Identity Proofing and Biometrics
Review status: This foundation page requires specialist review before public approval. Its claims must remain within the scope stated here.
Identity proofing establishes the evidence used before an issuer creates a high-value credential or an institution approves a sensitive identity action. It asks whether the person and source evidence have been evaluated to the assurance level required for the purpose.
Biometrics can strengthen a proofing process, but they are sensitive personal data and are not treated as a universal answer. Their use must be necessary, proportionate, protected, purpose-bound, and governed for the relevant jurisdiction and sector.
Proofing is not authentication
The terms are related but distinct:
- Identity proofing establishes evidence about who a person is or whether an attribute is valid.
- Authentication confirms control of an approved authenticator or session.
- Credential issuance converts approved claims into a signed artifact.
- Verification evaluates a presented credential against policy.
- Authorization decides whether an operation is allowed.
A person may authenticate strongly to an account that was originally enrolled with poor evidence. Conversely, a high-quality credential may still require fresh authentication before a sensitive presentation.
Sources of assurance
An approved proofing process may combine several evidence categories:
- authoritative identity or institutional records;
- document integrity and format checks;
- machine-readable document evidence;
- issuer or registry confirmation;
- biometric liveness and face comparison;
- device and session signals;
- prior trusted relationships;
- human review and exception handling.
The appropriate combination depends on the credential, risk, sector, accessibility needs, and applicable rules.
Document evidence
A document should not be trusted merely because it looks authentic in a photograph or PDF. A proofing process may evaluate:
- document type and expected structure;
- visible and machine-readable data consistency;
- signs of alteration or substitution;
- validity and expiration information;
- issuer provenance or registry status;
- relationship between the document and the applicant;
- consistency with other approved evidence.
Public documentation does not disclose fraud thresholds, vendor configurations, decision rules, or bypass conditions.
Biometric controls
Where biometrics are used, an institution should define:
- the specific purpose and necessity;
- the lawful basis or authorization condition;
- a suitable alternative where required or appropriate;
- whether the comparison is one-to-one or broader;
- liveness and presentation-attack controls;
- template protection and isolation;
- retention and destruction rules;
- human review and appeal paths;
- accessibility and demographic performance review;
- processor and cross-border restrictions.
Raw biometric captures and templates should not become general-purpose identifiers or appear in ordinary credentials, logs, or public ledgers.
Assurance levels and policy
Proofing is not simply "passed" or "failed" in the abstract. The evidence supports a defined assurance level for a defined purpose.
A low-risk community credential may use different evidence from a government identity credential, professional license, financial onboarding credential, or recovery authorization. The verifier must understand what the assurance result means and whether it is sufficient for the transaction.
Human review and exceptions
Automation can improve consistency and reduce manual workload, but high-impact identity decisions require governed exception handling.
Human review may be necessary when:
- evidence is incomplete or conflicting;
- a legitimate document is not recognized automatically;
- a person cannot use a biometric method;
- accessibility or device limitations affect capture quality;
- a fraud or risk signal requires contextual assessment;
- the consequence of an error is significant.
Reviewers need defined authority, training, evidence access, segregation of duties, and an auditable decision process.
Fairness and accessibility
Identity systems should not make participation dependent on one device, physical ability, biometric modality, or document format unless the institution can justify that requirement.
Deployments should test performance across relevant populations, provide understandable failure messages, support alternative channels, and avoid treating an automated mismatch as proof of fraud.
Retention and deletion
Source images, video, templates, extracted document data, and review evidence have different purposes and risks. Each class needs a defined retention period, access rule, deletion process, and incident treatment.
A final credential generally should contain only the approved claims and assurance references necessary for its purpose—not the complete raw proofing package.
Public documentation boundary
This page explains governance and assurance principles. It does not publish vendor secrets, capture configuration, fraud heuristics, model thresholds, source-data examples, customer rules, biometric templates, or operational review procedures.
See Biometric Governance, UbID Proof, and Authentication and Device Security.