Gartner’s newly released 2026 Magic Quadrant for Identity Verification confirms something the market has known for a while: document verification and biometric liveness are now table stakes. Investment in presentation attack detection (PAD), injection attack detection (IAD), and GenAI-content detection is critical, and it’s paying off — the AI-driven threats targeting these checks are very real. Doc-v has never been more accurate at answering one question: is this a real document, held by a real, live human, in front of this camera, right now?
But that question, however well it’s answered, is not the same as the question an enterprise actually needs answered: is this the right human, using their own identity, in a session the enterprise can trust?
Gartner’s own report draws this distinction directly. In the “Context” section, the analysts write that PAD, IAD, and inspection for GenAI-created images “are not enough in the current aggressive threat landscape,” and that the leading vendors “have invested in a range of additional risk signals, such as those focused on device, phone number, email, behavior and location.” The report goes further, noting that not every impersonation attack even involves a deepfake. Some are simpler: a real person, live and present, using someone else’s real, stolen identity. A document check and a liveness check can both pass cleanly in that scenario, because neither one asks whose identity the live human is actually holding. That’s the gap, and it’s exactly the gap that contextual, phone-based signals are built to close.
Consider what doc-v and liveness actually verify: the document is genuine, the face matches the document, and a live human is present. All three can be true and the transaction can still be fraudulent:
In each case, the document-and-face check can pass cleanly. The risk is sitting one layer below it, in signals doc-v was never built to see.
Most verification flows still start from the same assumption: send a one-time passcode or a verification link to the phone number on file, then trust whatever comes back. That assumption is exactly what a SIM swap or call-forwarding attack is designed to exploit — the OTP goes out, and it goes straight to the attacker, who now clears every downstream check including doc-v.
The fix isn’t a better OTP. It’s not sending one blind in the first place. Before an SMS link or OTP goes out, the phone number itself should be evaluated:
This reframes the order of operations: phone risk assessment happens first, as a gate, not as an afterthought bolted on after doc-v has already passed.
Once the line itself checks out, there’s a second, complementary layer: mobile network authentication. Silent Network Authentication (SNA) confirms, directly with the carrier and without any customer action, that the SIM in the device making the request actually belongs to the registered subscriber on the account — no code to type, no link to tap. SIM-based Authentication (SBA) extends that same carrier-level confirmation to networks or devices where a silent check isn’t available, asking only for the user to acknowledge their phone number rather than requiring a full OTP round-trip. Between the two, the phone gets verified on nearly every network and device — fully silently where possible, with a single lightweight step where it isn’t.
That distinction matters. An OTP only proves that whoever holds the phone at this moment can receive a message. Mobile network authentication — whether silent via SNA or acknowledged via SBA — proves that the phone itself, at the carrier level, is genuinely tied to the identity being claimed. It’s a fundamentally different, harder-to-forge signal, and it’s one no synthetic identity or session hijack can produce — because there’s no real subscriber relationship behind it to confirm.
The third layer is the device and session context itself. Device fingerprinting, IP intelligence, and location consistency answer a question doc-v never asks: does this session look like the customer’s established pattern of behavior, or does it look like someone else operating from an unfamiliar device, network, or geography?
An attacker can present a stolen or synthetic identity that sails through document and liveness checks. What they can’t do is make their device, IP, and location quietly match months or years of the real customer’s established profile. That mismatch is often the clearest signal available — and it’s sitting in a completely different data layer than anything a doc-v vendor evaluates.
None of this is an argument against doc-v. Document authenticity and biometric liveness remain a necessary foundation — they’re the only layer that directly answers “is there a real, live human here, and does the document check out?” That foundation keeps getting pushed forward against AI-fabricated documents and deepfakes, and it needs to.
The point is that foundation alone leaves a gap that sophisticated fraud — and, per Gartner’s own reporting, plenty of decidedly low-tech impersonation — walks straight through. The layered answer looks like this:
Enterprises that treat a passed doc-v check as the finish line are trusting a single signal — one that AI has gotten increasingly good at spoofing, and one that isn’t sufficient on its own even before AI enters the picture. The organizations getting this right are the ones treating identity verification as a stack of independent, corroborating signals — document, biometric, and contextual — where no single layer has to be perfect, because the others are watching for exactly what it misses.
Learn more about our solutions to combat to the unique threats posed by AI to enterprise identity here.
Madhu Vudali is VP, Product Management at Zumigo. Comments or questions? Connect on LinkedIn: @madhuvudali