Skip to content
KEDBYTE
How Identity Works
Chapter
7

Enrolment

Part I · What Identity Is|11,631 words|about 51 min read|Volume 1

7.0 What this chapter gives you#

  1. You will be able to name the three separate steps hidden inside the phrase “identity proofing” — resolution, validation and verification — and say what each one can prove and what it cannot.
  2. You will be able to use the words proofing, validation and verification the way the standards use them, and correct the three most common industry misuses of them on the spot.
  3. You will be able to look at any document and grade it FAIR, STRONG or SUPERIOR against the criteria in NIST SP 800-63A-4, and name the exact criterion it fails.
  4. You will be able to specify a remote enrolment flow with document capture, liveness checking and a face match, and state the exact error rates the standard demands from each component.
  5. You will be able to say what a trusted referee is, what an applicant reference is, and which specific failures each is permitted to rescue.
  6. You will be able to explain the bootstrap problem — needing an identity to obtain the credential that proves identity — and describe three real systems’ answers to it.
  7. You will be able to describe how a synthetic identity is manufactured at an enrolment counter, and place the two checks that catch it earliest.
  8. You will be able to bind an authenticator to a proven identity correctly, including the code lifetimes and the notification that the standard requires.
  9. You will be able to draw a complete enrolment flow with every decision point and every failure branch, and say what the resulting record must store instead of a single flag.

Every identity system has a first moment. Before it, you do not exist inside that system. After it, you do. Some clerk, or some piece of software, looked at whatever you brought, decided it was enough, and wrote a new row. Everything the system will ever do for you or against you rests on that row being right.

This is the moment fraud goes for. It is not a coincidence and it is not a failure of imagination on the attackers’ part. It is arithmetic. Once the row exists, the system will defend it with cryptography that a national laboratory cannot break. Before the row exists, the system is defending itself with a photograph of a piece of plastic and a person’s word. An attacker who is any good at all attacks the second thing.

The trade calls this moment enrolment, and the checking that happens inside it identity proofing. The two are not the same. Proofing is the decision that a particular real person exists and is standing in front of you. Enrolment is the act of writing that decision down and handing over the key that will represent it from then on. A system can proof beautifully and enrol carelessly, and be robbed.

This chapter is about that moment in detail: the three questions it really asks, the grades it gives to evidence, the way the same job is done in a shop and over a phone camera, the specific frauds that live there, and the flow you would actually build. Two neighbours to mark and leave alone. What a passport physically is, and why it proves only that an authority once believed something, is chapter 6. Deciding whether two records already in the system are the same person is a statistical problem with its own mathematics, and that is chapter 8. Here we are concerned only with the door.

The plain version#

A club that has to decide who gets a key#

Picture a small rowing club on a river. For a hundred years it kept its boats in a shed with a padlock, and the padlock key hung in the pub next door. Then the club buys eight new boats, and the committee decides that members will each get their own key to the shed, so they can row at dawn.

Now the club secretary has a job she never had before. When a stranger walks in and says “I would like to join, and I would like a key”, she has to decide something. Not “is this person nice”. Not “can they row”. She has to decide whether this is a real, particular person, and whether that person is the one the papers in her hand describe. And then she has to hand over a key that will, from that day on, open the shed at four in the morning with nobody watching.

Everything else the club does about security depends on this one decision. The lock can be excellent. The key can be uncuttable. If the secretary gives a key to the wrong person on a wet Tuesday in March, the lock and the key are working perfectly for a thief.

The three questions inside one question#

The secretary thinks she is asking one question — “who are you?” — but she is really asking three, and they can each fail on their own.

The first question is: which one person is this? Not “is this person real” but “which real person”. The town has two Fatima Noors. One lives on Mill Street and is thirty-four. One lives on the Green and is nineteen. If the secretary writes down “Fatima Noor” and nothing else, she has not identified anybody; she has written a label that fits two people. So she asks for a birth date, and a street, and she keeps asking until only one person in the town could be the answer. That is the first job, and it is finished when the description narrows to exactly one.

The second question is: is this paper real, and is what it says true? Those are two things, not one. A driving licence can be a genuine licence, printed by the licensing authority, with every security feature correct, and still say an address the person left four years ago. So the secretary looks at the paper itself — the printing, the feel, the little shifting picture in the corner — and separately she picks up the telephone and asks the licensing authority whether they issued licence number D4471 to a Fatima Noor born on that date. The first check is about the object. The second is about the facts on it.

The third question is: is this the person the paper is about? This is the one people forget, and it is the only one that is about the human standing there rather than the paperwork. The secretary looks at the photograph and looks at the face. Or, if the applicant sent the papers by post, the secretary posts a numbered card to the address on the licence and waits to see whether the applicant can read the number back. The paper belongs to somebody. The question is whether it belongs to this somebody.

Three questions: which person, is the paper good, is it your paper. Get all three right and the secretary has done her job. Get the first two right and the third wrong and she has just admitted a thief carrying a genuine, valid, entirely truthful driving licence belonging to somebody else.

Not all paper is worth the same#

The secretary quickly learns that the papers people bring are not equal, and she starts sorting them into rough piles.

The bottom pile is paper that anybody could have made. A letter from an employer on headed notepaper. A membership card from another club. A utility bill printed at home. These say a name exists somewhere. They say nothing about who is holding them, and nothing about who made them.

The middle pile is paper from an organization that checked something before it issued the paper, that posted it to a named address, that carries a number, and that is hard to copy. A bank card. A mobile telephone account. The organization behind it had a reason to care who it was dealing with, and there is somebody the secretary can telephone.

The top pile is paper from an organization that made the person come in and stand in front of a member of staff before it issued anything, that put a photograph on it, and that signed it in a way that cannot be forged. A passport. A national identity card. These cost the issuer real effort, and that effort is what the secretary is borrowing.

The secretary’s rule is not “how many pieces of paper” but “how good is the best piece, and does anything else agree with it”. Three items from the bottom pile are still the bottom pile. One from the top pile does more work than five from the bottom.

Handing over the key is a separate act#

Here is the part that clubs get wrong. The secretary can do all three checks perfectly on Monday, and then on Friday post the key to an address a different person gave her over the telephone. The proofing was sound. The key went to a stranger.

Attaching the key to the person is its own step, with its own way of going wrong. The trade calls it binding: tying the thing you will use from now on — the key, the card, the password, the phone — to the person whose identity was just proven. If the checking and the handing over happen in two different sittings, something has to carry the decision across the gap, and that something is a new place to attack.

The good practice is simple to state. Hand the key over in the same sitting where you did the checking, to the same person you were looking at. If you cannot, then post it to an address you checked yourself, and tell the person, by a separate route, that a key has been issued in their name, so that if it was not them they can shout.

Fatima Noor joins the club, with numbers#

Take one applicant all the way through. On the fourth of March, Fatima Noor, thirty-four, walks into the club office.

She gives a name, a birth date of the eleventh of July 1991, and an address on Mill Street. The club register has 312 members. Two of them are called Noor. Neither has that birth date. The description now fits exactly one person in the register and nobody else. First question answered.

