Online identity verification: methods, PVID and assurance levels
Verifying a person's identity remotely has become a prerequisite for any digitized banking, insurance or contractual journey. This guide reviews the available methods, the ANSSI's PVID framework and the assurance levels of the eIDAS regulation, to help you choose a solution that is both seamless and compliant.
Regulatory framework for remote identity verification
In France, identity verification is first governed by due diligence obligations under anti-money laundering and counter-terrorism financing (AML-CTF) rules, which require identifying and verifying the customer's identity before establishing a business relationship. When this verification is conducted remotely, it relies on the PVID framework (Remote Identity Verification Providers) published by ANSSI, and aligns with the assurance levels defined by the European eIDAS regulation. The choice of level depends on risk: the higher the stakes, the stronger the assurance required on identity.
To move from theory to practice, discover the Certyneo electronic signature solution and its offer dedicated to your sector — eIDAS compliant, no installation required.
- Monetary and Financial Code (art. L. 561-5 et seq.): obligation to identify and verify the customer's identity.
- ANSSI's PVID framework: security requirements for remote identity verification, with substantial and high assurance levels.
- eIDAS Regulation: assurance levels low, substantial and high for electronic identification.
- Order of 6 September 2021 (remote AML-CFT): additional due diligence measures in the absence of physical presence.
Elements verified during an online identity check
Steps in an online identity verification
- 1
Document collection
The customer photographs or scans their identity document; data is extracted automatically and format is checked.
- 2
Authenticity check
The document's security features are analyzed (holograms, MRZ, NFC chip) to detect forgery or counterfeiting.
- 3
Biometric matching and liveness
A facial capture with liveness detection confirms that the person present is indeed the holder of the document.
- 4
Decision and traceability
The result (accepted, to review, refused) is logged with timestamped proof, ready for AML-CFT audit.
Frequently asked questions
- What is the difference between identification and identity verification?
- Identification consists of collecting declared identity elements (name, surname, date of birth). Verification consists of ensuring, on the basis of reliable evidence and technical checks, that these elements are accurate and that the person is indeed their holder.
- What is the ANSSI PVID framework?
- PVID regulates remote identity verification service providers in France. It defines security requirements across two levels, substantial and high, covering in particular document verification, facial biometrics and liveness detection.
- Which eIDAS assurance level to choose?
- This depends on the risk of the use case: a substantial level is suitable for many customer onboarding journeys, while the high level is required for the most sensitive uses, such as certain qualified signatures or access to state services.
- Is remote verification as reliable as in-branch verification?
- When properly equipped, it can achieve an equivalent or even higher assurance level, thanks to NFC reading, liveness detection and automated screening. The PVID framework is specifically designed to secure this remote journey.
- How long should verification evidence be retained?
- In the AML/CFT framework, identification elements and verification evidence are generally retained for five years after the end of the business relationship, in order to respond to requests from authorities.
Related guides and solutions
Explore the related resources from our electronic signature hub.