PasskeyBridge

Intel · 2026-06-29

IDV Margin Compression: Per-Verification Pricing Toward Zero by 2027

By J. W. Bouckaert

IDV Margin Compression: Per-Verification Pricing Toward Zero by 2027

Per-verification pricing for document-centric identity verification (IDV) is collapsing toward zero. The trajectory is a structural margin compression, and a cyclical price war between four mid-cap vendors competing for the same RFP is the wrong model for it. Three substitutes that did not exist at scale during the last pricing cycle are driving the compression: carrier-signal APIs under the GSMA Open Gateway, nationally-issued reusable digital credentials under EU Regulation 2024/1183 and the California mobile driver license programme, and browser-native wallet selection under the W3C Digital Credentials API that Chrome 141 and Safari 26 now mediate.

This article models the curve, identifies which IDV business models break first, and names the three patterns that survive past 2027.

The origin of per-verification pricing

The pricing logic for document-plus-selfie IDV in the 2018-2024 era was straightforward. A KYC-grade verification combined four roughly fixed inputs (document forensics, liveness ML, optional manual review, a sanctions/PEP screen) and one variable input (per-jurisdiction document-template library) into a single SKU billed per attempt. Industry list prices clustered between $1.50 and $3.00 per verification at mid-volume tiers, with enterprise discounts producing $0.80-$1.20 floors at the largest banking and crypto-exchange accounts.

That pricing held because no substitute existed at the same evidentiary weight. A SIM swap signal was nowhere near a verified-document equivalent. A passkey did not contain a name. A bank-account check produced ownership signal but no identity binding. The IDV vendor's wedge was: we are the only place you can buy a single artefact that satisfies a regulator that the human in front of the camera is the person on the document.

Three things changed between 2024 and 2026.

SubstituteStatus at end of 2024Status mid-2026
GSMA Open Gateway carrier APIs16 operator commitments, limited live coverage76+ operator deployments across 55 markets, Number Verify and KYC Match generally available
EUDI Wallet under EU 2024/1183Regulation in force, no production walletsMember-state pilots live, mandatory acceptance window 2026-2027
Mobile driver licences (US)~10 states issuing, no acceptanceCalifornia, Arizona, Iowa, Maryland and 8+ states issuing, TSA acceptance at 30+ airports
W3C Digital Credentials APIW3C Working Draft, no shipping browsersChrome 141 and Safari 26 mediate wallet selection in production
Verifiable Credentials 2.0Recommendation finalized May 2025Production issuance across EU, US state-level, financial sector

Each row is a primitive that the IDV vendor used to sell as a bundled component of the per-verification SKU. Each row is now available as a standalone primitive at a marginal cost the document-IDV vendor cannot match.

The unit economics that break first

A document-IDV verification has roughly the following cost stack (industry mid-points, public vendor filings and S-1 disclosures from Mitek 2024 10-K, the Onfido pre-acquisition disclosures, and the Trulioo Series D materials):

Cost componentApproximate share of COGS
ML inference (document classification, OCR, liveness)18-25%
Manual review (analyst time on flagged cases)25-40%
Document-template library licensing and maintenance8-12%
Sanctions/PEP screening data licensing6-10%
Cloud infra, storage, network egress10-15%
Compliance and audit overhead8-12%
Customer success and integration support5-8%

Two of those rows do not compress at the same rate as price. Manual review is bounded below by analyst wages plus quality-assurance overhead. Document-template library maintenance is a per-jurisdiction fixed cost that does not shrink when the per-check price halves. The other rows scale with volume, but the two anchored rows define the floor.

The substitute economics are different in kind. A carrier-issued Number Verify call against Vodafone or Verizon does not consume an analyst. A presented EUDI Wallet credential does not require the relying party to maintain a passport-template library. A reusable-credential second presentation is, at the verifier, a JWS signature check that costs roughly one millisecond of CPU. The substitute's cost floor is approximately edge-RTT plus a signature verification. The incumbent's cost floor is approximately one analyst-minute amortized across a queue.

