us

216.73.217.78

The North America Guide to Docless Identity Verification — report cover: how to reduce document-upload friction without weakening CIP or FINTRAC compliance
US & Canada

The North America Guide to Docless Verification

Reduce document-upload friction without weakening CIP or FINTRAC compliance.

Remote onboarding is now the default way to open an account across the US and Canada, yet both countries wrote their identity rules around checking a person against authoritative data, not a photo of an ID. This guide shows how to close that gap.

Book a demo
The Problem

Document-first onboarding is now a conversion and fraud problem.

US consumers reported 15.9 billion dollars lost to fraud in 2025, the highest figure on record and up from 12.5 billion the year before FTC Consumer Sentinel 2025. The document upload step, the artefact most onboarding flows are built around, now works against operators on two fronts at once: it is where genuine users quit, and it is where fabricated documents walk in.

Digital account opening is the mainstream channel behind that pressure. In the US, 48.3 percent of banked households used mobile banking as their primary way to reach an account in 2023. In Canada, digital methods made up 86 percent of a 22.5 billion transaction payment volume in 2024.

$15.9BUS consumer fraud losses, 2025, record highFTC
$20.9BFBI IC3 reported losses across 1,008,597 complaints, +26%IC3
$704MCanada reported fraud losses, 2025, record (only 5–10% of fraud is reported)Competition Bureau Canada
$182M2021 potential synthetic-identity fraud, likely underestimatedFinCEN data, cited by GAO

The FBI’s Internet Crime Complaint Center logged 1,008,597 complaints and about 20.9 billion dollars in reported losses in 2025, a 26 percent rise FBI IC3 2025 Report. Canadians reported more than 704 million dollars stolen the same year, also a record, and the Canadian Anti-Fraud Centre estimates only 5 to 10 percent of fraud is reported at all.

Two failures land on the same upload step.

The step where genuine users quit. Asking an applicant to find a physical document, photograph it in good light, and retry after a blurred frame is the highest-friction moment in remote onboarding, and users lost here are rarely recovered. This is a field observation from verification funnels across the region, not a cited statistic.

The step where fraud now enters. Generative AI has made convincing fake identity documents cheap to produce at scale. FinCEN warned financial institutions in November 2024 that criminals use deepfake media, including fabricated identity documents, specifically to defeat verification controls FinCEN deepfake alert.

The document was never the identity. It was only a proxy. When criminals can fabricate both the document and the person behind it, verification must move beyond document checks alone.

Underneath both sits a third problem, and it is distinctly North American: synthetic identity. Because the US has no national ID and Social Security numbers are not verified in real time when most accounts open, criminals fabricate people, pairing a real SSN with an invented name and date of birth and letting the profile mature. Financial institutions reported 182 million dollars in synthetic-identity suspicious activity in 2021 across roughly 3,000 SARs, a figure the GAO notes undercounts the real total GAO synthetic identity.

A document photo does nothing against this, because the synthetic applicant presents a person who does not exist rather than impersonating someone real. A flow that runs every applicant through the same document check concentrates friction on the genuine majority while leaving the region’s signature fraud unaddressed.

The Legal Basis

CIP and FINTRAC already support docless checks.

Docless verification is written into US and Canadian law under the regulator’s own word for it, non-documentary, and it has been there for over two decades. Elsewhere the docless case rests on a regulator having allowed electronic verification. Here the route is named in the regulation text itself, which is the page’s central point and Shufti’s strongest ground in the region.

In the US, the load-bearing authority is the Customer Identification Program rule. Under Section 326 of the USA PATRIOT Act, FinCEN’s CIP rule for banks at 31 CFR 1020.220 permits non-documentary verification and lists the methods in its own words.

These methods may include contacting a customer; independently verifying the customer’s identity through the comparison of information provided by the customer with information obtained from a consumer reporting agency, public database, or other source; checking references with other financial institutions; and obtaining a financial statement.
31 CFR 1020.220(a)(2)(ii)(B)(1), the US Customer Identification Program rule · view on eCFR

The same docless provision appears in the parallel CIP rules for broker-dealers, mutual funds, and futures firms. The rule even names the exact situation remote onboarding creates: the customer who opens the account without appearing in person.

