Verify Online News
GPG45 Identity Proofing: Practical Guidance for UK Businesses
15 Sept 2026 · 6 Min. To Read · By Verify Online

Understanding GPG45 identity proofing is essential for UK businesses that must verify customers, contractors or job applicants. This post explains the guidance from the UK government, describes practical verification levels, and offers clear steps HR and compliance teams can adopt to reduce risk while meeting legal obligations.
What is GPG45 and why it matters
GPG45—the Government Paper on identity proofing and verification—sets out principles, technical standards and risk-based requirements for proving an individual’s identity. It is not a statute but it is the benchmark the UK government uses when determining acceptable levels of assurance for digital and face-to-face identity checks. For regulated sectors and public sector suppliers, following GPG45 reduces operational risk and demonstrates robust practice.
Verification levels: a risk-based approach
GPG45 adopts a risk-based model of verification levels. Rather than a one-size-fits-all rule, organisations determine the appropriate level of assurance based on the transaction’s risk, financial exposure and potential harm from impersonation or fraud.
Higher verification levels require stronger evidence and stricter document validation. For example:
- Low-risk interactions may accept basic ID and online checks.
- Medium-risk onboarding (e.g. opening accounts or contractor access) typically needs validated documents plus electronic checks against authoritative data sources.
- High-assurance operations (sensitive roles, regulated financial transactions) call for multi-factor identity proofing: verified government ID, biometric checks, and independent document validation.
Practical example
A financial services firm hiring treasury staff should apply a higher verification level than a retail employer recruiting seasonal shop assistants. The former will require document validation against passport databases, a biometric liveness check, and a screened Right to Work check; the latter may accept a face-to-face check of originals and a standard online Right to Work check.
Document validation in practice
Document validation is central to GPG45-compliant identity proofing. Effective validation means confirming the authenticity of passports, driving licences, residence documents and other identity evidence using a combination of automated and manual checks.
- Automated checks: machine-readable zones (MRZ), chip data reading for e‑passports, and database checks reduce human error and speed processing.
- Manual verification: trained staff should inspect holograms, security printing and photo consistency when documents are presented in person.
- Biometric cross-checks: face matching and liveness detection help link the document to the person presenting it.
Using both automated validation and trained human decision-making achieves the balance GPG45 advocates: technical rigour with professional oversight.
Right to Work and GDPR considerations
Employers must conduct robust Right to Work checks under UK immigration law; failure can lead to civil penalties. Integrating GPG45-compliant identity proofing into recruitment reduces the risk of hiring ineligible workers. For practical guidance on employer obligations and acceptable processes, see our article on Right to Work compliance.
Alongside Right to Work, data protection law applies. Under the GDPR and UK data protection legislation, identity data is sensitive personal data when linked to biometric identifiers or immigration status. Employers must:
- Establish a lawful basis for processing (e.g. legal obligation for Right to Work checks).
- Minimise retained data and apply retention schedules consistent with audit needs and legal obligations.
- Securely store verification results and document images, using encryption and access controls.
Implementing GPG45 in your organisation
Adopting GPG45-aligned processes need not be disruptive. Follow these practical steps:
- Assess your risk profile: map services and roles to verification levels based on potential harm.
- Define acceptable evidence for each level: list documents, electronic checks and biometric requirements.
- Choose technology wisely: combine automated document validation and face-match services with clear human oversight.
- Train staff: ensure those performing ID checks can spot fraud indicators and understand escalation paths.
- Document your processes: maintain audit trails to demonstrate compliance if challenged by regulators or auditors.
For many HR teams, integrating digital identity tools improves speed and compliance. Our article on understanding GPG45 identity proofing explores the standards in greater detail and helps translate them into HR workflows.
Real-world example: onboarding remote hires
A UK technology employer hires engineers from multiple locations and needs remote identity proofing. They implement a two-stage approach: first an automated document validation and biometric liveness check to achieve a medium assurance level, then a short video interview with HR for role-specific verification. Documents are retained for the statutory retention period and encrypted at rest. This approach balances candidate experience with regulatory prudence and aligns with GPG45 principles.
Key takeaways for HR and compliance teams
- GPG45 is the leading guidance for identity proofing: treat it as the standard for assurance and documentation.
- Apply verification levels proportionately: the greater the risk, the stronger the evidence and checks required.
- Combine automated document validation with human review and appropriate biometric checks.
- Observe Right to Work and GDPR obligations when collecting, storing and disposing of identity data.
Adopting GPG45-aligned identity proofing helps reduce fraud, protects your organisation from regulatory risk and improves recruitment integrity. For practical implementation across sectors, see our broader guidance on industry-specific verification and the technologies that support secure compliance.