Identity Proofing
Identity proofing is the process of establishing that a claimed identity belongs to a real person, and that the person presenting it is the rightful owner of that identity. For a bank, that question matters long before money moves. It matters at account opening, account recovery, device registration, and any request that could hand control to a criminal.
The term is often used loosely, which creates risk. Identity proofing is not the same as login authentication, and it is broader than a document check alone. Entersekt helps financial institutions connect identity checks to transaction risk, so trust is assessed at the moments that matter most.
Key takeaways: Identity proofing
- Identity proofing links a claimed identity to a real person before an institution issues access, approves a sensitive action, or restores control of an account.
- For banks, identity proofing is relevant at onboarding, account recovery, device enrollment, payment limit changes, and other moments where impersonation risk is high.
- Document checks, biometric comparison, liveness tests, and data validation each answer different questions, so strong design combines them thoughtfully.
- Entersekt connects identity verification to contextual risk, which helps banks challenge high risk actions while keeping routine journeys easier for legitimate customers.
- NIST, FinCEN, and FFIEC guidance all point to the same principle: identity controls should be risk based, auditable, and appropriate to the action.
What identity proofing means
Identity proofing means establishing a relationship between a digital account and a real life person to a defined level of confidence. NIST uses the term for the full process of identity resolution, evidence validation, attribute validation, identity verification, enrollment, and fraud mitigation. You can review that model in NIST SP 800 63A.
That definition matters because a single selfie or document image does not equal identity proofing by itself. A document can be authentic while the presenter is an imposter. A face can match a document while the account context still looks suspicious.
How identity proofing works
Identity proofing usually starts with identity resolution. The institution collects core identity attributes and enough evidence to decide that the claimed person exists as a unique individual in the population it serves.
Next comes validation. Evidence such as government issued identity documents, authoritative data sources, and key attributes are checked for authenticity and consistency.
Then comes verification. The institution confirms that the person presenting the evidence is the person tied to it, often through face matching, liveness testing, or another binding step.
Last comes enrollment or decisioning. If confidence is high enough, the bank opens the account, restores access, or approves the step up event. If confidence is weak, the request is declined or sent for review.
Common identity proofing methods
No single method answers every risk question. That is why effective identity proofing combines evidence checks, person binding, and contextual signals.
Document validation checks whether an identity document appears authentic and unaltered. Biometric comparison checks whether the presenter matches the face or trait tied to that document. Liveness testing checks that the sample came from a live human rather than a replay or synthetic artifact.
Data validation checks whether core attributes align with trusted sources. Device and channel signals add more context by showing whether the request comes from a familiar environment or an unusual one.
For banks that want a broader trust layer after enrollment, digital account authentication adds device, behavioral, and channel context to later decisions.
Where banks use identity proofing
Identity proofing is often associated with digital account opening, but that is only one use case. It is also valuable when an existing customer tries to recover access, register a new device, raise a payment limit, change sensitive profile data, or add a new transfer destination.
These are high consequence moments because the requester may already know personal details or hold stolen account data. Entersekt applies identity verification to critical moments such as account recovery, trusted device registration, and other elevated risk interactions. That makes identity proofing part of fraud control, not only a front door check.
In the broader journey, identity proofing works alongside digital banking and fraud prevention controls that assess user behavior, transaction context, and scam signals.
Identity proofing, identity verification, and authentication
Identity proofing is the broad process. Identity verification is one part of that process. Authentication comes later, when the institution tests whether a person or device should be trusted for access or action.
This distinction is easy to miss. You can authenticate a session successfully and still have risk if the original identity was never established well, or if the request now looks inconsistent with known behavior.
That is why banks increasingly connect proofing to later controls. Entersekt links authentication to transaction context, which helps financial institutions ask a better question than “is this the user?” The more useful question is whether this user should be doing this action right now.
For institutions reducing reliance on shared secrets, passwordless authentication can reduce exposure to phishing and impersonation after the proofing stage is complete.
Regulatory and standards context for financial institutions
For financial institutions, identity proofing sits close to customer identification and access control obligations. In the United States, Customer Identification Program rules require risk based procedures for verifying the identity of each customer to the extent reasonable and practicable. The core rule is outlined in 31 CFR 1020.220.
FinCEN guidance makes the same point in practical terms. A bank should design identity procedures around account type, opening method, available information, and customer risk. That position appears in FinCEN’s Customer Identification Program guidance.
FFIEC guidance extends the picture beyond onboarding. It explains that authentication and access controls should follow periodic risk assessment and fit customers, employees, third parties, and system access. The Federal Reserve hosts that FFIEC interagency guidance.
Why identity proofing must extend beyond onboarding
Identity risk does not end after enrollment. Criminals target recovery flows, device changes, beneficiary setup, and scam driven payment activity because these moments can reset trust or move funds quickly.
A bank that only proofs identity at account opening leaves later gaps. Account takeover often begins after a valid login, then expands through profile changes, payee setup, or social engineering that persuades the account holder to act.
Entersekt supports high risk decisions across logins, account changes, and transactions by combining identity verification, device signals, and risk aware authentication. That approach lines up with the move from simple identity checks to stronger trust decisions across the customer journey.
Entersekt’s account takeover guidance highlights how identity theft and manipulation form part of a broader fraud pattern.
In practice: making identity proofing useful to banks
Good identity proofing is proportionate. The control should match the risk of the action, the channel, the customer context, and the cost of being wrong.
For low risk events, a bank may only need modest assurance. For account opening, account recovery, wire setup, or large value money movement, the bank may need stronger evidence, tighter binding, and more reviewable records.
The goal is not to collect every possible signal. The goal is to make a defensible trust decision that regulators, fraud teams, and customers can all understand.
FAQs about Identity Proofing
➡️ What is identity proofing in simple terms?
Identity proofing is the process of confirming that a claimed identity belongs to a real person. It also confirms that the person presenting that identity is the rightful owner before access, enrollment, or a sensitive action is approved.
➡️ Is identity proofing the same as KYC?
No. Identity proofing is one control used in KYC and related onboarding programs. KYC also covers customer due diligence, risk profiling, beneficial ownership for certain entities, and monitoring tied to anti money laundering obligations.
➡️ Is identity proofing the same as authentication?
No. Identity proofing establishes who a person is at a required confidence level, while authentication tests trust for access or action later. Entersekt connects authentication to context so high risk actions can receive closer scrutiny than routine activity.
➡️ When should a bank use identity proofing?
A bank should use identity proofing whenever a mistake could hand control or funds to the wrong person. Entersekt applies identity verification to moments such as account recovery, new device registration, and other elevated risk requests.
➡️ What methods are used in identity proofing?
Identity proofing can include document validation, attribute checks, biometric comparison, liveness testing, and contextual risk signals. Entersekt adds device and transaction context so an identity check can support a stronger decision, not a point check alone.
➡️ Why is identity proofing important in fraud prevention?
Identity proofing is important because many fraud events begin with impersonation or account control abuse. When a bank confirms both identity and context, it is better placed to stop account takeover, recovery fraud, and scam related account changes.