Canada’s governing statute is the Proceeds of Crime (Money Laundering) and Terrorist Financing Act, and two of FINTRAC’s prescribed methods are docless by design.

Docless by design

Credit-file method

A single Canadian credit file verifies identity on its own if it is current, at least three years old, draws on more than one source, matches name, address and date of birth, and is searched live at the moment of verification.

Docless by design

Dual-process method

Identity verified from two independent reliable sources, drawn from name plus address, name plus date of birth, or name plus a confirmed financial account.

Document required

Photo-ID method

For a person not physically present, technology must authenticate the document and match name and photo. FINTRAC states plainly that viewing a person and their ID over a video call is not enough.

FINTRAC’s own guidance sets out these routes FINTRAC methods guidance. The credit-file method turns on a live search: a stored copy, or one supplied by the customer, does not qualify. The dual-process method can use a Canadian credit file that has existed for at least six months as one of its two sources.

Neither country treats docless verification as an exception to be justified. Both describe it as a standard route, specify what sources qualify, and expect the same record-keeping either way. The question a North American compliance team faces is not if the regulator permits a database check. It is if their current onboarding flow reflects what the regulator already wrote.

Does your onboarding flow reflect what the regulator wrote?

Shufti’s North America team can walk your current flow through the CIP and FINTRAC methods and show where a docless route already fits.

How It Works

Passive checks should carry the low-risk majority.

Shufti’s eIDV runs three verification methods, each built for a different assurance level and user journey. In North America they do not carry equal weight, and understanding why is most of the deployment decision: the database match the regulators describe is exactly what the Passive method does.

Regional hero method

Passive Verification

User provides name, date of birth, address, and a national identifier such as an SSN. The match runs in the background against credit bureaus, government records, and other authoritative databases. Nothing for the user beyond the form they were already filling in.

230+ authoritative databases
Credential login

Active Verification

User proves identity through a credential they already hold (a bank or government eID login, or a wallet-held government credential), and the issuer confirms in real time.

Canada: Interac + provincial IDs US: mDLs live, more states on demand 40+ national eID schemes
Strongest docless

Biometrically Enriched

A live selfie matched against the photo held by the authoritative source, layered on the Passive or Active match. The mDL portrait can be the match source.

Counters synthetic identity iBeta PAD Level 2
Passive → Active (where a rail exists) → Document + biometric. Escalation is automatic, and no genuine user is lost to a failed database check.

Biometrically Enriched binds a live selfie to the photo on the authoritative record. It is the direct counter to synthetic identity: the fabricated applicant may hold a real SSN and a plausible file but cannot present the face the record belongs to. It runs as 1+1 (single source) or 2+2 (dual-source cross-reference).

The mDL Shift

The Mobile Driver’s Licence Is America’s eID Moment, and It Is Live Today

The mobile driver’s licence gives the US its first sovereign digital credential to verify against, and it is already in use. An mDL is issued by a state motor vehicle agency, signed cryptographically by the issuer, and held in a phone wallet. Until now the Active method mapped to Canada and Europe rather than the US, because there was no US credential to present. The mDL changes that.

More than 20 states plus Puerto Rico issue mDLs as of early 2026, a count that still moves quarterly. TSA already accepts them at 250+ airport checkpoints TSA mobile driver’s licences, which normalises the behaviour for millions of travellers.

1Phone wallet holds the mDL
2ISO/IEC 18013-7 remote presentationShares only what is requested: age, address
3Issuer signature validated
4Verified attributes + compliance record delivered to the business

ISO/IEC 18013-7, published October 2024, is what makes an mDL usable inside a remote onboarding flow.

The piece that matters for onboarding is remote presentation. ISO/IEC 18013-7, published in October 2024, extends mDL presentation over the internet, which is what makes it usable inside a remote flow. Selective disclosure is built in, so a flow can request a date of birth or an age-over threshold without pulling the full licence.

The rulebook is catching up too. In March 2026, NIST released the initial public draft of SP 1800-42A, a reference architecture for financial institutions accepting mDLs in customer identification NIST SP 1800-42A. The CIP rule was always technology-neutral; this is the document that turns mDL acceptance into an examinable practice. NIST SP 800-63-4, the federal Digital Identity Guidelines, was published final in July 2025.

