When a company hires someone it has never met in person, one question quietly underpins everything that follows: is this new hire actually a real human being, and the same one who was interviewed?
For years, onboarding simply assumed the answer was yes. In 2026, with AI capable of generating convincing fake faces, voices, and even ID documents on demand, that assumption is dangerous.
This is where new-hire identity proofing comes in, and understanding how it actually works, from the government ID to biometric liveness detection to the promise that no data is stored, makes it much easier to tell strong verification from security theatre.
Why new-hire identity proofing matters
The pressure is coming from two directions. Onboarding was built for speed, so temporary passwords, access handoffs, and service-desk requests have long assumed identity rather than verified it.
At the same time, AI has made impersonation cheap and scalable. The 2026 Verizon Data Breach Investigations Report documented North Korean fake-worker schemes that may have leveraged as many as 15,000 stolen identities, and fraud-prevention firm Sift reports that AI now assists more than 82 percent of phishing emails. Proving identity at the point of hiring is no longer paranoia; it is basic hygiene.
Modern identity proofing generally works in three layers: verifying the document, matching the face, and proving the person is real and present. Here is what each layer does.
Layer 1: Verifying the government-issued ID
The first step is authenticating a government-issued ID, such as a passport, national ID card, or driver’s license. A good system does far more than read the text off the card.
It inspects security features like fonts, holograms, microprint, and the machine-readable zone, checks that the data is internally consistent, and looks for signs of tampering or, increasingly, fully synthetic documents generated by AI.
Fraudsters now use generative AI to produce fake IDs pre-populated with real personal details harvested from data breaches, so document authentication must detect forgeries that appear flawless to the human eye.
Coverage matters here, too. A platform that supports thousands of document types across many countries, in Specops Secure Onboarding’s case, more than 16,000 document types across 254 countries and territories, can verify a genuinely global, remote workforce.
For a Nigerian employer or a company hiring in Nigeria, that means locally issued documents such as the international passport, the National Identity Number (NIN) slip, a driver’s license, or a voter’s card can serve as the anchor for verification rather than a foreign document that the system does not recognize.
Layer 2: Matching the face to the ID
Once the document is trusted, the system compares the face on the ID to a selfie or short video captured from the new hire. This is a one-to-one biometric face match: it confirms that the person holding the document is the person the document belongs to.
On its own, though, a face match is weak because a printed photo or a deepfake video can also “match” the ID. That is exactly why the third layer exists.
Layer 3: Proving the person is real and present (liveness detection)
Biometric liveness detection is the check that confirms the face in front of the system belongs to a real, physically present human, not a photo, a replayed video, a mask, or a deepfake.
It typically runs alongside or just before the face match. There are two broad styles: passive liveness, which analyzes a single capture for tell-tale signs of a spoof without asking the user to do anything, and active liveness, which asks the user to blink, turn their head, or follow a prompt.
Passive liveness is smoother for the user; active liveness adds friction but an extra signal. Many strong systems combine multiple signals, analyzing 3D facial depth, micro-movements, and lighting consistency at once, because a single signal is easy for modern deepfakes to fool.
Presentation Attacks vs Injection Attacks
Here is the distinction between real protection and a checkbox. Liveness detection was designed to stop presentation attacks, where a fraudster holds a spoof, a printed photo, a screen, a mask or a replayed video, in front of the camera.
The international standard ISO/IEC 30107-3:2023 defines how systems are tested against these attacks, and third-party certifications such as iBeta Level 1 and Level 2 validate that a vendor’s presentation attack detection actually performs.
But in 2026, the harder threat is the injection attack. Instead of showing a fake to the camera, the attacker bypasses the camera entirely, feeding a pre-recorded or AI-generated video straight into the verification pipeline using virtual-camera software or SDK-level hooks.
The camera never sees the spoof because the camera was never involved, which is why injection attacks can sail past standard liveness checks. Security researchers reported that injection attacks surged dramatically through 2024 and 2025 as virtual-camera exploits became commoditized, and regulators have taken note. The US FinCEN issued an alert on deepfake media used in identity fraud, and Deloitte has projected that generative AI-enabled fraud losses in the US could reach $40 billion by 2027.
Defending against injection requires a separate pipeline-integrity layer that verifies that the capture is from a genuine device, not a substituted stream, in addition to liveness. When you evaluate any identity-proofing tool, ask specifically how it handles injection, not just presentation, attacks.
Why “No end-user data stored” matters
A recurring claim in modern identity proofing, and one Specops makes for Secure Onboarding, is that no end-user data is stored.
This is a data-minimization principle. The system verifies the person in the moment and does not retain their biometric template or ID document afterward.
The security logic is simple. Data you never keep cannot be breached, leaked, or misused later.
For compliance teams, that shrinks the regulatory surface around sensitive biometric and identity data considerably, and for employees, it means submitting to a verification check does not hand the employer a permanent copy of their face and passport.
Where this fits in the new-hire journey
Identity proofing is only useful if it sits at the moments where identity was previously assumed.
In Specops Secure Onboarding, for example, the new employee sets their own first Active Directory password through a secure enrollment link and verifies their identity via liveness and government ID at that point, rather than receiving a temporary password via email.
Because the service desk is a favorite target for social engineering, callers can be re-verified before sensitive support actions, with that verification running within existing ServiceNow, Jira, and other ITSM workflows, and every check logged for audit purposes.
“Verification needs to start with the very first password and continue through high-risk support interactions.”
said Darren James, Senior Product Manager at Specops, framing the point of building proofing into onboarding rather than bolting it on later.
A quick checklist for evaluating identity proofing
When comparing tools, look for certified presentation attack detection tested to ISO/IEC 30107-3, explicit injection attack detection, broad document coverage for your workforce’s countries, reliable one-to-one face matching, clear data-minimization (ideally no data stored), audit logging for every verification, and integration with the systems your IT and service-desk teams already use.
A tool that only ticks the liveness box, with nothing said about injection attacks or data handling, is addressing yesterday’s threat.
Frequently Asked Questions
What is new-hire identity proofing? It is the process of confirming that a new employee is a real, specific person, typically by authenticating a government-issued ID, matching it to the person’s face, and using biometric liveness detection to prove they are physically present rather than a photo or deepfake. It is applied at onboarding, when identity was traditionally assumed.
What is biometric liveness detection? Biometric liveness detection is a check that confirms a face belongs to a live, present human rather than a printed photo, a replayed video, a mask or a deepfake. It runs alongside face matching and comes in passive (no user action) and active (blink, turn, follow a prompt) forms.
What is the difference between a presentation attack and an injection attack? A presentation attack shows a spoof to the camera, such as a photo, screen or mask, and is defended by presentation attack detection. An injection attack bypasses the camera entirely by feeding a synthetic video stream into the verification pipeline, so it needs a separate pipeline-integrity defence, not liveness alone.
What does “no end-user data stored” mean? It means the system verifies the person’s identity in the moment but does not retain their biometric template or ID document afterwards. Because retained data can be breached or misused, not storing it reduces both security risk and regulatory exposure.
Why is identity proofing important for Nigerian employers? Nigerian firms and companies hiring Nigerian talent increasingly onboard people they never meet in person. Identity proofing lets them anchor verification to local documents such as an international passport, NIN slip, driver’s licence or voter’s card, protecting against fraud while letting genuine applicants prove they are real.







