Identity-verification methods compared
No identity-verification method is strongest in every circumstance. The right design combines evidence validation, proof that the applicant controls or owns that evidence, fraud controls, and a usable fallback appropriate to the Irish service.
Irish organisations use a mix of documents, data, biometrics and manual processes. EUDI credentials add a reusable presentation route, but existing methods and alternatives will continue during transition.
For: Irish product, risk, fraud, privacy and procurement teams. This is independent information, not legal, compliance or security advice.
Comparison
| Method | What it contributes | Principal limitation |
|---|---|---|
| Document image | Visible and machine-readable evidence | Image quality, forgery and possession are not ownership |
| NFC chip | Digitally signed chip data and portrait | Device/document support and user friction |
| Face match | Compares applicant to evidence portrait | Biometric governance, errors and spoofing controls |
| Data check | Confirms attributes against a source | Access, freshness and population coverage |
| Manual review | Handles ambiguity and exceptions | Consistency, cost, privacy and queue delay |
| Reusable credential | Presents previously verified signed attributes | Issuer trust, status, wallet availability and fallback |
Validation is not verification
Checking that a passport appears genuine validates evidence. Establishing that the applicant is its legitimate holder verifies ownership. A complete process also resolves attributes to an identity, binds the resulting account and supports correction or redress.
Choose by failure consequence
- Low-consequence access may require little or no identity proofing.
- Regulated onboarding may need multiple evidence and ownership controls.
- Age-gated access should disclose only the required age result where possible.
- High-risk recovery may require re-proofing rather than repeating a weak knowledge check.
Minimum comparison questions
- What does the method actually prove?
- Which attacks remain possible?
- Who cannot complete it and what alternative exists?
- What data is created, retained and shared?
- Which independent evidence covers the exact product and configuration?
Evidence and limits
MyID separates enacted rules, official implementation material, testing and vendor claims. A source can establish what its publisher says; it does not prove that every product, deployment or interpretation works as claimed. Where Irish implementation remains unsettled, this page says so.
- NIST SP 800-63A-4 identity proofing
- ENISA Remote Identity Proofing: Attacks and Countermeasures
- European Commission EUDI Wallet Toolbox and ARF
Sources checked 22 August 2026. Re-check the linked primary material before making a consequential decision.
Next useful pages
Follow the Irish evidence
Get the business briefing when Irish wallet, verification and age-assurance evidence changes.
Join the business briefing