Coverage arrives state by state and wallet by wallet, which is exactly why it needs an orchestration layer. Shufti verifies California and Louisiana mDLs today; the remaining issuing states activate on client demand through configuration, not new integration work.

The Routing Model

Route users by risk, not by one default document step.

The practical question for a North American onboarding team is how to route each applicant to the right method, using risk level, data availability, and the fraud typology this region actually produces. The answer is a single decision flow: verify the low-risk majority against the data the regulators already point to, add a biometric bind where synthetic identity is the threat, and reserve the document flow for the cases that need it.

Start: applicant’s risk assessment against product type and jurisdiction.
A · Low risk

Passive Verification

Background match against bureau + government data (CIP rule / FINTRAC credit-file or dual-process). Where the applicant holds an mDL in a supported state, an Active presentation carries the check instead. No upload.

B · Synthetic-risk signals

Active + Biometrically Enriched eIDV

Thin or new credit file, mismatched attribute histories, or high-value credit products route here. Live facial match bound to the source record. The data can be stolen or fabricated. The face cannot.

C · Standard/high risk

Document + Biometric Matching

Applies to standard or high risk, or when no confident match is returned. In Canada, technology must authenticate the document, per FINTRAC. Thin-file, new-to-country, and young applicants stay onboardable.

The fallback step is what makes the model safe to deploy. Database coverage is broad in both countries, but no source covers everyone. Recent immigrants, young applicants with no credit history, and anyone with a thin or absent bureau file will not always clear a Passive check. An automatic route to the document flow keeps them onboardable while everyone else skips the step entirely.

A routing model imported from Europe or APAC treats biometric enrichment as a premium tier for high-value accounts. In North America it belongs in the mainstream risk logic, because the signature fraud is a fabricated person with real-looking data. A live face bound to the authoritative record is the one check the synthetic applicant cannot rehearse.

Side by Side

The US and Canada Run Different Rails Under Different Rules, and a Flow Has to Respect Both

Both countries permit docless verification and neither has a national ID, but the rails, the named methods, and the fraud pressure differ in kind. A verification programme that treats North America as one market will misconfigure one side of the border.

 United StatesCanada
National IDNoneNone
Regulatory basisCIP rule, 31 CFR 1020.220 and parallels, under USA PATRIOT Act s.326PCMLTFA and PCMLTFR, with FINTRAC methods guidance
Named non-documentary methodMatch against a consumer reporting agency, public database, or other sourceCredit-file method and dual-process method
Credit-bureau railExperian, Equifax, TransUnion (credit-header data)Equifax Canada, TransUnion Canada
Government match servicesSSA eCBSV for SSN confirmation, AAMVA DLDV for driver’s licence dataProvincial registries, bank-login verification via Interac
Sovereign credential / eID login (Active)mDLs, live in early states and expanding, with remote presentation standardisedInterac bank login, provincial digital IDs (BC, Alberta, Quebec)
Assurance frameworkNIST SP 800-63-4, IAL1 to IAL3 (final July 2025)FINTRAC method framework
Signature fraud pressureSynthetic identity (real SSN, fabricated person)Identity fraud, the most-reported fraud type (CAFC 2024)

Source · US CIP rule and NIST SP 800-63-4; Canada PCMLTFA/PCMLTFR and FINTRAC methods guidance; CAFC 2024.

The US runs on credit-header data from the three nationwide bureaus, backed by government match services: the SSA’s eCBSV confirms an SSN, name, and date-of-birth combination, and AAMVA’s DLDV checks driver’s licence data against the issuing agency. The Active rail is the mDL, now live in early states.

Canada runs on Equifax Canada and TransUnion Canada for the FINTRAC credit-file method, with bank-login verification through Interac and provincial digital IDs (the BC Services Card and Alberta.ca Account are live; Quebec’s programme gained its legal basis in October 2025; Ontario’s remains paused and should not be treated as an available rail).

Customer opening an account remotely on a mobile phone
BANKING

Safwa Bank achieved 175% faster mobile onboarding and a 99% verification success rate with Shufti. Bring the same speed and reliability to your customer onboarding.

Book a Demo
Why Shufti

One Shufti integration runs the full North American flow.

