Identity assurance is the confidence level your identity checks have earned, judged on the evidence you kept. NIST rewrote the levels in July 2025, and older guidance is still circulating.
Most people think that the term ‘identity assurance’ refers to the methods and tools a business uses to verify its customers, such as document checks, liveness checkers, screening software, etc. But the term actually refers to how accurate and effective these tools and methods are. It’s the grade awarded to the identity evidence your process produced and kept.
In the US, NIST updated and finalised Special Publication 800-63-4 on 31 July 2025, and the update rewrote the requirements for the lowest level. Guides that are written against the earlier revision are still easy to find, but they describe rules that no longer apply.
What is identity assurance?
Identity assurance is the level of confidence that a claimed identity is real and belongs to the person presenting it, and this confidence is graded on how well a business or a system documents evidence. To do that, auditors usually look at what data you collected, how you made sure it was genuine, whether you confirmed the details against an official record, and how you proved the person presenting the evidence also owned it.
Three related terms cause most of the confusion about what identity assurance means.
Identity assurance vs identity verification
Identity verification is a single check, and identity assurance is the grade given to the whole process that contains that check. A verification either passes or fails, whereas an assurance level tells a third party how much weight that pass deserves. Two firms can run the same document and face check and end up at different assurance levels because one kept a record of the evidence and the other did not.
Identity proofing vs identity assurance
Identity proofing is the work itself. It covers collecting documents, running face comparisons, and confirming details against official records, and identity assurance is the result of all that work. The gap between the two shows up at audit, because careful proofing with no retained evidence has the same level as careless proofing.
Identity assurance vs authentication
Authentication and identity assurance answer different questions at different points. Authentication tells whether the person signing in right now controls the same account as before, and it runs on every session. Identity assurance, on the other hand, asks how well that account holder’s real identity was established in the first place, and it is decided during proofing.
The four terms side by side
Each term answers a different question at a different point in the customer lifecycle.
| Term | What it answers | When it happens |
| Identity proofing | Did we collect and check real evidence? | At onboarding, or at a risk trigger |
| Identity verification | Is this document or biometric genuine? | Inside the proofing process |
| Identity assurance | How much confidence has the finished process earned? | Graded after proofing, reviewed at audit |
| Authentication | Is the same person returning | Every session after enrolment |
What are the identity assurance levels?
NIST sets out three identity assurance levels in SP 800-63A, the identity proofing volume of SP 800-63-4. IAL1, IAL2, and IAL3 describe how rigorously an identity was checked. Each level sets its own rules for the evidence you collect, how you validate it, how you confirm the applicant owns it, and where the session takes place.
How NIST grades evidence strength
The levels are built on three tiers of evidence strength, so the tiers come first.
- FAIR: The weakest tier. Examples include a student ID card, a corporate ID card, and a financial or phone account held in the person’s name.
- STRONG: Examples include a physical driving licence or state ID card and a US permanent resident card.
- SUPERIOR: Evidence carrying a cryptographic credential that a system can check directly. Examples include an international e-passport, a mobile driving licence, and the personal identification element of the European Digital Identity Wallet.
Note: These examples come from an informative appendix in SP 800-63A and are not a complete list.
IAL1 now requires real proofing
IAL1 no longer means self-asserted. Under the previous revision, no identity proofing was required at IAL1, so details the applicant typed in could stand unchecked. SP 800-63-4 changed that. A credential service provider, which is NIST’s term for the organisation running the check, must now collect at least one piece of evidence, confirm the core details and at least one government identifier against an official or credible source, and prove the applicant owns the evidence. Face matching stays optional at this level.
The accepted evidence at IAL1 is one STRONG piece, one SUPERIOR piece, or one FAIR piece that either carries a photo or can be checked digitally.
IAL2 gives you three ways to verify
IAL2 raises the evidence requirement and then offers three routes to confirming ownership. The evidence must be one FAIR piece plus one STRONG piece, two STRONG pieces, or one SUPERIOR piece. Verification then follows the biometric pathway, the Non-Biometric pathway, or the digital evidence pathway.
