KYC / ID Verification

KYC Document Verification: 7 Signs an ID or Residence Permit May Have Been Altered

No single visual clue proves an ID has been altered, and no single clean check proves it is genuine. A professional KYC review compares format, data consistency, security features, machine-readable data, the correct issuing-country version and the applicant, then escalates anomalies instead of declaring fraud.

On this page
Get Expert Help

Key Takeaways

  • Authenticating the document, validating its data and matching it to the applicant are separate questions. Passing one says nothing about the others.
  • Review against the right country, document type and version. False alarms can arise when a genuine older design is compared with a newer version.
  • Data consistency matters as much as appearance. Machine-readable data should agree with printed fields, but agreement alone does not prove authenticity.
  • Remote review removes some physical and tactile checks. NIST-conforming remote optical document validation uses live capture and document-presence controls, while the exact legal and technical requirements differ by jurisdiction and assurance framework.
  • Manual and automated review have different strengths. How far either can stand alone depends on the applicable rules, assurance level and tested capabilities.
  • A suspicious document may be poor quality, outdated, unsupported, altered, counterfeit, or genuine but not the applicant's. Whether to report is a separate legal analysis.
  • Record what you checked, against which reference, and why you decided. "ID verified" or "ID rejected" alone cannot be defended.

Picture a residence permit card uploaded by a new remittance customer. The image is sharp and the name matches the application. But one field's font weight differs from other cards of that type, the design appears to postdate the stated issue date, and the printed date of birth does not agree with the machine-readable lines. Each has an innocent explanation; together they justify escalation.

KYC document verification is not "spot the fake." It is structured comparison: the document against the correct reference for its type and version, its printed data against its machine-readable data, and the document against the person presenting it. This guide covers how to run that comparison, seven anomalies that justify closer review, where manual and automated review fall short, and how to handle a failed document without accusing a genuine customer.

It is written for international fintechs, MSBs, PSPs and crypto businesses, using NIST, ICAO and EU PRADO material as technical references and FINTRAC as a Canadian regulatory example. It describes detection and review controls only.

What KYC Document Verification Actually Tests

KYC identity verification at the document level answers three different questions. Teams that blur them approve documents that look polished and reject documents that merely look unfamiliar.

Question NIST SP 800-63A-4 term What the reviewer examines Common controls
Is the document authentic? Evidence validation (authenticity) Correct format, no signs of counterfeiting or tampering, expected security features Trained visual inspection, automated validation, cryptographic checks on digital evidence
Are the data accurate and valid? Evidence validation (accuracy, validity); attribute validation Printed fields consistent with each other and with machine-readable data, plausible dates, core attributes checked against authoritative or credible sources MRZ and barcode comparison, version and date logic, data-source checks
Does it belong to this person? Identity verification Portrait against the applicant, or proof of control over the evidence Visual or automated facial comparison, confirmation codes

Same word, different meanings. NIST uses "valid" to mean unexpired or within a timeframe the service provider defines, and notes that expired evidence can remain useful depending on policy. FINTRAC's government-issued photo ID method uses "valid" to mean unaltered and not counterfeit, and "current" to mean not expired. Define each term in your procedures so reviewers and auditors read them the same way.

What each source can and cannot tell you. NIST SP 800-63A-4 (July 2025, superseding the earlier SP 800-63A) is a technical guideline for federal agencies and identity service providers. Its mandatory wording binds those claiming conformance, not every private business. ICAO Doc 9303 specifies documents for issuing authorities and creates no KYC obligations. PRADO, the EU's public register of authentic documents, is a reference tool and says it is incomplete. FINTRAC guidance is a Canadian regulatory example. This guide keeps legal requirements, technical practice and practical controls apart. For how document checks sit beside KYB and CDD, see KYC vs KYB vs CDD.

Start With the Correct Document Reference

Before looking for red flags, establish what the document claims to be (issuing country, type, version, issue and expiry dates, format), then compare it with a reference for that exact version.

