deepidv
Identity VerificationSeptember 21, 202612 min read
260

Remote Client Verification for Canadian Law Firms: Virtual ID That Holds Up

Remote client verification law firm Canada: what law society rules require for virtual ID, why a video call is not enough, the fraud risks, six-year record-keeping, and how deepidv verifies clients remotely.

Remote client verification is now a normal part of running a law firm in Canada, and the rules for doing it have changed more than most lawyers realize. A client who never walks into your office still has to be identified and verified before you touch their funds, and a video call by itself no longer satisfies your obligations. If your intake process still relies on a webcam glance at a driver's licence, you are running a file that a regulator, a title insurer, or a fraudster can pick apart.

This guide explains remote client verification for law firms in Canada: what the law society rules actually require for virtual identity checks, what a compliant remote flow looks like step by step, the fraud risks that make weak verification dangerous, and the record-keeping that has to survive an audit. The rules trace back to the Federation of Law Societies of Canada Model Rule on Client Identification and Verification, which each provincial and territorial law society adapts into its own binding form.

deepidv is a verification engine and agentic compliance suite built in San Francisco. Firms use it to confirm the human on the other end of a remote call, detect forged and AI-generated documents, and keep a retained audit file that maps to law society requirements. The sections below cover the rules first, then how technology helps you meet them.

Identification versus verification: two obligations, not one

Every discussion of remote onboarding falls apart when people use these two words interchangeably. They are separate steps with separate rules.

  • Identification means recording who your client says they are: name, address, occupation, and for organizations, the incorporation details and beneficial ownership. You must identify every client you are retained by, and you can do this over the phone or by email.
  • Verification means proving that identity is real using reliable, independent documents or technology. Verification is required when you are retained to provide legal services that involve a financial transaction, meaning you receive, pay, or transfer funds.

The Law Society of Ontario sets this out plainly in its client identification and verification rules under By-Law 7.1. A useful shorthand: identification is the interview, verification is the proof. Remote client verification is where the newest and strictest rules apply, because that is where fraudsters concentrate.

Suggested read: Client Identity Verification for Canadian Lawyers

When verification is triggered (and the litigation exemption that no longer exists)

Verification is not required for every matter. It is triggered when you engage in or give instructions about the receiving, paying, or transferring of funds for a client. A payment into or out of trust is the classic trigger.

Two changes from the March 2023 amendments to the FLSC Model Rule matter here. First, the old exemption for funds received or paid in the settlement of a legal proceeding is gone. Second, funds paid pursuant to a court order are no longer exempt either. According to guidance summarized by Law360 Canada, this closes a gap that some firms had used to skip verification on litigation files that moved money.

A narrow exemption survives: you do not need to verify again for funds received from the trust account of another Canadian lawyer or a Quebec notary, because that lawyer already carried the obligation. Alongside verification, firms retained for a financial transaction now have to record the client's source of funds, a requirement the LSO details in its source of funds guidance. These rules connect directly to Canada's anti-money-laundering regime overseen by FINTRAC under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act.

The four methods to verify a client's identity

The Model Rule and the provincial rules give you four ways to verify an individual, and understanding which ones work remotely is the whole point of this article.

MethodHow it worksWorks remotely?
Government-issued photo IDExamine an authentic, valid, current government photo ID and confirm the name and photo match the personYes, only with authentication technology that confirms the ID is genuine
Credit fileObtain a credit report that has existed for at least three years directly from a Canadian credit bureauYes, the person need not be present
Dual processMatch information from two reliable, independent sources (name plus address, name plus date of birth, or name plus a financial account)Yes
AgentRetain an agent under a written agreement to verify identity on your behalfYes, if the agent applies one of the methods above

The Law Society of Alberta and the Law Society of British Columbia both publish detailed breakdowns of these methods. The credit file and dual process methods have always worked remotely because they do not require you to look at a physical card. The photo ID method is the one that changed.

Suggested read: Remote Client Verification and Real Estate Fraud

Why a video call is no longer enough

During the pandemic, most law societies temporarily allowed lawyers to verify a client by holding up ID to a webcam. That emergency measure has ended. The Law Society of Ontario ended it on January 1, 2024, and BC set its own permanent rule in March 2024.