The second and third routes are widely overlooked, and missing them narrows vendor selection for no good reason. A selfie matched against the photo on the document is not the only option at IAL2. A confirmation code posted to an address taken from the evidence and confirmed with an official source satisfies the Non-Biometric pathway. A customer can also sign in to an existing account linked to that evidence, provided the login meets the AAL2 and FAL2 benchmarks NIST sets for authentication strength and federated sign-in. A provider offering more than one route has to keep a record of which route each customer took and pass that on to the businesses relying on the check.
IAL3 requires an in-person session
IAL3 asks for exactly the same evidence as IAL2. The summary table in SP 800-63A lists identical evidence requirements for both levels, so the common claim that IAL3 needs more documents is wrong. However, the other two things change instead.
The session must run on site with a trained proofing agent present, either in the same room as the applicant or through a provider-controlled kiosk with the agent joining by video. The provider must also collect and keep a biometric sample. Verification at IAL3 has to be a face or biometric comparison, so the posted-code route allowed at IAL2 is not available.
The three levels side by side
| Level | Evidence required | How ownership is verified | Where the session happens |
| IAL1 | One STRONG, or one SUPERIOR, or one FAIR piece that carries a photo or can be checked digitally | One piece of evidence, face matching optional | Remote or on-site, with or without an agent |
| IAL2 | One FAIR plus one STRONG, or two STRONG, or one SUPERIOR | All presented evidence, through the Biometric, Non-Biometric or Digital Evidence pathway | Remote or on-site, with or without an agent |
| IAL3 | Same as IAL2 | The strongest piece of evidence, by face or biometric comparison only | On site, with a trained agent present |
Source: NIST SP 800-63A, Identity Assurance Level Requirements, pages.nist.gov/800-63-4, finalised 31 July 2025.
Why strong checks can still produce a low assurance level
Your assurance level is as strong as the weakest stage of your process. This means no matter how strong the rest of the process is, if one link in the chain is weak, it isn’t considered good enough.
SP 800-63A sets separate requirements at each stage, and an auditor works through them one at a time. Four of those stages decide most real-world outcomes.
The four stages that set your level
- Evidence collection: You gathered evidence of the right strength, in the right quantity, for the level you are claiming.
- Evidence validation: You confirmed the evidence is genuine through automated document authentication, a check of its digital security features, or inspection by a trained agent.
- Attribute validation: You confirmed the core details and the government identifier against an official or credible source.
- Ownership verification: You proved the applicant is the person the evidence describes, using a route the level allows.
Fall short at any one of these, and the whole process is graded at the level of that weakest stage, no matter how well the others were.
Match the depth of the check to the risk
A business that checks every customer to the strictest standard spends more than it can justify, and one that checks everyone to the loosest standard leaves its regulated products exposed. The workable answer is to set the level of the check against the risk of the product and the customer.
Roger Redfearn-Tyrzyk, Chief Commercial Officer at Shufti, makes the case for checks that step up rather than sit at one fixed depth, drawing on behavioural, biometric and compliance signals as the risk of a case rises. He describes the goal as “a multi-layered adaptive framework that escalates checks only when necessary.”
Speaking on Shufti’s Age Assurance 2.0 panel. Watch the discussion.
How do eIDAS and UK assurance levels compare to NIST?
Digital identity assurance is graded in the EU and the UK as well, and neither system converts neatly into a NIST level. All three answer the same question of how much confidence an identity claim deserves, but each one grades a different thing.
The three eIDAS levels
The eIDAS Regulation, Regulation (EU) 910/2014, sets three assurance levels for national electronic identification schemes, and Commission Implementing Regulation (EU) 2015/1502 sets out what each one requires. The levels are low, substantial and high.
