Identity verification should not end after account creation. A customer who passed KYC months or years ago may later change their identity information, lose control of their account, use a suspicious device, or perform an unusually risky transaction.
Identity reverification allows digital platforms to confirm that the current user is still the legitimate account owner. It is an important component of ongoing KYC, account takeover prevention, and risk-based customer due diligence.
Global standards increasingly support this risk-based approach. The FATF Recommendations establish a common framework for ongoing customer due diligence, while FinCEN guidance states that customer information should be updated when monitoring identifies a change relevant to the customer’s risk profile.
1. What Is Identity Reverification?
Identity reverification is the process of confirming an existing user’s identity again after initial onboarding. Depending on the risk level, it may involve:
- Comparing a current face with the trusted enrollment portrait
- Performing liveness detection
- Recapturing an identity document
- Extracting and validating updated document information
- Checking changes in customer, device, or session data
- Reviewing the customer’s overall risk profile
Reverification does not always mean repeating the entire KYC process. A low-risk event may require only a face verification check, while a significant identity or compliance change may require full document and biometric verification.
Face++ can be integrated as a step-up identity layer within this process. Its face comparison and liveness capabilities help platforms determine whether the person currently accessing the account matches the previously verified identity and is genuinely present.

2. When Is Identity Reverification Required?
2.1 Identity Information Has Changed
A change to a customer’s legal name, address, nationality, identity document, or other material profile information may require reverification.
The platform should determine whether the change affects only one field or calls the original identity record into question. An address update may require a new proof-of-address document, while a changed legal name or identity document may justify broader KYC reverification.
2.2 An Identity Document Has Expired
Expired documents may no longer provide sufficient evidence for regulated services. Platforms can request a new document, extract its fields through OCR, validate its format and authenticity, and compare its portrait with a live face.
The new document should also be checked against existing account information to identify unexplained changes in name, date of birth, nationality, or document number.
2.3 The User Requests Account Recovery
Password resets alone may be insufficient when a user has lost access to their email, phone number, authenticator, or trusted device.
Face verification can provide stronger evidence of identity ownership. A current facial image is compared with the trusted enrollment portrait, while liveness detection helps prevent printed-photo, screen-replay, deepfake, and injection attacks.
Face++ can support this recovery workflow without requiring every user to complete full document verification again.
2.4 A High-Risk Transaction Is Initiated
Large withdrawals, new beneficiaries, unusual transfers, payment-method changes, or other sensitive actions may justify step-up identity verification.
The decision should consider transaction value, customer history, device information, location, behavioral signals, and account relationships. When risk rises, the platform can trigger Face++ face verification and liveness before allowing the transaction to continue.
2.5 A New or Suspicious Device Appears
A new device does not automatically indicate fraud. However, a new device combined with a password reset, unusual location, proxy connection, emulator use, or rapid account changes can indicate account takeover.
Device intelligence identifies the session risk, while facial verification binds the session back to the legitimate person. This layered approach is more reliable than treating device fingerprinting as standalone proof of identity.
2.6 Account Behavior Changes Significantly
Reverification may be appropriate when current behavior differs sharply from the customer’s established profile. Examples include:
- Sudden changes in transaction frequency
- Multiple accounts linked to the same device or face
- Rapid profile and security-setting changes
- Unusual login locations
- Repeated verification failures
- Activity inconsistent with the account’s expected purpose
These signals should enter a risk engine rather than act as automatic rejection rules. Medium-risk cases may receive a face check, while higher-risk cases may require complete KYC reverification or manual review.
2.7 Compliance or Screening Risk Changes
A change in sanctions, politically exposed person status, adverse information, ownership structure, jurisdiction, or expected customer activity may require updated customer due diligence.
FinCEN’s current guidance emphasizes that updates should be driven by relevant risk changes rather than an inflexible schedule. Platforms must still configure their workflows according to the regulations that apply in each market.
3. Event-Driven vs Periodic Reverification
Periodic KYC reviews remain useful, especially for higher-risk customers. However, a fixed annual or multi-year schedule may leave long gaps during which important risk changes go undetected.
Event-driven reverification responds when a meaningful signal appears. A practical digital identity verification strategy normally combines both approaches:
- Periodic reviews based on customer risk level
- Real-time monitoring for material changes
- Step-up face verification for moderate-risk events
- Full reverification for major identity or compliance changes
This model reduces unnecessary friction for trusted customers while applying stronger controls when risk actually increases.

4. How Face++ Supports Risk-Based Reverification
Face++ can serve as the biometric identity-binding layer within an event-driven workflow. The platform’s own risk systems first identify a trigger, such as a new device or high-risk transaction. Face++ capabilities can then help:
- Capture the current user’s face securely
- Confirm genuine presence through liveness detection
- Compare the live face with a trusted reference image
- Return verification results to the platform’s decision engine
The final action may be to continue the session, request additional evidence, route the case for review, or block the activity. Face matching should therefore be combined with liveness, device intelligence, document checks, and behavioral risk analysis.
5. Frequently Asked Questions
Q: Is identity reverification required for every customer?
Not necessarily. The appropriate frequency and depth depend on applicable regulations, customer risk, product type, and detected events. Risk-based reverification is generally more proportionate than forcing every user through the same process.
Q: Can face verification replace full KYC reverification?
Face verification is suitable when the platform needs to confirm that the current user matches a trusted identity. If core identity information or documents have changed, additional document and compliance checks may still be required.
Q: Why combine Face++ liveness detection with face matching?
Face matching measures identity similarity, but it does not by itself prove genuine presence. Liveness detection helps identify presentation and digital media attacks, making Face++ identity reverification more robust for remote digital platforms.
6. Conclusion
Identity reverification should be triggered when identity data, account control, transaction behavior, or compliance risk changes materially. By combining continuous monitoring with Face++ face verification and liveness detection, digital platforms can strengthen account security without repeatedly sending every customer through a full onboarding process.



