Identity Proofing
What is identity proofing?
What are the stages of identity proofing?
- Identity resolution: Establish that the claimed identity corresponds to a particular individual within the relevant population
- Identity validation: Check whether the identity evidence is genuine and whether the required attributes are accurate
- Identity verification: Confirm that the applicant is the person to whom the evidence belongs
What evidence can support identity proofing?
How can Regula help with identity proofing?
FAQ
Is identity proofing the same as identity verification?
The terms overlap in commercial use. Under NIST's terminology, verification is one stage of proofing: connecting the applicant to validated evidence. A provider may use identity verification for a broader service, so specifications should state which checks are included.
Does higher-assurance proofing always require automated biometrics?
Requirements depend on the framework and level. <a href="https://csrc.nist.gov/pubs/sp/800/63/a/4/final">NIST Special Publication 800-63A Revision 4</a> permits IAL2 methods using automated biometrics, other verification methods, or digital evidence. A selfie-and-document process must meet all applicable requirements before it can be described as meeting a particular level.
Can a business accept a self-declared identity at IAL1?
Self-declared details alone do not meet NIST IAL1 under Revision 4. That level requires identity evidence, attribute validation, and steps associating the applicant with the identity. Services that require no identity proofing belong to a separate category.
What should happen when an applicant cannot complete standard proofing?
The organization should offer an approved alternative where available, such as different evidence or assisted verification. Record why the original method failed. A capture problem or unsupported document should not automatically become a fraud finding.
When should a business repeat identity proofing?
Repeat proofing may be appropriate when the service needs stronger assurance, the existing identity evidence becomes doubtful, or account recovery cannot rely on registered authenticators. Ordinary login and routine profile maintenance do not automatically require the full process again.
What should an identity-proofing record contain?
Record the evidence types, checks performed, sources consulted, relevant dates, decision reasons, and any reviewer action. Include the framework and policy version where applicable. Retain personal data and biometric material only for documented purposes and applicable retention requirements.