eSign.AIeSign.AI

Buying Guides

Identity Verification in eSignatures: How to Confirm the Signer Is Who They Say (2026 Buying Guide)

Compare the four signer identity verification methods — OTP, KBA, ID + selfie, and certificate/eID — and how Europe, North America, APAC and mainland China differ.

eSign.AI Regulatory & Industry Research Team7 min read

Why identity verification decides whether your signature holds up

Every e-signature law is built on one principle: a signature is only as strong as your ability to prove it was made by the person it claims to be. That link is created by identity verification — the step that confirms the signer really is who they say they are, before or at the moment of signing. There is no global standard for how strong that verification must be: Europe mandates a specific level for legally privileged signatures, North America mostly leaves it to commercial judgment, and Asia-Pacific swings between government-grade digital ID and almost nothing. This guide walks through the four verification methods in common use, ranks their strength, maps them to the major regions — including mainland China — and gives you a checklist to evaluate any vendor against.

At a glance

01

Email/SMS OTP proves only that the signer controls an inbox or phone number — nothing about who they are.

02

Knowledge-based authentication (KBA) checks what the signer knows, but its strength is declining as personal data leaks.

03

ID document + selfie/liveness verifies a genuine document and a biometric match to the holder.

04

A digital certificate or government eID guarantees identity through a trusted third party — the highest assurance level.

The four verification methods, weakest to strongest

Level 1 — Email / SMS OTP

A one-time code sent to email or SMS unlocks the signing session. It proves possession of that inbox or phone number, not the signer's identity. Very low friction and cost; best for low-risk documents, internal workflows, and repeat signers you already know.

Level 2 — Knowledge-Based Authentication (KBA)

The signer answers questions from credit history or personal records. It proves knowledge, not identity — and because that data is increasingly obtainable from breaches, the U.S. NIST has formally downgraded KBA as a strong authentication factor. Used mostly in North America, where credit-bureau data makes it possible.

Level 3 — ID document + selfie / liveness

The signer uploads a government ID and takes a selfie; automated checks compare the faces, verify document security features, and run liveness detection against replay attacks. This proves the document is genuine and the holder matches the photo. Strong, but higher friction and per-use cost.

Level 4 — Digital certificate / government eID

Identity is verified once through a strong, often in-person or government-anchored process, and a digital certificate binds that verified identity to every signature thereafter — sometimes delivered through a government eID the signer already holds. This is the highest assurance level and, in Europe, what enables Qualified Electronic Signatures (QES).

Strength comparison at a glance

Match the verification level to the value at stake and the legal bar of the governing jurisdiction — not to what a vendor offers by default.

L1 · OTPL2 · KBAL3 · ID + SelfieL4 · Certificate / eID
What it provesPossessionKnowledgeDocument + biometric matchState/CA-guaranteed identity
SecurityWeakWeak→moderateStrongStrongest
Repudiation riskHighMediumLowVery low
Signer frictionVery lowModerateHighLow (if eID held)
Typical costLowModerate, per-useHigher, per-useHigh upfront / bundled
Common inEverywhereNorth AmericaGlobal, growingEurope (QES), APAC eID

The verification strength ladder

Each step up adds proof of who the signer really is — from possession, to knowledge, to biometric match, to state-guaranteed identity.

Identity verification strength ladder

From a simple OTP (weakest) to a certificate or government eID (strongest).

Regional differences

Europe — eIDAS sets the floor

Europe is the only major region with a legal ladder for signature strength: SES (Simple), AES (Advanced), and QES (Qualified). Only QES — built on a qualified certificate from a QTSP, with identity verified up front — carries the legal effect of a handwritten signature across all member states. eIDAS 2.0 (Regulation (EU) 2024/1183) adds the EU Digital Identity Wallet, which member states must provide by end of 2026.

North America — consent over identity

The U.S. ESIGN Act and UETA do not mandate a verification level; legality rests on consent, intent, association, and record retention. Vendors default to OTP and offer KBA (credit-bureau powered) and ID + selfie as premium options, with no national eID. Because the law won't force a level, your repudiation defense is the audit trail.

Asia-Pacific — strong government eID, fragmented

APAC has the world's most advanced government digital identities but no regional mutual recognition: Singapore's Singpass Face Verification matches a live scan against government records; India uses Aadhaar eKYC; Japan has the My Number Card; South Korea's 2020 Act revision opened a plural private-certificate market. Strong is achievable — but only if the vendor integrates each market's local government eID.

China (mainland) — real-name + MIIT-licensed CA

China's Electronic Signature Law ties a "reliable electronic signature" — one with the legal effect of a handwritten signature or company seal — to a digital certificate from an electronic certification service provider (CA) licensed by the Ministry of Industry and Information Technology (MIIT), combined with real-name authentication (face / ID / bank-card checks). For mainland signers, verify the vendor integrates an MIIT-licensed CA rather than only a foreign certificate, and that data residency satisfies the PIPL.

Decision framework: which level for which scenario

Find your risk row, read across for the region you sign in. If you sign in multiple regions, pick the highest applicable level — or use a vendor that can vary verification per document and per signer.

EuropeNorth AmericaAPAC (excl. China)China (mainland)
Internal / low-valueSES / OTPOTPOTPOTP / simple signature
Standard B2BAES (certificate)OTP + audit trailOTP or local eIDMIIT-licensed CA + real-name authentication
Regulated / high-valueQESID + selfieLocal government eIDReliable e-signature (MIIT-licensed CA + real-name)
Cross-border / court-proofQESEvidence packageCountry-specificReliable e-signature + electronic evidence

Frequently asked questions

Match it to the value at stake and the governing law. Low-value internal documents need only OTP; regulated or high-value agreements in Europe need QES, and in mainland China need a reliable electronic signature backed by an MIIT-licensed CA.

Legal and regulatory requirements change over time and vary by jurisdiction. This guide reflects publicly available information as of 2026-08-19 and is not legal advice. Verify current requirements and each vendor's integrations with qualified counsel before purchasing.

Team discussing the right eSignature approach for a business

Explore the right eSignature approach for your business

Talk to our team about eSignature requirements, compliance considerations, and document workflows across your target markets.