Identity verification is moving beyond the moment an employee joins a company. Sumsub has launched Workforce Verification, a product designed to apply document checks, biometric liveness and other identity controls throughout the employee lifecycle, including at moments when risk changes.
The most significant part of the launch is not onboarding. Sumsub says the product can be used for step-up identity verification when a password is reset, privileges are escalated or a login appears suspicious. That reflects a broader security problem created by deepfakes, credential theft and AI-assisted social engineering: possession of a password, token or authenticated session does not necessarily prove who is behind it.
In the traditional enterprise identity model, a user proves who they are during enrolment and then repeatedly authenticates with credentials. That remains important, but high-risk workflows are increasingly creating demand for stronger forms of re-verification. The emerging model is closer to: verify the person, authenticate the credential, and re-prove identity when the risk of the action justifies it.

Sumsub describes the checks as deepfake-resistant. AI360 is deliberately not reproducing a numerical deepfake-performance figure here: Sumsub currently publishes inconsistent percentages across its own launch material and product page, and neither figure should be treated as an independent benchmark without a disclosed, comparable test methodology. The broader architectural point does not depend on the percentage.
That shift has implications beyond cyber security. Biometric verification raises questions about consent, retention, purpose limitation, data minimisation and supplier accountability. Those issues are especially important in jurisdictions with biometric privacy laws and in financial services, where identity controls must operate alongside fraud prevention, customer protection and regulatory obligations.
It also creates a useful distinction between credential assurance and human identity assurance. Multi-factor authentication can raise confidence that the user controls the required authentication factors, but it does not by itself prove the real-world identity of the person presenting them. Biometric or document-based re-verification aims to raise confidence that the person is who they claim to be. In some high-risk workflows, enterprises may increasingly want both.
The commercial race will be to make stronger verification usable enough that it can be inserted into sensitive workflows without creating unacceptable friction. The governance race will be to prove that the additional biometric data and verification steps are proportionate to the risk they are meant to reduce.