Genuine designs change. An older valid version can differ materially from the current one, and a reviewer who flags the difference creates a false positive. The reverse also happens: a reviewer who has never seen the real design cannot recognize a wrong one.

For many European documents, PRADO publishes descriptions by version, compiled by national document experts. An entry records the document category (for example identity card or residence-related document), version number, date first issued, dimensions, validity rules and described security features. The entry for a Dutch residence-related card first issued on 1 June 2022 (NLD-HO-02005), for instance, describes a UV feature, an optically variable device, optically variable ink and a laser-perforated secondary image visible in transmitted light. Treat the live entry as the reference.

Know the register's limits. PRADO states that its information is not yet complete and that several documents and versions are missing, and its examination FAQ says only the most important security features are described. A version absent from PRADO, or a feature absent from a description, is a reason to look elsewhere, not evidence of forgery. ICAO Doc 9303 (Eighth Edition, 2021) also leaves many presentation choices, such as the typeface and type size in the visual zone, to the issuing State, so it cannot tell you what a particular document should look like.

Seven Signs an ID or Residence Permit May Have Been Altered

Treat each sign as a prompt for comparison, not a verdict. None proves alteration alone, and most can also come from wear, poor capture or an unfamiliar genuine version.

Sign 1: Layout, typography or spacing does not match the genuine version

What you notice. Field positions, font style or weight, spacing, label wording or card dimensions differ from the reference, or one data field looks set differently from its neighbours.

Why it can matter. Genuine documents are typically personalized in a controlled process, so fields tend to share typography and alignment.

Compare it against. The reference for the exact version. FINTRAC's examples of characteristics to check include size, character spacing, format and design.

Do not conclude too quickly. Printing tolerances, scanner scaling and compression shift appearance. One anomaly is not forgery.

Escalate when. Several layout anomalies cluster in the biographical data area, or the layout matches no version that existed on the stated issue date.

Sign 2: The portrait or biographical-data area shows signs of substitution or alteration

What you notice. A visible discontinuity around the portrait, gloss, texture or edges that differ across the data area, a portrait flatter or sharper than the surrounding print, or a secondary image that does not correspond to the main portrait.

Why it can matter. PRADO's examination guidance names photo substitution and alteration of personal details as document-fraud methods. Issuers integrate portraits so that replacing one without leaving traces is difficult.

Compare it against. The portrait technique the reference describes, the chip portrait where your technology can read it, and the applicant.

Do not conclude too quickly. Flash glare, creases, worn laminate and compression around faces can mimic discontinuity, and ageing between photo and applicant is not substitution.

Escalate when. The discontinuity persists across more than one capture, the printed and chip portraits differ by more than the small deviations printing and security treatment can cause (ICAO notes the two may not be identical), or a secondary image contradicts the primary one.

Sign 3: Printed data conflicts with the MRZ, barcode, chip or other machine-readable data

What you notice. Name, date of birth, document number, nationality or expiry differ between the printed zone and the machine-readable zone, barcode or chip, or the machine-readable lines are unreadable on an otherwise clear image.

Why it can matter. Where an MRZ or barcode is present, NIST SP 800-63A-4 requires conforming providers' optical inspection to compare machine-readable data with printed data. Validation software can also evaluate the MRZ's built-in check characters, so reviewers need not do so by hand.

Compare it against. The printed fields, the machine-readable data, the application data and, where your tools can verify a chip's digital signature, the chip, a stronger test than reading printed text.

Do not conclude too quickly. OCR errors on the MRZ are a capture problem before they are a fraud signal, so recapture first. ICAO Doc 9303 Part 3 also notes that MRZ names can differ from the printed form: national characters are transliterated, and names that exceed the available positions are truncated. ICAO records that some genuine documents carry MRZ errors, such as a date of birth that does not match the printed page, so a mismatch calls for escalation, not a verdict. And agreement is necessary, not sufficient: consistent data can still sit on a counterfeit.

