Electronic Identity
Identity proofing, digital IDs, biometrics and trust services
What identity evidence establishes
Electronic identity connects a person with attributes and credentials used in digital services. Identity proofing asks whether a claimed identity exists and whether the applicant is associated with it to an appropriate confidence level. Authentication later tests control of an accepted authenticator; authorisation determines what action that user may perform.
A verified name is not a complete banking mandate. Business customers also require relevant entity, ownership and representative checks. An identity-provider assertion should be interpreted within its scope rather than treated as a global guarantee about the person's eligibility or authority.
Resolution, validation and verification
Resolve the claimed identity, validate evidence and attributes, and verify that the applicant is the appropriate holder. Enrollment can then bind authenticators to the proofed identity. Maintain traceable references and decision evidence while minimising unnecessary sensitive data.
NIST SP 800-63A Revision 4 describes identity assurance levels and this proofing framework. It concerns natural persons and digital-identity assurance; it does not itself replace a bank's national customer-due-diligence obligations or define every corporate onboarding check.
Evidence methods and limits
Documents, authoritative data sources, attended checks and accepted digital identity services can provide different evidence. Assess supported populations, document authenticity, source freshness and fraud threats. A matching name alone may not distinguish two people.
Reading a cryptographically signed document chip can support evidence integrity, but the complete process still needs to establish who is presenting it and handle compromise or inconsistent attributes. A chip read is not an unconditional guarantee that every applicant is genuine. Visual capture and video also need appropriate anti-tampering and injection controls.
Biometric comparison has false accept and false reject risks. Presentation-attack detection does not automatically detect every injected or synthetic stream. Evaluate vendor performance in the actual capture environment, populations and threat model rather than relying only on a demonstration score.
Federation and trust services
If a bank relies on another identity provider, check issuer trust, intended audience, signature, freshness and replay protection of relevant assertions. Map the asserted assurance and attributes to the bank's use. Possession of a token or wallet does not itself establish that its assertion is acceptable for every banking action.
Electronic signatures, certificates and legal trust-service classifications are separate questions. Their legal effect depends on applicable law and the actual service and signature type. Do not equate every click, biometric check or identity assertion with a qualified legal signature.
Worked example: changed name
In this fictional application, the customer's current name differs from an older document. Automatic matching refers the case. An authorised reviewer assesses appropriate supporting evidence and records how the mismatch was resolved.
The customer is neither automatically rejected as fraudulent nor accepted merely because the names look similar. A controlled alternative route maintains assurance and reduces unnecessary exclusion. Related customer records are updated only through the appropriate correction process.
Operation and assurance
Track false matches, failed verification, referrals, abandonment and confirmed impersonation by relevant method and population. Reassess changes to sources and provider algorithms. Set escalation and assisted routes for customers lacking supported evidence or capture capability where appropriate.
Protect document and biometric information with purpose, access, retention and provider controls. A vendor assurance certificate does not prove the entire bank journey is sound. Test evidence reuse, expired assertions, duplicate identities and recovery that could undo the original binding.
Takeaway
Electronic identity provides assessed evidence within a defined trust framework. Proofing, authentication, banking authority and legal signature effect remain distinct, even when one journey uses them together.
Continue to Authentication & Consent.