She hands over a driving licence. The secretary holds it to the window and finds the shifting picture that changes colour when you tilt it, and the raised lettering under her thumb. She telephones the licensing authority’s checking line and reads out the licence number. The authority says: issued, not reported lost or stolen, name and birth date match, address on file is Mill Street. Object good, facts good. Second question answered, both halves.

The secretary looks at the photograph on the licence and looks at Fatima. Same face. Third question answered — with one honest caveat that matters later: the secretary is not good at this, nobody is, and if Fatima had a sister the secretary might well have said yes to the sister.

Now the key. The secretary does not post it. She takes a key from the safe, writes key number 27 next to Fatima’s name in the register, hands it across the desk, and posts a short letter to Mill Street the same afternoon saying “a shed key was issued to you today; if this was not you, telephone the club”. The letter costs eighty pence and it is the cheapest fraud control the club owns, because it is the only one that works after the fact.

Total elapsed time: eleven minutes. Total cost: one telephone call, one stamp. What the club now has in its register is not “Fatima Noor: verified”. It is five separate facts: which person, which document, whether the document was genuine, whether the authority confirmed it, and how the face was checked. Anyone reading the register in five years can see exactly how much the club actually knows.

Where the plain version stops being true#

The secretary is trusting somebody else’s Monday#

The whole scheme rests on the licensing authority having done a good job years ago. The secretary is not checking Fatima’s identity. She is checking that a licensing authority once decided something, and borrowing that decision. If the authority was fooled in 2014, the secretary is being fooled today, politely, at second hand, with every check passing.

The honest version: identity proofing almost never establishes identity. It transfers confidence from an earlier decision made by somebody else, and the transfer is never lossless. What a document is and what it can carry is chapter 6’s material; here the point is only that the borrowing is where the confidence comes from.

Some people have no paper at all, through no fault#

The plain version assumes everybody has something in the middle or top pile. Enormous numbers of people do not. The World Bank’s Identification for Development programme estimated that as of 2024 around 800 million people worldwide had no official proof of identity, down from about 850 million in its 2021 estimate and just over a billion in 2017. Those people are not fraudsters. They are newborns, refugees, people whose records burned, people who never had a birth registered.

A system that says “no paper, no entry” is not secure; it is simply closed. Every serious enrolment standard therefore has a side door for people who cannot use the front one, and that side door is itself a fraud target, because it is the place where a human being is allowed to say “I believe you anyway”. The whole design problem of enrolment is that the door for the excluded and the door for the fraudster are the same door.

A perfect check on a person who does not exist#

The plain version assumes that behind the paper there is a person. Suppose there is not. Suppose somebody assembles a name that belongs to nobody, a birth date that belongs to nobody, and a national number that belongs to a real child too young to notice, and then spends two years making that combination appear in commercial databases — a mobile account here, a store credit account there. By year three, every check the secretary can perform comes back clean, because the databases she consults are exactly the databases the fraudster has been feeding.

This is synthetic identity fraud, and it defeats resolution, validation and verification all at once, without forging anything. There is no false document to detect. The face matches the face because the face is real; it just does not belong to the name.

The camera is not an eye#

When the applicant is remote, the secretary is not looking at a licence and a face. She is looking at a video stream, and a video stream is a file. The attacker’s job stops being “make a convincing fake licence” and becomes “make a convincing file”, which is a completely different and much cheaper problem.

There are two families of attack and the difference matters. A presentation attack puts a fake in front of a real camera: a printed photograph, a mask, a screen. An injection attack skips the camera entirely and feeds a synthetic stream into the software as if it came from a camera. Liveness detection, as normally sold, addresses the first. It does not by itself address the second at all, because there is nothing live to detect.

In August 2022 the Chaos Computer Club demonstrated this publicly. Martin Tschirsich showed that six different video identification services used for German electronic health records could be defeated using open source software and, as the club’s own write-up put it, a little red watercolour paint. The demonstration reached a test subject’s prescriptions, sick notes and treatment documents. Germany’s health IT authority, gematik, prohibited the use of video identification in its telematics infrastructure on the ninth of August 2022.

The honest version: “we checked a document and matched a selfie” is a statement about pixels, not about a person, unless you can also say where the pixels came from.

One check, one number, one truth — none of these hold#

Three more places the plain story is too clean.

The face comparison is not a yes or no. It is a similarity score against a threshold, and thresholds are chosen, not discovered. Choose it tight and you reject genuine people; choose it loose and you accept lookalikes. The secretary’s eye has the same property and no dial.

“Is this person already in the register” is not a lookup. At scale it is a statistical judgement with its own error rates, and treating it as exact manufactures both duplicate people and merged strangers. That is chapter 8, and it is a whole chapter for a reason.

And “verified” is not a fact you can store. It is a summary of five different findings of different strengths, at a particular moment, under a particular threat picture. A database column called identity_verified BOOLEAN is not a simplification. It is a deletion.

The technical version#

The three words, fixed#

The industry uses proofing, validation and verification almost interchangeably in marketing and precisely in standards. Fix the standards’ meanings now and the rest of the field becomes readable.

Identity proofing is the whole process by which an organization establishes that a claimed identity corresponds to a real person, and that the applicant in front of it is that person. It is the umbrella. In NIST SP 800-63A-4, Digital Identity Guidelines: Identity Proofing and Enrollment, published in final form on 31 July 2025, proofing has three named steps.

Resolution narrows the claim to one person. Section 2.3 of SP 800-63A-4 puts it as collecting “the minimum amount of identity evidence and attribute information that is needed for identity proofing and to distinguish a unique identity in the population served”. Two things are worth pausing on. It says minimum, which makes over-collection a defect and not diligence. And it says in the population served, which makes resolution relative: a birth date plus a surname may resolve uniquely in a company of 400 and resolve to 900 people nationally.

Validation is about the evidence and the attributes, not the person. Evidence validation determines that the evidence is authentic, meaning not forged or altered; accurate, meaning the information on it is correct; and valid, meaning unexpired or within the provider’s defined window. Attribute validation confirms the accuracy of the core attributes against an authoritative or credible source. A genuine document carrying a stale address passes the first and fails the second.

Verification is about the human. Section 2.5 of SP 800-63A-4: the goal “is to establish the linkage between the claimed validated identity and the real-life applicant engaged in the identity proofing process to a specified level of confidence”. Verification is the only step that touches the body.

Two further distinctions that get muddled in procurement documents. Proofing is not authentication. Proofing happens once, at the start, and produces a subscriber account. Authentication happens every time afterwards and proves control of an authenticator already bound to that account. And identity verification, in the marketing sense of “IDV vendor”, almost always means the entire proofing process, not the narrow third step. When a vendor says “we do verification”, ask which of the three they mean, and you will learn a great deal in ten seconds.