Escalate when. An unexplained mismatch persists after a good-quality recapture.

Sign 4: Expected security features are absent, inconsistent or behave differently from the reference

What you notice. A feature the reference describes is missing, static where it should change, or positioned or rendered differently. Candidates include optically variable devices, optically variable ink, UV response, watermarks, microprinting, laser engraving, tactile elements and transparent windows.

Why it can matter. Security features make reproduction difficult. NIST expects evidence to carry such features, and FINTRAC lists holograms, barcodes, magnetic strips, watermarks and embedded chips among those technology may compare.

Compare it against. The reference for the exact version. Features vary by country, type and generation, so never assume every ID carries all of them. PRADO's advice is to feel, look and tilt, with a magnifier and UV light where available.

Do not conclude too quickly. A feature missing from a description may still be on the document, and a feature that cannot be assessed in a flat image cannot be judged. PRADO also warns that reproduction colour may differ from the original, so detection cannot rest on colour comparison alone.

Escalate when. A feature the reference confirms for that version is demonstrably absent or behaves wrongly under proper inspection, such as a live tilt capture.

Sign 5: Issue date, expiry date and document version do not make sense together

What you notice. A stated issue date earlier than the version's first-issued date, a validity span longer than the reference allows, a document number format that does not fit the version, or dates that conflict with the document category.

Why it can matter. Each design version has a lifecycle. PRADO records a first-issued date and validity parameters per version, and a version cannot have been issued before it existed.

Compare it against. The first-issued date and validity data for the version. PRADO also links to resources on invalid document numbers.

Do not conclude too quickly. Do not assume immigration rules from memory. The NLD-HO-02005 entry notes that certain holders receive a separate certificate extending their stay beyond the card's expiry. An expired document fails a currency test such as FINTRAC's "current" requirement, but expiry is not evidence of alteration.

Escalate when. The dates are impossible against authoritative reference data for that version.

Sign 6: The document looks plausible but fails cross-source or authoritative-data checks

What you notice. Core attributes do not match an authoritative or credible source, earlier customer records, the application or other documents, or the document number does not resolve as expected.

Why it can matter. NIST separates evidence validation (is the document genuine?) from attribute validation (do core attributes check out against an authoritative or credible source?). A good forgery, or a genuine stolen document, can pass a visual check.

Compare it against. Issuer-side verification where available, credible data sources, prior KYC records and application fields. NIST defines an authoritative source as the issuing source or one with direct access to it, and a credible source as one correlating information from several sources.

Do not conclude too quickly. Many private firms have no direct issuer access, and third-party data lags behind name changes and moves. NIST treats a partial mismatch such as a recent name change as a case for reviewing supporting evidence.

Escalate when. The mismatch concerns a core identifier such as the document number or date of birth, or several independent sources disagree with the document.

Sign 7: The document capture itself creates authenticity concerns

What you notice. A screenshot instead of a camera capture, a photo of a screen (pixel patterns, moiré, glare), a flat image where a variable feature should move, cropped borders, the same image appearing under different applicants, or device signals such as a virtual camera or emulator.

Why it can matter. NIST SP 800-63A-4 requires conforming providers to use live document capture with passive or active document-presence checks, and adds controls against injected and manipulated media, noting that generative AI tools make forged media more available.

Compare it against. Capture signals your platform exposes, a live challenge-response capture and earlier submissions.

Do not conclude too quickly. Poor light, low-end cameras and compression degrade genuine images. Poor image quality is not itself proof of fraud.

Escalate when. Presence checks fail repeatedly, the same document image appears under different applicants, or media-integrity controls flag manipulation. Otherwise the proper response is recapture, an alternative verification method or enhanced manual review.

Residence Permits Need Version-Specific Review

Residence permits can be especially challenging to review because they come from many countries in several classes, designs change, validity follows immigration status, and cards sit alongside legacy formats. Feature combinations differ accordingly, so review has to be tied to the specific version.

