Identity verification is the part of remote hiring that asks a different question from proctoring. Proctoring asks what were you doing during the assessment. Identity verification asks are you the person whose name is on the application. In 2026 the two arrive together often enough that candidates conflate them, but they capture different data, follow different retention rules, and carry different consequences when they fail. This guide covers what the major assessment platforms document about their identity checks, what happens to a photo of your driver's license after you upload it, and how to tell a legitimate verification step from a scam that wants your ID for other reasons.
What identity verification means in a hiring context
An identity check in technical hiring is a step that binds a real human to an application record. It usually takes one of three forms:
- A webcam photo taken at the start of an assessment, stored in the candidate report for a human to look at later.
- A document-and-selfie match, where you photograph a government ID and your face, and software compares the two.
- A live re-verification, where a recruiter or interviewer confirms on camera that the person in a later round is the person from the earlier one.
None of these examine your code, your browser, or your machine. That is what HackerRank's proctoring signals and session recording do, and it is a separate system with separate settings. A test can have identity verification on and proctoring off, or the reverse.
What each platform documents that it captures
Vendor documentation is the most reliable source here, because the depth of the check varies more than candidates expect. The descriptions below are what each vendor's own support material stated as of August 2026.
HackerRank's Photo Identification captures a single webcam photo before the test begins. HackerRank's knowledge base states that candidates must select "Allow Photos" to proceed, and that if no photo is captured manually, "the system captures it automatically after a short countdown." Notably, the same page states that "the system does not automatically validate or flag candidates based on their captured photo. The hiring team must manually verify each candidate's photo after the test" (HackerRank Knowledge Base). This is a weak check by design — a photo filed for later human review, not an automated match.
Codility's Identity Verification is a full document check. Its support documentation says candidates provide "photos of front and back sides of the document and a selfie," along with country and ID type, and that "candidates can't skip ID verification if it is enabled for the test" (Codility Support). The employer sees a pass or fail with reasoning attached, and can re-trigger the check.
CodeSignal's proctored assessments go furthest. Its knowledge base describes prompting candidates to share "camera, microphone, and screen for the duration of the assessment," along with a photo of the candidate's face and a government-issued photo ID (CodeSignal Support).
The practical takeaway: "identity verification" on an invitation email tells you almost nothing about scope. A webcam snapshot and a document-plus-liveness check are both called the same thing.
Why employers added these checks
The shift is recent and it is a fraud response, not a cheating response. Gartner has projected that by 2028, one in four candidate profiles worldwide could be fake (HR Dive's coverage of the Gartner prediction). Forbes reported in August 2026 on the scale of the surrounding problem, citing a Checkr survey of 3,000 hiring managers in which 59% said they had suspected a candidate of using AI to misrepresent themselves, and a GetReal Security benchmark in which 41% of IT, security, risk, and fraud leaders said their company had hired and onboarded a fraudulent candidate (Forbes, August 17, 2026).
Vendors have moved into the gap. HireID announced an "Interview Integrity Platform" on August 17, 2026, which the company says verifies identity before interviews, screens documents "for document fraud, tampering, forgery, and synthetic or altered records," and monitors "more than 20+ fraud signals during live interviews," claiming "over 98% accuracy on synthetic identity detection in internal benchmark testing" (HireID press release). That accuracy figure is a vendor claim from internal testing, not an independent evaluation, and should be read as such.
The relevant point for a candidate is directional rather than statistical: the number of hiring stages that ask you to prove who you are is going up, and legitimate applicants absorb the friction created by fraudulent ones.
What happens to your ID after you upload it
This is the question candidates should ask more often, and the answers differ sharply.
Codility states that identity data "is protected according to the highest data security standards and is not accessible to the Recruiter or Hiring Team" — the employer sees the verdict, not your passport. CodeSignal is more specific about time: its documentation states that identification and proctoring data "is reviewed by CodeSignal only" and is "stored and deleted within 15 days," and that the company receiving your report "will simply receive a copy of your assessment result and score." HackerRank's photo, by contrast, is explicitly surfaced to the hiring team in the candidate's summary report, and its documentation gives no retention period.
