Identity Proofing

Identity proofing is the process of establishing that a person is who they claim to be, at first contact, using evidence. It happens once, before any credential exists. Everything afterwards — passwords, biometrics, device binding, access control — is authentication, and all of it inherits whatever proofing established.

Reference framework NIST SP 800-63A, the U.S. digital identity guidelines
Three stages Resolution, validation, verification
Resolution Collecting enough evidence to distinguish one person from everyone else
Validation Confirming the evidence is genuine, current, and accurate
Verification Binding the validated evidence to the person presenting it
Assurance levels IAL1, IAL2 and IAL3 — increasing confidence, increasing evidence
Evidence strength Graded from weak to superior, based on issuance process and security features
Happens Once, at enrollment — not repeatedly

The three stages, and why they are separate

Most descriptions of identity verification collapse these into one step. Keeping them apart explains precisely where a given process is weak.

Stage The question How it fails
Resolution Which unique person is this claim about? Insufficient attributes to distinguish one person from another with a similar name
Validation Is this evidence genuine and accurate? Reading a document without authenticating it — extraction mistaken for verification
Verification Is the presenter the person the evidence describes? No biometric binding — a genuine document in anyone’s hands passes

A process can perform one stage well and skip another entirely, which is the common case. Matching a name and date of birth against a credit file does resolution and a weak form of validation, and does no verification at all — it confirms the data describes a real person, not that the applicant is that person. That single gap is what synthetic identity fraud and stolen-identity applications both exploit.

Assurance levels, and choosing one

NIST separates identity assurance from authentication assurance for the good reason that they are different questions. Identity Assurance Level describes how confident you are about who the person is:

IAL1 requires no proofing at all — attributes are self-asserted. An email signup sits here, and it is entirely appropriate for services where identity does not matter.

IAL2 requires evidence, and permits it to be presented remotely. This is where most regulated commercial onboarding lands: an authenticated identity document plus a biometric comparison to the person presenting it.

IAL3 adds a trained operator and, in the original formulation, physical presence — now generally read to include supervised remote sessions with strict controls.

The useful discipline is choosing deliberately rather than by default. Applying IAL2 evidence requirements to a service that needs IAL1 costs conversion for nothing; applying IAL1 to an account that holds money is the failure that produces every problem described elsewhere in this glossary.

Why proofing is the step everything else depends on

The relationship is worth stating as plainly as possible: authentication confirms the same person returned; proofing establishes who that person is. A system with excellent authentication and no proofing will faithfully protect an account for whoever opened it, indefinitely, and every log will look clean.

Two practical consequences follow. First, enrollment deserves more scrutiny than any subsequent sign-in, because it is the only moment when identity itself is in question — and it is routinely the least-defended step in the flow.

Second, account recovery is proofing repeated. When someone has lost every credential, the system must establish identity from scratch for a person it cannot authenticate. Doing that with knowledge-based authentication means relying on information that breaches have published. Doing it with document and biometric evidence asks something an attacker cannot look up.

The validation and verification stages are where identity document verification does the work — authenticating the document rather than reading it, and binding it to a live person. Identity verification is the operational form of proofing, and the assurance level it targets should be a decision rather than an accident.

What identity proofing can’t do

It does not persist. Proofing establishes identity at a moment. It says nothing about who controls the account a year later, which is authentication’s job.

It cannot exceed its evidence. A process built on weak evidence produces weak assurance however well it is executed.

It does not assess risk or intent. Correctly identifying someone says nothing about whether they should be onboarded.

Higher assurance costs real applicants. Every additional evidence requirement excludes people who cannot meet it, disproportionately those without standard documents — which is why the level should match the risk rather than the ambition.

Frequently asked questions

What is the difference between identity proofing and authentication?

Identity proofing establishes who someone is at first contact, using evidence such as an authenticated document and a biometric comparison. Authentication confirms on later visits that the same person has returned, by comparing a credential against what was enrolled. Proofing happens once; authentication happens repeatedly and inherits whatever proofing established.

What are the three stages of identity proofing?

Resolution — collecting enough evidence to distinguish this person from everyone else. Validation — confirming the evidence is genuine, current and accurate. Verification — binding that validated evidence to the person actually presenting it. Processes commonly perform the first two and skip the third.

What are Identity Assurance Levels?

NIST’s grading of how much confidence a proofing process produces. IAL1 requires no proofing and attributes are self-asserted. IAL2 requires evidence and permits remote presentation, which is where most regulated commercial onboarding sits. IAL3 adds a trained operator and controlled presence.

Is identity proofing the same as KYC?

No, though they overlap. KYC is a regulatory obligation covering identity verification, risk assessment and ongoing monitoring. Identity proofing is the technical process of establishing identity, and it is how the identity component of KYC is actually performed. Proofing also applies well outside regulated finance.

Related reading

Discover Our Solutions

Exploring our solutions is just a click away. Try our products or have a chat with one of our experts to delve deeper into what we offer.

Report
Mapping the Rise of AI-Powered Identity Fraud

AI didn't just make fraud faster. It made it a system. We analyzed millions of identity interactions to map how identity attacks are evolving across regions, attack types, and sophistication levels — and what organizations need to rethink to keep pace.

See the Data