Sure, though not every small project needs to worry about that. Perhaps the payment workflow is a tight loop that has KYC through physical memberships (ID + Photo), say a gym membership for example, and the entire system is private just needs a gateway to do transactions.
Stealing someone's identity and pretending to be them and buying a gym membership with a fake id and a stolen credit card might seem far fetched to you, but Stripe doesn't want to be on the hook for that, especially if the scammer signs up for, say, Equinox and it isn't discovered for year+. (ex-Stripe; didn't work directly on fraud, however)
Even if that was true literally no payment processor cares about what a small project worries about and they never will.