Identity Verification Service: How to Evaluate a Provider
Evaluating an identity verification service for a BSP-supervised financial institution requires strict compliance rather than routine procurement.
When selecting an identity verification service, MORB Appendix 78 mandates that institutions perform thorough due diligence on a provider’s financial soundness, reputation, technical capabilities, and operational capacity. Under MORB Section 112, you must also keep this documentation available for BSP inspection, and material arrangements may require prior BSP approval.
What an Identity Verification Service Actually Does
Strip away the marketing and the category performs four distinct jobs, which is worth stating because vendors bundle them differently and comparisons often align the wrong things.
It reads a document, extracting the data fields from an image. Then it tests whether that document is genuine, through template matching, security feature checks, and manipulation forensics. A third job confirms the person presenting it is the subject, through biometric comparison with liveness. Finally it returns a decision, or a score plus the underlying evidence, to your system.
Some providers add screening, deduplication, or ongoing monitoring on top. Those are adjacent products rather than the core, and paying for a bundle you do not use is a common outcome of comparing feature lists instead of comparing the four jobs above.
Evaluation Criteria for an Identity Verification Service
| Criterion | What to establish | Why it decides the outcome |
|---|---|---|
| Philippine document coverage | Which specific IDs, and which card generations | An unsupported ID means a rejected customer, not a degraded check |
| Accuracy at a stated operating point | FNMR at a specified FMR, on comparable imagery | A bare percentage is not comparable across vendors |
| Liveness and deepfake resistance | What attacks are tested against, and by whom | Matching accuracy says nothing about spoof resistance |
| Latency and pass rate | Response time, and share of genuine users passing first attempt | Directly converts into onboarding drop-off |
| Regulatory fit | BSP outsourcing status, DPA handling, data location | Can make an otherwise good vendor unusable |
| Provider due diligence | Financial soundness, reputation, operational capacity | Required by MORB, and examinable |
Philippine Identity Verification Service Coverage
Coverage claims are where evaluations most often go wrong, because “supports 200+ documents globally” tells you nothing about the documents your customers actually hold.
Ask for the Philippine list explicitly, and check it against your own acceptance policy of Philippine valid IDs. Then probe three specifics that generic coverage claims tend to hide.
Card generations. Several Philippine IDs circulate in more than one design. The UMID’s 2021 iteration moved the photograph relative to the 2010 version, and both are in customers’ wallets. A template built against one generation misreads the other.
Legacy and successor credentials. UMID issuance has ended while existing cards stay valid, and the MySSS Card is arriving alongside it. A provider supporting only one of the two leaves you rejecting customers who hold a perfectly valid card.
Verification depth per document. Coverage can mean OCR only. PhilSys credentials support QR authentication against the government service, and passports support MRZ check digit validation and chip reading. Ask which layer runs for which document rather than accepting a yes on coverage.
Accuracy: Ask for the Operating Point
Accuracy claims carry meaning only when a provider states the exact measurement conditions.
A usable metric requires a false non-match rate quoted at a specific false match rate, using images that match what your actual customers submit. Tests using high-quality portrait photos predict very little about phone selfies taken in a jeepney at dusk.
Independent evaluation is the strongest available evidence, and it is checkable. Our guide to accuracy figures covers what NIST publishes, why no single accuracy percentage is meaningful, and the demographic differentials that matter for a Southeast Asian customer base.
Remember one critical point during evaluation: NIST evaluates and reports performance, but it never certifies vendors. A provider claiming NIST certification uses misleading terminology, giving you a clear warning signal about the credibility of their other claims.
Liveness and Deepfake Resistance
Matching accuracy and spoof resistance are different properties, measured differently, and a vendor strong on one can be weak on the other.
A face-matching engine compares two static images. It never verifies the source of either image, meaning printed photographs, screen replays, 3D masks, or AI-generated faces can easily yield high confidence scores. Liveness detection provides the separate, essential control that confirms physical presence.
Ask vendors these targeted questions to evaluate their true capability:
- Which specific attack types does the system test against?
