Email/SMS OTP proves only that the signer controls an inbox or phone number — nothing about who they are.
Why identity verification decides whether your signature holds up
Every e-signature law is built on one principle: a signature is only as strong as your ability to prove it was made by the person it claims to be. That link is created by identity verification — the step that confirms the signer really is who they say they are, before or at the moment of signing. There is no global standard for how strong that verification must be: Europe mandates a specific level for legally privileged signatures, North America mostly leaves it to commercial judgment, and Asia-Pacific swings between government-grade digital ID and almost nothing. This guide walks through the four verification methods in common use, ranks their strength, maps them to the major regions — including mainland China — and gives you a checklist to evaluate any vendor against.
At a glance
Knowledge-based authentication (KBA) checks what the signer knows, but its strength is declining as personal data leaks.
ID document + selfie/liveness verifies a genuine document and a biometric match to the holder.
A digital certificate or government eID guarantees identity through a trusted third party — the highest assurance level.
The four verification methods, weakest to strongest
Level 1 — Email / SMS OTP
A one-time code sent to email or SMS unlocks the signing session. It proves possession of that inbox or phone number, not the signer's identity. Very low friction and cost; best for low-risk documents, internal workflows, and repeat signers you already know.
Level 2 — Knowledge-Based Authentication (KBA)
The signer answers questions from credit history or personal records. It proves knowledge, not identity — and because that data is increasingly obtainable from breaches, the U.S. NIST has formally downgraded KBA as a strong authentication factor. Used mostly in North America, where credit-bureau data makes it possible.
Level 3 — ID document + selfie / liveness
The signer uploads a government ID and takes a selfie; automated checks compare the faces, verify document security features, and run liveness detection against replay attacks. This proves the document is genuine and the holder matches the photo. Strong, but higher friction and per-use cost.
Level 4 — Digital certificate / government eID
Identity is verified once through a strong, often in-person or government-anchored process, and a digital certificate binds that verified identity to every signature thereafter — sometimes delivered through a government eID the signer already holds. This is the highest assurance level and, in Europe, what enables Qualified Electronic Signatures (QES).
Strength comparison at a glance
Match the verification level to the value at stake and the legal bar of the governing jurisdiction — not to what a vendor offers by default.
| L1 · OTP | L2 · KBA | L3 · ID + Selfie | L4 · Certificate / eID | |
|---|---|---|---|---|
| What it proves | Possession | Knowledge | Document + biometric match | State/CA-guaranteed identity |
| Security | Weak | Weak→moderate | Strong | Strongest |
| Repudiation risk | High | Medium | Low | Very low |
| Signer friction | Very low | Moderate | High | Low (if eID held) |
| Typical cost | Low | Moderate, per-use | Higher, per-use | High upfront / bundled |
| Common in | Everywhere | North America | Global, growing | Europe (QES), APAC eID |
The verification strength ladder
Each step up adds proof of who the signer really is — from possession, to knowledge, to biometric match, to state-guaranteed identity.

From a simple OTP (weakest) to a certificate or government eID (strongest).
Regional differences
Europe — eIDAS sets the floor
Europe is the only major region with a legal ladder for signature strength: SES (Simple), AES (Advanced), and QES (Qualified). Only QES — built on a qualified certificate from a QTSP, with identity verified up front — carries the legal effect of a handwritten signature across all member states. eIDAS 2.0 (Regulation (EU) 2024/1183) adds the EU Digital Identity Wallet, which member states must provide by end of 2026.
North America — consent over identity
The U.S. ESIGN Act and UETA do not mandate a verification level; legality rests on consent, intent, association, and record retention. Vendors default to OTP and offer KBA (credit-bureau powered) and ID + selfie as premium options, with no national eID. Because the law won't force a level, your repudiation defense is the audit trail.
Asia-Pacific — strong government eID, fragmented
APAC has the world's most advanced government digital identities but no regional mutual recognition: Singapore's Singpass Face Verification matches a live scan against government records; India uses Aadhaar eKYC; Japan has the My Number Card; South Korea's 2020 Act revision opened a plural private-certificate market. Strong is achievable — but only if the vendor integrates each market's local government eID.
China (mainland) — real-name + MIIT-licensed CA
China's Electronic Signature Law ties a "reliable electronic signature" — one with the legal effect of a handwritten signature or company seal — to a digital certificate from an electronic certification service provider (CA) licensed by the Ministry of Industry and Information Technology (MIIT), combined with real-name authentication (face / ID / bank-card checks). For mainland signers, verify the vendor integrates an MIIT-licensed CA rather than only a foreign certificate, and that data residency satisfies the PIPL.
Decision framework: which level for which scenario
Find your risk row, read across for the region you sign in. If you sign in multiple regions, pick the highest applicable level — or use a vendor that can vary verification per document and per signer.
| Europe | North America | APAC (excl. China) | China (mainland) | |
|---|---|---|---|---|
| Internal / low-value | SES / OTP | OTP | OTP | OTP / simple signature |
| Standard B2B | AES (certificate) | OTP + audit trail | OTP or local eID | MIIT-licensed CA + real-name authentication |
| Regulated / high-value | QES | ID + selfie | Local government eID | Reliable e-signature (MIIT-licensed CA + real-name) |
| Cross-border / court-proof | QES | Evidence package | Country-specific | Reliable e-signature + electronic evidence |
Frequently asked questions
Match it to the value at stake and the governing law. Low-value internal documents need only OTP; regulated or high-value agreements in Europe need QES, and in mainland China need a reliable electronic signature backed by an MIIT-licensed CA.
Legal and regulatory requirements change over time and vary by jurisdiction. This guide reflects publicly available information as of 2026-08-19 and is not legal advice. Verify current requirements and each vendor's integrations with qualified counsel before purchasing.







