Join our Newsletter — 33% off our NHI Course

In-Person Verification

In-Person Verification is the step used to confirm that the applicant is physically present and matches the identity presented during onboarding. It can occur face to face or through approved video-based methods. The purpose is to reduce impersonation risk and strengthen the reliability of remote identity verification.

What In-Person Verification Is Used For

In-person verification is a higher-assurance identity step used when an organisation wants stronger evidence that the applicant is physically present and corresponds to the identity being asserted. It is often reserved for onboarding paths where impersonation risk is higher or regulatory assurance is stronger.

The core value is that it adds a human presence check to identity proofing. That can be done face to face, or through approved remote video procedures that preserve the same verification intent while reducing travel and operational friction.

How In-Person Verification Works

The process typically compares the live person to submitted identity evidence, then checks that the presenter is the same individual associated with the application. Depending on the programme, the verifier may inspect a government-issued document, ask challenge questions, or review liveness and document authenticity through a controlled video session.

What matters is not the setting alone, but the quality of the identity-binding step. A weak process that only looks presentable on camera can still fail if it does not reliably detect impostors, stolen documents, or proxy applicants.

In practice, organisations use this step as one part of a broader identity assurance model, not as a standalone guarantee. It supports later access decisions, but it does not replace credentialing, policy enforcement, or ongoing account protection after onboarding.

Security Implications of In-Person Verification

When done well, this step reduces impersonation, synthetic identity abuse, and enrolment fraud. It is especially useful where the downstream account or entitlement is sensitive, such as regulated services, high-value financial activity, or systems with strong access consequences.

It can also improve trust in the initial identity record, which matters because onboarding mistakes often become durable security problems later. If the wrong person is admitted at the start, every later control inherits that error.

For identity-heavy verification flows, OWASP ASVS is a useful companion reference because it covers the surrounding authentication, session, and access-control requirements that depend on trustworthy identity proofing.

When In-Person Verification Matters Most

This control becomes most important when remote onboarding creates meaningful risk, when the legal or contractual standard requires stronger proof of presence, or when fraud attempts tend to cluster around account opening. It is also relevant where an organisation needs a defensible audit trail for who was verified, how, and under what procedure.

Video-based approval can be acceptable, but only if it is governed as a controlled verification method rather than treated as a casual substitute for face-to-face review. The better the procedure, the more it helps prevent downstream identity compromise and disputed enrolment.

That is why the term is less about location and more about assurance: the organisation is choosing a verification method that raises confidence in the initial identity binding before access is granted.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP ASVS and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
OWASP ASVS V6 — Authentication In-person verification supports trustworthy authentication setup before account creation.
V8 — Authorization Verified identity underpins later access decisions and entitlement assignment.
Recommendation — Use V6 to require stronger identity proofing before issuing credentials. Use V8 to ensure access rights are granted only after reliable identity verification.
NIST SP 800-63 Digital Identity Guidelines The guideline family defines identity proofing and verifier assurance concepts relevant to in-person checks.
Recommendation — Apply NIST 800-63 identity-proofing guidance to set the required assurance level for onboarding.