
Maintenance
Part of A working brief on identity verification
Identity verification risks as practitioners see it
Identity verification risk is about permanence: documents and face images cannot be changed, so each copy you create is an exposure that never closes.
A password is a bad secret you can replace. A face and a passport number are the opposite: better evidence, and impossible to reissue when they leak.
That asymmetry is the whole risk. Verification is often right, but each time you do it, a copy of something unchangeable is created somewhere you cannot inspect.
This page is about deciding when that trade is worth making, and about what actually happens when it goes wrong. The ground it stands on is in identity verification.
What to take away
- Passwords rotate. Documents and biometrics do not.
- The risk of a verification is not the check. It is the copy left behind, and who else can reach it later.
- A leaked document mostly enables things being opened in your name, not access to what you already have.
What each thing you hand over actually costs
Can it be changed
- A password
- Yes, in a minute
- A phone number
- With effort
- A document number and image
- Rarely, and slowly
- A selfie or liveness video
- No
- A full document plus a selfie together
- No
What a copy enables
- A password
- Access, until you rotate it
- A phone number
- Recovery attempts and approaches
- A document number and image
- Applications made in your name
- A selfie or liveness video
- Reuse against checks that rely on appearance
- A full document plus a selfie together
- The strongest package, and the one asked for most
The bottom row is the one to think about before you agree. Separately, each item is limited. Together they are a complete kit, which is why fraudulent processes ask for both at once and why real ones increasingly ask for less.
What you hand over costs
What you provide
- A password
- Yes, in a minute
- A phone number
- With effort
- A document number and image
- Rarely, slowly
- A selfie or liveness video
- No
- Document plus selfie together
- No
Can it be changed
- A password
- Access until rotated
- A phone number
- Recovery attempts
- A document number and image
- Applications in your name
- A selfie or liveness video
- Reuse against appearance checks
- Document plus selfie together
- Strongest package
What a copy enables
- A password
- A phone number
- A document number and image
- A selfie or liveness video
- Document plus selfie together
Where the copies actually live
You are rarely giving a document to the organization you are dealing with.
Most services use a verification provider, which may use its own data source. Retention rules for each sit in contracts you will never see. That is not sinister.
Some of those rules come from law rather than from a contract. US banks must keep customer identification records for five years after an account closes, and EU anti-money-laundering rules set the same figure once the relationship ends. In the United States, the FTC's Safeguards Rule also requires covered financial institutions to oversee their service providers.
It does mean the number of copies is larger than the number of checks you remember agreeing to, and a breach anywhere in the chain reaches you without ever naming you.
The practical response is not paranoia, it is arithmetic. Reduce the number of optional checks. Refuse the ones that are collections rather than checks, which are set out in identity verification examples 2027. Ask what is retained and for how long, since the question itself changes how some services behave.
What happens after a document leaks
The instinct is to expect break-ins. That is not usually the shape.
Documents are used to open things: accounts, credit, phone contracts, sometimes tenancies. A leaked passport scan is enough to open a store credit card or a phone line in your name.
That is why the monitoring that helps is watching for what appears in your name rather than watching your existing accounts. The effect can arrive months after the exposure, in a place you have no relationship with.
The steps that help are procedural. Get your own consumer file and read it. Consider whatever freeze or notice mechanism exists where you live, which is usually free and is described by the relevant regulator. Keep a record of what was exposed and when, because you will be asked.
The US route for that, including the checklist that comes with a report, is at IdentityTheft.gov's guidance on lost or stolen information, and the general overview sits at USAGov's identity theft page.
In Canada, the same consumer file steps run through Equifax Canada and TransUnion Canada. Complaints about how a company handled your data go to the Office of the Privacy Commissioner under PIPEDA. Reports of identity theft go to the Canadian Anti-Fraud Centre.
The biometric question, honestly
Face verification is convenient and hard to fake at scale. Both are true and they pull in different directions.
The realistic risk is not that somebody wears your face. It is that an image of you sits in another system, subject to the same breach and retention questions as everything else, with no way for you to revoke it.
Where a service offers an alternative, taking it costs you a few minutes and removes one item from the ledger. Where it does not, the decision is whether the account is worth it, and for a low-value account it often is not.
Anyone who wants the technical framing rather than the vendor framing can read the NIST digital identity guidelines, which describe what different levels of assurance are actually for.
The risks people get backwards
Over-fearing the ordinary check. Refusing a legitimate verification with your own bank, inside your own app, does not protect anything and can lock you out of your own money.
Under-fearing the casual copy. Sending a document image by chat to a landlord, a seller, or a recruiter feels smaller and is worse, because that copy is unmanaged and permanent.
Assuming a verified badge means something about the other person. It means a check happened once, on somebody, at some point. Accounts change hands, and the account-side reasoning is in account security risks.
Treating a leak as an emergency about your existing accounts. It usually is not. It is a slow problem about new things being opened, and slow problems are managed with records and reminders rather than with panic.
Reducing exposure without refusing everything
Five habits cover most of it.
Five habits that reduce exposure
- Complete checks inside a service's own flow
- Ask whether a partial document is enough
- Prefer services that state a retention period
- Keep a personal log of every check
- Close low-value accounts holding old documents
- Ask what is retained and for how long before you upload a document.
- Send the least that worksa document number instead of a full image where the check allows it.
- Verify inside the service you are already using, not in a chat thread or an email attachment.
- Take the alternative when one is offered, even when it takes longer.
- Keep a dated note of each check you agreed to, and set one annual reminder to read your consumer file.
The wider settings work that reduces how much is visible about you in the first place is in privacy settings.
Common questions
Should I refuse face verification?
Where an alternative exists and the account is not important, taking the alternative is reasonable. Where it does not, weigh what the account is worth. There is no universal answer, and anyone giving you one is not weighing anything.
My documents were in a breach. What is the single most useful thing to do?
Get and read your own consumer file, then set a reminder to read it again. Everything else follows from knowing what is currently in your name.
Can I get a copy of my document removed from a service?
Sometimes, by asking, and the answer depends on where you and they are. Ask in writing and keep the reply.
Is verification getting safer or riskier?
Both. Checks are getting better at their job and more numerous, which means more copies. The exposure is going up even as any individual check improves.
How long should I worry after documents leak?
Years, at a low level. Set an annual reminder rather than carrying it around, since the risk is durable and the vigilance is not.







