SUSPECTED when the document and face checks themselves succeeded, but the system attached one or more fraudTags or mismatchTags to the result. SUSPECTED never appears without at least one of those tags present — it exists specifically to carry that signal to you.
Worked Examples
The same shape repeats every time:autoDocument/autoFace (and manualDocument/manualFace, if reviewed) come back clean, but a tag is present. Only the tag differs.
A Data Mismatch
You created the session withfirstName: "Jon". The document reads “John”.
An Age Policy Flag
You configuredageLimit, and the document’s date of birth puts the client under it.
An AML/Watchlist Hit
AML screening (checkAml) found the client on a PEPs or sanctions list.
A Duplicate Signal
checkDuplicateFaces is enabled, and this selfie matches a face from a previous verification — possibly under a different clientId.
Next Steps
Status Handling
What to do with every overall status, not just SUSPECTED.
Verification Statuses
Full definitions of every tag value.
Resolving False Positives
Clear a tag from the dashboard.
Request Update
Reactivate the token — POA, Risk Assessment, or Questionnaire cases only.