Think Build Implement Repeat
London, UK +44 7367 067226
WhatsApp FOLLOW f in X
AI & Machine Learning

ID and Document Verification With Machine Learning

Last updated:

Manual checks do not scale and do not catch much

A lettings agency onboarding 150 tenants a month has a member of staff compare a scanned passport to a video call. A small lender does the same for loan applicants. It is slow, it annoys legitimate customers, and a good forgery on a phone screen passes easily because the person checking has never been trained to spot one.

Machine learning verification does the checks more consistently: reading the document, looking for tampering, comparing faces and confirming a live person is present. Done well, most genuine customers verify in minutes and staff only see the cases that look wrong.

Done badly, it rejects honest people with unusual documents, lets through sophisticated fraud and hands you a compliance problem. This is one area where we are firm about buy versus build.

What a verification flow checks

  1. Document capture. Guided photo of the document, with glare and blur checks.
  2. Classification. Identifying document type, issuing country and version.
  3. Data extraction. Reading printed fields and the machine-readable zone, and checking they agree.
  4. Authenticity checks. Fonts, layout, holograms, microprint patterns and signs of editing or screen replay.
  5. Chip reading. Where the device supports it, reading the passport or ID card chip, which is a much stronger check than the image.
  6. Face match. Comparing the document photo to a live selfie.
  7. Liveness. Confirming a real person is present rather than a photo, mask, screen or deepfake video.

Each step has its own failure modes, and fraudsters target the weakest one. Deepfake injection attacks, where a synthetic video is fed into the camera stream, are a growing concern that verification providers now invest heavily to counter.

Why we usually recommend buying the core checks

ConsiderationEstablished providerBuilding in-house
Document coverageThousands of document types and versionsEach new document type needs samples and work
Fraud researchDedicated teams tracking new attack methodsYou find out about new attacks from losses
CertificationOften certified against recognised standardsYou would need to achieve and maintain it
Cost at low volumePer-check feeHigh fixed cost
Control and flexibilityLimited to their API and rulesFull

The document and face models are the part that takes years to get right and never stops needing work. A small business building them in-house is taking on a permanent fraud research programme. For almost every client, we would integrate a provider for the core checks and build the surrounding workflow ourselves.

Where the custom work actually sits

  • Risk-based routing. Low-risk customers get a light check; higher-risk ones get chip reading and enhanced checks. The rules reflect your regulatory position, not the provider's defaults.
  • Combining signals. Verification results alongside device data, address checks, sanctions screening and your own history.
  • Proof of address and supporting documents. Bank statements, utility bills and payslips need document extraction and consistency checks that ID providers often do not cover well.
  • Review queues. A clear screen for compliance staff showing why a case was referred, with the evidence.
  • Audit trails. Records of what was checked, when, and what decision was made by whom.

This is the kind of joined-up onboarding build that our AI integration projects cover, and it is where most of the conversion and compliance improvement comes from.

Bias, exclusion and fairness

Face matching and liveness models have historically performed unevenly across skin tones, ages and some disabilities. Document checks can fail on older or less common documents. The result is that some legitimate customers are rejected more often than others.

  • Ask providers for performance data across demographic groups and document types
  • Always offer a fallback route, such as manual review or an in-person check
  • Monitor rejection and referral rates by document type and, where lawful, by group
  • Remember that face matching uses biometric data, which carries extra obligations under UK and EU data protection law
A verification flow is judged by how it treats the honest customer with an unusual passport, not the demo with a perfect one.

When you might not need it

If regulations do not require identity verification and the risk of impersonation is low, adding a document and selfie step costs conversions for little benefit. A lighter check, such as verified email, payment card checks or a database-based identity check, may be proportionate. Check what your sector actually requires before designing the flow; it varies a great deal between lettings, lending, gambling, crypto, recruitment and healthcare.

Questions SpiderHunts would ask first

Which regulations apply to you, and in which countries? What is your monthly volume and expected growth? Which documents do your customers typically hold? What happens to a customer who fails? The answers point to a provider shortlist and a workflow design within a couple of conversations, well before anyone writes code.

At SpiderHunts we also ask to see your current referral and drop-off numbers, if you have them. A verification step that is technically excellent but loses a fifth of genuine applicants at the selfie screen is a commercial problem, and it is usually fixable with better capture guidance, clearer copy and a sensible fallback route. Measure completion rate by device and document type from the first week, because that is where the quiet losses hide.

Frequently asked questions

How does AI verify an ID document?

It classifies the document type, reads the printed data and machine-readable zone, checks security features and layout for signs of tampering, and often reads the chip where available. It then compares the document photo to a live selfie and checks the person is physically present.

What is a liveness check?

A liveness check confirms that a real person is in front of the camera, not a printed photo, a screen, a mask or a synthetic video. It can be passive, analysing a single capture, or active, asking the person to move.

Should we build our own ID verification system?

Rarely. Established providers cover thousands of document types and invest continuously in fraud research. Building the surrounding workflow, risk rules and review tools is usually where custom development adds real value.

Does ID verification with face matching fall under GDPR?

Yes. Face matching for identification uses biometric data, which is special category data under UK and EU data protection law. You need a lawful basis, an appropriate condition, clear information for users and usually a data protection impact assessment.

Keep reading

Onboarding stuck on manual ID checks?

Tell us your onboarding volumes, where you operate and what your compliance team needs to see. We will help you decide between a verification provider and a custom layer on top.

Book a free 30-minute call Get a project estimate WhatsApp us

Related services

What we build for problems like this one

AI AgentsMachine LearningAI Integration