Verihubs Logo
Home Blog Identity Verification Services: How to Evaluate a Provider
16 min read ID Check Published on August 17, 2026

Identity Verification Services: How to Evaluate a Provider

Identity Verification Services: How to Evaluate a Provider

Most guidance on choosing an identity verification provider treats it as a procurement exercise. For a BSP-supervised financial institution it is something stricter.

Per MORB Appendix 78, the institution must perform due diligence on the provider’s financial soundness, reputation, managerial skills, technical capabilities, operational capability, and capacity, and per Section 112 must keep documentation of that review available for BSP inspection.

Where the arrangement is material, BSP approval may be required before you sign.

What an Identity Verification Service Actually Does

Strip away the marketing and the category performs four distinct jobs, which is worth stating because vendors bundle them differently and comparisons often align the wrong things.

It reads a document, extracting the data fields from an image. Then it tests whether that document is genuine, through template matching, security feature checks, and manipulation forensics. A third job confirms the person presenting it is the subject, through biometric comparison with liveness. Finally it returns a decision, or a score plus the underlying evidence, to your system.

Some providers add screening, deduplication, or ongoing monitoring on top. Those are adjacent products rather than the core, and paying for a bundle you do not use is a common outcome of comparing feature lists instead of comparing the four jobs above.

Evaluation Criteria That Matter

CriterionWhat to establishWhy it decides the outcome
Philippine document coverageWhich specific IDs, and which card generationsAn unsupported ID means a rejected customer, not a degraded check
Accuracy at a stated operating pointFNMR at a specified FMR, on comparable imageryA bare percentage is not comparable across vendors
Liveness and deepfake resistanceWhat attacks are tested against, and by whomMatching accuracy says nothing about spoof resistance
Latency and pass rateResponse time, and share of genuine users passing first attemptDirectly converts into onboarding drop-off
Regulatory fitBSP outsourcing status, DPA handling, data locationCan make an otherwise good vendor unusable
Provider due diligenceFinancial soundness, reputation, operational capacityRequired by MORB, and examinable

Philippine Document Coverage: The First Filter

Coverage claims are where evaluations most often go wrong, because “supports 200+ documents globally” tells you nothing about the documents your customers actually hold.

Ask for the Philippine list explicitly, and check it against your own acceptance policy of Philippine valid IDs. Then probe three specifics that generic coverage claims tend to hide.

Card generations. Several Philippine IDs circulate in more than one design. The UMID’s 2021 iteration moved the photograph relative to the 2010 version, and both are in customers’ wallets. A template built against one generation misreads the other.

Legacy and successor credentials. UMID issuance has ended while existing cards stay valid, and the MySSS Card is arriving alongside it. A provider supporting only one of the two leaves you rejecting customers who hold a perfectly valid card.

Verification depth per document. Coverage can mean OCR only. PhilSys credentials support QR authentication against the government service, and passports support MRZ check digit validation and chip reading. Ask which layer runs for which document rather than accepting a yes on coverage.

Accuracy: Ask for the Operating Point

Accuracy claims are only comparable when they state the conditions they were measured under.

What makes a figure usable is false non-match rate quoted at a specified false match rate, on imagery resembling what your customers actually submit. A number measured on high-quality portrait photographs predicts very little about phone selfies taken in a jeepney at dusk.

Independent evaluation is the strongest available evidence, and it is checkable. Our guide to accuracy figures covers what NIST publishes, why no single accuracy percentage is meaningful, and the demographic differentials that matter for a Southeast Asian customer base.

One point worth carrying into the evaluation: NIST evaluates and reports, it does not certify. A vendor claiming NIST certification is using a phrase that does not correspond to anything NIST issues, which is itself a useful signal about how the rest of their claims are constructed.

Liveness and Deepfake Resistance

Matching accuracy and spoof resistance are different properties, measured differently, and a vendor strong on one can be weak on the other.

A face matching engine compares two images. It does not ask where either image came from, so a printed photograph, a screen replay, a mask, or an AI-generated face can produce a confident match. Liveness detection is the separate control that establishes physical presence.

