Digital identity verification confirms a person is who they claim to be using ID scans, biometric matching, or knowledge-based questions instead of an in-person check. In the U.S., NIST SP 800-63-4 (July 2025) defines the reference assurance levels, and state remote online notarization laws set the rules for notarization sessions.
What Is Digital Identity Verification?
Digital identity verification is the process of confirming a person’s real-world identity through electronic means – validating a government-issued ID, matching a live photo or video to that ID, and sometimes asking knowledge-based questions – rather than requiring an in-person meeting with a document check. It’s the foundation that lets services like online banking, digital account opening, and remote online notary sessions operate without a physical visit.
In the U.S., the most widely referenced standard is NIST’s Digital Identity Guidelines, Special Publication 800-63-4, published in July 2025. It replaced SP 800-63-3, which NIST withdrew on August 1, 2025 (NIST SP 800-63-4). The guidelines are written for federal agencies and their identity service providers, and they define Identity Assurance Levels (IALs) that set how confidently an organization can verify someone’s identity during initial enrollment, separate from how a returning user proves their identity at login.
This distinction matters more than it might seem: identity proofing (covered by IAL) happens once, when you first establish who you are with a service, while ongoing authentication (covered by a related but separate framework called Authenticator Assurance Levels, or AAL) happens every time you log back in afterward. A notarization session is fundamentally an identity-proofing event, so IAL is the closest reference framework, although the rules that actually apply to a notarization come from state law.
What Are NIST’s Identity Assurance Levels (IAL1, IAL2, IAL3)?
NIST defines three Identity Assurance Levels – IAL1, IAL2, and IAL3 – each representing a different degree of confidence that a digital identity matches a real person, letting organizations choose a level appropriate to their risk tolerance. Below IAL1, NIST also describes a “no identity proofing” tier for services that don’t need to link an account to a real person.
| Level | Confidence | What It Requires | Typical Use |
|---|---|---|---|
| IAL1 | Some confidence | At least one piece of identity evidence, with core attributes validated against authoritative or credible sources; remote or on-site | Lower-risk services that still need to tie an account to a real person |
| IAL2 | High confidence | Additional evidence and more rigorous validation and verification; remote or on-site, with or without biometric comparison, through one of three pathways (biometric, non-biometric, or digital evidence) | Higher-risk transactions such as banking and many federal services |
| IAL3 | Very high confidence | An on-site, attended session with a trained proofing agent, plus at least one biometric characteristic | Highest-security government and enterprise use cases |
Source: NIST SP 800-63A-4, checked September 29, 2026.
Under the current revision, identity proofing at every level follows the same three steps: resolution, where evidence and attributes are collected; validation, where the evidence is confirmed to be genuine and accurate; and verification, where the applicant is confirmed to be the rightful owner of that evidence. Approved verification methods include automated biometric comparison, a trained agent’s visual comparison of the applicant’s face to the ID photo, and confirmation codes, among others. Skipping the verification step means the process no longer meets the standard, however thorough the other steps were.

How Does Digital Identity Verification Work for Electronic Notarization?
Remote online notarization platforms combine several checks before the notary session begins, and state RON laws decide which methods are allowed. Many states require credential analysis plus an approved identity-proofing method, and the permitted methods vary by state.
- Credential analysis. The platform examines your government-issued ID for authenticity markers, checking it hasn’t been altered or forged.
- Identity proofing. The signer completes either knowledge-based authentication (KBA) or biometric verification. KBA asks five questions about personal history, and the signer must answer at least four correctly. Biometric verification compares a live selfie, taken from several angles with liveness detection, to the photo on the ID, and doesn’t require a Social Security number.
- Notary review. A commissioned notary reviews the verification results and your ID directly during the live video session before proceeding.
BlueNotary supports both identity-proofing paths. U.S. signers can choose KBA or biometrics. Signers outside the United States are recommended to use biometrics, because KBA questions are drawn from U.S. records and often can’t be generated for someone without a U.S. history; they verify with a passport and a biometric scan instead. With KBA, signers get two attempts, and after two failed attempts there is a 24-hour wait before they can try again (BlueNotary help center: KBA and biometrics; types of identity authentication).
This sequence adds automated ID checks to the notary’s own review, without either party needing to be in the same room. The notary’s own judgment still matters at the final step – automated checks handle the heavy lifting, but a commissioned professional makes the final call on whether to proceed.
Why Do Identity Checks Use More Than One Method?
