Identity assurance level
Also known as: IAL
Identity assurance level, or IAL, measures the confidence that a person’s claimed identity is their real identity after an identity-proofing process. It describes the strength of evidence and verification, not the security of login authentication.
An identity assurance level is a structured way to state how rigorously an organization has established who an applicant is. It is used in digital identity programs to match proofing requirements to the risk of a service or transaction.
IAL is most closely associated with the US National Institute of Standards and Technology, or NIST, digital identity guidelines. Other frameworks, including European rules and sector-specific schemes, use comparable concepts but may apply different terminology and requirements.
What IAL measures
Identity proofing is the process of collecting identity evidence, checking that it is genuine and valid, and determining whether it belongs to the person presenting it. An IAL expresses the resulting confidence in that identity binding.
- IAL concerns identity proofing, such as validating a passport, driving licence, address record or authoritative database record.
- It is distinct from authentication assurance level, or AAL, which concerns how securely a person signs in, such as with a password, passkey or hardware security key.
- It is also distinct from federation assurance level, or FAL, which concerns the security of assertions shared between an identity provider and a relying service.
Common NIST levels
Under NIST guidance, IAL1 generally permits self-asserted identity information without identity proofing. IAL2 requires stronger verification of identity evidence and checks intended to establish that the applicant is the rightful holder of that identity. IAL3 is intended for higher-risk uses and requires more rigorous proofing and protections.
The exact procedures for document validation, biometric comparison, database checks, liveness detection, remote or in-person proofing, and fraud review depend on the applicable version of the guidance and the organization’s risk assessment. A higher IAL does not mean fraud is impossible; it means the proofing process is designed to provide greater confidence.
Why it matters
Organizations use IAL requirements when access to a service could affect money, health information, government benefits, legal rights or public safety. Selecting an unnecessarily high level can exclude people who lack particular documents or devices, while selecting a level that is too low can increase impersonation and account fraud risk.