Identity evidenceVerify that the person and evidence presented are sufficiently trustworthy for the risk.
A remote process should make the identity-verification chain reviewable. Record what evidence is accepted, what attributes are captured, how authenticity/integrity are assessed, what data sources are used, how inconsistencies are handled, and which conditions trigger additional verification or human review.
Where the institution uses documents, electronic identification, video, biometrics, device signals, databases, or third-party identity services, define the role each signal plays in the decision. Avoid treating one technology as proof by itself when the overall risk model requires corroboration.
Build explicit failure paths for unreadable documents, mismatched attributes, suspected manipulation, repeated attempts, unsupported identity evidence, poor capture quality, unusual device/network behaviour, or other conditions that reduce confidence.