Forrester's 2022 evaluation of this market scored twelve providers against twenty two criteria. Deepfake detection was not among them.
In the Q3 2025 evaluation, it is a scored criterion, and Persona's Leader placement rests partly on taking the highest possible score in it alongside vision and roadmap.
Three years is a short time for a criterion to go from absent to decisive. It happened because the attack that criterion measures went from theoretical to routine, and because this category has a structural vulnerability that each new technology generation exposes again.
The problem that cannot be solved, only moved
Identity verification asks whether a person is who they claim to be, at a moment when the organisation has never met them.
Forrester's framing of the difficulty is precise: the applicant is essentially anonymous at the start of a digital process, so the device and the session become the proxy for the person.
The older approach was knowledge-based. Ask something only the real person would know: a previous address, a loan amount, a mother's maiden name. That worked while such information was private.
It is not private. Successive large-scale breaches have put the personal details of most adults in developed economies into circulation, and the industry's own honest assessment is that some or all of any given individual's identifying information has probably already been stolen. Knowledge-based verification now tests whether someone has access to a database, which the fraudster reliably does.
So the industry moved to documents and biometrics. Photograph the passport, photograph the face, compare them, check the document is genuine, check the face is live.
That worked while producing a convincing fake document and a convincing fake face was hard. Generative models made both considerably easier, which is why deepfake detection became a criterion.
The pattern is the recurring feature of this category. Each generation of verification is defeated either by the accumulated data of previous breaches or by the current generation of synthesis. The problem is never solved. It moves.
Inside the evaluations
The Forrester Wave: Identity Verification Solutions, Q4 2022 scored twelve providers against twenty two criteria across current offering, strategy, and market presence: DocuSign, GBG, HID Global, IDnow, LexisNexis Risk Solutions, Mitek, Onfido, Pipl, Prove, Socure, Sumsub, and TransUnion.
LexisNexis Risk Solutions placed as a Leader with maximum scores in seventeen of the twenty two criteria, on a portfolio assembled through acquisitions spanning device intelligence, identity analytics, email risk scoring, and behavioural biometrics. TransUnion also placed as a Leader with TruValidate.
The Forrester Wave: Identity Verification Solutions, Q3 2025 assessed vendors on current offering, strategy, and customer feedback.
Persona placed as a Leader, taking the highest possible scores in vision, deepfake detection, and roadmap, and positioned by Forrester for heavily regulated enterprises with extensive and complex document-based verification requirements. Forrester also credited its coverage across both individual and business verification.
Veriff placed as a Strong Performer.
Worth noting the vendor population around those evaluations. Forrester mapped thirty eight providers in 2018, twenty eight in 2022, and thirty four in the Q2 2025 Landscape. This market has not consolidated the way most categories in this series have, and the reason is geography: document coverage, data sources, and regulatory acceptance are country-specific, so regional specialists remain viable against global platforms in a way that does not happen in, say, cloud cost management.
Presentation and injection are different attacks
The technical distinction that matters most in current evaluations rarely appears in vendor marketing, and it determines whether a defence works.
A presentation attack shows something fake to a real camera. A printed photograph, a screen displaying a face, a silicone mask. Liveness detection defeats these by looking for signs of a real three-dimensional person: depth, involuntary movement, skin texture, reflections.
An injection attack bypasses the camera entirely. Malware, a virtual camera driver, or a manipulated mobile application feeds synthetic video directly into the verification stream. The system never sees a physical scene, so every signal it uses to assess liveness is fabricated along with the face.
The second is considerably harder to defend and it is where generative video has changed the economics. Producing a convincing synthetic face is now cheap. Getting it past a camera was the remaining obstacle, and injection removes the camera.
Defending it requires signals from outside the image: device integrity, application attestation, evidence that the video came from a physical sensor, and behavioural and network signals around the session. That is why the credible vendors talk about device intelligence and session risk rather than only about image analysis, and it is the specific question worth asking when a vendor claims deepfake detection.
Every check costs conversion
The commercial tension in this category is unusually sharp, and it is the reason the best technical answer is frequently not the right purchase.
Verification sits in the onboarding flow. Every additional step, every retry after a rejected document photograph, every request for a second form of identification, loses a proportion of legitimate applicants. Those losses are large and they are immediate revenue.
