Database Verification: How Electronic Identity Checks Work
Not every identity check needs a passport photo. Database verification confirms who a customer is by matching the details they give against independent data sources — in seconds, with no document upload. This guide explains how it works, what regulators accept, and where it needs to be combined with document and biometric checks.
Database verification is the identity check that customers barely notice: they type their details, and the system confirms them against records that already exist. For low- and standard-risk onboarding, it can replace a document upload entirely — which is why it is one of the main levers for reducing onboarding drop-off.
Its limitation is just as important. A database can confirm that a real person called Jane Tan lives at a given address and was born on a given date. It cannot confirm that the person typing those details is Jane Tan.
How Database Verification Works
Capture
The customer enters their full name, date of birth, current address and, where relevant, a national identifier.
Query
The verification service queries one or more independent data sources — ideally more than one, as single-source checks are weak.
Match
Each data element is compared with each source, allowing for formatting differences, abbreviations and transliteration. The result is a set of matches per source.
Decide
The matches are tested against the firm's rule — for example the 2+2 standard below. Customers who pass are verified; those who do not are referred to document verification rather than declined outright.
Common Data Sources
| Source | What it confirms | Watch out for |
|---|---|---|
| Credit reference agencies | Name, address history and date of birth from credit activity | Thin files for young people and recent arrivals |
| Electoral rolls / voter registers | Name at an address | Not everyone registers; a single electoral roll match is not enough on its own |
| Government sources | Identity attributes held by the state, where access is permitted | Availability differs widely by country |
| Telecom and utility data | Name linked to a phone number or service address | Accounts in another household member's name |
| Singapore Myinfo | Government-verified personal data shared with the customer's consent | Available only to customers with Singpass |
Matching Rules: The 2+2 Standard
A single match proves little — an address can be guessed and a name is common. Regulators and industry guidance therefore expect corroboration across sources.
The UK's Joint Money Laundering Steering Group (JMLSG) guidance sets a standard level of confirmation, where nothing gives rise to concern, of:
- one match on the customer's full name and current address, and
- a second match on full name and either current address or date of birth.
This is widely called the "2+2" rule. JMLSG also notes that a check against a single source — for example, the electoral roll alone — is not normally enough on its own. Firms elsewhere often adopt the same logic as their internal standard, adjusted for local data availability and risk appetite.
Database vs Document Verification
| Database verification | Document verification | |
|---|---|---|
| What it proves | The identity exists and the details are consistent | The applicant holds a genuine identity document |
| Customer effort | Type details only | Photograph or upload a document |
| Speed | Seconds | Seconds to minutes, plus manual review for edge cases |
| Coverage gaps | Thin-file customers, many non-residents | Unfamiliar document types, poor image quality |
| Main weakness | Stolen or synthetic identities can pass | Forged or altered documents |
The strongest onboarding flows combine them by risk: database verification for low-risk customers, document verification where it fails or risk is higher, and biometric and liveness checks to bind the identity to the person in front of the camera.
Where Regulators Accept It
- United Kingdom — electronic verification is accepted under JMLSG guidance, subject to the standard level of confirmation and the reliability of the sources used.
- United States — the Customer Identification Program rule (31 CFR 1020.220 for banks) allows non-documentary verification, including comparing customer information with information from a consumer reporting agency, public database or other source. The CIP must set out when non-documentary methods are used — for example where a customer opens an account without appearing in person.
- Singapore — MAS allows Myinfo to be used for non-face-to-face customer identification and verification. Firms that obtain a customer's identity data through Myinfo are not required to collect additional documents to verify that identity, or a separate photograph.
- European Union — the AML framework recognises electronic identification means and trust services under the eIDAS Regulation as a way to verify identity.
In every jurisdiction the underlying test is the same: the source must be reliable and independent of the customer, and the firm must document why its method is adequate for the risk.
Limitations and Fraud Risks
- Synthetic identities — fraudsters combine real and invented data that can build a credit footprint over time and pass database checks.
- Stolen identities — a genuine person's details pass every match; only a link to the real person (document plus biometrics, or device and behavioural signals) catches the impostor.
- Data recency — recent house moves and name changes cause false failures.
- Coverage — young adults, recent immigrants and many non-residents have little data, so database checks fail them disproportionately.
These are reasons to layer database verification with other checks, not to avoid it. Used as the first layer in a risk-based flow, it removes friction for most legitimate customers and concentrates manual effort on the cases that need it. See our eKYC and digital identity guide for how the layers fit together.
Frequently Asked Questions
What is database verification?
Database verification confirms a customer's identity by matching the details they provide — name, address, date of birth — against independent data sources such as credit bureaus, electoral rolls or government records.
Is database verification enough for KYC?
For lower-risk customers it can be, where the regulator accepts electronic verification and the matching standard is met. For higher-risk customers it is usually combined with document and biometric checks, because database checks cannot prove the applicant is the person whose details they entered.
What is the 2+2 rule in identity verification?
It is the UK JMLSG standard level of confirmation: one match on full name and current address, plus a second match on full name and either current address or date of birth.
What is electronic identity verification (eIDV)?
eIDV is another name for database verification — checking identity electronically against reliable data sources rather than, or as well as, inspecting a physical document.
Can Myinfo be used for KYC in Singapore?
Yes. MAS allows financial institutions to use Myinfo for non-face-to-face customer identification and verification, without collecting additional documents to verify the identity data obtained through it.
Sources
- JMLSG — Guidance Part I, Chapter 5: Customer due diligence
- eCFR — 31 CFR 1020.220, Customer identification program requirements for banks
- MAS — Circular on non-face-to-face customer due diligence measures
This article is general information, not legal advice. Requirements change — check the current text with the regulator before relying on it.
Identity Verification That Adapts to Risk
One Constellation combines document, biometric and liveness verification with screening and risk scoring, so each customer gets the level of check their risk requires.
