KuppingerCole’s Buyer’s Compass for Providers of Verified Identity is a practical starting point for narrowing and evaluating vendors during RFI/RFP cycles. It structures selection around primary use cases, weighted functional and non-functional criteria, and the technical and organizational prerequisites required for a successful rollout. The intended outcome is an efficient shortlisting process that leads into deeper RFIs and proofs of concept, rather than a complete end-to-end procurement playbook.
Providers of Verified Identity are defined as solutions that verify a digital identity corresponds to a real-world identity and enable that verified identity to be used across platforms, services, or companies. The market is future-oriented, anticipating greater reliance on verified identities to improve privacy, meet KYC/AML compliance needs, and streamline onboarding and ongoing relationships. Technologies vary widely—passwords, certificates, biometrics, eTokens, federated trusted sources, decentralized identifiers (DIDs), and AI-supported approaches—yet all aim to underpin IAM and CIAM security while enabling remote verification at higher assurance levels. A reusable verified identity is positioned as potentially disruptive, changing how trust, data storage, compliance effort, and fraud prevention work, though no dominant approach has yet emerged.
The document highlights five key use cases: customer onboarding, employee/partner onboarding, transaction-grade KYC/AML verification, authentication based on verified identity (often via biometrics as a second factor), and sharing verified identity attributes far beyond basic demographics. Selection is guided by 20 functional criteria (document processing, biometrics, liveness, fraud detection, risk scoring, privacy, ZKPs, AI governance, APIs/SDKs, storage, user control, and more) and 10 non-functional criteria (deployment models, time-to-value, vendor viability, partner ecosystems, roadmap, and pricing). A matrix maps use cases to criteria priorities, complemented by technical prerequisites (Identity Fabric, monitoring, extensibility) and organizational requirements (ownership, training, incident response, budget, and authority).
See All Locations
See All Locations