Language

Identity Proofing

What is identity proofing?

Identity proofing is the process of establishing that a claimed identity exists and belongs to the applicant, to a defined level of confidence. An organization collects and evaluates evidence before associating the person with an account, credential, or service.
The process may take place remotely or in person. Its requirements depend on the service's risks, applicable rules, and any assurance framework the organization follows.

What are the stages of identity proofing?

NIST describes three principal stages:
  • Identity resolution: Establish that the claimed identity corresponds to a particular individual within the relevant population
  • Identity validation: Check whether the identity evidence is genuine and whether the required attributes are accurate
  • Identity verification: Confirm that the applicant is the person to whom the evidence belongs
Successful proofing can be followed by enrollment, when the organization creates a subscriber record and connects authenticators to it.

What evidence can support identity proofing?

Evidence may include passports, national identity cards, official digital credentials, and records from issuing authorities or other reliable sources. Its usefulness depends on how it was issued, how it can be checked, and how it can be connected to the applicant.
In a remote document-based process, the organization may authenticate an identity document, validate relevant attributes, and compare a captured facial image with the document portrait. Liveness detection and capture-security controls help assess whether the remote evidence was supplied through a trustworthy process.
Other methods may be acceptable under the chosen framework. Evidence requirements should account for applicants who lack a supported document or cannot complete the standard capture process.

How can Regula help with identity proofing?

Regula Document Reader SDK supports document examination and data extraction, including reading and verifying supported electronic-document chips. Its database contains more than 16,500 document templates from 254 countries and territories. Regula Face SDK can compare the applicant's facial image with the document portrait and assess liveness.
These capabilities can form part of a documented proofing process. The organization must also address any required source checks, alternative evidence, enrollment procedures, and assurance requirements.

FAQ

Is identity proofing the same as identity verification?

The terms overlap in commercial use. Under NIST's terminology, verification is one stage of proofing: connecting the applicant to validated evidence. A provider may use identity verification for a broader service, so specifications should state which checks are included.

Does higher-assurance proofing always require automated biometrics?

Requirements depend on the framework and level. <a href="https://csrc.nist.gov/pubs/sp/800/63/a/4/final">NIST Special Publication 800-63A Revision 4</a> permits IAL2 methods using automated biometrics, other verification methods, or digital evidence. A selfie-and-document process must meet all applicable requirements before it can be described as meeting a particular level.

Can a business accept a self-declared identity at IAL1?

Self-declared details alone do not meet NIST IAL1 under Revision 4. That level requires identity evidence, attribute validation, and steps associating the applicant with the identity. Services that require no identity proofing belong to a separate category.

What should happen when an applicant cannot complete standard proofing?

The organization should offer an approved alternative where available, such as different evidence or assisted verification. Record why the original method failed. A capture problem or unsupported document should not automatically become a fraud finding.

When should a business repeat identity proofing?

Repeat proofing may be appropriate when the service needs stronger assurance, the existing identity evidence becomes doubtful, or account recovery cannot rely on registered authenticators. Ordinary login and routine profile maintenance do not automatically require the full process again.

What should an identity-proofing record contain?

Record the evidence types, checks performed, sources consulted, relevant dates, decision reasons, and any reviewer action. Include the framework and policy version where applicable. Retain personal data and biometric material only for documented purposes and applicable retention requirements.

On our website, we use cookies to collect technical information. In particular, we process the IP address of your location to personalize the content of the site

Cookie Policy rules