The distinction the regulators drew is between verification and authentication. A video call can help you confirm that the person on screen matches the photo. It cannot tell you whether the document itself is real. As the Law Society of British Columbia guidance puts it, a video conference with the individual by itself is not sufficient. To verify photo ID remotely you now have to use reliable technology that confirms the government-issued ID is genuine.

That technology has to assess the actual security features of the document: size, texture, character spacing, raised lettering, format, design, holograms, barcodes, magnetic strips, watermarks, and embedded electronic chips. The Ontario Bar Association and provincial societies have each stressed that the lawyer, not the vendor, remains responsible for the result. Law societies do not certify or endorse specific technology vendors, though BC points lawyers to the DIACC trust framework as a reference for evaluating providers.

The fraud that remote verification has to stop

Weak remote onboarding is not a paperwork problem. It is an open door for the fastest-growing category of fraud in the country.

  • Better fake IDs. Counterfeit documents now pass in-person inspection, let alone a webcam glance. The Financial Crimes Enforcement Network and title insurers have both flagged synthetic and forged identity documents as a primary vector.
  • Deepfakes on the call. Face-swap tools can put a homeowner's face over a fraudster's in real time on a video call. The National Association of Realtors has warned consumers and professionals about exactly this technique in property transactions.
  • Someone else on camera. A coached impostor holds up a stolen but real ID. Facial matching against the document photo, plus liveness, is what catches this.
  • Title and real estate fraud. Canadian title fraud losses have run into the tens of millions. Canadian Lawyer has covered how remote transactions widen the exposure, and title insurer FCT has documented the shift to technology-based ID verification.

The scale is not abstract. The Canadian Anti-Fraud Centre reported more than 638 million dollars in fraud losses in 2024, with identity fraud among the most frequently reported categories, and the agency estimates only a small fraction of incidents are ever reported. A law firm that moves a client's money on the strength of a spoofed identity can face the loss, the professional liability claim, and the regulatory finding all at once.

Ready to get started?

Start verifying identities in minutes. No sandbox, no waiting.

Get Started Free

What a compliant remote verification flow looks like

Put the rules and the risks together and a defensible remote flow has a clear shape. Here is a sequence that meets the photo ID method virtually.

  1. Capture the document. The client photographs the front and back of a valid, current government-issued photo ID through your intake tool.
  2. Authenticate the document. Technology checks the security features listed above and confirms the ID is genuine, not a template, screenshot, or edited image.
  3. Match the face. The client takes a live selfie, and the system confirms the face matches the photo on the ID.
  4. Prove liveness and rule out AI. A liveness check confirms a real person is present, and deepfake or AI-face detection confirms the face is not synthetic or replayed.
  5. Screen for repeat offenders. A one-to-many check flags whether the same face has already been rejected or banned under a different name.
  6. Record source of funds. For any financial transaction, capture where the client's money is coming from.
  7. Retain the file. Store the documents, results, timestamps, and method used in a format you can produce on demand.

deepidv runs this whole sequence in one pass. Its verification engine authenticates the document and matches the face, deepeye handles liveness and deepfake detection, and the platform keeps a retained audit file for every check. For firms that onboard clients across marketplaces or third-party portals, deepidv also verifies both parties in a transaction while validating the products and services being exchanged, which matters when a legal matter turns on the authenticity of an asset. The underlying technology is described in more detail on the platform pages.

Record-keeping: the file that has to survive an audit

Verification is only half done if you cannot prove it later. The rules require you to keep the records, and the retention period is long.

Across Canadian jurisdictions you must retain the client's identification and verification records, including copies of the documents used, for at least six years following the completion of the work for which you were retained. The Law Society of Yukon and other societies state this six-year rule directly, and it echoes the retention expectations under FINTRAC for reporting entities.

A defensible audit file records more than the ID copy. It should capture:

  • The method used (photo ID with authentication, credit file, dual process, or agent) and why.
  • The results and evidence, including document authentication output, face match, liveness, and deepfake detection where technology was used.
  • Timestamps and the identity of the person or system that performed each step.
  • Source of funds for financial transactions.
  • Ongoing monitoring notes, since the rules expect you to reconsider risk as a relationship continues.

