Identity proofing is the process of establishing that a person claiming an identity can be associated with that real-world identity to a defined level of confidence. It is used when an organisation needs to establish who a person is before giving them access to a service, account or other resource.
The process can use identity evidence, personal attributes, trusted data sources and biometrics, depending on the required level of assurance. NIST’s current SP 800-63A- 4 Digital identity Guidelines defines technical requirements for identity proofing and enrolment across three identity assurance levels.
How the Identity Proofing Process Works
The identity proofing process starts with information supplied by the applicant and establishes whether it can be linked to a real-world identity.
Identity resolution determines whether the information can be associated with one individual. Attributes such as name, date of birth, address and government identifiers can help distinguish one person from another.
Evidence and attribute validation checks whether the identity evidence is genuine and whether the information it contains is valid. Depending on the evidence, this can include document inspection, automated checks, security-feature checks and comparison with authoritative or credible sources.
Identity verification establishes that the person presenting the evidence is the person to whom it belongs. Depending on the assurance level, this can involve visual comparison, biometric comparison or other permitted methods. Once the requirements are met, the proofed identity can be enrolled into the relevant identity service. After enrolment, the person proves it is still them at each sign-in through identity authentication.
Identity Assurance Levels
An identity assurance level (IAL) describes the level of confidence established in a person’s claimed identity. NIST defines three levels.
| Level | What it establishes |
| IAL1 | Establishes the real-world existence of the claimed identity and provides some assurance that the applicant is associated with it. |
| IAL2 | Requires additional evidence and a more rigorous process for validating evidence and attributes and verifying the applicant. |
| IAL3 | Adds stricter requirements including an on-site attended proofing session with a trained proofing representative and collection of at least one biometric. |
The appropriate identity assurance level depends on the service, its risks and the consequences of accepting an incorrect identity. Higher levels require stronger evidence and more rigorous proofing controls.
Identity Proofing Methods
NIST SP 800-63A-4 describes several approaches for establishing an applicant’s association with identity evidence:
- Confirmation Code: Control of the identity evidence is confirmed through a verification code.
- Digital Account or Credential Control: Control of a digital account or signed digital assertion is established through an authentication or federation protocol.
- Microtransaction Confirmation: Control of the evidence is confirmed through a value associated with a microtransaction such as micro-deposit.
- Agent-Led Facial Comparison: A proofing agent compares the applicant’s face with the facial image on the identity evidence either remotely or on-site.
- Automated Biometric Matching: An automated system compares the applicant’s biometric sample with corresponding biometric information from identity evidence or authoritative records.
Remote Identity Proofing vs In-Person Proofing
Remote identity proofing lets an applicant complete the process without visiting a physical location. In-person proofing takes place at a controlled location. NIST describes four proofing types based on where proofing happens and whether a proofing agent is involved:
- Remote unattended: completed remotely and fully automated, with no proofing agent.
- Remote attended: a proofing agent joins through a secure video session.
- On-site unattended: completed at a controlled location, such as a kiosk, without an agent directly involved.
- On-site attended: completed at a physical location with a trained proofing agent.
These types describe how proofing is carried out, not the level of assurance it provides.
Identity Proofing vs Identity Verification
Identity verification is one part of identity proofing rather than an alternative to it. In everyday use, identity verification may refer to the overall process of confirming a person’s identity during onboarding. In NIST terminology, identity verification is a specific step within identity proofing that confirms the applicant is associated with the claimed identity.
| Identity Proofing | Identity Verification |
| Establishes confidence in a claimed identity using identity evidence and attributes. | Confirms that the person presenting the evidence is the person associated with it. |
| Can include resolution, evidence validation, attribute validation and verification | Focuses on the person presenting the evidence. |
| Covers the wider process of establishing and enrolling an identity. | Represents one stage within the identity proofing process. |
Where Identity Proofing Is Used?
Identity proofing is used when an organisation needs to establish a person’s identity before providing access to a service, account or resource. It is commonly used in financial services, government services, healthcare, workforce onboarding and other digital services where a person’s identity needs to be established with confidence.
Standards and Frameworks for Identity Proofing
Identity proofing is covered by several standards and frameworks and they do not all use the same terminology or assurance model. NIST SP 800-63A-4 provides requirements for digital identity proofing and enrolment and establishes NIST’s identity assurance framework. Published in July 2025, it is the current version of NIST’s identity proofing guidance.
ETSI TS 119 461 focuses on identity proofing for trust service components and sets policy and security requirements for collecting and validating identity attributes and evidence.
ISO/IEC 29115:2013 provides a broader framework for entity authentication assurance and defines four levels of authentication assurance. ISO states that the 2013 edition remains current while a new edition is under development.
These standards serve different purposes, so their assurance levels should not be treated as equivalent.
