Shufti’s advantage in North America is the combination: docless verification and document verification across the US and Canada, through a single integration, with AML screening alongside. Businesses onboarding across both countries usually assemble this from parts, one vendor for bureau checks, another for document capture, a third for watchlist screening, and internal engineering to hold the seams together. Shufti runs the full routing model through one API.

Passive checks draw on 230+ authoritative databases, including the US and Canadian bureau and government rails. Active verification connects to 40+ national eID schemes through the same hub that runs BankID, Singpass, and the European schemes, and in North America that now includes the US mDL rail alongside Interac and the provincial digital IDs. Shufti verifies California and Louisiana mDLs today, with the remaining issuing states activating on client demand through configuration.

99.8%verification accuracy
<3 secondsprocessing time
1,000+enterprise clients
PCI DSS Certified iBeta Level 3 ISO 30107-3 compliant GDPR Fundamentals certified Cyber Essentials Plus CCPA compliant ISO 27001 certified AICPA SOC 2 Type 2

Biometrically Enriched verification binds a live selfie to the source record with liveness detection certified to iBeta PAD Level 3. Where the record is an mDL, the match runs against the licence portrait the issuer returns, which answers the case where the phone in the flow is not held by the person the licence belongs to.

When a case needs a document, the fallback is already in the same flow. Shufti’s document verification supports 10,000+ document types from 240+ countries and territories, combining OCR, NFC chip reading where the document supports it, and biometric face matching. That matters in a region defined by cross-border movement, a US fintech onboarding a new arrival with a foreign passport, or a Canadian platform verifying a customer whose credit file is six months too young for the credit-file method.

AML screening runs in the same flow, so a user verified through either route is screened against sanctions and watchlists without a second integration. Routing logic lives in Journey Builder configuration, not code, so compliance teams can adjust risk tiers or fallback conditions without an engineering release. Teams that prefer to configure and price a full stack without a sales call can start there at any tier.

Map the routing model to your market, product, and risk tiers.

One session maps your products, risk tiers, and markets to the configuration above, across both countries.

What’s inside the full guide

The guide covers the regulatory framework and the arguments for the adoption of Docless KYC in the North American region:

  • North America’s Onboarding Problem
  • How Docless Identity Verification Works
  • Docless Verification Is Written into the Law
  • The Verification Rails, per Country
  • The Risk Routing Model
  • Shufti’s North America Coverage
  • Alongside eIDV: US AML, Bill C-12, and Biometric Privacy Law
  • Getting Started, plus the FAQ
The North America Guide to Docless Identity Verification — guide cover
Guide page — contents
Guide page — the verification rails
Guide page — the risk routing model
Previous
01 - 04
Next

Certifications

Independently audited and certified for enterprise-grade security and data protection.

  • GDPR Compliant
  • GDPR Fundamentals
  • ISO 27001 Certified
  • CCPA
  • iBeta Level 3 ISO 30107-3 Compliant
  • PCI DSS Compliant
  • Shufti SOC 2 Type 2 Compliant

Frequently asked questions (FAQs)

Yes. The CIP rule at 31 CFR 1020.220 expressly permits verifying identity by comparing customer details against a consumer reporting agency, public database, or other source. Parallel rules cover broker-dealers, mutual funds, and futures firms, and it has been in the regulation for over two decades.

Was this content helpful?

Two are docless by design. The credit-file method verifies against a Canadian credit file at least three years old, searched live at the time of verification. The dual-process method uses two independent reliable sources. Both are set out in FINTRAC’s methods guidance under the PCMLTFA.

Was this content helpful?

Database matching alone does not, because a matured synthetic profile can look plausible on paper. Biometrically Enriched verification counters it by requiring a live facial match against the authoritative source record, which a fabricated person cannot supply.

Was this content helpful?

They fall back automatically to document verification with biometric matching in the same flow. Thin-file, new-to-country, and young applicants stay onboardable, and nobody is turned away because a bureau file is missing.

Was this content helpful?

Yes, live today. Shufti verifies state-issued mDLs starting with California and Louisiana, returning issuer-signed attributes including age and address, with a live selfie matched against the licence portrait where proof of person is needed. Additional states and wallets activate on client demand through configuration.

Was this content helpful?
n-img-roi-cross

Form submitted successfully!

