authID vs CLEAR vs deepidv: Benchmarking Person-Based Human Verification
An operational engineering analysis evaluating deepidv, CLEAR, and authID on sub-150ms response latency, device attestation, and deepfake prevention.
Remote client verification law firm Canada: what law society rules require for virtual ID, why a video call is not enough, the fraud risks, six-year record-keeping, and how deepidv verifies clients remotely.
Remote client verification is now a normal part of running a law firm in Canada, and the rules for doing it have changed more than most lawyers realize. A client who never walks into your office still has to be identified and verified before you touch their funds, and a video call by itself no longer satisfies your obligations. If your intake process still relies on a webcam glance at a driver's licence, you are running a file that a regulator, a title insurer, or a fraudster can pick apart.
This guide explains remote client verification for law firms in Canada: what the law society rules actually require for virtual identity checks, what a compliant remote flow looks like step by step, the fraud risks that make weak verification dangerous, and the record-keeping that has to survive an audit. The rules trace back to the Federation of Law Societies of Canada Model Rule on Client Identification and Verification, which each provincial and territorial law society adapts into its own binding form.
deepidv is a verification engine and agentic compliance suite built in San Francisco. Firms use it to confirm the human on the other end of a remote call, detect forged and AI-generated documents, and keep a retained audit file that maps to law society requirements. The sections below cover the rules first, then how technology helps you meet them.
Every discussion of remote onboarding falls apart when people use these two words interchangeably. They are separate steps with separate rules.
The Law Society of Ontario sets this out plainly in its client identification and verification rules under By-Law 7.1. A useful shorthand: identification is the interview, verification is the proof. Remote client verification is where the newest and strictest rules apply, because that is where fraudsters concentrate.
Suggested read: Client Identity Verification for Canadian Lawyers
Verification is not required for every matter. It is triggered when you engage in or give instructions about the receiving, paying, or transferring of funds for a client. A payment into or out of trust is the classic trigger.
Two changes from the March 2023 amendments to the FLSC Model Rule matter here. First, the old exemption for funds received or paid in the settlement of a legal proceeding is gone. Second, funds paid pursuant to a court order are no longer exempt either. According to guidance summarized by Law360 Canada, this closes a gap that some firms had used to skip verification on litigation files that moved money.
A narrow exemption survives: you do not need to verify again for funds received from the trust account of another Canadian lawyer or a Quebec notary, because that lawyer already carried the obligation. Alongside verification, firms retained for a financial transaction now have to record the client's source of funds, a requirement the LSO details in its source of funds guidance. These rules connect directly to Canada's anti-money-laundering regime overseen by FINTRAC under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act.
The Model Rule and the provincial rules give you four ways to verify an individual, and understanding which ones work remotely is the whole point of this article.
| Method | How it works | Works remotely? |
|---|---|---|
| Government-issued photo ID | Examine an authentic, valid, current government photo ID and confirm the name and photo match the person | Yes, only with authentication technology that confirms the ID is genuine |
| Credit file | Obtain a credit report that has existed for at least three years directly from a Canadian credit bureau | Yes, the person need not be present |
| Dual process | Match information from two reliable, independent sources (name plus address, name plus date of birth, or name plus a financial account) | Yes |
| Agent | Retain an agent under a written agreement to verify identity on your behalf | Yes, if the agent applies one of the methods above |
The Law Society of Alberta and the Law Society of British Columbia both publish detailed breakdowns of these methods. The credit file and dual process methods have always worked remotely because they do not require you to look at a physical card. The photo ID method is the one that changed.
Suggested read: Remote Client Verification and Real Estate Fraud
During the pandemic, most law societies temporarily allowed lawyers to verify a client by holding up ID to a webcam. That emergency measure has ended. The Law Society of Ontario ended it on January 1, 2024, and BC set its own permanent rule in March 2024.
The distinction the regulators drew is between verification and authentication. A video call can help you confirm that the person on screen matches the photo. It cannot tell you whether the document itself is real. As the Law Society of British Columbia guidance puts it, a video conference with the individual by itself is not sufficient. To verify photo ID remotely you now have to use reliable technology that confirms the government-issued ID is genuine.
