Build1 publisher3 min readPublished
Mixing unattended capture with a live video session triggers IAL1's documentation SHALL
The IAL1 section of NIST's identity proofing guidance is marked normative, and its SHALL statements set the evidence floor and the ownership check while leaving biometric matching optional. Hybrid flows pick up a separate obligation.
The Engineer · Build desk

What happened
- NIST marks the IAL1 identity proofing requirements as normative, and the collection floor is one piece of FAIR evidence that can be digitally validated or carries a facial portrait, or one STRONG or SUPERIOR piece.
- A CSP verifying the applicant's ownership of one piece of evidence may pick from six listed methods, among them a returned confirmation code and an AAL2/FAL2-equivalent login to a related account.
- Where a proofing agent makes the facial comparison asynchronously, the CSP SHALL add presentation attack detection plus passive or active document presence checks.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- cost Choosing offline agent review to smooth staffing schedules buys two engineering line items, presentation attack detection and document presence checks, that a live session avoids.
- decision Any team that bolted a live video call onto an automated capture pipeline now owes a written mapping of requirements to proofing type, which is work for a compliance writer and not for the build.
- constraint Cross-source attribute consistency and reference number checks sit at SHOULD, so an assessor's hard questions land on collection, attribute validation and ownership verification.
The document's verbs sort the work. Inside the IAL1 section, seven statements use SHALL and two use SHOULD [3][4]. The SHALLs cover what evidence is collected [4], collection of all core attributes including at least one government identifier [7], validation of each piece of evidence [6], validation of those attributes against an authoritative or credible source [10], verification of ownership of one piece of evidence [8], documentation of any hybrid process [5], and two extra controls when facial comparison happens asynchronously [9]. Evaluating attributes from different sources for consistency and validating reference numbers on the evidence are both SHOULD [11][12].
Verification of ownership has six acceptable methods, and three of them never compare a face: returning a confirmation code delivered to a validated address associated with the evidence, returning a microtransaction value delivered to a validated financial or similar account, and completing an authentication and federation protocol equivalent to AAL2/FAL2 or higher to reach an account related to the evidence [8][1]. The section frames IAL1 as allowing a range of techniques while minimizing the rejection of legitimate users and reducing application departures [14]. It also says outright that biometric matching, given as automated comparison of the applicant's facial image to a facial portrait on supplied evidence, is optional at IAL1 [3].
Two of the four evidence validation methods are machine work: interrogating the digital security features of digital evidence, and automated scanning that detects physical security features under Sec. 3.14. The other two need a proofing agent, either inspecting security features visually in real time or asynchronously, or inspecting the document physically and tactilely at an on-site location [6][2].
The clause that catches flows already in production is the hybrid one. NIST's own example is remote unattended validation run in advance of a remote attended session where the verification takes place [5]. Teams assembled this shape because document capture automates cleanly and the ownership check often does not. Combining is permitted. The written account of it is the easiest deliverable to skip, since nothing in the pipeline fails when it is missing. The guidance requires the CSP to document the hybrid process and state how the applicable requirements for each of the employed proofing types are met [5].
Remote unattended proofing, on its own, has no additional requirements beyond those in Secs. 2, 3 and 4 [13].
Asynchronous facial comparison adds two required controls. A CSP that lets an agent do the comparison later SHALL implement presentation attack detection and passive or active document presence checks, to raise confidence that both the live applicant and the physical documents were present at the submission or capture event [9]. The supplied text of the page ends mid-heading in the remote attended requirements, so whatever that path adds is not in the record reviewed here [15].
What to watch
- The remote attended requirements that follow this section, and whether that path adds controls beyond Secs. 2, 3 and 4.
- Whether IAL1 vendor packages document the three non-biometric ownership verification paths or only sell face match.
- What assessors accept as a hybrid process document, specifically how granular the per-proofing-type requirement mapping has to be.