Remote hiring created an industry-scale identity problem: the interview process a company built to see people now sees only frames on a screen. Candidate-impersonation fraud — hired-forum ringers, proxy interviewers, fabricated identities — exploits exactly that gap, and the damage isn't hypothetical: payroll flowing to someone who never did the work, credentials issued to a stranger, sensitive systems exposed by a person whose name on the offer meant nothing. Here's the verification stack that catches it, ordered from cheap to strongest.
Layer 1: Document verification
A government-issued ID (passport, national ID, driver's license) checked through a vendor that validates the physical document — holograms, fonts, MRZ checksums — not just a photo upload. Automated services (the kind used in gig-platform onboarding) do this at signup cost. It catches the largest category of fraud — fabricated and edited IDs — and it's table stakes for any fully remote hire.
What it doesn't catch: a genuine ID belonging to someone else — which is exactly how professional proxy rings operate: the documents are real, they belong to a low-level accomplice, and the person interviewing and working is someone else entirely.
Layer 2: Liveness and biometric matching
The step that defeats the document layer's blind spot: the candidate performs a live check (face video with a random challenge, or a short unedited video statement), matched against the ID photo by the vendor. This is liveness detection. Done correctly, it kills the static-photo and deepfake-lite attacks. Key operational rule: run it before credential provisioning and payroll, and for high-risk roles, repeat it at first login from a new device or location.
Layer 3: Employment and history verification
Identity fraud pairs with résumé fraud: fabricated roles at companies that don't exist, employment dates stretched over gaps. Verification here is procedural and boring and works — direct confirmation through corporate HR channels, payroll-based evidence (W-2 or equivalent, payslips) when the claimed employer can't be reached, and reference checks structured for discrepancy detection. If the person you're verifying is real but their history isn't, this is the layer that says so.
Layer 4: Technical and behavioral signals during assessment and interview
- Require camera on for live interviews, no exceptions negotiated mid-call; inconsistent framing, lighting that shifts as if the person moved, or answers that arrive with typing-like pauses after questions are classic proxy patterns.
- Run live follow-ups on the take-home or assessment: ask the candidate to walk through code or work they submitted, screen-share, explain trade-offs. Stolen work survives an interview; it rarely survives an unscripted walkthrough.
- For technical roles, proctored assessments with behavioral flags add real signal (the mechanics of what gets flagged is a whole field — for a practical breakdown, our guide on how to detect candidate impersonation covers the interview-side tells).
- Post-hire, device and location attestation (VPNs flagged, MFA hardware, login geography) protects against account-sharing that starts after the clean hire.
Layer 5: Sequence and consistency
Verification fails when it's done selectively. If the process differs by candidate — some get an ID check, some get nothing — you're verifying against yourself in any dispute. Build one standard per role tier, disclose every check plainly to the candidate ("we'll ask for ID and a short video before offers; here's why"), and keep vendor audit trails; biometric and ID data carries consent and jurisdiction rules (several US states regulate biometric collection — BIPA-adjacent — and ID-document handling triggers FCRA questions where third-party reports are involved).
Which raises the honest point about tools: the checks above are exactly the signals a structured screening pipeline should consolidate — ID result, liveness match, employment verification, assessment integrity, live walkthrough — into one per-candidate evaluation record with a defensible decision trail, instead of five vendor portals and a recruiter's memory. That's the design problem AI candidate evaluation addresses, and remote-heavy hiring is where it stops being optional.
Bottom line
How to verify a remote worker's identity: government-ID document checks (vendor-validated), live selfie/liveness matched against the ID before provisioning, direct employment-history verification, camera-on interviews with unscripted walkthroughs of submitted work, and consistent post-hire device/location attestation — all applied uniformly, disclosed to candidates, and consolidated into one evaluation record. Documents prove a person exists; the layers around them prove they're the one you're paying.