us

216.73.217.78

Back
Blogs

What is identity assurance? Levels, Frameworks, and What changed in 2025

What is identity assurance? Levels, Frameworks, and What changed in 2025
Madiha Khatoon MAY 10, 2026 12 minutes read

Identity assurance is the confidence level your identity checks have earned, judged on the evidence you kept. NIST rewrote the levels in July 2025, and older guidance is still circulating.

Most people think that the term ‘identity assurance’ refers to the methods and tools a business uses to verify its customers, such as document checks, liveness checkers, screening software, etc. But the term actually refers to how accurate and effective these tools and methods are. It’s the grade awarded to the identity evidence your process produced and kept.

In the US, NIST updated and finalised Special Publication 800-63-4 on 31 July 2025, and the update rewrote the requirements for the lowest level. Guides that are written against the earlier revision are still easy to find, but they describe rules that no longer apply.

What is identity assurance?

Identity assurance is the level of confidence that a claimed identity is real and belongs to the person presenting it, and this confidence is graded on how well a business or a system documents evidence. To do that, auditors usually look at what data you collected, how you made sure it was genuine, whether you confirmed the details against an official record, and how you proved the person presenting the evidence also owned it.
Three related terms cause most of the confusion about what identity assurance means.

Identity assurance vs identity verification

Identity verification is a single check, and identity assurance is the grade given to the whole process that contains that check. A verification either passes or fails, whereas an assurance level tells a third party how much weight that pass deserves. Two firms can run the same document and face check and end up at different assurance levels because one kept a record of the evidence and the other did not.

Identity proofing vs identity assurance

Identity proofing is the work itself. It covers collecting documents, running face comparisons, and confirming details against official records, and identity assurance is the result of all that work. The gap between the two shows up at audit, because careful proofing with no retained evidence has the same level as careless proofing.

Identity assurance vs authentication

Authentication and identity assurance answer different questions at different points. Authentication tells whether the person signing in right now controls the same account as before, and it runs on every session. Identity assurance, on the other hand, asks how well that account holder’s real identity was established in the first place, and it is decided during proofing.

The four terms side by side

Each term answers a different question at a different point in the customer lifecycle.

Term What it answers When it happens
Identity proofing Did we collect and check real evidence? At onboarding, or at a risk trigger
Identity verification Is this document or biometric genuine? Inside the proofing process
Identity assurance How much confidence has the finished process earned? Graded after proofing, reviewed at audit
Authentication Is the same person returning Every session after enrolment

What are the identity assurance levels?

NIST sets out three identity assurance levels in SP 800-63A, the identity proofing volume of SP 800-63-4. IAL1, IAL2, and IAL3 describe how rigorously an identity was checked. Each level sets its own rules for the evidence you collect, how you validate it, how you confirm the applicant owns it, and where the session takes place.

How NIST grades evidence strength

The levels are built on three tiers of evidence strength, so the tiers come first.

  • FAIR: The weakest tier. Examples include a student ID card, a corporate ID card, and a financial or phone account held in the person’s name.
  • STRONG: Examples include a physical driving licence or state ID card and a US permanent resident card.
  • SUPERIOR: Evidence carrying a cryptographic credential that a system can check directly. Examples include an international e-passport, a mobile driving licence, and the personal identification element of the European Digital Identity Wallet.

Note: These examples come from an informative appendix in SP 800-63A and are not a complete list.

IAL1 now requires real proofing

IAL1 no longer means self-asserted. Under the previous revision, no identity proofing was required at IAL1, so details the applicant typed in could stand unchecked. SP 800-63-4 changed that. A credential service provider, which is NIST’s term for the organisation running the check, must now collect at least one piece of evidence, confirm the core details and at least one government identifier against an official or credible source, and prove the applicant owns the evidence. Face matching stays optional at this level.

The accepted evidence at IAL1 is one STRONG piece, one SUPERIOR piece, or one FAIR piece that either carries a photo or can be checked digitally.

IAL2 gives you three ways to verify

IAL2 raises the evidence requirement and then offers three routes to confirming ownership. The evidence must be one FAIR piece plus one STRONG piece, two STRONG pieces, or one SUPERIOR piece. Verification then follows the biometric pathway, the Non-Biometric pathway, or the digital evidence pathway.

