Identity-verification procurement checklist
Start with the decision and evidence you need, not a provider demo. An Irish procurement should define the use case, assurance and failure consequences before comparing document, biometric, database or reusable-credential capabilities.
There is no single Irish list of technology that automatically satisfies every identity or CDD requirement. Regulated organisations must connect method choice to their own applicable rules and risk assessment.
For: procurement, compliance, fraud, privacy, security and product teams. This is independent information, not legal, compliance or security advice.
1. Define the job
- Person, business representative, age or credential being checked.
- Legal or policy trigger, assurance needed and decision owner.
- Geographies, documents, languages, devices and accessibility needs.
- Consequences of false acceptance, false rejection and abandonment.
- Required non-digital or manual fallback.
2. Examine methods and fraud controls
- Document authenticity and chip/NFC support.
- Face match, liveness/PAD and injection protection.
- Authoritative or credible data sources and their permitted use.
- Device, session, rate-limit and duplicate-identity controls.
- Manual-review training, evidence and escalation.
3. Demand evidence
- Exact product/version and scope of tests or certifications.
- Accuracy and demographic results at relevant thresholds.
- Known limitations, unsupported documents and retry behaviour.
- Published integration documentation and sandbox access.
- Incident history and material changes affecting the offered service.
4. Govern data and operations
- Controller/processor roles, data categories, retention and deletion.
- Processing locations, subprocessors and transfers.
- Security, access, audit logs and incident notification.
- Pricing for attempts, retries, manual reviews and minimums.
- SLAs, support, change notice, portability, exit and deletion proof.
5. Pilot before production
Test representative users, documents, fraud cases, accessibility and failure journeys. Set acceptance and stop conditions before the pilot. A high completion rate is not enough if fraud, unfair rejection, privacy or manual-review load is unacceptable.
Evidence and limits
MyID separates enacted rules, official implementation material, testing and vendor claims. A source can establish what its publisher says; it does not prove that every product, deployment or interpretation works as claimed. Where Irish implementation remains unsettled, this page says so.
- Central Bank of Ireland AML/CFT guidance
- NIST SP 800-63A-4 identity proofing
- ENISA Remote Identity Proofing: Attacks and Countermeasures
- General Data Protection Regulation
Sources checked 22 August 2026. Re-check the linked primary material before making a consequential decision.
Next useful pages
Follow the Irish evidence
Get the business briefing when Irish wallet, verification and age-assurance evidence changes.
Join the business briefing