The European rules use a different carve-up for the same ground. The Commission Implementing Regulation (EU) 2015/1502 of 8 September 2015, which sets minimum technical specifications for assurance levels under Article 8(3) of Regulation (EU) 910/2014, treats “identity proofing and verification” as a single heading at section 2.1.2 of its Annex, and defines it by level rather than by step. The UK splits it five ways, and we come to that shortly.

Evidence strength: what earns a grade#

SP 800-63A-4 grades a piece of evidence FAIR, STRONG or SUPERIOR. Each grade is a conjunction: the evidence must meet all of the listed requirements to earn it. There is no partial credit and no averaging.

To be FAIR, evidence must satisfy every one of the following. There is a reasonable expectation that the issuing source confirmed the claimed identity by following formal procedures — the standard’s own examples are financial institutions operating under the Customer Identification Program rule, and the procedures for opening a mobile network account. The issuance process delivers the evidence to the person it relates to, by post, in person, or by a protected remote provisioning process. It contains the name of the claimed identity. It contains at least one reference number, a facial image or other biometric, or enough attributes to identify the person uniquely. It carries physical or digital security features that make it difficult to reproduce. Its core attributes can be validated against an authoritative or credible source. It can be validated by an approved method, and it can support the verification step.

STRONG adds three things and tightens one. The issuing source’s procedures must be written, and subject to recurring oversight by regulatory or publicly accountable institutions — the standard names states, the federal government and some regulated industries. The evidence must contain a reference number or other uniquely identifying attributes. And, no longer as an alternative but as a requirement, it must contain a facial image or other biometric characteristic of the person.

SUPERIOR adds cryptography and a body. The evidence must contain attributes and data objects that are cryptographically protected and can be validated using approved cryptography through verification of a digital signature applied by the issuing source. And the issuing source must have had the subject participate in an attended enrolment and identity proofing process that confirmed their physical existence.

Grade Face image Signed by issuer
FAIR Optional Not required
STRONG Required Not required
SUPERIOR Required Required

That table hides the criterion that actually does the work, which is not on the document at all: what the issuer did before printing it. FAIR borrows a commercial onboarding check. STRONG borrows a regulated, audited process. SUPERIOR borrows a process in which a human being physically turned up. A biometric passport is SUPERIOR because somebody stood at a counter years ago, not because it has a chip.

Two practical consequences. A paper driving licence with no chip can be STRONG. A mobile phone account, which is not a document at all, can be FAIR. And an employee badge with a photograph but no oversight of the issuing process is neither, however impressive it looks.

The grades are a standard, written down and testable. The mapping from a particular real document to a grade is a convention that each provider makes and should publish, because reasonable people disagree about, for example, whether a given country’s residence permit meets the oversight criterion.

One more thing about the grades. Every older textbook lists five of them, and the older text is still widely deployed, so it is worth being exact about what changed and when.

SP 800-63A revision 3, from June 2017 with errata in March 2020, had Table 5-1, “Strengths of Identity Evidence”, with five rows: UNACCEPTABLE, WEAK, FAIR, STRONG and SUPERIOR. WEAK meant, in that table, evidence whose issuing source did not perform identity proofing at all, which could reasonably be assumed to have reached the applicant, and which carried either a reference number or a photograph.

Revision 4 does not have a WEAK tier. Evidence either meets the full FAIR conjunction or it is not counted as evidence for the purposes of the identity assurance levels. This is not a softening. It removes a category that was routinely used to pad a file with items that proved nothing, and it makes the failure explicit: name the criterion the item fails, and stop describing it as weak evidence. As of August 2026, revision 3 language still appears in live contracts and audit reports, so when somebody says “weak evidence” the first question is which revision they are quoting.

Identity assurance levels, and what each one actually buys#

SP 800-63A-4 defines three identity assurance levels. The base volume, SP 800-63-4, describes IAL1 as supporting the real-world existence of the claimed identity with some assurance that the applicant is associated with it; IAL2 as requiring additional evidence and a more rigorous process for validating it and verifying the identity; and IAL3 as adding a trained proofing agent interacting directly with the applicant in an on-site attended session, plus the collection of at least one biometric.

The evidence requirements are precise.

Level Evidence required
IAL1 One FAIR that is digitally
validatable or has a face
image, or one STRONG, or
one SUPERIOR
IAL2 One FAIR and one STRONG,
or two STRONG, or one
SUPERIOR
IAL3 Same as IAL2, plus a
biometric sample collected
and retained

At all three levels the provider must collect all core attributes, including at least one government identifier, and validate them against an authoritative or credible source.

The verification requirements differ more sharply than the evidence requirements. At IAL1 the provider must verify ownership of one piece of evidence, by a confirmation code returned from a validated address, by an authentication and federation protocol at AAL2 and FAL2 or higher against an account related to the evidence, or by automated facial comparison. At IAL2 the provider must verify ownership of all pieces of presented evidence in unattended and remote flows, and revision 4 organizes the ways of doing that into three named pathways: the Non-Biometric Pathway, the Digital Evidence Pathway and the Biometric Pathway. Providers offering more than one pathway must record in the subscriber record which pathway was followed and make that available to relying parties, and where the Non-Biometric Pathway was used, must additionally record whether a mailed confirmation code or a visual comparison was the deciding step.

That recording requirement is the single most useful sentence in the document for anyone building a system. It means the standard itself refuses to accept “IAL2” as a sufficient description of what happened.

At IAL3 proofing may only be delivered on-site and attended. The proofing agent may be co-located with the applicant or may attend through a provider-controlled kiosk or device — which is how a national network of unstaffed booths can still count as attended.

Knowledge-based verification, demoted#

Anyone who has opened an account by telephone has met knowledge-based verification: which of these four streets have you lived on, what was your monthly payment on a loan you closed in 2016. For roughly two decades this was the backbone of remote proofing in the United States.

It is now, in the American federal standard, not a verification method at all. SP 800-63A-4 places knowledge-based verification inside fraud management, in the single sentence that providers “MAY employ KBV as part of its fraud management program”. It is a signal you may consider alongside device fingerprinting and address risk. It is not a way to establish that the applicant owns the evidence.

The reason is not subtle. Knowledge-based verification assumes the answers are known to the subject and not to anybody else, and that assumption died in public. The Office of Personnel Management breach disclosed in 2015 exposed background investigation records on 21.5 million people, including 5.6 million sets of fingerprints. The Equifax breach of 2017 exposed personal data on about 147 million people according to the Federal Trade Commission’s settlement announcement of July 2019. After those, the questions are not secrets; they are a purchasable dataset.

This is an area where practice lags the standard. As of August 2026, knowledge-based verification remains in production in many regulated sectors as a primary control, and vendors continue to sell it as such. The standard’s position and the market’s position are different, and saying so is more useful to a reader than pretending the argument is settled.

