Identity Verification for RTW, RTR and DBS ID checks
Yoti’s Identity Verification service enables organisations to complete Right to Work, Right to Rent and DBS ID checks remotely using AI-led document verification, biometric liveness, and reusable Digital ID. It automates compliance, reduces fraud, and delivers statutory excuse reporting through secure, government-certified digital identity processes.
Features
- Automated document capture, classification, and authenticity checks across global IDs
- Biometric facial matching with liveness detection preventing spoofing attacks globally
- NFC chip reading for passports, verifying cryptographic data securely remotely
- Real-time API, SDKs, webhooks for seamless system integrations across platforms
- Expert human review fallback for edge cases and compliance assurance
- Global document coverage, multilingual support, configurable verification workflows for businesses
- Advanced fraud signals, duplicate detection, and risk scoring capabilities included
- Privacy-by-design architecture, encryption, and GDPR-compliant data handling by default standards
- Capabilities to reduced fraud at the person or document level
- Certified under DIATF for full compliance
Benefits
- Reduce manual checks, accelerating onboarding and customer conversion rates significantly
- Prevent identity fraud, lowering chargebacks, losses, and operational risk exposure
- Meet KYC, AML, and regulatory requirements with auditable verification evidence
- Scale globally without building complex identity infrastructure internally from scratch
- Improve user experience through fast, mobile-first identity checks anywhere instantly
- Automate workflows, reducing costs, errors, and processing time for teams
- Gain real-time insights through dashboards, analytics, and reporting tools provided
- Launch quickly using APIs, SDKs, and prebuilt integrations today easily
- Streamline services with comliant identity checks
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 1 5 4 6 2 4 5 2 4 8 9 6 6 0
Contact
YOTI LTD
Carl Dawson
Telephone: 07487521320
Email: carl.dawson@yoti.com
About your service
- Service categories
-
Applications
Enterprise resource management
Human capital management
- Core Human Resources Applications
- Talent Management Applications
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- ATS and CRM software via exisiting integrations
- Cloud deployment model
-
- Private cloud
- Hybrid cloud
- Service constraints
- None
- System requirements
-
- HTTPS-enabled backend capable of secure REST API communications with Yoti
- Supported programming environment using Yoti SDKs or REST integration methods
- Outbound internet access over port 443 for API calls securely
- Secure server-side storage for private keys and credentials at rest
- Ability to receive HTTPS webhooks for real-time status updates events
- Modern web or mobile browsers supporting camera access for capture
- Firewall rules allowing secure connections to Yoti endpoints over HTTPS
User support
- Email or online ticketing support
- Yes
- Support response times
- Yoti aims to respond to customer support queries promptly during business hours. Publicly reported metrics indicate that approximately 67% of queries receive a response within one hour, and 98% within eight hours. Response times may vary at weekends and public holidays, when reduced staffing levels can apply. Priority handling and defined service-level targets can be agreed contractually for business customers requiring guaranteed response times, including out-of-hours or incident-based escalation support.
- User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- No
- Support levels
-
Yoti provides tiered support models for its Identity Verification service, tailored to customer size, risk profile, and operational requirements.
Standard Support is included for all business customers and provides access to Yoti’s support team via email and ticketing, covering integration queries, configuration guidance, and service usage assistance during business hours.
Enhanced Support options are available contractually, offering faster response targets, prioritised issue handling, and extended coverage hours. These tiers are designed for customers with higher transaction volumes or regulated compliance obligations.
Enterprise Support packages can include defined service-level agreements (SLAs), incident escalation procedures, and proactive service monitoring. For large or complex deployments, Yoti can provide access to a dedicated technical contact, such as a Technical Account Manager or cloud support engineer, to support onboarding, optimisation, and change management.
Support pricing varies based on service tier, transaction volumes, coverage hours, and SLA requirements. Costs are agreed commercially as part of the contract rather than through fixed public pricing.
This flexible model allows customers to align support levels with operational needs, compliance obligations, and business criticality. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Yoti supports customers through a structured onboarding process designed to enable rapid and secure deployment of its Identity Verification service. New customers begin by registering a business account, after which they gain access to the Yoti Hub, where they can create applications, generate API credentials, configure verification workflows, and manage users, permissions, and billing.
Yoti provides comprehensive online documentation, including step-by-step setup guides, API references, SDK integration instructions, and sample code. These resources cover both hosted SDK integrations and API-only implementations, enabling customers to choose the approach best suited to their technical and accessibility requirements.
Sandbox and test environments are available, allowing customers to validate integrations before going live. Webhooks and logging tools support real-time testing and troubleshooting during implementation.
Yoti also offers remote onboarding support, including guided setup sessions, technical walkthroughs, and integration reviews for business customers. Ongoing support is available through online help resources and ticket-based assistance.
