Broker guide
Onfido Pricing for Mortgage Brokers 2026
Review Onfido pricing, document and biometric checks, consent, integrations and evidence retention before assessing it for a mortgage brokerage.
- Published
- Updated
Onfido pricing is quote-based through Entrust, which now sells the service as Entrust Identity Verification. For a mortgage brokerage, the buying decision combines the checks you need with the work of capturing documents, reviewing exceptions and keeping evidence. A hosted capture link can reduce development work, while a direct integration gives your team more control over the surrounding onboarding process.
Choose a direct implementation when you have someone to maintain the connection and a defined review process. Use a platform-delivered service when that platform already handles your borrower records and evidence. For lower volumes, Entrust’s own hosted-link route is also an option.
Onfido Pricing and Current Product
Onfido is now part of Entrust, and its current product name is Entrust Identity Verification. Onfido names still appear in dashboard addresses and technical documentation. They describe the same product lineage, so a newer Entrust heading doesn’t by itself indicate a different verification service.
As at October 2026, Entrust’s public product pages direct buyers to its sales team. The service schedule defines the purchased checks through an order. Treat the quote as a specification for your brokerage’s use, with the following items written into it.
| Quote item | What the brokerage needs priced or defined |
|---|---|
| Verification scope | Document checks, the selected face check and any Australian database checks |
| Billing unit | What counts as a chargeable check or user, including retries and additional checks |
| Volume | Expected borrower volume, minimum commitments and overage treatment |
| Staff access | Reviewer and administrator access, separate from people undergoing verification |
| Environments | Sandbox testing and live access, with the selected hosting region |
| Currency and tax | Invoice currency and whether goods and services tax (GST) is added |
| Implementation | Your development work and any purchased onboarding or professional services |
| Support and term | Applicable support terms, contract duration, renewal notice and exit arrangements |
Entrust’s July 2026 general terms put fees in the order and make the customer responsible for applicable taxes. Partner purchases use the partner’s fee and tax terms. A quote in a foreign currency therefore needs a different budget treatment from an Australian-dollar invoice.
For subscription purchases under those general terms, renewal is automatic unless cancellation notice arrives at least 60 days before the term ends. Read the order and applicable schedule together, because they set the offering’s term.
Entrust’s identity-verification schedule treats onboarding, customer success and professional services packages as separately purchased services.
Document and Biometric Checks
Onfido identity verification can combine a document authenticity check with a comparison between the document portrait and the person presenting it. Entrust documents an Australian Workflow Studio configuration using Document Report and Facial Similarity Report tasks. Australian passports and driving licences also appear in the supported-document list for Document Report Instant.
Document Report Instant has its own coverage list. A document supported by one report type doesn’t establish that every document variant or another report type accepts it. Scope the purchased workflow to the document types your clients actually use, including overseas-issued documents where relevant.
Facial Similarity compares a captured face with the face on the identity document. Its variants are Motion, Video, Photo and Photo Fully Auto. Motion adds a head-movement liveness assessment, alongside face comparison and capture-integrity checks.
Australian electronic-source checking is a separate workflow choice. Entrust lists Australia 2+2 and two Document Verification Service (DVS) options: Australia 2+2 with DVS and Australia DVS-only. The DVS configurations need document inputs as well as the applicant’s name and date of birth.
The Office of the Australian Information Commissioner (OAIC) guidance on ID scanning treats automated biometric verification information as sensitive information. For entities covered by the Privacy Act, collection must meet its applicable requirements. Explain the purpose before capture and obtain consent where required, with an accepted alternative for clients who cannot complete biometric capture.
Example: A Remote Borrower’s Identity Check
This fictional example shows the information flow, without assuming a verification result. Alex applies through a brokerage that has configured document and Motion checks.
- The brokerage explains what it collects, who processes it and why it needs the check. Alex receives the collection notice and gives the required consent.
- Alex follows the capture journey and submits a supported identity document. The face-capture step records the motion required by the configured check.
- The service returns the configured check results. The brokerage’s reviewer reads any exceptions and matches the record to Alex’s application.
- The reviewer records the action taken and keeps the required evidence under the brokerage’s retention policy. Any unresolved issue follows the alternative verification route.
A successful identity check supports the identity evidence in the file. Loan affordability, suitability and approval require their own assessment. For the property-file requirements, use the verification of identity guide.
Implementation and Review Outcomes
Entrust has both developer-led and hosted capture routes, so implementation effort depends on how you connect the verification journey to your borrower records. Assign technical ownership and review ownership separately. A working connection still needs someone responsible for unresolved outcomes.
| Route | How it works | Who maintains or reviews it |
|---|---|---|
| Application programming interface (API) | Your backend creates records and exchanges results with Entrust | Your developer or integration supplier maintains the connection |
| Software development kit (SDK) | Capture screens sit inside your website or application | Your developer maintains compatibility and the capture journey |
| Workflow Studio and dashboard | Configured tasks determine the route and display results | An administrator manages configuration and trained staff review cases |
| Smart Capture Link | Entrust hosts capture, using a generic link or a light integration | Staff match generic-link results manually, or a developer connects individual records |
| Official platform connector | A documented connector links the named platform and service | The platform’s supported setup defines ownership and available evidence |
| Third-party automation or custom connector | Another system passes data between services | The supplier and brokerage own permissions, mapping and failure handling |
The last two routes are categories of integration, not promises that your particular platform includes an Onfido connector. A platform-delivered package gives you the capabilities enabled by that platform’s configuration and contract.