NIST’s current guidelines no longer allow knowledge-based verification (KBV) as a method for verifying identity, though a provider may still use it as one signal in a fraud management program (NIST SP 800-63A-4). The reasoning is practical: a knowledge quiz confirms you know certain facts about a person, but it doesn’t confirm you physically match their photo ID, and the answers can be researched.
That NIST rule applies to identity services that follow SP 800-63. A notarization session is governed by state law, which decides the methods a notary can rely on: KBA is widely used, and biometrics are allowed in many states but not all (BlueNotary help center). That is why BlueNotary offers both, and why ID analysis and a live notary review sit on top of either path – no single check has to carry the whole verification.
There are two flavors of KBA worth distinguishing: static KBA, based on questions a person sets up themselves in advance (like a childhood pet’s name), and dynamic KBA, which generates real-time questions from public and private data sources the person didn’t choose. Dynamic KBA is generally considered the stronger of the two, since an impersonator can’t prepare answers ahead of time.
- KBA can be researched or guessed by someone with access to a target’s personal or public records, especially with static questions set up in advance.
- Biometric comparison is harder to fake, particularly with liveness detection built in to catch a photo or video substitute.
- Combining methods closes gaps that any single check leaves open, which is why a credential scan, an identity check, and a live notary review are layered together.
A permanent record of each verification step matters too: if a session is ever challenged, that record shows the process was followed. BlueNotary’s electronic notary journal logs the identity verification outcomes and the audio-video session for each notarization (BlueNotary help center).
The move toward biometrics reflects a broader trend across the identity verification industry, not just notarization. As personal information has become more widely available through data breaches and public records, questions that once served as reliable identity proof – previous addresses, past employers, vehicle history – have become easier for a determined bad actor to research or purchase, which is why biometric methods are increasingly the preferred check where the law allows them.
For how signatures fit into the same session, see electronic vs digital signature vs notarization.
Is Digital Identity Verification Secure?
When it combines credential analysis, biometric comparison with liveness detection, and a live review by a trained professional, digital identity verification is generally considered secure enough for regulated uses including banking, federal services, and online notarization, though no verification method is completely immune to sophisticated fraud.
The security bar keeps moving upward as fraud techniques evolve, particularly around AI-generated deepfake images and video. NIST’s 2025 revision added requirements for injection attacks and forged media such as deepfakes (NIST SP 800-63), which is part of why liveness detection has become a standard feature at reputable identity verification providers. A static photo or a simple video loop is no longer enough to fool a well-implemented biometric check, though the arms race between verification technology and fraud techniques is ongoing on both sides.
For businesses evaluating a notarization or identity-verification vendor, it’s worth asking for independent audit reports or certifications, since self-reported compliance and independently verified compliance aren’t the same level of assurance.
BlueNotary’s remote online notarization sessions include ID credential analysis and either KBA or biometric verification, followed by a live review by the notary, typically completed in about 10 minutes.
See the full notarization process walkthrough to see exactly what happens during a session.
Have a question about the identity verification process for a specific document? Email BlueNotary directly at [email protected] and the team will help you out.
FAQ Section
Q1. What is digital identity verification?
The process of confirming a person’s real-world identity electronically, using ID scans, biometric matching, and sometimes knowledge-based questions, instead of an in-person check.
Q2. What are NIST’s Identity Assurance Levels?
Three levels – IAL1, IAL2, and IAL3 – representing increasing confidence that a digital identity matches a real person, defined in NIST SP 800-63A-4, part of the 800-63-4 Digital Identity Guidelines published in July 2025.
Q3. What level of verification does electronic notarization use?
State remote online notarization laws set the requirements, which typically combine credential analysis with an approved identity-proofing method such as KBA or biometric verification. BlueNotary supports both, followed by a live review by the notary.
Q4. Can knowledge-based authentication alone verify my identity?
Not under NIST’s current guidance, which no longer allows KBA as an identity verification method, though it can support fraud checks. In a notarization session, KBA is used alongside ID analysis and a live notary review, and signers can choose biometrics where their state allows it.
Q5. Is digital identity verification as secure as an in-person check?
When it combines credential analysis, biometric comparison with liveness detection, and a live notary review, it adds checks that a visual ID inspection alone can’t provide.
Q6. What happens if I fail KBA or don’t have a U.S. credit history?
BlueNotary gives two KBA attempts, and after two failed attempts there is a 24-hour wait before trying again. Signers without a U.S. history, including signers outside the United States, are recommended to use biometric verification with a passport or other accepted ID instead.