  1. Identify the issuing country and authority.
  2. Identify the document category and permit class.
  3. Identify the version from the layout and any version marker, then confirm it against the reference.
  4. Confirm that the stated issue date is compatible with the version's first-issued date and validity rules.
  5. Compare the layout and the key security features the reference describes.
  6. Verify data consistency, including any machine-readable data, and the applicant's details.

Where PRADO covers the version, use it. Where it does not, record that and use another reference or a specialist. Do not infer immigration status or entitlement from the card alone; confirm it from a current official source for that country.

Passport Checks vs Residence-Permit Checks

KYC passport verification and permit verification ask the same three questions, but reviewers can assume different things. The table is illustrative, and specifics vary by country and version.

Check Passport Residence permit
Authoritative reference Issuing state's specimen; PRADO for many European passports; Doc 9303 for format specifications PRADO's residence-related category for many European permits; otherwise the issuing immigration authority. Coverage is uneven
Machine-readable zone Standard on machine readable passports Present on some cards. Confirm for the specific version
Chip Many current passports carry one; older ones do not Varies. Do not assume
Versions in circulation Several, because multi-year validity keeps older designs valid Often several at once, varying by permit class
Validity Set by issuer rules, commonly multi-year Follows immigration status; may be short, and extension rules vary
Immigration-status data None (nationality is shown) Permit category, status or purpose, sometimes remarks
Governing specification Doc 9303 applies to travel documents No single worldwide specification equivalent to Doc 9303 for all permits; the format comes from the issuing country or region

Manual Review vs Automated Document Authentication

Manual and automated document review in KYC ID verification have different strengths and limitations. Whether either can operate without the other depends on the applicable rules, assurance level, document type and the system's tested capabilities. The useful question is what each can see, and what it will miss.

Manual review Automated review
Can assess Visible layout, information consistency, obvious surface anomalies, comparison with a reference specimen, customer context Template match, OCR consistency, MRZ or barcode comparison, security-feature detection where capture allows, tampering indicators, document presence; facial matching if separately implemented
Strengths Handles unusual cases, uses context, can request a different capture Consistent, fast, applies identical checks to every submission, leaves logs
Typical limits Fatigue and inconsistency, limited tooling remotely, difficulty with unfamiliar foreign versions Unsupported or old versions, poor capture, compression, false rejection of unusual genuine documents, false acceptance of attacks it was not tested on
Depends on Training, a reference library, an escalation path A coverage list of supported documents, tested error rates, a human fallback

NIST SP 800-63A-4 recognizes several evidence-validation methods: trained visual inspection, automated document validation and cryptographic verification of digital evidence. It supports fully automated remote proofing under defined requirements, and recommends (SHOULD) that remote visual inspection be supported by automated validation. For automated document validation, NIST requires conforming providers (SHALL) to meet document false-acceptance and false-rejection measures and to publish test results, while periodic independent testing is a recommendation (SHOULD). None of this means every KYC review legally needs both human and automated review, or that either is always enough. The lesson holds anywhere: ask what the tool was tested on. OCR extracts text, and extracting text is not authenticating a document. AI-based scoring is a signal to be tested like any other control, not a conclusion.

Remote KYC Changes What You Can Examine

An in-person reviewer can feel raised elements, tilt the document and use a magnifier or UV lamp. A remote reviewer sees an image or video feed, so remote review leans on live capture, authentication technology, reference libraries and an alternative path when confidence is low.

Canada. For KYC photo ID verification without the person present, FINTRAC requires a process to authenticate the document, for example technology that compares a scan with known characteristics and security features. Separately, the reviewer must determine that the document is valid and current and that the name and photo are the person's, for instance by live video comparison or a selfie checked with facial recognition. FINTRAC states that viewing a person and an ID over video is not enough, and that procedures must describe each step. The steps need not happen at the same time. Methods, triggers and records are in ComplyFactor's FINTRAC identity verification guide, which this article does not repeat.