Smart Capture Link has a genuine no-code route for low-volume use with manual review. Generic links cannot pass existing applicant or custom input data into the workflow. That limits workflows requiring those inputs, including the documented Australian database configurations.
Entrust’s Studio documentation puts workflows ending in review with the customer. Its Manual Decision task handles a decision inside an unfinished workflow. Later case handling belongs in the brokerage’s own case-management process.
Use a review procedure that distinguishes the cause of an unresolved check.
| Outcome | Brokerage action | Escalation |
|---|---|---|
| No match | Compare the result breakdown with the application details and document | Refer unresolved discrepancies to the designated identity reviewer |
| Suspected fraud | Hold identity acceptance and preserve relevant evidence | Escalate through the brokerage’s fraud procedure |
| Poor capture | Ask for a legible recapture using the supported capture route | Use an accepted alternative after unsuccessful attempts |
| Unsupported document | Move to another accepted document or verification method | Refer to the lender’s identity-evidence requirements |
| Service failure | Keep the case pending and record the technical error | Send the technical team or Entrust Support the failure details |
A technical error doesn’t establish that the person failed identity verification. Entrust’s API documentation separates request, permission and service errors from verification results. Include the affected record reference and reproducible failure details in a support case, without sending extra borrower information unnecessarily.
Evidence, Privacy and Retention
Entrust’s results and exports can support an identity file, but your brokerage must decide which records it needs and who can access them. Studio records workflow outcomes and result reasons. Its PDF Timeline File shows tasks chronologically, with captured information and returned results.
The Timeline File is unsigned. An evidence folder is a separate account-enabled export, so ordinary timeline access doesn’t imply access to that package. Studio also supports a comma-separated values (CSV) export restricted to Owner and Admin users.
Keep the workflow reference beside the reviewer’s decision and the reason for any override or alternative route. That lets another staff member follow the decision without interpreting a final status alone. Store exported evidence through the controls used for secure borrower document collection.
Entrust’s September 2026 product privacy notice distinguishes processing on a customer’s behalf from processing for its own purposes. Those purposes include developing and improving services where permitted by law. Your borrower notice needs to describe the processing relevant to the configuration you use.
Entrust’s API documents European Union, United States and Canadian storage regions. The European region stores data in Ireland with backup storage in Germany. These regions are overseas storage choices for an Australian brokerage, so an Australian-document check doesn’t establish Australian hosting.
Entrust’s documentation states International Organization for Standardization (ISO) 27001 certification and Service Organization Control (SOC) 2 Type II compliance. Compare the applicable assurance scope with your requirements for identity images and biometric information. Your own access restrictions and export storage controls remain part of that assessment.
The deletion guide supports individual deletion through the dashboard or API and configurable rolling deletion. The default delay before permanent deletion is 20 days. Rolling deletion has a minimum initial retention of 48 hours, with the deletion delay added separately.
Deleting an applicant includes their documents and workflow results. Backup and logging data follows separate processing records. Set a retention schedule for both the provider’s records and your exported copies, including any required fraud-case treatment.
For technical incidents, Entrust’s published support terms use severity-based responses. A response target means acknowledgement and response, which is different from a guaranteed repair time. Platform-delivered users need an escalation route through their platform when it owns the Entrust relationship.
Onfido Fit and Alternatives
A direct Entrust implementation fits a brokerage that needs configurable document, face and Australian database checks, with someone to maintain the integration. Its workflow controls suit a defined review process. Budget for maintaining the connection as well as handling identity exceptions.
Receiving the service through another platform fits when that platform already keeps your borrower records and supplies the required results. The brokerage’s usable package depends on that platform’s capture flow and evidence access. Its support and retention arrangements determine how you investigate a disputed result or leave the platform.
For a small volume of checks, consider Entrust’s hosted Smart Capture Link before assuming you need a custom app. Manual record matching is practical only when staff can reliably connect every result to the correct borrower. A generic link is unsuitable for a workflow that needs preloaded applicant or custom inputs.
Choose another provider or an accepted manual route when a required document is unsupported, biometric capture is unsuitable or the hosting arrangement doesn’t meet your requirements. The same applies when required evidence cannot be retained through your chosen package. Cost can also favour a simpler service when the proposed commitment exceeds the brokerage’s expected use.
The identity-verification software comparison separates providers by the verification job they perform. Choose the route that supplies the required evidence, then assign one person to own exceptions and retention before the first borrower enters it.