The regulation itself describes them in relative terms, so low gives a limited degree of confidence and high gives more confidence than substantial. The detail that separates them sits in the Annex, which sets minimum requirements for enrolment, for managing the electronic identification means, and for authentication. Those specifications draw on ISO/IEC 29115, an international standard for assurance levels. In practice, teams work from the Annex rather than from the level names.
The UK framework changed its name in 2025
The UK scheme is no longer called DIATF. Under the Data (Use and Access) Act 2025, the UK digital identity and attributes trust framework became the UK digital verification services trust framework, and version 1.0 was published as a pre-release on 3 March 2026.
It recognises four levels of confidence, which are low, medium, high and very high. Each level groups a set of named identity profiles taken from GPG 45, the UK government’s guidance on checking someone’s identity. Any internal policy that still names DIATF, or that assumes the framework runs on only two confidence levels, needs updating.
Why you cannot map the frameworks one to one
Comparison tables help with planning and mislead in an audit. NIST grades a proofing process, eIDAS grades a national electronic identification scheme, and the UK framework certifies the provider delivering the service. Treat any mapping as a rough orientation, then confirm the real requirement with the regulator or scheme that applies to your business.
| Framework | Levels | What is graded |
| NIST SP 800-63-4 (US) | IAL1, IAL2, IAL3 | The identity proofing process |
| eIDAS (EU) | Low, substantial, high | A national electronic identification scheme |
| UK digital verification services trust framework | Low, medium, high, very high | A certified digital verification service |
Which identity assurance level does your business need?
Four things that decide your level
Start with the obligation, then raise the level where the risk justifies it.
- Your regulatory floor: Your licence sets a minimum. Confirm it in the regulator’s own wording, never in a vendor comparison table.
- The risk of the product: An account for a high-value or easily cashed-out product justifies deeper checking than a low-limit account.
- The evidence available in your markets: Where official registries have good coverage, electronic identity verification can confirm details without a document upload. Where coverage is thin, the document does the work.
- What you can store and produce later: An assurance level you cannot evidence at audit is not a level you hold.
How Shufti supports identity assurance
What usually holds a team back is evidence rather than detection quality. A verification can pass document forensics, iBeta Level 3 conformant liveness under ISO/IEC 30107-3 and AML screening, and still leave a compliance lead with no single record to put in front of an auditor.
Shufti’s identity verification solution flow adapts to risk. Lower-risk profiles take a faster route while higher-risk cases escalate, carrying pre-scored confidence levels and visual forensic evidence, and every check in the session lands in one evidence package instead of separate vendor logs. That package is what an assurance review reads.
Frequently Asked Questions
Q: What is identity assurance in simple terms?
Identity assurance is how much confidence you have earned that a person is who they claim to be, based on the evidence you collected and can still produce. It grades your whole process rather than any single check.
Q: What are the levels of identity assurance (IAL1, IAL2, IAL3)?
NIST SP 800-63-4 defines three. IAL1 requires one piece of validated evidence and proof that the applicant owns it. IAL2 requires stronger evidence and one of three verification routes. IAL3 requires the same evidence as IAL2, plus an on-site session with a trained agent and a retained biometric sample.
Q: How is identity assurance different from identity verification?
Identity verification is one check, such as confirming a passport is genuine. Identity assurance is the confidence grade given to your whole proofing process, including whether you confirmed details against official sources and kept the evidence. You can pass verification and still hold a low assurance level.
Q: Why does identity assurance matter for compliance?
Regulators and auditors examine the evidence behind your onboarding decisions rather than the vendors you use. An assurance level gives them a defined benchmark. Without documented evidence at the required level, a firm cannot show that its customer due diligence met the standard.
Q: What is an identity assurance framework?
An identity assurance framework is a published set of rules defining assurance levels and the evidence needed to reach each one. The main examples are NIST SP 800-63 in the United States, eIDAS in the European Union, and the UK digital verification services trust framework.