The same job under two other rulebooks#

The European approach under Implementing Regulation (EU) 2015/1502 is level-based rather than step-based. At assurance level low, the person must be shown to possess evidence recognized by the Member State representing the claimed identity, the evidence may be assumed genuine or checked to exist against an authoritative source, and an authoritative source must confirm the claimed identity exists. At substantial, the low requirements hold plus one of a set of alternatives, including that possession of recognized evidence is verified with checks on its genuineness, or that the procedure previously used achieved an equivalent result and was confirmed by a conformity assessment body. At high, the substantial requirements hold plus either verified possession of photographic or biometric evidence with a comparison against the person’s physical characteristics, or an equivalent prior procedure, or a national procedure for obtaining recognized photographic or biometric identification where the applicant does not hold such evidence. That last clause is the European answer to the bootstrap problem, written directly into the assurance rules.

The United Kingdom scores rather than levels. The guidance formerly and still colloquially known as GPG 45 was republished as How to check someone’s identity (1.0) on 3 March 2026 and last updated on 9 June 2026, issued by the Office for Digital Identities and Attributes and the Department for Science, Innovation and Technology. It accompanies the UK digital verification services trust framework 1.0, published 9 June 2026 and released as final on 10 June 2026 — the first revised statutory trust framework published under powers in the Data (Use and Access) Act 2025, with certification expected to become enforceable from 1 September 2026 and a UK CertifID trust mark for certified providers. The earlier UK digital identity and attributes trust framework gamma (0.4) remains certifiable alongside it as of August 2026.

The scoring has five parts, each scored separately.

Part of the check Score range
Strength of evidence 1 to 4
Validity of evidence 1 to 4
Activity history 1 to 4
Identity fraud check 1 to 3
Verification 1 to 4

A combination of scores is called a profile, and profiles map to four levels of confidence: low, medium, high and very high. Two real profiles, taken from the published identity profiles tables:

Check M1B H1B
Strength 3 3
Validity 2 3
Activity history 1 2
Identity fraud 2 1
Verification 2 3

Read those two columns side by side and you can see the British model’s distinctive move. Going from medium to high confidence with the same single piece of evidence does not require better evidence. It requires checking the evidence harder, checking the person harder, and finding more history — and it actually permits a lower fraud-check score, because the extra rigour elsewhere has taken over that job. Assurance is being treated as a budget that can be spent in different places.

The third part, activity history, has no counterpart in the NIST scheme and is the most interesting idea in the British guidance. It asks whether the claimed identity has left a trail over time: interactions over one year unauthenticated for score 1, up to rigorous checks under the Money Laundering Regulations or biometric verification over six months or more for score 4. A synthetic identity three months old cannot score on it. That is precisely what it is for.

Remote unattended proofing, component by component#

Remote unattended proofing — nobody watching, applicant alone with a phone — is the dominant form by volume and the hardest to secure. SP 800-63A-4 names four proofing types: remote unattended, remote attended, on-site unattended and on-site attended. Its blunt statement about the first is that “there are no additional requirements for remote unattended identity proofing beyond the requirements specified in Sec. 2, 3, and 4”, which sounds permissive until you read what sections 2 and 3 demand of the components.

Document capture and validation. Acceptable validation methods are visual and tactile inspection by trained personnel on-site, visual inspection by trained personnel remotely, automated document validation using appropriate technologies, and cryptographic verification of the source and integrity of digital evidence. For a chipped passport read over near-field communication, the fourth method applies and the document’s own signature does the work. For a photograph of a plastic card, the third applies, and you are asking a model to judge print quality, fonts, optically variable ink and layout from a compressed image taken in a kitchen.

Biometric comparison. If one-to-one comparison is used for verification against a claimed identity, the provider must meet a false match rate of 1 in 10,000 or better and a false non-match rate of 1 in 100 or better. If one-to-many identification is used to support resolution or deduplication, the false positive identification rate must be 1 in 1,000 or better, and tests demonstrating it must use a gallery no smaller than 90 per cent of the intended operational size.

Fairness. Biometric verification technologies must perform, for applicants of different demographic types, no more than 25 per cent worse than for the overall population, at a fixed threshold. The standard gives the arithmetic: if the false non-match rate for the whole population is 0.006, no demographic group may exceed 0.0075; if the false match rate is 0.0001, no group may exceed 0.000125. Demographic categories must include sex, age and skin tone where those affect performance. Testing must conform to ISO/IEC 19795-1:2021 and ISO/IEC 19795-10:2024, and results must be made publicly available.

Liveness. When collecting and comparing biometric characteristics remotely, the provider must implement presentation attack detection meeting an impostor attack presentation accept rate under 0.07, with testing conformant to ISO/IEC 30107-3:2023. Note what that number concedes: up to about one in fourteen well-built presentation attacks may be accepted by a conforming system. Liveness is a filter, not a wall.

Injection. Separately from liveness, the standard requires injection protection and modified media controls where video is used. This is the attack class the Chaos Computer Club demonstrated in 2022, and it is handled by different machinery entirely: attested capture on the device, signed frames, sensor-level checks, session integrity. A system with excellent liveness and no injection protection is defended against the attacker who holds a mask up to a phone and undefended against the attacker who never holds anything up to anything.

Independent testing exists for parts of this. The FIDO Alliance launched its Face Verification Certification programme on 29 May 2024, testing remote biometric identity verification for accuracy, liveness and bias across skin tone, age and gender with a minimum of 10,000 tests; it sits alongside the Alliance’s Document Authenticity certification programme. Certification of a component is an established fact about that component. That a certified component makes a deployment safe is a marketing claim, because the deployment includes the channel, the device and the operator.

Metric Threshold in 800-63A-4
False match, 1:1 1 in 10,000 or better
False non-match, 1:1 1 in 100 or better
False positive ID, 1:N 1 in 1,000 or better
Liveness, IAPAR under 0.07

Attended proofing, the humans in it, and the side door#

The attended forms put a trained person in the loop, and the standard is specific about what that person must be able to do.

In a remote attended session — live video with a proofing agent — the applicant must remain in view of the agent during each step, and the video quality must be sufficient to support inspection of evidence and comparison of the applicant against it. The agent must be trained to identify signs of manipulation, coercion or social engineering during the session. That last requirement is aimed at a specific and growing harm: the applicant who is genuinely who they say they are, holding their own genuine document, while somebody off camera is telling them what to do.

On-site attended sessions add physical controls: the provider must supply the physical setting, and devices must be protected by baseline security features comparable to FISMA moderate controls, including malware protection, administrator-specific access controls and software update processes. When biometrics are collected on-site, the operator must view the biometric source — fingers, face — for unexpected non-natural materials as part of the process.

Anyone performing visual facial image comparison, whether proofing agent or trusted referee, must be trained in it, assessed on it, reassessed annually, and remedially trained if needed. The standard requires the training to reflect real attack scenarios including comparison against images of relatives, twins and people of similar appearance. Providers must give remote agents high-quality image feeds, high-definition monitors and image analysis software. This is a proper corrective to a common assumption. Untrained humans are poor at unfamiliar face matching, and the standard treats the skill as one that must be taught and re-tested rather than assumed.

The standard also assumes the humans themselves are an attack surface. Providers must implement insider threat controls to detect and prevent collusion involving representatives directly involved in, or able to intervene in, proofing processes or decisions.