The second and third routes are widely overlooked, and missing them narrows vendor selection for no good reason. A selfie matched against the photo on the document is not the only option at IAL2. A confirmation code posted to an address taken from the evidence and confirmed with an official source satisfies the Non-Biometric pathway. A customer can also sign in to an existing account linked to that evidence, provided the login meets the AAL2 and FAL2 benchmarks NIST sets for authentication strength and federated sign-in. A provider offering more than one route has to keep a record of which route each customer took and pass that on to the businesses relying on the check.

IAL3 requires an in-person session

IAL3 asks for exactly the same evidence as IAL2. The summary table in SP 800-63A lists identical evidence requirements for both levels, so the common claim that IAL3 needs more documents is wrong. However, the other two things change instead.

The session must run on site with a trained proofing agent present, either in the same room as the applicant or through a provider-controlled kiosk with the agent joining by video. The provider must also collect and keep a biometric sample. Verification at IAL3 has to be a face or biometric comparison, so the posted-code route allowed at IAL2 is not available.

The three levels side by side

 

Level Evidence required How ownership is verified Where the session happens
IAL1 One STRONG, or one SUPERIOR, or one FAIR piece that carries a photo or can be checked digitally One piece of evidence, face matching optional Remote or on-site, with or without an agent
IAL2 One FAIR plus one STRONG, or two STRONG, or one SUPERIOR All presented evidence, through the Biometric, Non-Biometric or Digital Evidence pathway Remote or on-site, with or without an agent
IAL3 Same as IAL2 The strongest piece of evidence, by face or biometric comparison only On site, with a trained agent present

Source: NIST SP 800-63A, Identity Assurance Level Requirements, pages.nist.gov/800-63-4, finalised 31 July 2025.

Why strong checks can still produce a low assurance level

Your assurance level is as strong as the weakest stage of your process. This means no matter how strong the rest of the process is, if one link in the chain is weak, it isn’t considered good enough. 

SP 800-63A sets separate requirements at each stage, and an auditor works through them one at a time. Four of those stages decide most real-world outcomes.

The four stages that set your level

  1. Evidence collection: You gathered evidence of the right strength, in the right quantity, for the level you are claiming.
  2. Evidence validation: You confirmed the evidence is genuine through automated document authentication, a check of its digital security features, or inspection by a trained agent.
  3. Attribute validation: You confirmed the core details and the government identifier against an official or credible source.
  4. Ownership verification: You proved the applicant is the person the evidence describes, using a route the level allows.

Fall short at any one of these, and the whole process is graded at the level of that weakest stage, no matter how well the others were.

Four Stages of Identity AssuranceMatch the depth of the check to the risk

A business that checks every customer to the strictest standard spends more than it can justify, and one that checks everyone to the loosest standard leaves its regulated products exposed. The workable answer is to set the level of the check against the risk of the product and the customer.

Roger Redfearn-Tyrzyk, Chief Commercial Officer at Shufti, makes the case for checks that step up rather than sit at one fixed depth, drawing on behavioural, biometric and compliance signals as the risk of a case rises. He describes the goal as “a multi-layered adaptive framework that escalates checks only when necessary.”

Speaking on Shufti’s Age Assurance 2.0 panel. Watch the discussion.

How do eIDAS and UK assurance levels compare to NIST?

Digital identity assurance is graded in the EU and the UK as well, and neither system converts neatly into a NIST level. All three answer the same question of how much confidence an identity claim deserves, but each one grades a different thing.

The three eIDAS levels

The eIDAS Regulation, Regulation (EU) 910/2014, sets three assurance levels for national electronic identification schemes, and Commission Implementing Regulation (EU) 2015/1502 sets out what each one requires. The levels are low, substantial and high.

The regulation itself describes them in relative terms, so low gives a limited degree of confidence and high gives more confidence than substantial. The detail that separates them sits in the Annex, which sets minimum requirements for enrolment, for managing the electronic identification means, and for authentication. Those specifications draw on ISO/IEC 29115, an international standard for assurance levels. In practice, teams work from the Annex rather than from the level names.

The UK framework changed its name in 2025

The UK scheme is no longer called DIATF. Under the Data (Use and Access) Act 2025, the UK digital identity and attributes trust framework became the UK digital verification services trust framework, and version 1.0 was published as a pre-release on 3 March 2026.

It recognises four levels of confidence, which are low, medium, high and very high. Each level groups a set of named identity profiles taken from GPG 45, the UK government’s guidance on checking someone’s identity. Any internal policy that still names DIATF, or that assumes the framework runs on only two confidence levels, needs updating.

