Every organization's risk appetite is different, and so is the workflow needed to support it. A neobank onboarding thousands of users a day might accept a higher tolerance for false positives to keep signups fast, while a mortgage lender handling six-figure transactions wants borderline sessions escalated for a closer look. Even two companies in the same industry can land on completely different thresholds, escalation logic, and reporting needs depending on their user base, regulatory expos: ure, and appetite for friction.
Plaid Identity Verification (IDV) has always let you build custom templates and workflows to match your program — that's the foundation. Our latest round of updates pushes that same configurability deeper into the layers underneath: the risk logic that decides when a session escalates, the reports that show what happened, and the channels used to reach your users. And because configurability is only useful if you can see what it's doing, several of these updates also pair that control with the visibility to use it with confidence — so you're not left guessing how a change will play out after you've already made it.
Here's a roundup of the latest enhancements for Plaid IDV.
Configure your risk logic, and see the impact before you commit
Escalate on the risk factors that matter to you
Risk-based escalation in IDV has historically relied on a single Trust Index threshold — a broad, useful signal, but a blunt instrument. It couldn't express the kind of nuanced policy most fraud teams actually want, like escalating based on certain document types or behavioral risk signals. The result: customers either applied the same coarse cutoff to every session, or sent more users through extra verification steps than necessary.
With Rule Group Escalations, you can now choose Trust Index Threshold or Rule Groups as your workflow's escalation mechanism, and configure ordered Rule Groups independently after Data Source Verification and Document Verification. The first Rule Group that matches escalates the session to the next verification step; no match means the session continues normally. That opens up policies that weren't possible before and uses the same Risk Engine rules your team already knows and maintains, instead of learning a second scoring system just for escalation.
Know how a rule change will play out before you publish it
Fraud and risk teams have told us for years that tuning IDV rules feels like flying blind — you make a change to a Data Source or Risk Check rule and won't know what it actually did to your pass rate until it's already live and users are moving through it.
Pass Rate Preview, now live in Protect Configure, closes that gap. It shows your overall and per-check pass rates for US sessions based on a 30-day lookback, and — more importantly — lets you preview how a draft change to a Data Source or Risk Check rule would shift those numbers before you publish anything. The feature currently covers standard checks, including documentary fallbacks, with support for additional signals and non-US sessions on the roadmap. No more guessing how a configuration change is going to land.
See the full picture, in the format you actually need
One customizable report
If you run multiple workflow templates, generating a usable report used to mean exporting several CSVs and manually combining them yourself — and even then, the exports didn't break out enough detail on Document Verification, Liveness, Risk Check, or custom rule outcomes to fully understand why a session landed where it did.
Improved IDV Reports allows you to export verification sessions across every workflow template in your organization in a single report, and choose exactly which sections to include — Datasource, Document Verification, Liveness, Risk Check, and User PII. PII details are permission-gated, so authorized users can pull identity and contact information without exposing sensitive document, biometric, or provider-specific data to everyone else. Risk Check exports now also surface custom rule outcomes and the names of any rules that failed a session, so investigators get the "why," not just the "what." The net effect: one CSV to analyze your entire IDV program, with only the information relevant to your use case.
Spot anomalies quickly
Investigating a session often means piecing together location signals scattered across different fields — where's the address on the document, where did the user say they live, where is the connection actually coming from. Individually, none of those data points tell you much. Together, they can be the fastest way to catch a session that doesn't add up.
The new Customer Location Map in the IDV dashboard plots those signals against each other for a given session — Document Address, Submitted Address, IP Address, and IP Address (VPN) — and shows the distance between them along with a risk level. An IP address in an unexpected country, or a submitted address hundreds of miles from the actual connection point, becomes visible at a glance instead of something you have to notice buried in a table.
Meet your users on their terms
Not every end user interacts with a phone the same way — and a verification flow built around one default channel or format can quietly leave people behind. Two updates give your users more ways to get through IDV on their own terms.
Reach users by email, not just SMS
Hosted verification links have always gone out over SMS. That works well for a lot of use cases, but most businesses don't primarily reach their customers by text — and requiring a phone number just to send a verification link adds friction that has nothing to do with actually verifying someone's identity.
Mailable Verification Links give you the option to send hosted verification sessions by email instead of, or alongside, SMS. Email also leaves a clearer audit trail and reaches users who don't have a phone on them, have spotty cell coverage, or are outside their carrier's coverage area. If your users expect an email and not a text, they can now get one — no extra integration work required.
Let users hear their code instead of reading it
SMS one-time codes work well for most people, but not everyone interacts with text messages easily, and that gap in accessibility could stall a verification entirely for some users.
IDV Phone Call Verification adds a "Get a phone call instead" option to the verification flow. Users who choose it receive the same code by phone call, read aloud slowly and repeated several times, instead of by text. It's a small addition with an outsized effect: more users are able to complete verification, and customers get a straightforward way to meet accessibility standards without building anything themselves.
Configurability that meets you where you are
None of these updates require rebuilding your templates or workflows — they build directly on top of the ones you already have, with no new integration work required. They're in the dashboard today, which means the control described above is available to every customer running IDV, whether you're tuning escalation logic for the first time or you've been running Rule Groups in Protect for years.
If you're already a Plaid customer, log into your dashboard to try Rule Group Escalations, Pass Rate Preview, the rebuilt IDV Reports, and the Customer Location Map directly, or turn on email and phone call delivery for your users. If you're evaluating IDV and want to see how configurable risk logic and reporting fit into your fraud program, we're happy to walk through it.
