Identity and Authentication Assurance Levels
NIST Digital Identity Guidelines define Identity Assurance Levels (IAL) and Authenticator Assurance Levels (AAL) to ensure secure identity verification at enrollment and login, with IAL2 requiring government ID validation and record checks for initial proofing, and AAL2 mandating multi-factor authentication combining knowledge, possession, or biometric factors to protect user data and reduce fraud.
The short answer: NIST (National Institute of Standards and Technology) Digital Identity Guidelines define assurance levels that determine how confidently a platform can verify who someone is — both at enrollment (IAL) and at login (AAL). Proof uses these frameworks to meet compliance requirements, reduce fraud, and protect user data.
IAL and AAL work together as part of a layered security approach:
- Identity Assurance Levels (IAL) focus on how confidently an organization can verify a person is who they claim to be during initial enrollment.
- Authenticator Assurance Levels (AAL) determine how securely users prove their identity during subsequent logins.
IAL2 — Identity Assurance Level 2
IAL2 is the middle of three identity proofing levels and strikes a good balance between strong protection and user convenience. To be IAL2-compliant, a platform must do both of the following:
- Validate a government-issued photo ID.
- Confirm the authenticity of identifying information through record checks.
Businesses, title agents, and lenders can choose IAL2-compliant identity verification when creating certain transactions. An IAL2-compliant identity verification transaction on the Proof platform includes knowledge-based authentication, credential analysis of a primary ID, and selfie comparison.
Learn more about how to create transactions that use IAL2 identity verification:
- Send a transaction for eSignature
- Create an Identify transaction
- Complete a Certify transaction
AAL2 — Authenticator Assurance Level 2
AAL2 is the middle of three levels that determine how users prove their identity at login. To be AAL2-compliant, a platform must use multi-factor authentication (MFA) — requiring users to provide two different types of verification.
Users must provide #1 and either #2 or #3 from the list below:
- 1.Something they know (like a password)
- 2.Something they have (like a security key)
- 3.Something they are (like a fingerprint)
AAL2 significantly reduces the risk of account takeovers and unauthorized access compared to single-factor methods, making it essential for protecting valuable data and transactions.
Summary Checklist
- IAL2 requires validating a government-issued photo ID and confirming identity through record checks.
- IAL2 on Proof includes KBA, credential analysis, and selfie comparison.
- AAL2 requires MFA: a password plus a security key or biometric.
Still unsure? Contact Proof Support for help.
Related
Evolving Identity Verification: From KBA to Biometrics
The article discusses the transition in identity verification from Knowledge-Based Authentication (KBA), which relies on personal historical data and security questions, to biometric facial comparison that verifies real-time physical presence by matching live selfies to government IDs, highlighting biometrics' superior accuracy, enhanced security against fraud, inclusivity for users without extensive credit histories, regulatory compliance with NIST standards, and the effectiveness of combining both methods for robust identity proofing.
Capture Selfie Photos for Identity Verification – Proof Help Center
The Proof Help Center explains that Selfie Comparison, an IAL2-compliant biometric verification method, securely verifies a signer's identity by automatically capturing real-time selfies and comparing them to their government-issued ID photos, with guidance on proper lighting, removing accessories, and using a smartphone to ensure clear images, and includes steps like centering the face and looking left and right for enhanced verification, serving as a primary or secondary identity check during the signing process.
What is NIST IAL2 identity verification? | Proof
NIST Identity Assurance Level 2 (IAL2), defined in Special Publication 800-63, is a government standard that requires verifying the real-world existence of an identity and confirming the applicant as its rightful owner, providing a high degree of confidence suitable for remote digital transactions and widely adopted by federal agencies, private businesses, and state and local governments as a practical and robust identity verification method.
How Financial Institutions Can Keep Customers Safe with Authentication
The article emphasizes that financial institutions must implement strong, layered, and biometric-based authentication methods—moving toward passwordless solutions and combining identity verification with fraud intelligence platforms like Proof—to effectively combat rising threats such as account takeover, credential stuffing, and SIM-swapping, thereby protecting customer assets, maintaining trust, and ensuring regulatory compliance.
Why Fraud Prevention is Key to the Auto Market | Proof
The article emphasizes that as the auto market rapidly shifts from paper to digital documents, implementing NIST IAL2-compliant identity proofing and robust fraud prevention measures is crucial to combat rising risks of odometer and title fraud, meet regulatory requirements, reduce costs, ensure legal compliance, and enable secure remote operations for dealerships and lenders.
Identity Verification Overview – Proof Help Center
Proof's identity verification for notarizations varies by notary commission state and transaction type, offering four methods: IAL2-compliant verification (credential analysis plus selfie comparison), multi-step verification (combining knowledge-based authentication, credential analysis, and/or selfie comparison), personal knowledge of identity (notary personally knows the signer), and credible identifying witness (a verified witness vouches for the signer).