This obligation sits against privacy law. Under PIPEDA, you should not keep personal information longer than you need it, so build a disposal schedule that releases files once the six-year window closes. deepidv keeps the audit trail structured and exportable so the retention and disposal both stay under your control. Its compliance agents, including Arbiter for policy decisions and Arc for case handling, keep the record consistent across every matter.

Suggested read: Building Trust in Peer-to-Peer Marketplaces

Choosing technology that fits law society expectations

Because no law society certifies vendors, the responsibility to choose well is yours. A few questions separate technology that will hold up from technology that will not.

  • Does it authenticate the document, not just photograph it? Confirm it checks real security features and flags edited or synthetic documents. Guidance from the Law Society of Saskatchewan and BC describes what that assessment should cover.
  • Does it detect deepfakes and injected video? Ask specifically about AI-face detection and camera-injection attacks, not just basic liveness.
  • Does it produce a retained, exportable audit file? You need to reproduce the whole check years later.
  • Does it map to your province's rule? Alberta, Ontario, BC, and the Law Society of Manitoba each phrase requirements slightly differently even though they follow the same Model Rule.
  • Does the pricing fit your matter volume? Review the pricing against how many financial-transaction files you actually open in a year.

The goal is not to outsource your judgment. It is to give you evidence strong enough that a regulator, a title insurer, and your own professional liability insurer all reach the same conclusion: you knew who your client was.

Remote Client Verification FAQ

Can Canadian lawyers verify a client's identity by video call alone?

No. A video call by itself is not sufficient to verify a client under current law society rules. To verify government-issued photo ID remotely you must use reliable authentication technology that confirms the document is genuine and that the face matches, which a plain video conference cannot do. The credit file method and dual process method remain valid remote alternatives.

When am I required to verify a client, not just identify them?

Verification is required when you are retained to provide legal services that involve a financial transaction, meaning you receive, pay, or transfer funds. Identification, the basic recording of who the client is, applies to every retainer. Since March 2023, the exemptions for funds tied to settling a legal proceeding or paid under a court order no longer apply.

How long must a law firm keep client verification records?

At least six years following the completion of the work for which you were retained. This covers copies of the identity documents used, the verification method, and the results. Balance this against privacy law by disposing of the records once the six-year retention period ends.

What is the difference between authentication and verification of ID?

Verification confirms that the client matches a government-issued photo ID. Authentication determines whether the ID document itself is real and genuine. The regulatory point is that you can perform verification remotely, but authenticating the document requires technology that inspects its security features rather than a human glance over video.

Do law societies approve specific ID verification vendors?

No. Law societies including Ontario and British Columbia state that they do not vet, endorse, or certify authentication technology vendors or their compliance claims. The lawyer remains responsible for the outcome. BC points to the DIACC trust framework as a reference, and firms should confirm any tool authenticates documents, detects deepfakes, and retains an audit file.

How does deepidv help law firms verify remote clients?

deepidv runs document authentication, face matching, liveness, and deepfake or AI-face detection in a single remote flow, then stores a retained, exportable audit file that maps to law society record-keeping. It also runs one-to-many checks to flag repeat or banned identities. For firms that touch marketplaces or third-party portals, deepidv verifies the people on both sides of a transaction while validating the products and services involved.

Start verifying identities today

Go live in minutes. No sandbox required, no hidden fees.

Related Articles

All articles

authID vs CLEAR vs deepidv: Benchmarking Person-Based Human Verification

An operational engineering analysis evaluating deepidv, CLEAR, and authID on sub-150ms response latency, device attestation, and deepfake prevention.

Aug 26, 202610 min
Read more

Jumio vs Persona vs deepidv: Benchmarking Sub-150ms Execution vs Camera Injection Defense

An operational engineering analysis evaluating deepidv, Persona, and Jumio on sub-150ms execution latency, device attestation, and deepfake interception.

Aug 15, 202610 min
Read more

Veridas vs Fourthline vs deepidv: European Identity Consolidation Trends

A technical evaluation comparing deepidv against Veridas and Fourthline following their merger, focusing on eIDAS 2.0 readiness and sub-150ms execution.

Aug 5, 20268 min
Read more