Identity Assurance Level (IAL)
NIST 800-63A levels describing identity proofing strength. IAL1: self-asserted. IAL2: remote or in-person verification with evidence. IAL3: in-person verification by a trained agent.
IAL is about proofing, not login: it answers "how sure are we this account belongs to a real, specific person" rather than "how strongly did they authenticate". Conflating it with AAL is the common mistake, and it produces systems with hardware keys protecting accounts that were opened with an unverified email. Regulated onboarding, benefits programs, and anything with fraud exposure need both levels stated separately.
See also: AAL, NIST 800-63, identity verification, identity verification vendors
Related on Start with Identity
- GlossaryCIAM
Customer Identity and Access Management. The identity stack for end users of a product, distinct from workforce IAM. CIAM optimizes for self-service signup, con
- BlogHow to vet a national digital ID before you build KYC on it
Not every national ID is equally trustworthy or equally easy to verify. A practical seven-point checklist for evaluating a country's digital ID before you wire
- GlossaryKYC
Know Your Customer. Regulatory obligations to identify and verify the identity of customers, primarily in financial services. KYC is a workflow built on top of
- GlossaryAnonCreds
A verifiable credential format, originating in Hyperledger Indy and now a standalone specification, built around zero-knowledge proofs for strong selective disc
- ArticleIdentity for Government: National eIDs, Assurance Levels, and Access
How identity works in the public sector: national eID schemes and citizen login, identity assurance levels under NIST 800-63 and eIDAS, workforce credentials li