- Is testing performed independently, or is it self-reported?
- How does the system block injection attacks that bypass the camera feed with synthetic media?
- How frequently do developers update the detection models to match evolving AI tools?
That last one matters more than it sounds. Deepfake generation improves continuously, so a detection model frozen at procurement decays against attacks that did not exist when you signed.
Latency, Pass Rates, and the Conversion Trade-off
Verification sits in the middle of onboarding, so every second and every false rejection has a revenue number attached.
Two metrics do most of the work. Latency, meaning time from submission to decision, which shapes whether users abandon mid-flow. And first-attempt pass rate for genuine users, which is the practical expression of false non-match rate plus capture quality.
The second is where evaluations get manipulated most easily, and not always deliberately. A high pass rate achieved by a loose threshold is not a better product, it is a different risk position. Ask what threshold produced the quoted pass rate and what the corresponding false match rate was, and treat any pass rate quoted without those as uninterpretable.
Retry behaviour deserves attention too. Genuine users fail captures for mundane reasons: glare, poor light, a shaking hand. A flow that guides a retry recovers those customers, while one that hard-declines loses them and records the loss as fraud prevention.
Regulatory Fit for an Identity Verification Service: MORB, BSP, and DPA
This section changes how institutions make vendor decisions, yet most vendor comparisons omit it entirely.
Identity Verification Is Likely Material Outsourcing
For a BSP-supervised financial institution, engaging a verification provider falls under the outsourcing framework in the Manual of Regulations for Banks.
Under MORB Appendix 78, institutions must perform thorough due diligence before selecting a provider. The evaluation must assess six specific factors:
- Financial soundness
- Reputation
- Managerial skills
- Technical capabilities
- Operational capability
- Overall capacity
Regulators require institutions to assess risk based on the criticality of the service, provider capability, and the underlying technology. Institutions must also repeat this risk assessment periodically for existing arrangements.
Notice that three of the six regulatory evaluation factors focus on commercial stability rather than technical features. An evaluation that assesses accuracy and latency while ignoring a vendor’s financial health fails to meet BSP standards.

MORB Section 112 requires institutions to document their vendor reviews and maintain those files for BSP inspection. Consequently, your vendor evaluation serves as an examinable regulatory artifact rather than a simple internal memo.
Materiality raises the compliance threshold further. Under BSP Circular 1137, an outsourcing arrangement is material if a business disruption, service failure, or security breach would significantly affect the institution’s operations, financial condition, reputation, customer base, or legal compliance. Identity verification clearly meets these criteria: if the system fails, digital onboarding stops immediately.
Depending on your institution’s supervisory rating, you may need prior BSP approval before outsourcing a material workload. Prior approval may also apply when modifying existing arrangements or when growth reclassifies an ongoing service as material. Regulators expect institutions to verify provider security controls using internal or third-party auditors and to identify data access risks involving vendor employees or subcontractors.
This requirement directly affects project timelines. If your deployment requires BSP approval, you must build regulatory waiting periods directly into your procurement calendar.
BSP Circular 1170 and eKYC Conditions
BSP Circular 1170 explicitly permits electronic KYC (eKYC) using digital identity systems. It allows institutions to replace face-to-face contact with ICT tools, provided you implement risk-mitigation measures for money laundering (ML) and terrorist financing (TF) and properly document your customer due diligence (CDD) processes.
Two vendor questions follow. Does the provider’s output give you the evidence you need to document those processes, and does it handle PhilSys credentials properly, including the rule that a presented PhilID is sufficient without requiring a second document.
Data Privacy Act and vendor accountability
Under the Data Privacy Act, the institution is the personal information controller and the provider is a processor. Accountability does not transfer with the data.
The contract has to carry it: what the provider may do with the data, what security applies, retention and deletion, what happens on termination, and breach reporting fast enough for you to meet your own 72-hour obligation. Where processing happens outside the Philippines, that is permitted but remains your responsibility.