That technology has to assess the actual security features of the document: size, texture, character spacing, raised lettering, format, design, holograms, barcodes, magnetic strips, watermarks, and embedded electronic chips. The Ontario Bar Association and provincial societies have each stressed that the lawyer, not the vendor, remains responsible for the result. Law societies do not certify or endorse specific technology vendors, though BC points lawyers to the DIACC trust framework as a reference for evaluating providers.
Weak remote onboarding is not a paperwork problem. It is an open door for the fastest-growing category of fraud in the country.
The scale is not abstract. The Canadian Anti-Fraud Centre reported more than 638 million dollars in fraud losses in 2024, with identity fraud among the most frequently reported categories, and the agency estimates only a small fraction of incidents are ever reported. A law firm that moves a client's money on the strength of a spoofed identity can face the loss, the professional liability claim, and the regulatory finding all at once.
Put the rules and the risks together and a defensible remote flow has a clear shape. Here is a sequence that meets the photo ID method virtually.
deepidv runs this whole sequence in one pass. Its verification engine authenticates the document and matches the face, deepeye handles liveness and deepfake detection, and the platform keeps a retained audit file for every check. For firms that onboard clients across marketplaces or third-party portals, deepidv also verifies both parties in a transaction while validating the products and services being exchanged, which matters when a legal matter turns on the authenticity of an asset. The underlying technology is described in more detail on the platform pages.
Verification is only half done if you cannot prove it later. The rules require you to keep the records, and the retention period is long.
Across Canadian jurisdictions you must retain the client's identification and verification records, including copies of the documents used, for at least six years following the completion of the work for which you were retained. The Law Society of Yukon and other societies state this six-year rule directly, and it echoes the retention expectations under FINTRAC for reporting entities.
A defensible audit file records more than the ID copy. It should capture:
This obligation sits against privacy law. Under PIPEDA, you should not keep personal information longer than you need it, so build a disposal schedule that releases files once the six-year window closes. deepidv keeps the audit trail structured and exportable so the retention and disposal both stay under your control. Its compliance agents, including Arbiter for policy decisions and Arc for case handling, keep the record consistent across every matter.
Suggested read: Building Trust in Peer-to-Peer Marketplaces
Because no law society certifies vendors, the responsibility to choose well is yours. A few questions separate technology that will hold up from technology that will not.
The goal is not to outsource your judgment. It is to give you evidence strong enough that a regulator, a title insurer, and your own professional liability insurer all reach the same conclusion: you knew who your client was.
No. A video call by itself is not sufficient to verify a client under current law society rules. To verify government-issued photo ID remotely you must use reliable authentication technology that confirms the document is genuine and that the face matches, which a plain video conference cannot do. The credit file method and dual process method remain valid remote alternatives.
Verification is required when you are retained to provide legal services that involve a financial transaction, meaning you receive, pay, or transfer funds. Identification, the basic recording of who the client is, applies to every retainer. Since March 2023, the exemptions for funds tied to settling a legal proceeding or paid under a court order no longer apply.
At least six years following the completion of the work for which you were retained. This covers copies of the identity documents used, the verification method, and the results. Balance this against privacy law by disposing of the records once the six-year retention period ends.
Verification confirms that the client matches a government-issued photo ID. Authentication determines whether the ID document itself is real and genuine. The regulatory point is that you can perform verification remotely, but authenticating the document requires technology that inspects its security features rather than a human glance over video.
No. Law societies including Ontario and British Columbia state that they do not vet, endorse, or certify authentication technology vendors or their compliance claims. The lawyer remains responsible for the outcome. BC points to the DIACC trust framework as a reference, and firms should confirm any tool authenticates documents, detects deepfakes, and retains an audit file.
deepidv runs document authentication, face matching, liveness, and deepfake or AI-face detection in a single remote flow, then stores a retained, exportable audit file that maps to law society record-keeping. It also runs one-to-many checks to flag repeat or banned identities. For firms that touch marketplaces or third-party portals, deepidv verifies the people on both sides of a transaction while validating the products and services involved.
Go live in minutes. No sandbox required, no hidden fees.
An operational engineering analysis evaluating deepidv, CLEAR, and authID on sub-150ms response latency, device attestation, and deepfake prevention.
An operational engineering analysis evaluating deepidv, Persona, and Jumio on sub-150ms execution latency, device attestation, and deepfake interception.
A technical evaluation comparing deepidv against Veridas and Fourthline following their merger, focusing on eIDAS 2.0 readiness and sub-150ms execution.