Document and Biometric Verification
The Document and Biometric Verification step in HYPR Affirm captures a government-issued photo ID and checks it for authenticity. With Liveness Check selected, it also compares a live selfie with the document image, and it can add compliance screening.
The step is disabled by default. Enable it for any verification flow that needs document proof, and select Liveness Check when the flow also needs face proof.
The step card has four control groups: Dual document verification (BETA), Document (document type restrictions), Settings (authentication, liveness and motion detection) and Checks (AML, OFAC and Identity Verification With Document Issuer).
For what this step captures, where it is evaluated and how long the data is kept, see Biometric Data and the Privacy Notice.
Prerequisites
- Name on record: The step needs the requester's first and last name from the directory or the verification request. It does not start without them. See Identity Provider Prerequisites.
- Tenant features: With Motion Detection, Dual document verification, the AML Checks and OFAC Checks options and Identity Verification With Document Issuer appear only when they are enabled on your tenant. See the Feature Flags Reference.
Configure the Step
The following table lists the step's settings, their allowed values and their defaults when the step is turned on.
| Setting | Allowed Values | Default |
|---|---|---|
| Document Authentication | Always selected when the flow is saved | Selected |
| Liveness Check | Selected or cleared, under Document Authentication | Cleared |
| With Motion Detection | Selected or cleared, under Liveness Check; shown when enabled on the tenant | Cleared |
| Simple Document Type Selection | Selected or cleared | Cleared |
| Document Type Restriction | Cleared, or one document type | Cleared |
| AML Checks, OFAC Checks | Selected or cleared; shown when enabled on the tenant | Cleared |
| Identity Verification With Document Issuer | Selected or cleared; shown when enabled on the tenant | Cleared |
| Report Visibility for Requester | Selected or cleared | Cleared |
| Retry Limit | 1 to 10 attempts, within 0 to 60 minutes in 5-minute steps | 1 attempt within 0 minutes |
| Failure Outcome | Deny Verification, Redirect to URL or Continue Workflow, with an optional Escalate to Live Chat | Continue Workflow |
The settings depend on each other. Selecting Liveness Check also selects Document Authentication, and selecting With Motion Detection selects both. Clearing Document Authentication clears Liveness Check and With Motion Detection, and Document Authentication is selected again when the flow is saved.
When your tenant uses the Affirm Risk Policy Builder, the Policy Evaluation Kit assigned to the flow sets retries and failure outcomes instead of the Retry Limit and Failure Outcome controls.
Each flow sets how long this step's data is stored after a session completes, under Advanced Customization > Data retention policy. See Data Retention.
Document Authentication and Liveness
The Settings group offers the following document and face checks:
- Document Authentication: The requester provides a government- or state-issued photo ID, which is checked for authenticity. It follows the on/off state of the Document and Biometric Verification step.
- Liveness Check: The requester takes a selfie in real time, and the selfie is compared with the photo ID. It is cleared by default; select it to add the selfie comparison.
- Name check: The first and last name on the document are compared with the requester's name. The result appears as Name Check in the Activity Log. There is no setting for this comparison; it runs whenever the step runs.
Motion Detection
Motion Detection adds a head-turn pattern during selfie capture to harden liveness checks against digital spoofs. It is available only when Motion Detection is enabled on the tenant; see the Feature Flags Reference.
To turn it on, select Verification Steps > Document and Biometric Verification > Liveness Check > With Motion Detection. Motion and liveness results can be shown to approvers and, through Report Visibility for Requester, to requesters.
Document Type Restriction
The Document group has two options that narrow the documents a requester can present. They work independently, and either one hides the issuing-country choice from the requester.
- Simple Document Type Selection: The requester can choose only Passport, Driving Licence or National Identity Card. Residence permits and other types are excluded.
- Document Type Restriction: The step accepts one document type, chosen from the Document type drop-down that appears when you select the option. The drop-down starts at Passport.
The Document type drop-down offers Passport, Driving Licence and National Identity Card, plus Residence Permit when Simple Document Type Selection is cleared. If Residence Permit is chosen and you then select Simple Document Type Selection, the drop-down changes to Passport.
See Supported Documents by Location for the list of accepted documents per country.
Dual Document Verification
The Dual document verification toggle appears at the top of the step. When enabled, the step verifies two documents in one continuous flow, against a single live biometric capture when Liveness Check is selected. Use it for workflows that require two identity documents per requester, for example a government-issued ID plus proof of residence.
Dual Document Verification is available in HYPR 11.3 and later. Contact your HYPR representative to enable Dual Document on your tenant. The canonical flag identifier is in the Feature Flags Reference.
Affirm captures both documents in sequence at the start of the flow. With Liveness Check selected, it then performs a single live selfie or video capture, and both document checks reuse that one capture, so the requester does not repeat the selfie for the second document. Affirm submits two correlated checks under a single Affirm verification session ID, one for each document. With a live capture, each check pairs its document with the same face.
Second-document type restriction: With dual document verification on, the Document group splits into Document #1 and Document #2. Each has its own Simple Document Type Selection and Document Type Restriction options, set independently, with the same document types: Passport, Driving Licence, National Identity Card and, when Simple Document Type Selection is cleared, Residence Permit. The settings in the Settings and Checks groups apply to both documents.
