TL;DR: Identity verification has become a core control for reducing identity theft, protecting sensitive data and supporting compliance as cyber attacks, data breaches and online financial crime increase, according to Yoti. The governance question is no longer whether to verify, but how to do it in ways that are proportionate, privacy-preserving and operationally defensible.
NHIMG editorial — based on content published by Yoti: Identity verification: the facts
By the numbers:
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security.
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage.
Questions worth separating out
Q: How should organisations reduce privacy risk in identity verification workflows?
A: Reduce privacy risk by removing unnecessary human access from the standard verification path.
Q: When does identity verification become more than a signup control?
A: It becomes a governance control when the platform uses it to decide who can join, when trust must be revalidated, and which accounts should be reviewed or restricted.
Q: What do security teams get wrong about identity verification for support requests?
A: They often rely on static personal data, a return call, or a quick manager check as if that were enough to defeat social engineering.
Practitioner guidance
- Define assurance thresholds for each flow Set different proofing requirements for onboarding, account recovery, payments and high-risk step-up events.
- Minimise identity data collected and retained Document which attributes are required, which are optional and how long each piece of evidence is stored.
- Link verification outcomes to lifecycle controls Feed proofing results into step-up authentication, manual review, recovery policy and account revocation workflows.
What's in the full article
Yoti's full article covers the product and policy context this post intentionally leaves for the source:
- The specific verification use cases Yoti is positioning for identity assurance, age checks and fraud reduction.
- The way Yoti frames privacy, biometric data handling and user choice across its identity products.
- The product-level explanation of how its verification approach fits into digital ID and authentication workflows.
- The surrounding article series and opinion context that inform Yoti's broader identity verification position.
👉 Read Yoti's identity verification overview and privacy-focused facts →
Identity verification and fraud risk: what should teams do now?
Explore further
Identity verification is now a governance control, not just a front-end check. The article is right to frame verification as a response to fraud, but practitioners should treat it as part of identity assurance architecture. Once verification is used to unlock onboarding, recovery or regulated transactions, its decisions become control decisions. That means policy, evidence quality and exception handling matter as much as the tooling itself. For identity and fraud teams, the practical conclusion is that verification must be governed like any other access gate.
A question worth separating out:
Q: Who is accountable when digital identity proof fails in a regulated workflow?
A: Accountability sits with the relying party and the organisation that designed the trust process, not just the provider that issued the certificate. Frameworks like eIDAS and internal governance both matter because the business must prove why the trust decision was acceptable.
👉 Read our full editorial: Identity verification is now a core control for online trust