That brings us to the side door, which in SP 800-63A-4 has two forms that get confused constantly and are not the same thing at all.

A trusted referee is an agent of the provider, trained and certified to make risk-based decisions that let applicants be proofed successfully given their circumstances. The standard’s own list of who may need one is worth reading in full because it defines the design problem: people who do not possess and cannot obtain the required evidence, persons with disabilities, older individuals, persons experiencing homelessness, individuals with limited access to online services or devices, persons without a bank account or with limited credit history, victims of identity theft, individuals displaced or affected by natural disasters, and children under eighteen.

Trusted referee training must cover document identification and validation, indicators of fraudulent documents, facial image comparison, indicators of social engineering such as distress, confusion or coercion, and an annual review of the referee’s abilities. Providers must publicize the availability of the service, and must record for every session involving a referee: why the referee was used, who the referee was, what evidence was presented, which processes were completed, and the referee’s decision with a rationale if negative.

Providers should offer referees for failures of automated verification such as biometric comparison, and for failures of automated validation such as mismatched attributes or absence from a record source; and should offer them to applicants who fail fraud checks in unattended remote processes, with a summary of the failure given to the referee so the decision is informed.

An applicant reference is not an agent of the provider. It is a person on the applicant’s side who vouches for the applicant’s identity, attributes or circumstances where other evidence, validation and verification are not available. The critical rule is that the reference must themselves have been identity-proofed to the same identity assurance level or higher. A voucher who was never proofed adds nothing but a name to blame.

The distinction is worth holding firmly. A trusted referee takes responsibility on behalf of the system. An applicant reference lends credibility on behalf of the applicant. Systems that let applicants supply their own referees have accidentally built the second while believing they built the first, and that is how vouching schemes get farmed.

The bootstrap problem, and four real answers#

The bootstrap problem is the oldest thing in this field: to obtain the credential that proves your identity, you must prove your identity. Any system that only accepts strong prior credentials has defined a closed set that can never grow, and the only people it admits are people another system already admitted.

Every large system has had to answer it. Four real answers:

  1. Enrol at birth, before the problem exists. The United States Social Security Administration began assigning nine-digit numbers in 1936; its Enumeration at Birth programme, which lets a parent request a number as part of birth registration in the hospital, has issued numbers to newborns since 1987. The identity is created before anybody could be impersonating anybody, and the evidence chain starts at the hospital rather than at the applicant.
  2. Let a proofed person vouch. Under the Aadhaar (Enrolment and Update) Regulations, 2016, a resident of India who cannot provide documentary proof of identity or address may be enrolled through a pre-registered introducer, or through head-of-family based enrolment where the applicant’s name appears in a family document. India’s programme began with the first Aadhaar number issued on 29 September 2010 to Ranjana Sonawane of Tembhli, in Nandurbar district, Maharashtra.
  3. Write the exception into the assurance rules. Implementing Regulation (EU) 2015/1502 permits assurance level high to be reached, where the applicant does not hold recognized photographic or biometric identification evidence, by applying national procedures that lead to obtaining it.
  4. Substitute history for documents. The British scoring model lets activity history — a demonstrable trail of interactions over months or years — carry part of the load that a document would otherwise carry, so that a person with a thin document file but a thick history can still reach a usable profile.

Each answer moves the fraud rather than removing it. Enrolment at birth moves it to the hospital form. Vouching moves it to the voucher. National exception procedures move it to whoever staffs them. History moves it to whoever can manufacture history, which is exactly what a patient synthetic identity operator does. There is no answer that keeps the door open for the excluded and shut to the determined; there are only answers that put the remaining risk somewhere you can watch it.

The frauds that live at the enrolment counter#

Five distinct attacks, which need distinct controls.

Breeder document fraud. Obtain a genuine foundational record for a person other than yourself, then use it to obtain everything else. The canonical form is named after Frederick Forsyth’s 1971 novel The Day of the Jackal: find a child who died young, request their birth certificate, use it to apply for a passport in that name. A 1997 to 1998 House of Commons Social Security Committee session recorded the technique by that name in evidence. In the United Kingdom the loophole remained open until 2007. The control is not better document inspection, because the document is real. The control is linking the registers, so that a birth record which has a death record attached cannot be used to breed anything.

Fraudulent breeding of a genuine credential. Feed a true but irrelevant fact into an issuing process to obtain a genuine credential under a name you control. The 9/11 Commission staff monograph 9/11 and Terrorist Travel, published in 2004, documents this precisely: several of the hijackers obtained genuine Virginia identification cards using falsely certified residency. The report cites Virginia Department of Motor Vehicles residency form DL51 for Ziad Jarrah, with residency certified by Hani Hanjour on 29 August 2001, and Hanjour using an address he had himself fraudulently obtained on 1 August 2001. Every document produced at the end of that chain was genuine. The failure was that one weakly-checked attribute, residency, was accepted as a sufficient basis for issuing a strong credential.

Synthetic identity creation. The Federal Reserve convened a focus group of twelve fraud experts which recommended this definition: synthetic identity fraud is “the use of a combination of personally identifiable information (PII) to fabricate a person or entity in order to commit a dishonest act for personal or financial gain”. The Federal Reserve had published a white paper on synthetic identity payments fraud on 9 July 2019, describing a synthetic identity as created by combining real information, such as a legitimate Social Security number, with fictional information such as a made-up name, address or birth date.

The mechanics are visible in the United States Department of Justice case announced on 5 February 2013, in which eighteen people were charged in a scheme with more than 200 million dollars in confirmed losses. The Justice Department described three stages. First, “make up” the identities, by creating fraudulent identification documents and a fraudulent credit profile with the major credit bureaus. Second, “pump up” the credit, by feeding false information to the bureaus until the false identity had excellent credit. Third, “run up” large loans, since the higher the fraudulent score, the larger the loan. The ring created over 7,000 false identities, obtained tens of thousands of credit cards, and maintained more than 1,800 drop addresses.

Read that as an enrolment problem rather than a credit problem and the lesson is sharp. The fraudsters were not defeating identity checks. They were supplying the sources that later identity checks would consult. An attacker with a three-year horizon does not forge your evidence; they become your authoritative source.

Two controls bite earliest. A death records check, which SP 800-63A-4 makes mandatory — providers “SHALL implement a death records check for all identity proofing processes”, noting that it aids in preventing synthetic identity fraud, use of stolen identity information, and exploitation by a close associate or relative. And an age-of-record or tenure check: how long has this attribute combination existed, and does its history predate the moment somebody would have needed it to exist. The Social Security Administration’s move to randomized number assignment on 25 June 2011 was partly a response to the same family of attacks, since the older geographic and sequential structure let an attacker infer whether a number was plausible for a claimed birth date and place.

Channel and media attacks. Injection of synthetic video, replay of captured sessions, and use of stolen sessions. Countered by injection protection, device attestation and channel analysis. SP 800-63A-4 requires providers to analyse all remote proofing communication channels for high-risk indicators such as blocklisted proxies and addresses.

Coercion and collusion. The applicant is real and present but not acting freely, or the operator is complicit. Countered by agent training in social engineering indicators, and by insider threat controls.