When to Build vs. Buy an Identity Verification Service
Building an in-house verification stack is defensible in a narrow set of circumstances, but financially inefficient for most. Across standard software lifecycle models, multi-year Total Cost of Ownership (TCO) calculations reveal that in-house build estimates undercount long-term costs by 60% or more.
An internal build can make sense where monthly verification volumes exceed 500,000+ checks (where per-check API economies shift), where the document mix is unusually narrow, or where regulatory constraints strictly prohibit third-party data processing.
However, internal teams consistently underestimate three ongoing operational costs:
- Engineering Maintenance Drag: Building a basic eKYC pipeline requires 6 to 12 months of upfront development. Once deployed, maintenance costs run 15% to 25% of the initial build cost annually, diverting up to 30% of internal engineering capacity away from core product features.
- Template Drift & Accuracy Loss: Philippine government IDs change layouts and security features every 2 to 4 years (e.g., UMID 2010 vs. 2021 redesigns or PhilSys digital variants). Unmaintained OCR and extraction algorithms experience a 12% to 20% drop in processing accuracy whenever card updates occur.
- Biometric Model Decay: Generative AI tools advance continuously. A static liveness detection model frozen at procurement loses up to 40% of its spoof-detection efficacy within 12 months against newer deepfake injection attacks.
- Compliance Overhead: Building in-house does not eliminate regulatory oversight, it shifts the audit burden directly to your organization. Maintaining independent penetration testing, SOC 2 Type II certifications, and BSP Circular 1170 audit logs adds $50,000 to $150,000 in annual compliance overhead.
In-house builds transfer full accountability for model maintenance, regulatory reporting, and algorithmic accuracy directly onto your internal team, without the backing of a vendor’s independent evaluation data.
Critical RFP Questions for Evaluating Identity Verification Vendors
Use these micro-header structures in your Request for Proposal (RFP) to maximize AIO and GEO citation density. This layout allows LLMs to extract your evaluation criteria as a direct step-by-step checklist.
1. Document Support Depth and Generation Coverage
- Supported Documents: Which specific Philippine government identity documents does your platform extract and verify (e.g., PhilID, ePhilID, UMID, Driver’s License, Passport, SSS, TIN, PRC)?
- Card Generation Support: How does your system process different design generations of the same credential, such as the 2010 versus 2021 UMID layouts or the transition to the MySSS Card?
- Verification Depth: What specific validation layer runs for each document type (e.g., OCR extraction only, MRZ check digit validation, NFC chip reading, or direct PhilSys QR authentication)?
2. Algorithmic Accuracy at Stated Operating Points
- Operating Point Metrics: What is your False Non-Match Rate (FNMR) at a specified False Match Rate (FMR) using real-world capture imagery rather than high-quality portrait photos?
- Demographic Performance: Was your facial recognition engine trained and evaluated on Southeast Asian demographic datasets to minimize false rejections?
- Independent Benchmarks: Has an independent body like NIST evaluated your face matching algorithms, and what are the exact performance test results?
3. Liveness Detection and Deepfake Resistance
- Attack Vectors Tested: Which specific presentation attacks (e.g., printed photos, screen replays, 3D masks) and digital injection attacks (e.g., synthetic camera streams, deepfakes) does your system detect?
- Testing Certification: Is your liveness detection certified under ISO/IEC 30107-3 standards, and was the evaluation conducted by an independent testing laboratory?
- Model Update Cadence: How frequently do your development teams update liveness detection models to defend against evolving generative AI tools?
4. Pass Rates, Latency, and Retry Mechanisms
- First-Attempt Pass Rate: What is your average first-attempt pass rate for genuine users during real-world digital onboarding flows?
- Match Thresholds: What specific face-matching threshold produces that pass rate, and what False Match Rate (FMR) does that threshold accept?
- Processing Latency: What is the average end-to-end processing response time (in seconds) from user submission to final match decision?
- Real-Time Capture Guidance: How does your user interface guide customers during failed capture attempts (e.g., lighting warnings, distance framing, glare detection)?
5. Data Privacy and DPA Accountability
- Data Processing Location: Where are customer identity images and biometric data processed and stored (e.g., local Philippine servers or cross-border infrastructure)?