Questions that separate providers here: which attack types are tested, whether testing is independent or self-reported, how the system handles injection attacks where a synthetic feed replaces the camera, and how often the models are updated as generation tools improve.

That last one matters more than it sounds. Deepfake generation improves continuously, so a detection model frozen at procurement decays against attacks that did not exist when you signed.

Latency, Pass Rates, and the Conversion Trade-off

Verification sits in the middle of onboarding, so every second and every false rejection has a revenue number attached.

Two metrics do most of the work. Latency, meaning time from submission to decision, which shapes whether users abandon mid-flow. And first-attempt pass rate for genuine users, which is the practical expression of false non-match rate plus capture quality.

The second is where evaluations get manipulated most easily, and not always deliberately. A high pass rate achieved by a loose threshold is not a better product, it is a different risk position. Ask what threshold produced the quoted pass rate and what the corresponding false match rate was, and treat any pass rate quoted without those as uninterpretable.

Retry behaviour deserves attention too. Genuine users fail captures for mundane reasons: glare, poor light, a shaking hand. A flow that guides a retry recovers those customers, while one that hard-declines loses them and records the loss as fraud prevention.

Regulatory Fit: Outsourcing Rules, BSP Circular 1170, and the DPA

This is the section that changes how the decision is made, and it is the part most vendor comparisons omit entirely.

Identity verification is likely material outsourcing

For a BSP-supervised financial institution, engaging a verification provider falls under the outsourcing framework in the Manual of Regulations for Banks.

Per MORB Appendix 78, before selecting a service provider the institution should perform appropriate due diligence of the provider’s financial soundness, reputation, managerial skills, technical capabilities, operational capability, and capacity in relation to the services to be outsourced. Risk assessment should consider the criticality of the service, the capability of the technology service provider, and the technology used to deliver it, and should be repeated periodically on existing arrangements.

Read that list again. It is a regulator-issued evaluation checklist, and three of its six items are commercial rather than technical. An evaluation that assesses accuracy and latency but never examines the provider’s financial soundness has not met it.

BSP material outsourcing due diligence criteria for selecting a technology service provider under MORB Appendix 78

Per MORB Section 112, the institution must maintain documentation showing the arrangement was properly reviewed and appropriate due diligence undertaken, kept on file and made available to BSP representatives for inspection. The evaluation is therefore an examinable artefact, not an internal memo.

Materiality raises the bar further. Per BSP Circular 1137 of February 2022, a material outsourcing arrangement is one that would significantly impact the institution’s operations, financial condition, reputation, customers, or compliance with laws in the event of a business disruption, service delivery failure, data breach, or security breach. Identity verification meets several of those tests on its face: if it stops, onboarding stops.

Depending on the institution’s supervisory rating, BSP approval may be required before outsourcing a material workload, and again where changes to an existing arrangement significantly affect service delivery, or where an existing arrangement becomes material. Institutions have been directed to ascertain the adequacy and effectiveness of a provider’s security controls through third-party auditors or internal audit, and for arrangements involving data transfer, to identify risks arising from access by the provider’s employees, subcontractors, and other parties.

The practical consequence is a timeline one. If approval may be needed, the procurement calendar has a regulatory step in it that a purely commercial plan will not have accounted for.

BSP Circular 1170 and the eKYC conditions

Circular 1170 permits electronic KYC using a digital ID system and allows face-to-face contact to be conducted using information and communications technology, provided the institution has measures to mitigate ML and TF risks and documents the key customer due diligence processes.

Two vendor questions follow. Does the provider’s output give you the evidence you need to document those processes, and does it handle PhilSys credentials properly, including the rule that a presented PhilID is sufficient without requiring a second document.

Data Privacy Act and vendor accountability

Under the Data Privacy Act, the institution is the personal information controller and the provider is a processor. Accountability does not transfer with the data.

The contract has to carry it: what the provider may do with the data, what security applies, retention and deletion, what happens on termination, and breach reporting fast enough for you to meet your own 72-hour obligation. Where processing happens outside the Philippines, that is permitted but remains your responsibility.

Build vs Buy: When Identity Verification Services In-House Makes Sense

Building is defensible in a narrow set of circumstances and expensive in most others.