The standard’s recommended fraud checks are worth listing because they are cheap and rarely all present: SIM swap detection, to confirm the phone number has not recently been ported to a new user or device; device or account tenure checks; mailing address checks for virtual post office boxes and other high-risk characteristics; device fingerprinting against scaled attacks and enrolment duplication; and transaction analytics on addresses, geolocations and velocities.

One requirement guards a subtle leak: providers must take measures to prevent unsuccessful applicants from inferring the accuracy of any self-asserted information against what was confirmed by authoritative sources. An enrolment form that says “that date of birth does not match our records” is a free oracle for testing stolen data.

Binding: attaching an authenticator to a proven identity#

Proofing produces a proven identity. Binding attaches the thing that will represent it. In SP 800-63A-4 this is initial authenticator binding, with the detailed authenticator rules in SP 800-63B-4 section 4.1.2.1 and subscriber account requirements in SP 800-63A-4 section 5.

The permitted methods are three: remote enrolment of a subscriber-provided authenticator consistent with the requirements for that authenticator type; distribution of a physical authenticator to a validated address; or distribution or on-site enrolment of an authenticator. Providers should encourage subscribers to bind at least two separate means of authentication, to reduce later account recovery, which is the weakest moment in the life of an account and a chapter of its own later in this book.

The rule that carries the most weight is the one about gaps. If authenticators are bound outside a single protected session with the user, the provider must confirm the presence of the intended subscriber by return of a continuation code, or by comparison against a biometric collected at the time of proofing. In other words: if proofing and binding are separated in time, you must re-establish the link, and you may do it with a secret you gave the applicant or with their face, but not with an assumption.

Two kinds of code appear, and they are not interchangeable.

A confirmation code proves that the applicant can receive something at an address associated with the evidence. It must include at least 6 decimal digits or equivalent from an approved random bit generator, and may be presented as text for manual entry, as a secure link containing a representation of the code, or as a machine-readable optical label such as a QR code. It must be invalidated on use.

Delivery channel Maximum validity
Postal, contiguous US 21 days
Postal, outside that 30 days
SMS or voice call 10 minutes
Email 24 hours

A continuation code re-establishes a link to an incomplete proofing session — for example when an applicant starts remotely and finishes on-site. It must include at least 64 bits from an approved random bit generator, be stored hashed using a FIPS-approved or NIST-recommended one-way function, be subject to throttling on verification, and be invalidated on use. It should be delivered in-session but may be sent out of band.

The asymmetry between six digits and sixty-four bits is the whole design. A confirmation code is protected by the difficulty of intercepting post or a phone; a continuation code is a bearer secret that travels with the applicant and must survive on its own.

Finally, and cheaply: on successful proofing the provider must send a notification of proofing to a validated address, and at IAL2 should send it to the applicant’s postal address. That is the club secretary’s eighty-pence letter, written into a federal standard. It does not prevent the fraud. It is how the victim finds out.

The standard is honest about the residual risk of the postal route. Mailed confirmation codes deter scaled, high-volume attacks and hurt the attacker’s time-to-value, which is why they remain viable at IAL2 when biometrics or visual comparison fail. But they “remain vulnerable to interception by close associates and family members and to other schemes (e.g., mail-forwarding fraud)”. Enrolment controls that assume the attacker is a stranger will always be weakest against the attacker who lives in the house.

The worked flow, end to end#

Fatima Noor from the plain version now enrols with a credential service provider for access to a government service that requires IAL2. She starts on her phone at 09:14 on 4 March. Follow every branch.

START (remote unattended)
  |
  v
[1] Collect claimed attributes
    name, DOB 1991-07-11, address, gov ID
  |
  v
[2] RESOLUTION: unique in population?
    yes -> [3]
    no  -> ask for one more attribute
           still ambiguous -> refer to ch 8
  |
  v
[3] Collect evidence
    passport chip (SUPERIOR) ......... captured
    OR licence (STRONG) + MNO (FAIR)
  |
  v
[4] VALIDATION a: is the evidence genuine?
    chip: verify issuer signature
    card: automated document scan
    fail -> retry once -> then [F1]
  |
  v
[5] VALIDATION b: are the attributes true?
    query authoritative source per attribute
    partial mismatch -> [F2]
  |
  v
[6] FRAUD CHECKS (mandatory + advised)
    death record check  ..... mandatory
    SIM swap, tenure, address, device
    fail -> [F3]
  |
  v
[7] VERIFICATION: is this her?
    biometric pathway: 1:1 face match
    live capture + PAD (IAPAR under 0.07)
    + injection protection
    match -> [8]
    no match -> [F4]
  |
  v
[8] Create subscriber account, record
    pathway used and every finding
  |
  v
[9] BINDING: enrol a passkey in session
    if out of session -> continuation code
                      or biometric compare
  |
  v
[10] Notify: proofing notice to postal
     address; account created
  |
  v
DONE (IAL2)

The failure branches are the design, not the exception.

[F1] Evidence not validated
     -> offer second evidence type
     -> offer remote attended session
     -> trusted referee reviews document
     -> if still no: decline, log reason,
        give redress route

[F2] Attribute mismatch (e.g. address)
     -> trusted referee reviews additional
        evidence for a recent move or
        name change
     -> corroborate against strongest
        evidence held
     -> resolve or decline with reason

[F3] Fraud check failure
     -> SHOULD route to trusted referee
     -> referee gets a summary of the
        failure, not just a red light
     -> never reveal which check failed
        to the applicant

[F4] Biometric no-match
     -> retry with guidance
     -> visual comparison by trained agent
        (remote attended or asynchronous
        with PAD + document presence)
     -> or non-biometric pathway: mailed
        confirmation code to validated
        postal address, 21 days
     -> or applicant reference, proofed at
        IAL2 or higher

Now the numbers for Fatima’s actual run. She presents a chipped passport, read over near-field communication. The chip’s signature verifies against the issuing country’s certificate, so the evidence is SUPERIOR and one piece suffices for IAL2. Her core attributes are validated against the authoritative source; her address does not match, because she moved in January. That is branch F2, and a trusted referee reviews a tenancy agreement dated 12 January 2026 as corroborating evidence for the change, records the rationale, and continues.

Verification runs on the biometric pathway. Her live capture is compared one-to-one against the facial image in the chip. The system operates at a false match rate of 1 in 10,000 and a false non-match rate of 1 in 100, so roughly one genuine applicant in a hundred will be rejected on first attempt for reasons that have nothing to do with fraud. Fatima is that one, on the first capture, because of backlighting. She retries and passes.

Binding happens in the same session: she creates a passkey on her phone. Because binding is in-session, no continuation code is needed. She is prompted to add a second authenticator and adds a security key. A notification of proofing goes to her postal address that evening.

What the provider stores is not a flag.