Why you cannot map the frameworks one to one

Comparison tables help with planning and mislead in an audit. NIST grades a proofing process, eIDAS grades a national electronic identification scheme, and the UK framework certifies the provider delivering the service. Treat any mapping as a rough orientation, then confirm the real requirement with the regulator or scheme that applies to your business.

Framework Levels What is graded
NIST SP 800-63-4 (US) IAL1, IAL2, IAL3 The identity proofing process
eIDAS (EU) Low, substantial, high A national electronic identification scheme
UK digital verification services trust framework Low, medium, high, very high A certified digital verification service

Which identity assurance level does your business need?

Four things that decide your level

Start with the obligation, then raise the level where the risk justifies it.

  1. Your regulatory floor: Your licence sets a minimum. Confirm it in the regulator’s own wording, never in a vendor comparison table.
  2. The risk of the product: An account for a high-value or easily cashed-out product justifies deeper checking than a low-limit account.
  3. The evidence available in your markets: Where official registries have good coverage, electronic identity verification can confirm details without a document upload. Where coverage is thin, the document does the work.
  4. What you can store and produce later: An assurance level you cannot evidence at audit is not a level you hold.

How Shufti supports identity assurance

What usually holds a team back is evidence rather than detection quality. A verification can pass document forensics, iBeta Level 3 conformant liveness under ISO/IEC 30107-3 and AML screening, and still leave a compliance lead with no single record to put in front of an auditor.

Shufti’s identity verification solution flow adapts to risk. Lower-risk profiles take a faster route while higher-risk cases escalate, carrying pre-scored confidence levels and visual forensic evidence, and every check in the session lands in one evidence package instead of separate vendor logs. That package is what an assurance review reads.

Map your onboarding flow against the assurance level your regulator expects, then book a demo to see the evidence package Shufti produces.

Frequently Asked Questions

Q: What is identity assurance in simple terms?

Identity assurance is how much confidence you have earned that a person is who they claim to be, based on the evidence you collected and can still produce. It grades your whole process rather than any single check.

Q: What are the levels of identity assurance (IAL1, IAL2, IAL3)?

NIST SP 800-63-4 defines three. IAL1 requires one piece of validated evidence and proof that the applicant owns it. IAL2 requires stronger evidence and one of three verification routes. IAL3 requires the same evidence as IAL2, plus an on-site session with a trained agent and a retained biometric sample.

Q: How is identity assurance different from identity verification?

Identity verification is one check, such as confirming a passport is genuine. Identity assurance is the confidence grade given to your whole proofing process, including whether you confirmed details against official sources and kept the evidence. You can pass verification and still hold a low assurance level.

Q: Why does identity assurance matter for compliance?

Regulators and auditors examine the evidence behind your onboarding decisions rather than the vendors you use. An assurance level gives them a defined benchmark. Without documented evidence at the required level, a firm cannot show that its customer due diligence met the standard.

Q: What is an identity assurance framework?

An identity assurance framework is a published set of rules defining assurance levels and the evidence needed to reach each one. The main examples are NIST SP 800-63 in the United States, eIDAS in the European Union, and the UK digital verification services trust framework.

Disclaimer: The views and opinions expressed on this webpage or weblink are those of the author only, and are not necessarily the views or opinions of Shufti Pro Limited. The material and information on this weblink is solely for general information purposes. You should not rely upon the material or information on the website as a basis for making any business or legal decision.

While we endeavor to keep the information up-to-date and/or correct, we make no representations or warranties of any kind, express or implied, or for any purpose about the completeness, accuracy, reliability, suitability, or availability of the contents or information herein. Any reliance on its content is thus entirely at your own risk.

For the avoidance of doubt, Shufti Pro Limited will not be liable for any false, inaccurate, inappropriate, or incomplete information presented herein, and all liabilities with respect to actions taken, or not taken, based on the contents or information herein, or for any loss sustained by you as a consequence are hereby expressly disclaimed by us.

Join the
Shufti Sphere Newsletter

Get the latest trends, insights, and expert opinions on KYC, AML, fraud prevention, and more, straight to your inbox.

    Pitch a piece and get a verified byline in the Media room.

    Partnership Inquiries?
    Email us at [email protected]

    iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
    Copyright © 2026 Shufti. All rights reserved.