Thank you for your interest — your report is loading now.

Build a faster North American onboarding flow with Shufti.

Adding docless verification to an existing document flow, entering the US or Canadian market, or evaluating identity verification for the first time, one session maps your products, risk tiers, and user base to the right configuration across both countries.

    Let’s Tailor Your Journey

    Which products would you like to check out?

    VideoIdent

    Address Verification

    eIDV (Docless)

    KYB

    AML Screening

    Deepfake Detection

    Face and ID Verification

    Age Verification

    Others

    What is your expected yearly verification volume?

    1 to 1,000

    1,001 to 5,000

    5,001 to 20,000

    20,001 to 50,000

    50,001 to 100,000

    100,001 to 1,000,000

    1,000,000+

    Valid Invalid number

    By clicking Submit, you accept our Privacy Policy and consent to marketing communications.

    Product Guide

    AMLR Readiness Checklist: 2027 Gap Assessment | Shufti

    Product Guide

    Shufti’s 2026 Context Gap in AML Risk Assessment

    Product Guide

    Customizable KYC Solution for KYC Product Owners

    Product Guide

    Docless KYC Verification in APAC to Onboard More Genuine Users

    Cover of the Shufti guide to docless KYC verification in APAC
    Product Guide

    EU AMLR Guide 2027: Requirements, Scope, Deadlines | Shufti

    Cover of the Shufti EU AMLR 2027 compliance guide
    Product Guide

    APAC Child Safety Age Verification Regulations

    APAC Child Safety Age Verification Regulations
    Product Guide

    Docless Identity Verification in the Middle East

    docless-identity-verification-middle-east
    Product Guide

    The Future of Docless Verification in Europe

    Onboard already verified users with Docless Verification in Europe
    Product Guide

    Cyprus 2026 KYC Operators Guide to Improve First Pass Rate

    Cyprus 2026 KYC Operators Guide to Improve First Pass Rate
    Product Guide

    Philippines KYC & Account-Owner Verification Playbook | Shufti

    Philippines KYC & Account-Owner Verification Playbook | Shufti
    Product Guide

    Digital Lending KYC Guide for Mexico: INE/IFE, CURP, RFC, Liveness and AML Controls

    Digital Lending KYC Guide for Mexico: INE/IFE, CURP, RFC, Liveness and AML Controls
    Product Guide

    CySEC Forex KYC Compliance Handbook 2026 | Shufti

    CySEC Forex KYC Compliance Handbook 2026 | Shufti
    Product Guide

    Singapore KYC & AML Compliance Guide 2026 | Shufti

    Singapore KYC & AML Compliance Guide 2026 | Shufti
    Product Guide

    Mexico 2026 KYC Handbook to Improve First Pass Rate

    Mexico 2026 KYC Handbook to Improve First Pass Rate
    Product Guide

    Where Can Identity Data Legally Live? 2026 Guide | Shufti

    Where Can Identity Data Legally Live? 2026 Guide | Shufti
    Product Guide

    Shufti Deepfake Fraud Index Report: Deepfake Fraud Set to Surge 495% in 2026

    Shufti Deepfake Fraud Index Report: Deepfake Fraud Set to Surge 495% in 2026
    Whitepaper

    KYC Compliance and Identity Fraud Challenge Across APAC

    KYC Compliance and Identity Fraud Challenge Across APAC
    Product Guide

    Brazil Bets KYC Playbook for .bet.br Operators 2026 | Shufti

    Brazil Bets KYC Playbook for .bet.br Operators 2026 | Shufti
    Product Guide

    Malta iGaming KYC & AML Readiness Guide 2026| Shufti

    Malta iGaming KYC & AML Readiness Guide 2026| Shufti
    Product Guide

    Brazil 2026 KYC Playbook to Improve First Pass Rate

    Brazil 2026 KYC Playbook to Improve First Pass Rate
    Product Guide

    Malta 2026 KYC Playbook to Improve First Pass Rate

    Malta 2026 KYC Playbook to Improve First Pass Rate
    Whitepaper

    The Deepfake Detection Gap

    The Deepfake Detection Gap
    Product Guide

    Choosing the Right Identity Verification Vendor for the Forex Sector

    Choosing the Right Identity Verification Vendor for the Forex Sector
    Product Guide