Elsewhere. Legal standards differ. As a technical benchmark, NIST distinguishes remote attended proofing (secure video with a trained agent) from remote unattended proofing (fully automated) and expects forged-media controls in both.

What a Reviewer Should Do When Something Looks Wrong

Build the exception path into the KYC verification process before you need it. A workable sequence:

  1. Do not accuse the customer. Treat the anomaly as a question, not a finding.
  2. Confirm the document type and version, and re-check the reference.
  3. Check data consistency across printed fields, machine-readable data and application details.
  4. Request a fresh live capture if image quality or integrity is the issue.
  5. Use another permitted verification method where your procedures and the applicable rules allow one.
  6. Escalate to a trained KYC, fraud or compliance reviewer with the evidence attached.
  7. Document the anomaly, the checks performed and the outcome.
  8. Review the wider customer context: other documents, onboarding behaviour, geography and linked applicants. Higher-risk cases may call for enhanced due diligence.
  9. Decide, as a separate step, whether reporting obligations are engaged under the applicable law.

What the anomaly turns out to be shapes the next step:

What the anomaly may be Typical next step
Poor image quality or glare Recapture, or assisted review
Older or unsupported version Check alternative references, use specialist review or another verification method
Genuine document, stale or different customer data (for example a name change) Request corroborating evidence under your policy
Suspected alteration Escalate, preserve images and logs, assess customer context
Suspected counterfeit Escalate to a specialist, then apply your policy on declining and reporting
Genuine document presented by someone else Treat as an identity-fraud case, escalate, assess reporting

A suspicious document is not automatically a suspicious transaction report or SAR. In Canada, FINTRAC's STR guidance applies where a financial transaction occurs or is attempted and there are reasonable grounds to suspect that it is related to the commission or attempted commission of a money laundering or terrorist activity financing offence. A document anomaly may feed that analysis or have an innocent explanation. Other jurisdictions, including the United States, set their own reporting thresholds. Record the reasoning: how to document a decision not to file shows what a defensible file looks like. Handle any reporting decision under the confidentiality and tipping-off rules of the applicable jurisdiction, and keep customer-facing requests within normal KYC and investigation procedures. FINTRAC's guidance, for example, cautions against requesting information you would not normally request if doing so could tip off the client.

What to Record in the KYC Review File

Separate legal requirements from good practice. Record content depends on the jurisdiction and method. In Canada, a reporting entity using the government-issued photo ID method must record the person's name, the verification date, the document type, its unique number, the province or state and country of issue, and the expiry date where one appears. Other jurisdictions and methods differ.

Practical internal notes, which no regulator prescribes in this form, usually add:

  • the document version and the reference consulted
  • the authentication tool and its result, where one was used
  • the checks performed and the discrepancies observed, with image evidence
  • the reviewer's decision and rationale, and any escalation
  • alternative evidence obtained, the final outcome and the date

Keep only what privacy law and your retention policy allow; FINTRAC notes that Canadian privacy legislation applies to this personal information.

False Positives: Genuine Documents Can Look Unusual

A process that treats every oddity as fraud rejects genuine customers and trains staff to ignore alerts. Beyond the points under each sign, common causes include colour differences between print batches or screens, normal wear and repair, valid older versions in circulation, unusual but legitimate residence statuses, long or non-Latin names with transliterations, and older phones in poor light. PRADO's colour warning generalizes: detection cannot rest on one visual comparison.

Controls that help: test reviewers and tools on known genuine samples of the documents customers present, measure false rejections as well as missed fraud, and give failed applicants a recapture, alternative-method and trained-reviewer route. For NIST-conforming identity-proofing services, trusted referees are one documented exception path: NIST recommends (SHOULD) offering them for defined failures such as failed automated validation, or fraud checks failed in unattended remote processes. Other organizations should build an appropriate human-review and redress path for their own framework.

