IDV Article
Every identity provider claims to stop fraud. Ask how many good customers they lose.
We spoke with Raul Liive to translate Veriff’s latest executive insights into six sharp questions every payments leader should ask before signing their next identity agreement.
At Money20/20 USA 2026, fraud catch rates will be on every booth. Few providers will tell you how many good customers they turn away, or how long a decision takes.
Those numbers matter more than ever. AI agents now initiate payments, real-time rails leave little room to decide, and embedded finance spreads accountability across partners.
Raul Liive, Product Director at Veriff, shares six questions to ask before you sign.

1. How do you tie an AI agent’s actions back to a verified human?
AI agents already act on behalf of people and businesses. Some identify themselves through agent protocols. The best will mimic humans convincingly; the worst won’t announce themselves at all.
So don’t try to spot the agent. Assume any session could be one, and decide which actions require the human. A new payee, a payout change or a high-value order may need live confirmation from the real person. That’s your call, because only you know your risk appetite. Your identity provider’s job is to make that policy enforceable.
Green flag: Fast re-confirmation that the person present is the same one verified at onboarding, triggered at the moments you define.
Red flag: Claiming to reliably detect agents, or treating a valid agent protocol as proof of the human behind it.
2. Can you stop GenAI fraud without hurting conversion?
Deepfakes and AI-generated documents are cheap to produce at scale. Every provider will quote a catch rate. Few will quote what it costs you.
Tighten detection and you turn away real customers. As our CTO Hubert Behaghel puts it, rejecting a good customer can cost a business far more than missing a fraudster. That customer doesn’t retry. They go to a competitor.
The right balance differs by use case. A payout change carries different stakes than a first deposit, so the thresholds shouldn’t be the same. A generic benchmark tells you little. Ask for both numbers on your own traffic.
Green flag: The provider shows fraud caught (FAR) and good users rejected (FRR) together, measured on your traffic, and tunes the balance per use case to your risk appetite and the cost of each error to your business.
Red flag: A 99% deepfake catch rate with no false rejection rate. That’s one column of the P&L.
3. Can you tell when one person is behind many accounts?
A clean document check proves the document is real. It doesn’t prove the person is new. Synthetic identities and fraud rings reuse the same faces, documents and devices to open account after account, each one passing on its own.
No single onboarding reveals the pattern. It only shows up across accounts.
Green flag: The provider detects repeat faces, documents and devices across accounts, flags fraud rings before they scale, and feeds those signals into your risk rules to trigger re-verification.
Red flag: Treating every onboarding as an isolated check.
4. Can your verification flow adapt by state and country?
Identity rules don’t stop at the border, or at the state line. In the US, biometric privacy laws such as Illinois’ BIPA set their own rules for consent, retention and deletion, and a growing number of states mandate age checks. Global platforms stack these on top of rules in the EU, the UK and beyond.
One flow can’t satisfy all of them. Get biometric consent wrong and the cost isn’t a delayed launch. It’s litigation.
Green flag: Consent, data retention and data residency configurable per jurisdiction, with documented biometric-privacy compliance and a clear timeline from rule change to live.
Red flag: One global flow with one consent screen, and a custom engineering ticket for every regulatory change.
5. Is your verification fast enough for real-time payments?
Real-time rails like FedNow and RTP settle in seconds, and payments are final. There’s no chargeback to fall back on. If identity isn’t confirmed before the money moves, the loss is yours.
That doesn’t mean verifying every payment. It means a fast identity check at the risky moments, with no customer parked in a review queue while the transaction waits.
Green flag: The provider states decision time as median, P90 and P95, so you see both the typical case and the tail.
Red flag: “Instant” or “real-time” claims with no definition of what’s being measured.
6. Will your verification hold up when your bank or payment partner audits it?
In embedded finance, the bank or payment provider behind your product carries regulatory risk for customers it never onboarded itself. As regulators tighten scrutiny, these partners now demand proof that every customer was properly verified, and they audit it.
A “pass” in your dashboard isn’t proof. If you can’t show what standard every approval met, your partner will treat the customer as unverified, and so will the regulator.
Green flag: A documented verification standard, agreed with you upfront, that every approval must pass, so you can show your partner exactly what “verified” means.
Red flag: Approvals with no defined standard behind them, decided by a black box you can’t explain to an auditor.

Where does Veriff stand on these questions?
We’re direct about our tradeoffs. We combine document authenticity, liveness, and device and network signals, and we’ll walk you through our accuracy so you can see the full conversion impact. We make fast IDV decisions, with an average decision time of around 6 seconds. And because we build our technology in-house, from biometrics to OCR, you have a single accountable partner across the identity stack.
Agentic commerce is a new problem, and the industry is still working out the answer – us included. We’ll show you exactly where our capabilities stand today and what we’re building toward. Be cautious of anyone who claims it’s fully solved.
Meet Veriff at Money20/20 USA, October 18–21, Las Vegas. Stop by to put these six questions to our team and see our identity verification in action.