    A Comprehensive Guide to Address Verification in Complex Markets

    A Comprehensive Guide to Address Verification in Complex Markets
    Whitepaper

    Beyond Benchmark Accuracy: Making Deepfake Detection Work for IDV Systems

    Beyond Benchmark Accuracy: Making Deepfake Detection Work for IDV Systems
    Product Guide

    Human – Assisted Video KYC for Regulated Businesses:

    Human – Assisted Video KYC for Regulated Businesses:
    Whitepaper

    Re-Thinking RegTech for KYC Compliance

    Re-Thinking RegTech for KYC Compliance
    Product Guide

    Enterprise Guide to Choose Right Identity Verification Solution

    Enterprise Guide to Choose Right Identity Verification Solution
    report

    Global Age-Verification Laws 2025 Snapshot

    Global Age-Verification Laws 2025 Snapshot
    Whitepaper

    The Backbone of Global Trust

    The Backbone of Global Trust
    report

    State of Global AML Compliance 2025

    State of Global AML Compliance 2025
    Product Guide

    Strategic ID Verification Vendor for Crypto Industry

    Strategic ID Verification Vendor for Crypto Industry
    report

    Market Positioning and Commercial Assessment Results Presentation

    Market Positioning and Commercial Assessment Results Presentation
    Whitepaper

    Preventing Account Takeover Fraud with Multilayered Defense

    Preventing Account Takeover Fraud with Multilayered Defense
    Whitepaper

    The Critical 1% Closing Systemic Gaps In Global Identity Verification

    The Critical 1% Closing Systemic Gaps In Global Identity Verification
    Whitepaper

    Outsmarting the Deepfake Threat to Identity Trust

    Outsmarting the Deepfake Threat to Identity Trust
    Product Guide

    Scale Without Borders

    Scale Without Borders
    report

    Streamlining Identity Verification: How Shufti Secure Capture Enhances Accuracy and Trust

    Streamlining Identity Verification: How Shufti Secure Capture Enhances Accuracy and Trust
    report

    Top 10 Most Difficult Countries for Identity Verification

    Top 10 Most Difficult Countries for Identity Verification
    Whitepaper

    KYC & AML IN THE MENA Region White Paper 2023

    KYC & AML IN THE MENA Region White Paper 2023
    Whitepaper

    Shufti’s iGaming White Paper 2023

    Shufti’s iGaming White Paper 2023
    report

    Shufti Identity Fraud Report 2022

    Shufti Identity Fraud Report 2022
    report

    Shufti Fraud Report 2021

    Shufti Fraud Report 2021
    report

    Holiday Season – The Prime Time for ID Thieves and Financial Criminals

    Holiday Season – The Prime Time for ID Thieves and Financial Criminals
    report

    Shufti Completes 4 Years of Fighting ID Fraud

    Shufti Completes 4 Years of Fighting ID Fraud
    Product Guide

    On-premises Identity Verification for the Banking Sector

    On-premises Identity Verification for the Banking Sector
    Whitepaper

    Shrinking the Space for Travel Industry Scams with Biometric Verification

    Shrinking the Space for Travel Industry Scams with Biometric Verification
    Product Guide

    Global Gambling Compliance: Regulations, Age Checks & Financial Safety

    Global Gambling Compliance: Regulations, Age Checks & Financial Safety
    report

    A comprehensive guide to KYC and AML compliance in Canada

    A comprehensive guide to KYC and AML compliance in Canada
    n-img-roi-cross

    Form submitted successfully!

    Thank you for your interest — your report is loading now.

    Take the next steps to better security.

    Contact us

    Get in touch with our experts. We'll help you find the perfect solution for your compliance and security needs.

    Contact us

    Get the Shufti newsletter

    Stay ahead of the curve with fresh takes on the latest identity innovations.

      Take the next steps to better security.

      Contact us

      Get in touch with our experts. We'll help you find the perfect solution for your compliance and security needs.

      Contact us

      Request demo

      Get free access to our platform and try our products today.

      Get started

      Pitch a piece and get a verified byline in the Media room.

      Partnership Inquiries?
      Email us at [email protected]

      iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
      Copyright © 2026 Shufti. All rights reserved.