Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM What is the difference between identity-proofing and identity…
Identity Beyond IAM

What is the difference between identity-proofing and identity comparison in eKYC?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 9, 2026 Domain: Identity Beyond IAM

Identity-proofing confirms that the submitted identity evidence is real and properly captured. Identity comparison checks whether the person in the selfie matches the portrait on the document and whether extracted personal details align with trusted records. Together, they solve different problems: proofing validates the inputs, while comparison validates that the applicant is the same person across those inputs.

Why identity-proofing and identity comparison are not interchangeable in eKYC

eKYC workflows often combine multiple checks, but they do not all answer the same question. Identity-proofing is about whether the identity evidence itself is credible, intact, and attributable to a real person. Identity comparison is about whether the applicant presented in one channel or image is the same person represented in another source, usually a document portrait or trusted record. Regulators and assurance frameworks treat those as separate assurance steps, so confusing them can leave a programme with a false sense of coverage. For the broader identity assurance context, the EU’s eIDAS 2.0 — EU Digital Identity Framework shows how identity confidence depends on distinct checks rather than a single binary approval.

When teams collapse the two concepts, they tend to over-trust one signal, such as a selfie match, even though the document or identity data may still be forged, altered, or captured from an untrusted source. The reverse error also happens: an apparently valid document can still belong to the wrong person if face matching or record matching is weak. In practice, many KYC teams discover this only after a fraud case or remediation review reveals that their “identity verification” step was actually only one half of the assurance chain.

How identity-proofing and identity comparison work together in practice

Identity-proofing usually answers whether the presented evidence can be relied on. That can include document authenticity checks, document capture quality, liveness or presentation-attack checks, and validating that extracted data is complete and consistent enough to support downstream decisions. The point is to reduce the chance that the pipeline accepts fabricated, altered, or mis-captured identity evidence.

Identity comparison then answers a different question: does the person now being assessed match the identity claims or reference artefacts already in the workflow? In a selfie-to-document flow, the comparison step checks facial similarity between the live capture and the identity document portrait. In a database-anchored flow, it may compare submitted details against authoritative records or previously enrolled data. The practical distinction matters because a strong comparison score cannot rescue weak proofing, and strong proofing cannot confirm that the applicant is the rightful subject if the comparison step is absent or poorly tuned.

  • Proofing evaluates the integrity and credibility of the identity inputs.
  • Comparison evaluates identity continuity across inputs, images, or records.
  • Both steps can fail independently, so one passing result should not be treated as end-to-end assurance.

In regulated onboarding, the best design is usually layered: first confirm the evidence is trustworthy enough to use, then confirm the applicant matches that evidence. FATF’s KYC expectations are relevant here because customer due diligence depends on verifying identity information, not merely collecting it, and that distinction affects how much confidence a firm can claim in the resulting profile. Where comparison is used as the only substantive control, the workflow breaks down as soon as the reference image, template, or record is weak, stale, or not reliably bound to the applicant.

Where the distinction breaks down in edge cases

Tighter verification often increases friction and false rejects, so organisations must balance assurance against onboarding completion and user experience. That tradeoff becomes sharper when the evidence source is low quality, cross-border, or inconsistent across documents and records.

Some eKYC flows blur the boundary because they run proofing and comparison inside one vendor journey, but that integration does not mean the functions are the same. A high-confidence document authenticity result can still coexist with a failed face match, and a successful face match does not prove that the document data was genuine. Guidance-vs-consensus is still evolving on the best ordering and weighting of these checks across different risk tiers, especially for remote onboarding and step-up verification.

Edge cases also arise when there is no reliable portrait to compare, when the identity document is not face-bearing, or when the customer is being enrolled through delegated or assisted channels. In those situations, the comparison step may need an alternative reference or additional assurance method rather than a forced selfie match. The answer is not to merge the concepts, but to choose the right control for the right assurance problem.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-63IAL — Identity Assurance LevelIdentity-proofing maps to identity evidence validation and assurance levels.
IAL2 — Identity Assurance Level 2Remote eKYC commonly targets stronger proofing and binding than basic registration.
AAL — Authenticator Assurance LevelComparison and binding support later authentication confidence after onboarding.
Recommendation — Set the required assurance level before accepting identity evidence. Use higher assurance checks when remote onboarding raises fraud exposure. Bind the verified identity to an authenticator that matches the required assurance.
NIST CSF 2.0PR.AA — Identity Management, Authentication, and Access ControleKYC assurance supports identity trust decisions that feed access and account creation.
Recommendation — Align onboarding checks with identity trust controls before provisioning access.
CIS Controls v85 — Account ManagementVerified identity quality directly affects account creation and lifecycle decisions.
Recommendation — Gate account creation on separately validated proofing and comparison results.

Practitioner Guidance

What to prioritise: Treat proofing as a document and evidence-assurance problem, and treat comparison as a subject-linking problem. If either one is missing, do not describe the process as full identity verification.

What to verify: Check that the workflow can show separate evidence for authenticity, capture quality, and matching confidence. Teams should be able to explain which failure caused a rejection, because that is often the fastest way to spot an over-reliance on one control.

Decision rule: If the main risk is forged or altered identity evidence, strengthen proofing first. If the main risk is impersonation or enrolment by the wrong person, strengthen comparison and binding to the applicant. The most common mistake is to tune for match accuracy while leaving the proofing layer too weak to trust the input.

Practitioner takeaway: The useful distinction is not academic. Identity-proofing answers “is this evidence believable,” while identity comparison answers “is this the same person,” and a mature eKYC design needs both answers before it can claim meaningful assurance.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 9, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org