Identity Assurance Levels (IAL)
What are identity assurance levels (IAL)?
What are NIST IAL1, IAL2, and IAL3?
- IAL1 requires evidence supporting a claimed identity, validation of important identity attributes against authoritative or credible sources, and steps confirming that the applicant is associated with those attributes. Proofing may be remote or on-site, attended or unattended. Biometrics are optional.
- IAL2 requires more or stronger evidence, stronger validation, and verification that the applicant owns the evidence. It may be completed remotely or on-site.
- IAL3 is the highest NIST level. Proofing must be performed on-site in an attended session with a trained proofing agent, and at least one biometric characteristic must be collected. Evidence and verification requirements are stricter than at IAL2.
How is an identity assurance level selected?
- Resolving the claimed identity to a single person
- Collecting the required quantity and strength of identity evidence
- Validating evidence and identity attributes with suitable sources
- Verifying that the applicant owns the evidence
- Applying fraud controls, exception handling, and protected communications
- Recording the proofing decision and evidence needed for audit or later review
When are identity assurance levels used?
How can Regula help with identity assurance levels?
FAQ
Is NIST IAL1 a self-asserted identity?
No, not under NIST Special Publication 800-63A Revision 4. IAL1 requires identity evidence and validation of important identity attributes. A service that performs no identity proofing is placed in the separate “no identity proofing” category. Organizations should check which NIST revision a policy or vendor statement refers to.
What is the difference between IAL and AAL?
IAL measures confidence in the identity proofing completed during enrollment or re-proofing. AAL measures confidence that someone authenticating later controls the account’s authenticators. A higher AAL does not repair weak proofing, and a higher IAL does not remove the need for suitable authentication. Access policy may specify both.
Does NIST IAL2 require biometric verification?
No. Revision 4 permits biometric, non-biometric, and digital-evidence paths at IAL2. If an organization uses remote biometric verification, the applicable NIST requirements include controls for presentation attacks. The chosen path must meet all other IAL2 evidence, validation, verification, and fraud-control requirements.
Can remote identity proofing meet NIST IAL3?
No. Under NIST Revision 4, IAL3 requires on-site, attended identity proofing by a trained proofing agent. Remote proofing can be used at IAL1 or IAL2 if the relevant requirements are met.
Do document and face checks automatically provide IAL2?
No. They may satisfy parts of an IAL2 design, but NIST assesses the complete proofing process. Evidence strength, attribute validation, applicant-to-evidence verification, fraud controls, notification, exception handling, records, and other requirements must also be met. The organization assigning the level must document that conformance.
Does every service need the highest identity assurance level?
No. The target level should match the possible harm caused by accepting an incorrect identity claim. Requiring IAL3 for a low-risk function may collect unnecessary personal data and create excessive cost or user difficulty. Higher-risk services may need stronger proofing, but the selection should follow the applicable framework and risk assessment.