Onsite training can be provided contractually for enterprise customers where required. This flexible onboarding model ensures customers can self-serve using documentation or receive hands-on assistance depending on project complexity. - Service documentation
- Yes
- Documentation formats
-
- Other
- Other documentation formats
- Website Developer information pages
- End-of-contract data extraction
-
Yoti’s Identity Verification service is designed to support real-time and on-demand data retrieval throughout the contract term, reducing the need for bulk extraction at contract end. Customers can access verification results, metadata, and decision outcomes programmatically via APIs and webhooks as checks are completed. This enables customers to store and manage all required data within their own systems in real time.
At contract end, users can extract any retained data through the same secure APIs, including verification status, reference IDs, timestamps, and configured outputs. Data is returned in structured, machine-readable formats such as JSON, enabling straightforward export into customer systems, data warehouses, or compliance archives.
Where Yoti-hosted dashboards or reports are used, customers can also export data manually via CSV or similar formats, subject to contractual configuration.
Yoti operates under a data minimisation and privacy-by-design model. By default, personal data is retained only for the agreed contractual period. Upon termination, data can be deleted or anonymised in line with contractual terms, regulatory obligations, and customer instructions.
This approach ensures customers retain full control of their data, with continuous access during service use and clear, secure extraction options at contract end. - End-of-contract process
- Yoti will work with clients at contract end to ensure all data has been succesfully transferred and then arrange/advise on deletion if required. This would be included in any contract costs.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Our website is compatible with assistive technology
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Yoti’s Identity Verification service is designed to work on mobile devices as well as desktop environments. Mobile users can capture documents, selfies, and liveness checks directly using their device camera through responsive web flows or SDKs. Desktop users may upload images or complete checks via webcam. Core verification processes, fraud detection, and compliance controls remain consistent across platforms, while the mobile experience is optimised for camera access, touch interaction, and on-the-go completion.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- Yoti’s Identity Verification service provides a web-based end-user interface and a secure business dashboard. End users complete identity checks through mobile-optimised web flows or SDK-based interfaces, capturing documents, selfies, and liveness data. Business users configure workflows, review results, and monitor performance through a secure administrative console. The service also exposes REST APIs and webhooks, enabling customers to embed Yoti verification journeys into their own web and mobile applications or build custom interfaces.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Yoti’s Identity Verification SDK user interface has been independently audited against the WCAG 2.2 AA standard. This includes assessment of key accessibility criteria such as colour contrast, text resizing, keyboard navigation, focus management, semantic structure, error handling, and compatibility with common screen readers and browser accessibility tools.
Testing includes validation across multiple device types and operating systems, ensuring compatibility with native accessibility features such as VoiceOver, TalkBack, screen magnification, and browser-based assistive technologies. The mobile-first design ensures large tap targets, clear instructions, and simplified flows to support users with motor, visual, and cognitive impairments.
Yoti continually iterates its interfaces using user feedback and usability testing to minimise friction during document capture, selfie submission, and liveness checks. Where customers have specific accessibility needs, Yoti can support additional testing, configuration, and guidance to ensure accessible deployment within their own applications. - API
- Yes
- What users can and can't do using the API
-
Yoti provides a REST-based API that allows customers to integrate Identity Verification directly into their own systems and user interfaces. Using the API, customers can programmatically create verification sessions, submit document and biometric data, retrieve verification outcomes, configure workflows, receive real-time status updates via webhooks, and store results within their own platforms.
Customers can update workflows, verification rules, and handling logic through API configuration, enabling dynamic changes without redeploying user interfaces. This approach gives full control over user experience, branding, and accessibility.
When using the API-only approach, Yoti does not provide an end-user interface. Customers are responsible for designing, hosting, and maintaining their own UI, including accessibility, localisation, and usability. In contrast, the SDK option provides Yoti’s fully managed, WCAG 2.2 AA–audited user interface.
Some elements, such as core verification logic, fraud models, and compliance controls, remain managed by Yoti and cannot be modified via API. - API documentation
- Yes
- API documentation formats
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Yoti can facilitate full HTML and CSS level customisations for the ID verification UI. This is a managed process whereby Yoti will collaboratively work with the client to create the required configuration for thier deployment.
Scaling
- Independence of resources
- All of Yoti's infrastructure including our reporting systems are fully scalable and designed to meet the needs of many enterprise clients in a global environment.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Yoti offers regular and ad hoc reporting via a Looker BI integration. Users can also access there Yoti hub account to view live session information, outocmes and media.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users export their data primarily through Yoti’s secure REST APIs and real-time webhooks, enabling on-demand, programmatic retrieval of verification results, metadata, and decision outcomes in structured, machine-readable formats such as JSON. This allows customers to store and manage data within their own systems continuously, rather than relying on periodic bulk exports. Where Yoti-hosted dashboards are used, data can also be manually exported in standard formats such as CSV, subject to configuration. This flexible approach supports automated pipelines, compliance archiving, and business reporting.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- JSON
- Original Media Format
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
Yoti’s Identity Verification service is designed for high availability using resilient, cloud-based infrastructure with redundancy, continuous monitoring, and automated failover mechanisms.
Yoti typically offers a 99.5% monthly uptime availability commitment, defined contractually within service level agreements (SLAs). SLAs specify availability measurement periods, planned maintenance windows, incident classification, and response targets. Scheduled maintenance is communicated in advance and excluded from availability calculations where contractually agreed.