Error handling: A retry starts the capture again from Document #1, so the requester captures both documents, and the selfie when one is required, again.
Requester flow: The requester sees the Document #1 prompt, the Document #2 prompt, the live capture when Liveness Check is selected, and then the outcome. The opening instruction screen tells the requester that two documents are needed.
Activity Log correlation: Both document results are correlated under the same verification flow ID with a shared biometric reference. The Activity Log detail view shows Document #1 and Document #2 as separate sections in the expandable drop-down, each with its own per-check outcome and report, alongside the single live capture session when there is one. See Activity Log for the detail-view fields.
Helpdesk visibility: Auditors and Helpdesk agents see dual-document outcomes in the same Helpdesk activity log used for standard verification. The verification record shows the dual-document mode as a flag.
Risk policy scoping: When Dual Document is on, the Risk Policy Builder shows its predicate fields per document, so rules can target Document #1 and Document #2 independently. See the Risk Policy Builder for the editor.
Optional Compliance Checks
The Checks group adds compliance screening: AML Checks and OFAC Checks screen the requester against watchlists, and Identity Verification With Document Issuer checks the requester against multiple sources of records.
Identity Verification With Document Issuer includes the requester's date of birth and address, and the Additional Information screen collects them when they are missing. For what each check screens and where its results appear, see KYC Compliance Checks (AML/OFAC/Watchlists).
What the Requester Sees
On the instructions screen, this step is listed as "Verify your ID documentation", or "Verify 2 of your ID documents" when dual document verification is on.
The capture screens come from the identity verification provider's capture component, which Affirm embeds in its own page and styles with the flow's Affirm Studio kit. The provider's logo is hidden. The wording on these screens is the provider's and is not edited in Affirm Studio.
The requester moves through these screens:
- A welcome screen introduces the capture.
- The requester chooses a document type and the issuing country. Both choices are skipped or narrowed when a document type restriction applies.
- The requester photographs the document: the front, and the back for two-sided documents.
- When Liveness Check is selected, the requester takes a selfie photo. With With Motion Detection, the requester records a short head-turn video instead.
- Affirm shows "Checking your details" with "Please wait while we review your information. You'll continue with the next steps shortly." while the results are prepared.
Identity Verification With Document Issuer needs a date of birth and an address that may be missing from the requester's record. When either is missing, an Additional Information screen first asks for the date of birth and address. It reads "Please provide your date of birth and address to continue with identity verification."
When Report Visibility for Requester is selected, the requester then sees an "Identity verification results" screen summarizing the checks, with a Next button.
The "Checking your details" text, the retry message and the results screen text are default wording. Administrators can change them on the Identity Verification Screen, Await Screen and Report Card Screen of the Document and Biometric Verification Step in Affirm Studio.
What Data Is Collected
The step captures images of the document and, with Liveness Check, a selfie or video. The identity verification provider evaluates the capture. It always runs a document check, and adds further checks for the selected settings:
- A face comparison against the document, with Liveness Check
- A motion check, with With Motion Detection
- A watchlist check, with AML Checks or OFAC Checks
- An issuer check, with Identity Verification With Document Issuer
Affirm retrieves the results and records them per check in the Activity Log. The record shows Document Type, Document Authentication, Name Check and Biometric Liveness Check, and the flow's Data Retention Policy. Each check shows as passed or failed. The images themselves are not added to the Activity Log. To store the images in your own directory, see Directory Image Writeback. For how HYPR processes, shares and retains biometric data, see the HYPR Affirm Biometric Data Policy and Consent.
Results, Retries and Failure Outcomes
Report Visibility for Requester lets the requester see the identity verification report after it is made available.
The step passes when every check it ran passes. When the step does not pass, Affirm shows "Please wait while we determine the next step. You may be prompted to try again!" and then does one of the following:
- With attempts left, the requester returns to the start of the capture.
- With no attempts left, the flow applies the step's failure outcome.
This step's defaults are 1 attempt and Continue Workflow. With Continue Workflow, the Verification Unsuccessful screen reads "We are unable to verify your ID documentation. You will be taken to the next step momentarily." For what each failure outcome does, including the redirect and escalation to live chat, see Injectable Outcomes and Retry Limits.
The Audit Trail records AFFIRM_WORKFLOW_DOCUMENT_BIOMETRIC_START and AFFIRM_WORKFLOW_DOCUMENT_BIOMETRIC_FINISH for each attempt.
Related
- KYC Compliance Checks: AML, OFAC and identity source-of-truth screening in detail
- Photo ID and Liveness Capture: lighter alternative without document authentication
- Liveness-Only (Anchor Image): liveness against an existing reference image, with no fresh document capture
- Biometric Data and the Privacy Notice: capture, evaluation and retention
- Customizable Consent Screen: the consent notices shown before this step
- Supported Documents by Location: accepted documents per country
- Configure Verification Steps: table of all verification steps
- Injectable Outcomes and Retry Limits: retry and failure-outcome configuration