When those two cost curves race each other, the incumbent loses on basis. Not on execution.

The five-year price curve

Drawing the price curve from public RFP redlines, RFI responses we have reviewed, and the published rate cards of three carriers, three IDV vendors, and two reusable-identity programmes, the trajectory looks like this:

Per-verification price (enterprise tier, USD), 2023-2028 trajectory

  $3.00 ┤●
        │  ●
  $2.50 ┤    ●
        │      ●
  $2.00 ┤        ●
        │          ●
  $1.50 ┤            ●           ─── Document IDV (incumbent SKU)
        │              ●
  $1.00 ┤                ●
        │                  ●
  $0.50 ┤  ──────────────────●●●  ─── Carrier-signal substitute
        │                          ─── Reusable VC substitute
  $0.10 ┤  ········░░░░░░░░░░░░░░░ ─── Cost floor (asymptote)
  $0.00 ┤___________________________________________
        2023  2024  2025  2026  2027  2028

The substitute curves do not start at zero. They start at the publishable marginal cost of a carrier signal (low single-digit cents in mature markets) or a reusable-credential check (sub-cent at scale, anchored by the issuer's amortized cost of running the wallet programme). They drop as adoption scales the fixed-cost denominator. The incumbent curve has further to fall, and a different floor.

The published rate cards that anchor the lower curve are not theoretical. The Vonage Number Verification API and carrier offerings exposed through the GSMA Open Gateway both publish per-call pricing in the single-cent range for high-volume tiers. The Mojaloop Foundation reference work on national digital ID rails shows the same pattern in lower-cost markets. The asymmetry holds across geographies.

The compression is not uniform across IDV use cases. Three sub-segments compress at very different rates:

IDV sub-segmentCompression rateWhy
Consumer one-time KYC (fintech onboarding)-40 to -60% per yearMost exposed to reusable-credential and carrier substitutes
Regulated AML/KYC at tier-1 bank-10 to -20% per yearRegulatory bias toward document-artefact custody slows substitution
Age verification (alcohol, gambling, 18+)-50 to -70% per yearmDL and EUDI Wallet age-attribute disclosure is a direct, regulator-blessed substitute
Workforce identity proofing-20 to -30% per yearReusable workplace credentials are growing but slower; HRIS lock-in extends the cycle
High-assurance government services-5 to -10% per yearNational wallets are the substitute and the vendor; pricing remains regulated

The blended-portfolio number that matters for an IDV vendor's P&L is a weighted average across those sub-segments. A vendor heavy in consumer fintech is compressing at 35-50% per year on the consumer book. A vendor heavy in regulated banking is compressing at 10-15%. Persona's growth in the SMB market and Veriff's exposure to crypto-exchange volume sit on different parts of this curve than Onfido's exposure to UK banking and Jumio's exposure to regulated US gaming. Same headline price, very different P&L trajectory.

Business models that survive

Three IDV business models survive the compression without margin collapse, and a fourth survives in a degraded form. The pattern is consistent with what we saw in adjacent infrastructure markets (CDN, message-delivery, SMS-OTP) during their own commoditization decades.

1. Orchestration and decisioning layers. Vendors who moved up the stack to sell the decision engine (which signal to ask for, in what order, with what fall-throughs) rather than the signal itself retain pricing power because the value sits in the policy graph above the primitive. Alloy, Unit21, and Persona's Workflows product sit in this category. Their per-decision price is sticky because the customer's compliance team has wired the policy graph into the firm's risk appetite, and swapping the underlying signal vendor inside the graph is a much lower-friction change than swapping the decisioning layer itself.

2. Regulated-evidence custody. Tier-1 banks under US BSA/AML, EU AMLD6, and the FATF travel rule are still required, in 2026, to retain human-reviewable identity evidence for retention periods of five to ten years. The IDV vendor that operates the regulated-custody vault, the audit trail, and the regulator-facing reporting surface retains a service contract that does not compress at the rate of the underlying scan. LexisNexis Risk Solutions and Refinitiv's World-Check product line are the structural reference points; the document-IDV vendors that win in this lane are the ones that re-engineer their offering as a compliance archive with a verification frontend, rather than the inverse.