{
  "subject_id": "b1f0-4a77-9c2e",
  "ial": "IAL2",
  "proofing_type": "remote_unattended",
  "pathway": "biometric",
  "evidence": [
    { "type": "epassport",
      "strength": "SUPERIOR",
      "validation": "issuer_signature_ok",
      "captured": "2026-03-04T09:17Z" }
  ],
  "attributes_validated": {
    "name": "authoritative_source_match",
    "dob": "authoritative_source_match",
    "address": "referee_corroborated"
  },
  "verification": {
    "method": "face_1to1",
    "attempts": 2,
    "pad": "iso_30107_3_2023",
    "injection_controls": true
  },
  "fraud_checks": {
    "death_record": "clear",
    "sim_swap": "clear",
    "address_risk": "clear",
    "device": "new_device"
  },
  "exception": {
    "type": "trusted_referee",
    "reason": "address_mismatch_recent_move",
    "referee_id": "TR-0198",
    "evidence_reviewed": "tenancy_2026-01-12"
  },
  "binding": [
    { "authenticator": "passkey",
      "bound_in_session": true },
    { "authenticator": "security_key",
      "bound_in_session": true }
  ],
  "notification_sent": "postal",
  "completed": "2026-03-04T09:31Z"
}

Seventeen minutes. Every finding separately recorded, every exception named with its rationale, the pathway declared as the standard requires, and enough detail that a fraud investigator in 2031 can reconstruct exactly what was and was not established on 4 March 2026.

Compare that with what most systems store, which is one column reading true. When the fraud surfaces three years later, the investigator asks “how was this identity established” and the honest answer from that column is “we do not know”. Enrolment records are written once and read under pressure. Write them for the reader who is angry.

What real enrolments actually fail on#

Standards describe the good path. Deployment data describes the real one, and the two are worth holding together.

The United Kingdom’s inclusion monitoring report on digital identity services, covering a survey of 54 certified services of which 47 had live services, run from February to April 2025, asked services why checks were unsuccessful. Among the 79 per cent of services that tracked reasons, 60 per cent cited a lack of necessary identity evidence, about 34 per cent cited technology failure, about 34 per cent cited inaccurate information, and 34 per cent cited suspicion of fraud. Two-thirds of services collected drop-out data, and the most common reason given for abandonment was a lack of understanding of how to complete the process.

The largest single cause of failure is not fraud and not fraud detection. It is people who do not have the evidence, followed by people who did not understand the instructions.

There is a matching lesson in the history of government schemes. The United Kingdom’s GOV.UK Verify programme forecast in 2016 that 25 million people would use it by 2020; by February 2019, according to the National Audit Office’s report Investigation into Verify, published on 5 March 2019, 3.6 million people had signed up. Many causes contributed, but a persistent one was that a large share of the population simply could not complete the proofing checks with the evidence they had.

Two design conclusions follow, and they are the practical payload of this chapter. First, an enrolment funnel must be instrumented at every branch, because the branch that loses most people is almost never the one the designers expected. Second, the exception paths — trusted referee, applicant reference, postal confirmation — are not charity. They are the majority path for the minority of users who most need the service, and building them badly is the most common way an identity system fails at its actual job while passing its audit.

7.98 Common wrong ideas#

Wrong: Identity verification means checking who somebody is. Right: In the standards, verification is only the third step — linking the applicant to an already-validated identity. The whole process is identity proofing, and it also contains resolution, which narrows the claim to one person, and validation, which checks the evidence and its attributes. A vendor selling “verification” is usually selling all three, and asking which one they mean will tell you what they actually test.

Wrong: A genuine, unexpired document proves the person is who they say they are. Right: A genuine document proves an issuer once made a decision and that this object records it. It says nothing about who is holding it. That is why every framework has a separate verification step that compares the person against the evidence, and why documents alone never satisfy any assurance level above the lowest.

Wrong: More documents means stronger proofing. Right: Strength is a conjunction of qualities, not a count. Under NIST SP 800-63A-4, IAL2 needs one FAIR plus one STRONG, or two STRONG, or one SUPERIOR. Five items that each fail the FAIR criteria are not evidence at all, and in revision 4 there is no WEAK tier to file them under.

Wrong: Liveness detection stops deepfakes. Right: Presentation attack detection addresses fakes held in front of a real camera, and SP 800-63A-4 permits an impostor attack presentation accept rate up to 0.07, so roughly one in fourteen good attacks may pass. Synthetic video fed directly into the software bypasses the camera entirely and is countered by injection protection, device attestation and channel integrity, which are separate controls that must be specified separately.

Wrong: Knowledge-based questions are a reasonable way to verify a remote applicant. Right: SP 800-63A-4 places knowledge-based verification inside fraud management rather than among verification methods. After the 2015 Office of Personnel Management breach affecting 21.5 million people and the 2017 Equifax breach affecting about 147 million, the answers are widely held data rather than shared secrets. They may contribute a risk signal; they cannot carry the verification step.

Wrong: Once identity is proven, issuing the credential is administrative. Right: Binding is a distinct step with its own failures. If it happens outside the proofing session, SP 800-63A-4 requires the provider to re-confirm the subscriber’s presence by a continuation code of at least 64 bits or by comparison against a biometric captured at proofing, and confirmation codes have hard lifetimes of 10 minutes by phone, 24 hours by email and 21 days by post within the contiguous United States.

Wrong: Vouching schemes are a soft option that weakens security. Right: They are mandatory in every serious framework because roughly 800 million people worldwide had no official identity as of the World Bank’s 2024 estimate. The security question is not whether to have them but which kind: a trusted referee is a trained, certified agent of the provider whose decisions are recorded with a rationale, while an applicant reference is the applicant’s own voucher and must themselves have been proofed to the same assurance level or higher.

Wrong: Synthetic identity fraud is caught by better document checking. Right: There is usually no false document. The attacker builds a record that real sources will later confirm, as in the United States Department of Justice case announced on 5 February 2013 involving over 7,000 invented identities and more than 200 million dollars in losses. The controls that bite are the mandatory death records check, tenure and history checks that ask how long the identity has existed, and one-to-many biometric deduplication.

Wrong: The enrolment record should store whether the person was verified. Right: It should store what was found: which pathway was used, which evidence at which strength, how each attribute was validated, how verification was performed and with how many attempts, which fraud checks ran, and any exception with the referee’s identity and rationale. SP 800-63A-4 itself requires providers offering multiple IAL2 pathways to record which pathway was followed and disclose it to relying parties.

Wrong: Most enrolment failures are attempted fraud. Right: In the United Kingdom’s 2025 inclusion monitoring survey of 54 certified services, 60 per cent of services that tracked reasons cited a lack of necessary identity evidence as a cause of unsuccessful checks, against 34 per cent citing suspicion of fraud. The most common reason for abandonment was not understanding how to complete the process.