The fraud prevented is a cost avoided, measurable only in aggregate and always disputable. The customers lost to friction are, as with false declines in fraud management, invisible: they simply do not complete, and nobody attributes it.
Which means the actual optimisation is not maximum security. It is the highest pass rate for genuine applicants at an acceptable fraud rate, and those two objectives pull against each other at every threshold.
This is also why Forrester's Landscape framing places customer experience alongside compliance and fraud reduction as the value of the category. A verification system that is highly secure and that a third of legitimate customers cannot complete has solved the wrong problem.
The practical consequence is that step-up verification, applying more checks only when risk signals warrant them, matters more than the strength of any individual check. A flow that verifies everyone to the standard required for the riskiest applicant is expensive in exactly the way that does not appear on the security budget.
The regulatory picture is diverging
Two developments are pulling this market in different directions, and European organisations sit at the intersection.
The first is state-issued digital identity. The European Union's revised electronic identification framework requires member states to offer digital identity wallets to citizens, with the intention that a person can prove attributes about themselves using credentials issued by a government rather than by submitting a passport photograph to a private company.
If that reaches meaningful adoption, it changes the category substantially in Europe. Verification becomes credential presentation, and the document-and-selfie apparatus becomes a fallback for people without a wallet or for cross-border cases the scheme does not cover. Vendors serving European markets are positioning for that shift, and how quickly it arrives is one of the largest open questions in this market.
The second is age assurance, which is pulling in the opposite direction. Several jurisdictions have introduced or proposed requirements for platforms to verify user age, extending identity verification into consumer contexts that previously had none. Persona's positioning references age verification in Australia as an example of the geographic variation this produces.
Those two trends have different implications. Digital identity wallets reduce the verification burden by moving trust to the state. Age assurance requirements expand the number of interactions requiring verification. A vendor's exposure to each depends heavily on which markets and sectors it serves.
What a buyer is actually choosing between
Underneath the vendor comparison sit three genuinely different approaches, and organisations often evaluate them as though they were interchangeable.
Data-centric verification checks the claimed identity against authoritative and commercial data sources: credit files, telecommunications records, government databases where accessible. It is fast, invisible to the user, and works well in markets with deep data coverage. It fails for thin-file individuals, recent immigrants, and young adults, which is a fairness problem as well as a coverage one.
Document-centric verification examines a physical identity document and matches it to a live face. It works across borders and for people with no data footprint, and it is the approach most exposed to synthetic media.
Signal-centric verification assesses the device, the network, the session, and the behaviour rather than the identity directly. It cannot verify identity alone but it is the layer that catches injection attacks and automated abuse.
Serious deployments use all three, weighted by market and risk. The evaluation question is which one a vendor is genuinely deep in, because most are strong in one and adequate in the others, and the category label conceals that entirely.
Where this goes
The uncomfortable summary is that identity verification is an arms race the defender cannot permanently win, because the underlying asset, personal information, is already compromised and the synthesis tools keep improving.
What can be won is cost asymmetry: making an attack expensive enough that it is not worth mounting against your particular institution for the value available. That is a different goal from making fraud impossible, and it is achievable.
The direction of travel points away from verifying a person at a moment and toward maintaining a continuously assessed relationship: an identity established once, bound to a device and a set of credentials, and re-evaluated on signal rather than re-verified from scratch. That reduces the number of high-stakes single verification events, which is where the deepfake risk concentrates.
Whether that arrives through private platforms or through state digital identity infrastructure is, in Europe at least, an open question with a legislative answer already partly written. Anyone signing a multi-year agreement in this market should have a view on it.
Analyst Source
Forrester Research
Category definition, vendor inclusion, and evaluation findings in this article draw on Forrester's coverage of identity verification, mapped in a Q1 2018 Now Tech report of 38 providers, a Q3 2022 Landscape of 28 providers, and a Q2 2025 Landscape of 34 vendors, and scored in the Q4 2022 Wave covering 12 providers against 22 criteria and in the Q3 2025 Wave assessing current offering, strategy, and customer feedback.
Source research
Forrester does not endorse any vendor named here, and tier placement should not be read as a recommendation to buy.