KYC Document Verification Checklist

A practical ComplyFactor checklist, not an official regulator checklist.

Document identity

  • Issuing country, type and version identified
  • Issue and expiry dates compatible with the version
  • Reference located, or its absence recorded

Physical and visual

  • Layout and typography consistent with the version
  • Portrait and data area free of discontinuity
  • Expected security features present and behaving as the reference shows

Data

  • Printed fields consistent with each other
  • MRZ, barcode or chip data consistent with printed data where available
  • Core attributes consistent with credible sources and prior records

Person

  • Name consistent with the application
  • Portrait compared with the applicant through an approved method

Remote capture

  • Live capture and presence check completed
  • Image quality sufficient to assess the features that matter
  • No indicators of screen recapture, editing or injected media

Decision

  • Pass, recapture, alternative method, escalate or reject per policy
  • Rationale recorded; reporting analysis done separately where triggered

How ComplyFactor Supports KYC and Customer Due Diligence Controls

ComplyFactor is an AML advisory firm that helps regulated businesses define, document and test KYC and customer due diligence controls. For Canadian MSBs, PSPs and fintechs, that can include AML compliance program work covering written client identification and verification procedures, customer risk rating with CDD and EDD trigger criteria, monitoring frameworks, training and governance. It can include a fractional compliance officer who reviews CDD and record-keeping procedures and owns escalation decisions, and an independent AML audit or effectiveness review that includes risk-based sampling of KYC and EDD files.

If your onboarding team cannot show how a document is authenticated, what happens to anomalies and what is recorded, speak with ComplyFactor's AML advisory team to book a consultation.

Frequently Asked Questions

What should we ask a document-authentication vendor?

Ask which document types and versions are supported, how often templates are updated, how false acceptance and rejection were tested and on which samples, whether manipulated media is detected, how failures reach human review, and what logs and retention apply. NIST requires conforming providers to publish test results, so use the same questions as a benchmark.

How should staff be trained for manual document review?

On the document types you accept: layouts, security features, how to assess them with the right tools, and common signs of tampering. NIST requires conforming providers to assess reviewers, reassess them annually and equip them with tools such as magnifiers, UV lights and barcode readers. For other businesses that is a benchmark, not a legal rule.

Does passing document verification make a customer low risk?

No. It supports identity assurance only. Customer risk turns on geography, products, ownership, expected activity and sanctions or PEP exposure, which sit in CDD and EDD.

What should happen when manual review and the document-authentication tool disagree?

Treat it as an exception, not a tiebreak, and trust neither result automatically. Check capture quality and whether the tool supports that document and version, review the reason or code behind the automated result where available, and compare the document with the correct reference. Then escalate under your documented policy and record the final rationale. Do not override a failed control casually: an override should be a recorded decision by someone with authority to make it.

How often should a KYC team update its document references and supported-version list?

No source reviewed for this guide sets a universal interval, so set your own and document it. Update when issuers release new versions (PRADO, for example, adds descriptions on an ongoing basis), when your accepted-document scope changes, when a vendor adds or removes support, or when threats change materially. Make sure reviewers know which versions the system can actually authenticate, and keep older references available because genuine older documents can remain valid. Record changes under your change-management procedure.

ComplyFactor Advisory Team

ComplyFactor specializes in FINTRAC MSB and PSP registration, independent AML effectiveness reviews, and compliance program design for Canadian and foreign money services businesses, payment service providers, fintechs, and virtual asset service providers.

Get started

Book a free Canada AML consultation

Tell us about your business and we'll confirm which services you need — free, no obligation, 30 minutes.

Free, no obligation, 30 minutes
Senior consultant on every engagement
Aligned with PCMLTFA & FINTRAC standards
+1 807 806 0444 · Suite 211, 320 Matheson Blvd West, Mississauga, ON

Talk to an AML expert

Thank you. Your message has been received — we'll be in touch within one business day.
Something went wrong while submitting the form. Please try again.