KYC Best Practices

The Proof was in the picture. Until the picture became the Fraud

Introducing Smile ID's Third Generation Technology, that catches what camera's can't.

Mala Goel
July 21, 2026
Estimating...

A picture isn't proof anymore

For years, identity verification ran on a simple premise: capture a document, capture a face, check that they match, and the verification is complete. 

That logic doesn't hold anymore. Attackers now generate synthetic faces, swap in injected video feeds, and reuse the same identity across a dozen accounts before anyone notices the pattern. And the riskiest moment isn't even onboarding. A growing share of attacks now hit post-onboarding, such as at login in or password change, when the account is already open and money is already moving.

A one-time check can confirm that a document looked valid at the moment it was scanned. It can't tell you that the same face was used to open four other accounts last week, or that this is a synthetic face completing the liveness check, rather than a real person.  

So we upgraded our defenses to answer a different question. Not "does this image look real," but "given everything we know about this request, how much should you trust it."

What changed, and why it matters to you

Smile ID’s Third Generation Technology now provides deeper signals, smarter risk logic, and protection that strengthens as the threat landscape evolves. This includes: 

With Smile Risk Intelligence you get a risk score you can act on. Every verification now returns a score, a risk band, and the specific indicators that drove it. You can now customise your verification flow to match your business logic. A low-stakes signup and a high-value transaction can be processed differently, because you can see exactly what's driving the score. Smile ID continues to reject any verification that has high risk scores, liveness failure, spoof or deepfake detection and failed document checks. 

Every verification now captures precise signals about the device fingerprint, user details, biometrics and document checks at the moment of submission with best-in-class legal and compliance safeguards. These precise signals allow you to see beyond the image, giving you the full picture to make the right call on risk.

Network Defence means someone else's blocked fraud attempt shrinks your exposure. When one attack is blocked, the fraudster metadata is added to our global blocklist daily, so every client is protected from threats we've already seen elsewhere.

Deduplication runs automatically, on every transaction. Every new verification is checked against the valid retention period   of prior submissions. Identity reuse and duplicate faces get caught without you building or maintaining a separate matching pipeline.

ISO 27560-compliant consent and verification receipts, generated automatically, across every market you operate in. Receive an auditable record with every verification you complete making it easier to meet cross-border KYC and compliance requirements.

Our scale is your protection

This is powered by our scale. With over 450M verifications completed across the markets we operate in, a fraud pattern caught in one place becomes a known signal everywhere else, before an attacker can try again. You get that benefit from day one, not after months of building your own history.

How do you access the latest APIs & SDKs

Not a Smile ID Customer yet but want to deploy these defenses? Contact us here.

If you are an existing customer, you can start with our developer docs here. If you’d rather talk it through, you can book time with your account manager or reach out for support at support@usesmileid.com.