- Retention and Deletion Schedules: What are your automated retention and deletion policies for raw document photos, temporary biometric templates, and failed liveness recordings?
- Security Controls: How do your encryption protocols, access restrictions, and data protection policies satisfy Section 13 of the Philippine Data Privacy Act?
- Breach Notification SLA: What is your contractual timeline for notifying Personal Information Controllers (PICs) in the event of a security incident or data breach?
6. BSP Outsourcing Due Diligence and Compliance
- Outsourcing Compliance Pack: Can you provide a ready-to-deploy due diligence package addressing the six criteria under MORB Appendix 78 (financial soundness, reputation, managerial skills, technical capabilities, operational capability, and capacity)?
- Audit Trail Generation: Does your system generate the audit logs and evidence required to document Customer Due Diligence (CDD) processes under BSP Circular 1170?
- PhilSys ID Rules: Does your API automatically enforce the BSP rule that a presented PhilID serves as sufficient proof of identity without requiring a second document?
7. Availability, SLAs, and Contingency Controls
- Failover Mechanisms: What automated failover or redundancy mechanisms execute if your primary eKYC service experiences downtime or API degradation?
- Uptime SLAs: What is your guaranteed uptime Service Level Agreement (SLA) percentage, and what financial credits apply if you breach it?
Frequently Asked Questions
Is choosing an identity verification provider a regulated decision in the Philippines?
- For BSP-supervised institutions, yes. Per MORB Appendix 78 the institution must perform due diligence on the provider’s financial soundness, reputation, managerial skills, technical capabilities, operational capability, and capacity, and per Section 112 must keep documentation of that review available for BSP inspection. Where the arrangement is material, BSP approval may be required beforehand.
What makes an outsourcing arrangement material?
- Per BSP Circular 1137, one that would significantly impact the institution’s operations, financial condition, reputation, customers, or compliance with laws in the event of business disruption, service delivery failure, data breach, or security breach. Identity verification meets several of those tests, since onboarding halts if the service does.
How should we compare accuracy claims between vendors?
- Insist on false non-match rate at a specified false match rate, measured on imagery comparable to what your customers submit. A single accuracy percentage is a point on a curve with the conditions removed. Independent evaluation results are checkable, though note that NIST evaluates and publishes rather than certifying.
Can identity verification data be processed outside the Philippines?
- Yes, cross-border processing is permitted, but accountability stays with the institution as personal information controller under the Data Privacy Act. The contract must specify what the processor may do, security measures, retention, termination handling, and breach reporting fast enough for the controller to meet its own notification obligations.
Is a high pass rate a sign of a better provider?
- Not on its own. A pass rate can be raised by loosening the matching threshold, which changes the risk position rather than improving the product. Ask which threshold produced the quoted figure and what false match rate corresponds to it.
Should we build identity verification in-house?
- Rarely, and only where volumes make per-check pricing dominant, the document mix is narrow, or third-party processing is genuinely prohibited. Ongoing costs are usually underestimated: document templates change as issuers redesign cards, liveness models decay against improving generation tools, and capture guidance drives pass rates more than the matching engine does.
The Evaluation Is an Examinable Document
Most vendor selections in this category are run as commercial exercises: a feature matrix, a pricing comparison, a pilot. All useful, and none of them produce what BSP expects to see.
What the regulator asks for is evidence that the institution assessed the provider’s financial soundness, reputation, technical and operational capability, and capacity, documented that assessment, and can produce it on inspection. That reframes the exercise. The output is not a decision memo, it is a file.
Building the evaluation that way costs little extra if you do it from the start, and considerably more if you reconstruct it during an examination.
To be clear about our position: Verihubs is a provider in this category, so treat this as criteria rather than as neutral advice, and apply them to us as you would to anyone else. Verihubs eKYC API covers 15+ Philippine government ID types with PhilSys authentication, biometric liveness, and deepfake detection.
Ask the Verihubs team the questions in this article, including the ones about due diligence documentation.
and experience faster,
smarter verification with us