAL2 identity verification, IAL2 compliance, and regulated onboarding.
What Is IDV Compliance?
IDV compliance means identifying applicable identity requirements, governing proofing controls, maintaining evidence, and adapting workflows as regulations and risks change.
How Does Identity Verification Support KYC and AML Compliance?
Identity verification helps organizations meet Know Your Customer (KYC) and Anti-Money Laundering (AML) requirements by verifying customer identities, validating identity attributes, and supporting risk-based onboarding processes. Combined with data verification, sanctions screening, and workflow orchestration, these controls can help organizations strengthen customer due diligence and maintain appropriate compliance records.
What Is ETSI-Certified Identity Verification?
ETSI standards establish requirements for remote identity proofing and provide a framework for auditable digital identity verification processes. Organizations operating under eIDAS and other regulatory frameworks may use ETSI-certified identity verification to support high-assurance onboarding, identity proofing, and qualified electronic signature workflows.
How Can Identity Verification Help Prevent Fraud?
Modern identity verification solutions combine document analysis, biometrics, device intelligence, and fraud detection capabilities to identify risks such as deepfakes, synthetic identities, injection attacks, impersonation attempts, and suspicious device behavior. By applying the appropriate level of identity assurance, organizations can reduce fraud while maintaining a smoother experience for legitimate users.
What Is IAL2?
IAL2 is defined in NIST SP 800-63-3 and requires stronger evidence, validation, and verification than IAL1. IAL2 identity verification may use non-biometric, biometric, or digital-evidence pathways.
How Can Entrust Support IAL2?
Entrust document, biometric, data, fraud detection, and orchestration capabilities can support higher-assurance proofing controls. depends on how the complete service is designed, implemented, and governed against NIST requirements.
Legislative and regulatory requirements can vary by jurisdiction, industry, product, and use case and may change over time. The information provided on this page is for general informational purposes only and reflects our understanding as of the date of publication. It does not constitute, and should not be relied upon as, legal, regulatory, or compliance advice. You should consult your own legal, compliance, or regulatory advisors regarding any questions or requirements that may apply to your business.