Language

Identity Assurance Levels (IAL)

What are identity assurance levels (IAL)?

Identity assurance levels (IAL) describe the degree of confidence that an applicant’s claimed identity is genuine and belongs to that applicant. The level reflects the strength of the complete identity-proofing process, including the evidence collected, how it was validated, and how the applicant was connected to it.
The best-known IAL framework comes from the NIST Digital Identity Guidelines. Other standards and national programs may define assurance differently, so an organization should name the framework and version it uses rather than relying on an IAL number alone.

What are NIST IAL1, IAL2, and IAL3?

  • IAL1 requires evidence supporting a claimed identity, validation of important identity attributes against authoritative or credible sources, and steps confirming that the applicant is associated with those attributes. Proofing may be remote or on-site, attended or unattended. Biometrics are optional.
  • IAL2 requires more or stronger evidence, stronger validation, and verification that the applicant owns the evidence. It may be completed remotely or on-site.
  • IAL3 is the highest NIST level. Proofing must be performed on-site in an attended session with a trained proofing agent, and at least one biometric characteristic must be collected. Evidence and verification requirements are stricter than at IAL2.

How is an identity assurance level selected?

The organization responsible for the service selects a target level from the possible harms caused by an identity-proofing error. Financial loss, unauthorized access, privacy harm, personal safety, and regulatory duties may affect the choice.
The proofing process must then meet every requirement for that level, which may include:
  • Resolving the claimed identity to a single person
  • Collecting the required quantity and strength of identity evidence
  • Validating evidence and identity attributes with suitable sources
  • Verifying that the applicant owns the evidence
  • Applying fraud controls, exception handling, and protected communications
  • Recording the proofing decision and evidence needed for audit or later review
The designation applies to the complete proofing process. Organizations using NIST terminology should document how every requirement is met and should not describe a product or SDK as “IAL-certified” solely because it performs one required check.

When are identity assurance levels used?

Government services, financial institutions, healthcare providers, employers, telecom companies, and other digital services may use identity assurance levels when issuing an account, credential, benefit, or privileged role. The selected level can also determine which functions an enrolled identity may access.
A user may be re-proofed when a service needs greater confidence than the original enrollment provided. This can happen before access to a higher-risk function, after major identity data changes, or during recovery from serious account compromise. Re-proofing must satisfy the requirements of the new target level; retaining an old label without the required evidence is not sufficient.

How can Regula help with identity assurance levels?

Regula can supply document and biometric evidence used within an identity-proofing process designed for a selected assurance level.
Regula Document Reader SDK authenticates identity documents and extracts information from the visual inspection zone, machine-readable zone (MRZ), barcodes, and supported NFC/RFID chips. Its database contains more than 16,500 document templates from 254 countries and territories. These checks can support validation of the presented document and extraction of attributes for any additional checks required by policy.
Regula Face SDK performs a 1:1 comparison between the applicant’s current facial image and a trusted portrait. Active or passive liveness detection can support a biometric verification path when the selected framework and proofing design call for it.
These results support parts of the proofing process. The organization remains responsible for selecting the target level, meeting all applicable requirements, handling exceptions, and assigning the final assurance level. An SDK result does not by itself establish NIST IAL1, IAL2, or IAL3.

FAQ

Is NIST IAL1 a self-asserted identity?

No, not under NIST Special Publication 800-63A Revision 4. IAL1 requires identity evidence and validation of important identity attributes. A service that performs no identity proofing is placed in the separate “no identity proofing” category. Organizations should check which NIST revision a policy or vendor statement refers to.

What is the difference between IAL and AAL?

IAL measures confidence in the identity proofing completed during enrollment or re-proofing. AAL measures confidence that someone authenticating later controls the account’s authenticators. A higher AAL does not repair weak proofing, and a higher IAL does not remove the need for suitable authentication. Access policy may specify both.

Does NIST IAL2 require biometric verification?

No. Revision 4 permits biometric, non-biometric, and digital-evidence paths at IAL2. If an organization uses remote biometric verification, the applicable NIST requirements include controls for presentation attacks. The chosen path must meet all other IAL2 evidence, validation, verification, and fraud-control requirements.

Can remote identity proofing meet NIST IAL3?

No. Under NIST Revision 4, IAL3 requires on-site, attended identity proofing by a trained proofing agent. Remote proofing can be used at IAL1 or IAL2 if the relevant requirements are met.

Do document and face checks automatically provide IAL2?

No. They may satisfy parts of an IAL2 design, but NIST assesses the complete proofing process. Evidence strength, attribute validation, applicant-to-evidence verification, fraud controls, notification, exception handling, records, and other requirements must also be met. The organization assigning the level must document that conformance.

Does every service need the highest identity assurance level?

No. The target level should match the possible harm caused by accepting an incorrect identity claim. Requiring IAL3 for a low-risk function may collect unnecessary personal data and create excessive cost or user difficulty. Higher-risk services may need stronger proofing, but the selection should follow the applicable framework and risk assessment.

On our website, we use cookies to collect technical information. In particular, we process the IP address of your location to personalize the content of the site

Cookie Policy rules