Biometric processing also carries legal weight in some jurisdictions. Illinois' Biometric Information Privacy Act requires written notice and consent before a private entity collects biometric identifiers such as face geometry. HireVue agreed to a $3.75 million settlement, granted preliminary approval on June 25, 2026, resolving claims that its video interview software extracted facial geometry and voiceprints from Illinois applicants without the required notice and consent (Deyerler v. HireVue settlement coverage). Nothing here is legal advice, and BIPA's protections are specific to Illinois — but the case is a useful signal that "we need to verify you" does not exempt an employer from disclosing what it collects and how long it keeps it.
Asking a recruiter three questions before you upload anything is reasonable and rarely goes badly: which vendor performs the check, whether the employer receives the document image or only a result, and how long the images are retained. The same instinct applies to any tool you bring to an interview — our privacy checklist for AI interview assistants works through the equivalent questions from the other direction.
Telling a real verification step from an ID-harvesting scam
Identity verification requests are now common enough that scammers imitate them. The distinguishing feature is when the request arrives and what channel it uses. The FTC's guidance is blunt: "Real employers won't ask for that kind of information before they've actually interviewed and hired you," referring to driver's licenses, Social Security numbers, and bank account details requested as "employment paperwork" (FTC Consumer Alert, July 7, 2025).
Legitimate checks in technical hiring look like this: they run inside the assessment platform you were formally invited to, they happen at the start of an assessment or interview rather than before any contact, they ask for an ID and a selfie rather than a Social Security number or bank details, and the vendor performing them is named. Requests that arrive by text message, that come before any interview, that ask for financial details alongside the ID, or that route you to a document upload form on a domain unrelated to the employer or a known assessment vendor deserve a direct email to the recruiter through a channel you established yourself.
Preparing so a legitimate check clears on the first try
Most verification failures for honest candidates are mundane. A few practical steps:
- Have the physical ID in the room before the session starts. Document checks generally require a live photograph of the card, not a scan or a photo of a photo.
- Light your face from the front. Backlighting from a window behind you is the most common cause of a failed selfie match.
- Use the name on the ID in your application where possible. A mismatch between a preferred name and a legal name is a frequent manual-review trigger.
- Check the webcam the platform will actually use. If you route your camera through virtual-camera software for other reasons, disable it — many verification flows reject virtual camera devices outright.
- Expect re-verification in later rounds. Confirming that the same person appears at each stage is exactly the "identity continuity" that vendors like HireID now market.
If a check fails and you are who you say you are, say so quickly and ask for a re-trigger. Codility's flow, for example, supports the hiring team re-sending the verification. Silence after a failed check is worse than an email.
What verification does and does not settle
Identity verification answers one question: whether the person in the chair is the applicant. It says nothing about which tools that person used, and the tool question is governed by a separate policy that varies by employer and is worth reading before the interview rather than during it — we cover the current landscape in whether you can use AI during a technical interview. Likewise, what an interviewer can observe of your machine during a live round is a screen-share question, not an identity one, and it has its own specific answers.
The line worth holding is simple. Having someone else sit the interview is misrepresentation of identity, and identity verification exists precisely to catch it. Preparing thoroughly, and using assistance within whatever the employer's stated policy permits, is a different act with different consequences. The two get discussed together because both appear in vendor fraud marketing, but a candidate deciding how to prepare should not treat them as the same decision.
Bottom line
Assume any technical hiring process you enter in late 2026 may ask you to prove your identity, possibly more than once. Read the invitation to learn which vendor runs the check, ask what the employer receives and how long images are kept, and prepare the practical details — ID in the room, front lighting, matching legal name — so the check is a thirty-second step rather than a rejected attempt.
Control is a desktop AI interview assistant for interviews, online assessments, and screen-share workflows, and new users get 5 messages and 2 minutes of voice at no cost to see how it behaves before committing to a paid pass. If you are working out how a live assistant fits alongside the policies and checks a specific employer runs, try it against a practice session first rather than a real one.
Share
Explore with AI
Continue exploring
Related guides
Guides · 8 min read
Does a Remote Interview Show Where You Actually Are?
Your IP is logged by the assessment platform, the video call, and the employer's fraud review. What each layer sees about your location, as of September 2026.
Guides · 8 min read
Can Interview Websites Detect Screenshots?
What a browser can observe when you take a screenshot, how proctoring changes the boundary, and when desktop assessment software can block capture.
Guides · 11 min read
How to Prepare for a Data Engineer Interview With AI
Use AI to rehearse data pipelines, modeling, quality, and recovery decisions without inventing schemas, runs, incidents, or ownership.