7.99 Chapter summary in 20 lines#

  1. Enrolment is the moment a system decides a new person exists, and it is the moment that determines the value of everything the system does afterwards.
  2. Identity proofing is the umbrella process, and it contains three named steps that fail independently: resolution, validation and verification.
  3. Resolution narrows a claim to exactly one person in the population served, using the minimum information needed to do so.
  4. Validation has two halves: proving the evidence is genuine, and proving that the attributes on it are true according to an authoritative or credible source.
  5. Verification is the only step that touches the human being, and it links the validated identity to the applicant actually present.
  6. NIST SP 800-63A-4, published in final form on 31 July 2025, grades evidence FAIR, STRONG or SUPERIOR, and each grade is a conjunction of requirements with no partial credit.
  7. The criterion doing most of the work is invisible on the document itself: what the issuer did before printing it.
  8. Revision 4 abolished the WEAK tier that revision 3 defined in Table 5-1, so evidence now either meets FAIR in full or does not count.
  9. IAL1 needs one qualifying piece of evidence, IAL2 needs one FAIR plus one STRONG or two STRONG or one SUPERIOR, and IAL3 adds an on-site attended session with a biometric collected and retained.
  10. Knowledge-based verification has been demoted from a verification method to a fraud signal, because the answers became public data after the 2015 OPM and 2017 Equifax breaches.
  11. Remote unattended proofing must meet hard numbers: false match rate 1 in 10,000, false non-match rate 1 in 100, false positive identification rate 1 in 1,000, and liveness with an impostor attack presentation accept rate under 0.07.
  12. Presentation attacks and injection attacks are different problems and need different controls, as the Chaos Computer Club’s August 2022 demonstration against six video identification services showed.
  13. Attended proofing puts a trained agent in the loop, and the standard requires that agent to be trained, assessed and reassessed annually on facial comparison and on detecting coercion.
  14. A trusted referee is a trained agent of the provider who may rescue specific documented failures, while an applicant reference is the applicant’s own voucher and must be proofed to the same level or higher.
  15. The bootstrap problem is unavoidable, and real answers include enrolment at birth, introducer and head-of-family enrolment, national exception procedures under the European rules, and substituting activity history for documents in the British model.
  16. Breeder document fraud uses a genuine record belonging to somebody else, and is defeated by linking registers rather than by inspecting documents harder.
  17. Synthetic identity fraud invents a person and then feeds the very sources that later checks will consult, which is why the mandatory death records check and tenure checks matter more than document forensics.
  18. Binding is a separate act from proofing, and when the two are separated in time the standard requires a continuation code of at least 64 bits or a biometric comparison to close the gap.
  19. Confirmation codes have fixed maximum lifetimes of 10 minutes by phone, 24 hours by email, 21 days by post within the contiguous United States and 30 days beyond it, and a notification of proofing must be sent on success.
  20. Most enrolment failures are not fraud but missing evidence and confusion, so the exception paths are the majority path for the people who most need the service and must be designed first, not last.

Chapter sources: NIST Special Publication 800-63A-4, Digital Identity Guidelines: Identity Proofing and Enrollment, final publication dated 31 July 2025, superseding SP 800-63A of March 2020, in particular section 2.3 on identity resolution, section 2.4 on evidence and attribute validation with the FAIR, STRONG and SUPERIOR requirement lists, section 2.5 on identity verification, the fraud management requirements including the mandatory death records check, the biometric performance thresholds of 1:10,000 false match, 1:100 false non-match and 1:1,000 false positive identification with demographic performance within 25 per cent of the overall population, the presentation attack detection requirement of IAPAR under 0.07 conformant to ISO/IEC 30107-3:2023, the biometric testing requirements under ISO/IEC 19795-1:2021 and ISO/IEC 19795-10:2024, the confirmation code lifetimes of 21 days, 30 days, 10 minutes and 24 hours, the 64-bit continuation code requirements, the trusted referee and applicant reference requirements, the four proofing types, and the IAL1, IAL2 and IAL3 requirements including the Non-Biometric, Digital Evidence and Biometric verification pathways; NIST Special Publication 800-63-4 for the assurance level descriptions and the distinction between proofing and authentication, and SP 800-63B-4 section 4.1.2.1 for authenticator binding; NIST Special Publication 800-63A revision 3, June 2017 with errata March 2020, Table 5-1 Strengths of Identity Evidence, for the superseded five-tier scale including WEAK; Commission Implementing Regulation (EU) 2015/1502 of 8 September 2015 on minimum technical specifications and procedures for assurance levels for electronic identification means pursuant to Article 8(3) of Regulation (EU) 910/2014, Annex section 2.1.2 on identity proofing and verification at levels low, substantial and high; Regulation (EU) 2024/1183 amending Regulation (EU) 910/2014, in force 20 May 2024, under which Member States must make a European Digital Identity Wallet available by the end of 2026; the UK digital verification services trust framework 1.0, published 9 June 2026 and released as final on 10 June 2026 under powers in the Data (Use and Access) Act 2025, together with How to check someone’s identity (1.0), the successor to GPG 45, published 3 March 2026 and last updated 9 June 2026 by the Office for Digital Identities and Attributes and the Department for Science, Innovation and Technology, including the five-part scoring scheme and the identity profiles M1B and H1B; the UK digital identity and attributes trust framework gamma (0.4); the Office for Digital Identities and Attributes inclusion monitoring report findings 2025, surveying 54 certified services from February to April 2025; the National Audit Office report Investigation into Verify, published 5 March 2019, recording the 2016 forecast of 25 million users by 2020 against 3.6 million by February 2019; the World Bank Identification for Development global dataset estimate of about 800 million people without official identification as of 2024, down from about 850 million in 2021; the Federal Reserve white paper on synthetic identity payments fraud of 9 July 2019 and the industry-recommended definition of synthetic identity fraud developed by a Federal Reserve focus group of twelve fraud experts; the United States Department of Justice press release of 5 February 2013, Eighteen People Charged in International 200 Million Dollar Credit Card Fraud Scam, describing over 7,000 false identities and more than 1,800 drop addresses; the 9/11 Commission staff monograph 9/11 and Terrorist Travel, 2004, including Virginia Department of Motor Vehicles residency form DL51 for Ziad Jarrah certified 29 August 2001; the Chaos Computer Club publication of 10 August 2022 by Martin Tschirsich on defeating six video identification services, and gematik’s prohibition of video identification in the German telematics infrastructure on 9 August 2022; the Social Security Administration on the introduction of the nine-digit number in 1936, the Enumeration at Birth programme issuing numbers to newborns since 1987, and Social Security number randomization implemented on 25 June 2011; the Aadhaar (Enrolment and Update) Regulations, 2016, on introducer-based and head-of-family based enrolment, and the first Aadhaar number issued on 29 September 2010 to Ranjana Sonawane of Tembhli, Nandurbar district, Maharashtra; the FIDO Alliance Face Verification Certification programme launched 29 May 2024 and its Document Authenticity certification programme; the Federal Trade Commission settlement announcement of July 2019 recording about 147 million people affected by the 2017 Equifax breach, and the United States Office of Personnel Management disclosures of 2015 covering 21.5 million background investigation records including 5.6 million sets of fingerprints; and Frederick Forsyth’s The Day of the Jackal, 1971, for the fraud technique that carries its name and which remained an open loophole in the United Kingdom until 2007.