3. Fraud-network and shared-signal consortia. Socure, SentiLink, and the larger insurance-fraud consortia (notably LexisNexis ThreatMetrix) sell outcome lift measured in basis points of fraud avoided per dollar of GMV processed. The price is anchored to a fraud loss-rate that the buyer measures independently, which means the contract survives commoditization of any individual signal because the value is in the network effect of pooled signal across the consortium. New entrants cannot replicate the network without years of data accumulation.

4. The degraded survivor: hardware-anchored proofing for high-assurance government identity. IDEMIA, Thales DIS, and the small handful of vendors who issue the underlying document substrate and operate the matching infrastructure for national passport, residency, and driver-licence systems remain protected by regulated procurement cycles and the integration depth their installed base represents. They lose the consumer KYC business entirely. They keep the regulated-issuer business at compressed but defensible margins.

The model that does not survive is the pure-play single-channel document-plus-selfie SKU billed per attempt, with no orchestration moat, no custody contract, and no fraud-network. That is the shape of the 2018-2024 cohort's flagship product. The transition is from a product business to a feature business, and the feature is consumed by whichever of the three surviving models the buyer is anchored to.

Vendor responses

The market is repricing in real time, and the strategic moves are public.

Entrust acquired Onfido for a reported $650M in April 2024, folding the document-IDV product into a broader PKI and credential-issuance portfolio. The acquisition rationale is the orchestration-and-issuance moat described above; Entrust monetizes credential issuance and lifecycle, and Onfido becomes the proofing primitive inside that motion.

Mitek acquired HooYu in 2022 and has continued to layer orchestration features (HooYu Identify, Mobile Verify Workflow) on top of its document-scan core. The 2024 10-K and subsequent quarterly filings show the company explicitly positioning away from per-check pricing toward platform subscriptions.

Persona launched its Workflows product and a Reusable Identity feature that explicitly stores a verified identity for later re-presentation, monetizing the cached-credential pattern rather than the per-scan one. This is the most direct vendor-side acknowledgement that the per-verification SKU is the wrong unit.

Veriff has invested heavily in its decisioning and orchestration platform and reusable-identity assertions for the same structural reason.

The vendors that are not making one of these moves are signalling, by absence, the cohort they expect to be in by 2027.

PasskeyBridge's position

PasskeyBridge is an ITRaaS attestation layer that sells verified signals (carrier, passkey, DPoP, presented verifiable credential, behaviour, posture) into the orchestration layer above it. We are not an IDV vendor. We participate in the compression as a substitute primitive: the carrier signal that replaces a document scan for low-assurance flows, the presented VC that replaces a re-scan for returning users, the behaviour signal that supplements a one-time KYC with continuous reassurance.

Our pricing is per-signal with reusable signal caching (see /pricing), which is a different unit-economic basis than per-document IDV. The signal's marginal cost is edge-RTT plus a signature verification, which is the structural floor the substitute curve is heading toward. We are aligned with the curve.

We have written separately about the supporting transitions:

Reading for 2026

The IDV market is not dying. The per-verification SKU is. The vendors who matter in 2028 are the ones who already accept that the document scan and the liveness selfie are commodity inputs to a higher-value decision, and who have priced and architected their products accordingly. The vendors who are still defending the per-attempt list price in mid-2026 are defending the wrong unit.

Buyers should decompose their existing IDV contracts now, re-price each underlying signal against its standalone marginal cost, pilot at least one reusable-credential channel, and demand a 2027 contract clause that lets them swap a vendor primitive for a reusable-credential primitive without minimum-commit breach. The vendors who refuse the clause are telling you which side of the compression curve they expect to be on.

The math is already in the rate cards.

---

Further reading:

Start free · Test the API