It can make sense where volumes are very large and per-check pricing dominates the cost base, where the document mix is unusually narrow, or where regulatory or contractual constraints genuinely prohibit third-party processing.

What in-house teams consistently underestimate: maintaining document templates as issuers change card designs, keeping liveness models current against improving generation tools, and building the capture guidance that determines pass rates more than the matching engine does.

Worth noting that building does not exit the regulatory picture, it moves you inside it. The institution then owns the accuracy, the model maintenance, and the audit evidence directly, without a provider’s independent evaluation results to point at.

Questions to Put in Your RFP

Which Philippine documents do you support, at which verification depth, and across which card generations?

What is your false non-match rate at a stated false match rate, on what imagery, and has the algorithm been independently evaluated?

Which liveness attacks do you test against, who tests them, and how often are models updated?

What is your first-attempt pass rate for genuine users, at what threshold, and what false match rate does that threshold produce?

Where is data processed and stored, who has access, and what are your retention and deletion terms?

Can you provide the documentation we need for BSP outsourcing due diligence, including financial statements, security audit reports, and operational capacity evidence?

What are your uptime commitments and what happens to onboarding when you are unavailable?

That sixth question is the fastest filter in the list. A provider that regularly serves BSP-supervised institutions will have the pack ready. One that has not been asked before will improvise, and you will be assembling their due diligence file for them.

Frequently Asked Questions

Is choosing an identity verification provider a regulated decision in the Philippines?

For BSP-supervised institutions, yes. Per MORB Appendix 78 the institution must perform due diligence on the provider’s financial soundness, reputation, managerial skills, technical capabilities, operational capability, and capacity, and per Section 112 must keep documentation of that review available for BSP inspection. Where the arrangement is material, BSP approval may be required beforehand.

What makes an outsourcing arrangement material?

Per BSP Circular 1137, one that would significantly impact the institution’s operations, financial condition, reputation, customers, or compliance with laws in the event of business disruption, service delivery failure, data breach, or security breach. Identity verification meets several of those tests, since onboarding halts if the service does.

How should we compare accuracy claims between vendors?

Insist on false non-match rate at a specified false match rate, measured on imagery comparable to what your customers submit. A single accuracy percentage is a point on a curve with the conditions removed. Independent evaluation results are checkable, though note that NIST evaluates and publishes rather than certifying.

Can identity verification data be processed outside the Philippines?

Yes, cross-border processing is permitted, but accountability stays with the institution as personal information controller under the Data Privacy Act. The contract must specify what the processor may do, security measures, retention, termination handling, and breach reporting fast enough for the controller to meet its own notification obligations.

Is a high pass rate a sign of a better provider?

Not on its own. A pass rate can be raised by loosening the matching threshold, which changes the risk position rather than improving the product. Ask which threshold produced the quoted figure and what false match rate corresponds to it.

Should we build identity verification in-house?

Rarely, and only where volumes make per-check pricing dominant, the document mix is narrow, or third-party processing is genuinely prohibited. Ongoing costs are usually underestimated: document templates change as issuers redesign cards, liveness models decay against improving generation tools, and capture guidance drives pass rates more than the matching engine does.

The Evaluation Is an Examinable Document

Most vendor selections in this category are run as commercial exercises: a feature matrix, a pricing comparison, a pilot. All useful, and none of them produce what BSP expects to see.

What the regulator asks for is evidence that the institution assessed the provider’s financial soundness, reputation, technical and operational capability, and capacity, documented that assessment, and can produce it on inspection. That reframes the exercise. The output is not a decision memo, it is a file.

Building the evaluation that way costs little extra if you do it from the start, and considerably more if you reconstruct it during an examination.

To be clear about our position: Verihubs is a provider in this category, so treat this as criteria rather than as neutral advice, and apply them to us as you would to anyone else. Verihubs eKYC API covers 15+ Philippine government ID types with PhilSys authentication, biometric liveness, and deepfake detection.

Ask the Verihubs team the questions in this article, including the ones about due diligence documentation.

Client Verihubs
Trusted by 400+ clients and experience faster, smarter verification with us
Get FREE Trial
View Blog