WHAT IT IS
VerifyID is INM's identity verification and strong authentication service. It reuses the biometric identity captured during onboarding - via a single API and OIDC/OAuth 2.0 - to confirm who is on the other side of any operation, channel, app or partner integration. It combines 3D biometric matching, document validation and a configurable risk matrix, so each operation triggers only the authentication factors its risk level requires. Core- and channel-agnostic, the same API answers a mobile app, a branch counter or a partner, whichever central system sits behind it.
WHY IT MATTERS
One API to verify identity - biometrics, document validation and OIDC external authentication - reusable by apps, portals and partners. One call, one decision, no duplicate integrations per channel.
ADVANTAGES
The same biometric identity captured at onboarding authenticates transfers, logins, device changes and partner integrations - no recapture, no duplicate enrolment.
Biometrics, document validation and OIDC/OAuth authentication behind a single API - no separate integration per channel or partner.
Biometrics and soft-token operate as two independent factors, meeting PSD2/PSD3 strong customer authentication requirements without extra steps.
Every biometric confirmation is sealed with a hash, timestamp and geolocation - audit-ready evidence, not a separate signature process.
HOW IT WORKS
An app, portal or partner sends a verification request via API or OIDC redirect.
The configurable risk matrix decides which authentication factors this operation requires.
If needed, a 3D selfie is captured and matched against the stored identity - or against watchlists for 1:N checks.
VerifyID returns a real-time decision to the calling system, with the evidence trail stored for audit.
FEATURES
Biometric step-up authentication for sensitive operations - high-value transfers, contact-detail changes, device changes.
Credential recovery without a branch visit: biometric match cross-checked against the original enrolment document.
Remote certification and binding of a new device, with cryptographic device association.
Soft-token registration and lifecycle: local TOTP, push approval for sensitive operations.
OIDC / OAuth 2.0 external authentication for apps, portals and third-party partners.
Biometric signature with legal evidence trail: selfie hash, 3D face map, timestamp and geolocation.
Configurable risk matrix per operation type - defines which authentication factors trigger automatically.
Optional government digital-ID integration (e.g. mobile digital key schemes) as an alternative or additional factor.
Built as the authentication layer sitting on top of the same biometric engine used for onboarding.
BUILT FOR
Mobile, internet banking, agents and third-party apps consuming the same verification API instead of building it four times.
Strong customer authentication met by design, without adding friction to every operation.
Credential recovery, device changes and high-risk operations resolved remotely, without a branch visit.
External OIDC integration lets non-banking apps and portals verify identity without building their own biometric stack.
It is INM's identity verification and authentication service. It reuses the biometric identity captured at onboarding - through a single API with OIDC/OAuth 2.0 - to confirm who is performing an operation, on any channel or partner integration.
Yes. The core connection is adapter-based - Banka, Finastra Essence, an in-house legacy system, whatever is already there - over API/ISO, with no change to the central system. The domestic side works the same way: each market's clearing house, EMIS in Angola included, plugs in through an adapter.
Both. Banks in markets with data-residency requirements usually choose on-premise; SaaS where regulation allows it.
It can run standalone via API for partners or apps with no INM onboarding in place, but it reaches full value when it reuses the same biometric identity OnboardID already captured - one enrolment, every subsequent verification.
INM's own teams - we don't subcontract implementation. The same team runs, evolves and supports the product 24/7 after go-live.
Talk to our team to see how this product fits your ecosystem.