Every document upload is a step where people leave. For a large share of your customers the upload is unnecessary, because the answer already exists in sources that can be asked directly.
Not "is a document more reliable than data". Sometimes. The question is which customers need the document at all, and whether your flow can tell before it asks.
Two data points, each confirmed by two independent sources. The market also calls this 2+2 verification.
Matched against two sources that do not share an origin.
Matched the same way.
Sources include credit bureaus, government registries, utilities, telcos and banking data. The independence is the point: two sources that ultimately copy the same file are one source.
The customer uploads nothing.
The case steps up to a document or another route, carrying what it already learned.
One data point confirmed by one source. It is a fallback for markets where the data to run the full check does not exist, and it should be recognised as the lighter check it is rather than presented as the same thing.
Sources include credit bureaus, government registries, utilities, telcos and banking data, combined per market.
A synthetic identity is built precisely to pass single-source checks: a real address, a plausible name, a thin but clean history. Requiring two independent confirmations of each data point is what makes it expensive to construct.
A synthetic identity is built to look like somebody who has been around for a while, and something that has been around for a while eventually has records in more than one place. That is the weakness of the 2+2 method stated plainly: it confirms that a matching record exists in two independent sources, and a patient fraudster can arrange for a matching record to exist in two independent sources. Asking twice raises the cost of the attack. It does not close it.
This is not a reason to drop the check. It is an established method, it is used in regulated onboarding today, and it clears customers without asking any of them to photograph anything. What it should not do is carry the decision on its own.
Our recommendation is to support it with other signals from the same portfolio, phone intelligence, address verification, open banking data and screening, so that the cases which warrant more attention are the ones that get it. The alternative most flows reach for is gating: a document check on everybody, or worse, a proof-of-address upload, a utility bill photographed in a hallway, a manual review somebody waits two days for. Those steps cost you customers at the moment they were about to become customers, and on most cases they are avoidable.
Which sources, which combinations, and what counts as sufficient are set per market. Some countries have rich data and this route is broadly usable; others do not. The flow should reflect that rather than pretending the map is uniform.
Most customers upload nothing, which is the drop-off point fixed without touching conversion anywhere else.
Which sources were asked, which matched, and on what.
A single data source is a claim, not a verification. We ask several and require them to agree, which is a different product even when the underlying sources overlap.