Go to main content
Certyneo
Identity verification

Online identity verification: methods, PVID and assurance levels

Verifying a person's identity remotely has become a prerequisite for any digitized banking, insurance or contractual journey. This guide reviews the available methods, the ANSSI's PVID framework and the assurance levels of the eIDAS regulation, to help you choose a solution that is both seamless and compliant.

Updated on

Regulatory framework for remote identity verification

In France, identity verification is first governed by due diligence obligations under anti-money laundering and counter-terrorism financing (AML-CTF) rules, which require identifying and verifying the customer's identity before establishing a business relationship. When this verification is conducted remotely, it relies on the PVID framework (Remote Identity Verification Providers) published by ANSSI, and aligns with the assurance levels defined by the European eIDAS regulation. The choice of level depends on risk: the higher the stakes, the stronger the assurance required on identity.

To move from theory to practice, discover the Certyneo electronic signature solution and its offer dedicated to your sector — eIDAS compliant, no installation required.

  • Monetary and Financial Code (art. L. 561-5 et seq.): obligation to identify and verify the customer's identity.
  • ANSSI's PVID framework: security requirements for remote identity verification, with substantial and high assurance levels.
  • eIDAS Regulation: assurance levels low, substantial and high for electronic identification.
  • Order of 6 September 2021 (remote AML-CFT): additional due diligence measures in the absence of physical presence.

Elements verified during an online identity check

Official identity document (national identity card, passport, residence permit) and verification of its authenticity.
Selfie or video capture of the person to establish the link between the bearer and the document.
Liveness detection to rule out photos, masks and video replays.
Reading the NFC chip of the document when it exists, a guarantee of enhanced assurance.
Consistency of extracted data (surname, given name, date of birth) with declared information.
Cross-verification with a certified digital identity when the customer has one.

Steps in an online identity verification

  1. 1

    Document collection

    The customer photographs or scans their identity document; data is extracted automatically and format is checked.

  2. 2

    Authenticity check

    The document's security features are analyzed (holograms, MRZ, NFC chip) to detect forgery or counterfeiting.

  3. 3

    Biometric matching and liveness

    A facial capture with liveness detection confirms that the person present is indeed the holder of the document.

  4. 4

    Decision and traceability

    The result (accepted, to review, refused) is logged with timestamped proof, ready for AML-CFT audit.

Frequently asked questions

What is the difference between identification and identity verification?
Identification consists of collecting declared identity elements (name, surname, date of birth). Verification consists of ensuring, on the basis of reliable evidence and technical checks, that these elements are accurate and that the person is indeed their holder.
What is the ANSSI PVID framework?
PVID regulates remote identity verification service providers in France. It defines security requirements across two levels, substantial and high, covering in particular document verification, facial biometrics and liveness detection.
Which eIDAS assurance level to choose?
This depends on the risk of the use case: a substantial level is suitable for many customer onboarding journeys, while the high level is required for the most sensitive uses, such as certain qualified signatures or access to state services.
Is remote verification as reliable as in-branch verification?
When properly equipped, it can achieve an equivalent or even higher assurance level, thanks to NFC reading, liveness detection and automated screening. The PVID framework is specifically designed to secure this remote journey.
How long should verification evidence be retained?
In the AML/CFT framework, identification elements and verification evidence are generally retained for five years after the end of the business relationship, in order to respond to requests from authorities.
Electronic signature guide · Banking & insurance solutions · Understanding the eIDAS regulation

Related guides and solutions

Explore the related resources from our electronic signature hub.

Verify your customers' identity in full compliance

Integrate a smooth and AML/CFT-compliant remote identity verification journey, backed by Certyneo electronic signature.

Certyneo Community

A question about electronic signatures?

Join the Certyneo community: ask your questions, share your answers and connect with thousands of users and our team.