Availability is monitored continuously, and customers may receive incident notifications and status updates via agreed communication channels.
If Yoti fails to meet the agreed availability threshold, customers are entitled to service credits in line with the SLA. Credits are normally applied as a percentage of the affected month’s service fees, rather than cash refunds, unless otherwise specified contractually. The credit structure and thresholds are defined within the commercial agreement.
This SLA-based approach ensures transparency, accountability, and resilience, allowing customers to align availability guarantees with their operational and regulatory requirements. - Approach to resilience
-
Yoti’s Identity Verification service is designed with resilience as a core architectural principle, ensuring continuity of service and protection of customer data. The platform is built on scalable, cloud-based infrastructure using redundancy, automated failover, and continuous health monitoring to minimise single points of failure.
Critical components are deployed across multiple availability zones, allowing services to continue operating even if individual components or zones become unavailable. Load balancing, auto-scaling, and real-time traffic management are used to maintain performance during peak demand or partial outages.
Yoti’s datacentre infrastructure is managed by established cloud providers with physically secure facilities, resilient power supplies, network redundancy, and environmental controls. Data is encrypted in transit and at rest, and backups are performed regularly to support rapid recovery.
Resilience is further supported by continuous monitoring, automated alerting, and incident management processes. Disaster recovery procedures are tested periodically, and recovery time objectives (RTOs) and recovery point objectives (RPOs) are defined contractually where required.
More detailed information on Yoti’s datacentre locations, redundancy architecture, and disaster recovery design is available on request under NDA, in line with security best practice. - Outage reporting
- We have a public dashboard at https://status.yoti.com and users can subscribe to email outage notifcaitons too.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Access restrictions in management interfaces and support channels
- Yoti restricts access to management interfaces and support channels through robust authentication and authorisation controls. Access to management interfaces is limited to authorised personnel based on their roles and responsibilities, enforced by unique user IDs and strong password policies. Multi-factor authentication (MFA) is implemented for privileged accounts. Support channels are similarly restricted, with access granted only to vetted support staff. All access activities are logged and monitored for suspicious behaviour, and regular reviews of access rights are conducted to ensure compliance with the principle of least privilege.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- SOC 2 Type II
- Information security policies and processes
-
ISO 27001
SOC 2 Type II - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Yoti employs a structured configuration and change management process to ensure service integrity and security. All components of Yoti’s services are tracked throughout their lifecycle using configuration management tools, maintaining an up-to-date inventory and ensuring traceability. Changes are subject to a formal change management process, which includes risk and security impact assessments, peer review, testing, and documented approval prior to implementation. Emergency changes follow an expedited but controlled process, with post-implementation review. All changes are logged and auditable, ensuring accountability and compliance with security policies.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Yoti employs a comprehensive vulnerability management process that includes regular vulnerability scanning, penetration testing, and continuous monitoring of its systems. Potential threats are assessed through automated vulnerability scans, manual reviews, and threat intelligence feeds from reputable sources. Yoti subscribes to industry-standard threat intelligence services and monitors vendor advisories to stay informed about emerging vulnerabilities. Upon identification of a vulnerability, Yoti prioritises remediation based on risk and impact, aiming to deploy critical patches within 24 hours and other patches as soon as possible. The process is overseen by the Information Security team, ensuring timely and effective mitigation of threats.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Yoti employs a comprehensive protective monitoring approach to identify and respond to potential compromises. Security events and logs are continuously monitored using automated tools and manual review. Alerts are generated for suspicious activities, such as unauthorised access attempts or abnormal system behaviour. When a potential compromise is detected, the incident response process is initiated immediately, involving investigation, containment, and remediation actions. Yoti’s Security Incident Response Policy outlines defined roles and escalation procedures to ensure prompt action. The response to incidents is prioritised based on severity, with critical incidents addressed within minutes to minimise impact and ensure service continuity.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Yoti employs a comprehensive protective monitoring approach to identify and respond to potential compromises. Security events and logs are continuously monitored using automated tools and manual review. Alerts are generated for suspicious activities, such as unauthorised access attempts or abnormal system behaviour. When a potential compromise is detected, the incident response process is initiated immediately, involving investigation, containment, and remediation actions. Yoti’s Security Incident Response Policy outlines defined roles and escalation procedures to ensure prompt action. The response to incidents is prioritised based on severity, with critical incidents addressed within minutes to minimise impact and ensure service continuity.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Yoti allows client to do time or volume limited trails of its services with full access to the servcie in use.
- Link to free trial
- N.A.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 15%
- Between £2,500,001 and £5,000,000
- 20%
- Over £5,000,001
- 30%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Intertek/UKAS
- ISO/IEC 27001 accreditation date
- Tuesday 26 March 2024
- What the ISO/IEC 27001 doesn’t cover
- N.A.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Intertek/UKAS
- ISO 9001 accreditation date
- Tuesday 26 March 2024
- What the ISO 9001 doesn’t cover
- N.A.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
- SOC 2 Type II
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
-