{"id":5,"date":"2026-08-11T09:56:57","date_gmt":"2026-08-11T13:56:57","guid":{"rendered":"https:\/\/instantid.io\/blog\/what-documents-are-needed-for-identity-verification\/"},"modified":"2026-08-11T12:21:42","modified_gmt":"2026-08-11T16:21:42","slug":"what-documents-are-needed-for-identity-verification","status":"publish","type":"post","link":"https:\/\/instantid.io\/blog\/what-documents-are-needed-for-identity-verification\/","title":{"rendered":"What Documents Are Needed for Identity Verification?"},"content":{"rendered":"<h1>What Documents Are Needed for Identity Verification?<\/h1>\n<p>There is no single document checklist that works for every identity-verification process. The right evidence depends on the service, the level of confidence needed, the people being served, and the way the evidence can be checked.<\/p>\n<p>This guide explains the main evidence categories and a practical way for a small business to prepare. It is general information, not legal or compliance advice. Confirm the rules that apply to your business, location, and industry before setting a policy.<\/p>\n<h2>Quick answer<\/h2>\n<p>An identity-verification process may use one or more of the following:<\/p>\n<ul>\n<li>a government-issued photo credential, such as a driver&#039;s license, state identity card, or passport;<\/li>\n<li>an account or organization credential, such as a student, corporate, veteran, financial, or phone-account record;<\/li>\n<li>a digital credential, such as a mobile driver&#039;s license, where the business has a way to validate it; and<\/li>\n<li>additional attributes or another evidence type when the first item does not provide enough confidence.<\/li>\n<\/ul>\n<p>These are examples, not a universal acceptance list. NIST describes its evidence list as non-exhaustive and says the organization running the process must evaluate and document what it will accept. <a href=\"https:\/\/pages.nist.gov\/800-63-4\/sp800-63a\/evidence\/\" rel=\"noopener noreferrer\">Review NIST&#039;s evidence examples<\/a>.<\/p>\n<h2>Why the required documents vary<\/h2>\n<p>Identity proofing is more than collecting a photocopy. NIST describes four important outcomes:<\/p>\n<p>1. <strong>Identity resolution:<\/strong> deciding whether the claimed identity corresponds to one real person in the relevant population. 2. <strong>Evidence validation:<\/strong> checking that the evidence is genuine, authentic, and accurate. 3. <strong>Attribute validation:<\/strong> checking core details against an authoritative or credible source. 4. <strong>Identity verification:<\/strong> confirming that the person presenting the evidence is its genuine owner.<\/p>\n<p>A document can help with one step without completing all four. A photo credential, for example, still needs an appropriate validation method and a way to connect the credential to the person presenting it. <a href=\"https:\/\/pages.nist.gov\/800-63-4\/sp800-63a.html\" rel=\"noopener noreferrer\">Review NIST SP 800-63A<\/a>.<\/p>\n<p>The UK government&#039;s identity-checking guidance makes a similar practical point: choose evidence only when it is appropriate for the service and when staff have the equipment and process needed to check it effectively. It gives a passport as one possible example, not as a requirement for every service. <a href=\"https:\/\/www.gov.uk\/government\/publications\/identity-proofing-and-verification-of-an-individual\" rel=\"noopener noreferrer\">Review GOV.UK Good Practice Guide 45<\/a>.<\/p>\n<h2>Common evidence categories<\/h2>\n<h3>Government-issued photo credentials<\/h3>\n<p>NIST&#039;s examples include physical driver&#039;s licenses or state identity cards, U.S. passports, international electronic passports, permanent resident cards, certain tribal photo identification cards, and other government credentials. Different items appear at different evidence-strength levels because their issuance, security features, validation methods, and verification methods differ.<\/p>\n<p>Do not assume that every government credential is acceptable for every purpose. Record which credentials your process accepts, which locations issue them, how staff validate them, and what happens when a credential cannot be checked.<\/p>\n<h3>Account and organization credentials<\/h3>\n<p>NIST also lists examples that are not ordinary government photo IDs. These include certain financial and phone accounts, student identification cards, corporate identification cards, and veteran credentials. Such evidence may support a process when its issuance and validation methods meet the required level of confidence.<\/p>\n<p>Again, the label alone is not enough. A business needs a documented way to validate the evidence and confirm that it belongs to the person presenting it.<\/p>\n<h3>Digital credentials<\/h3>\n<p>Some processes may use digital evidence, such as a mobile driver&#039;s license or another signed digital credential. Accepting a screenshot is not the same as validating a digital credential. The business needs a supported method to check the credential&#039;s digital security information and, when available, its status.<\/p>\n<h3>More than one piece of evidence<\/h3>\n<p>NIST encourages organizations to offer multiple evidence types and combinations so that people with different circumstances can complete the process. The organization must evaluate the risks of each option and use controls that provide comparable assurance overall.<\/p>\n<p>This means a well-designed process should not simply say \u201cpassport or nothing\u201d unless that rule is genuinely required and justified. It should also explain an exception or assistance path for people who cannot meet the standard route.<\/p>\n<h2>A practical preparation checklist for a small business<\/h2>\n<h3>1. Define the purpose<\/h3>\n<p>Write down why identity needs to be checked. The evidence needed for account recovery may differ from the evidence needed for a regulated transaction or access to a sensitive service.<\/p>\n<h3>2. Choose the confidence level<\/h3>\n<p>Decide how much confidence the process needs and what could go wrong if the wrong person is accepted. Seek qualified legal or compliance advice when a law or industry rule applies.<\/p>\n<h3>3. Create an acceptance table<\/h3>\n<p>For each evidence type, record:<\/p>\n<ul>\n<li>the document or credential name;<\/li>\n<li>the issuing location or organization;<\/li>\n<li>the details staff need to see;<\/li>\n<li>the approved validation method;<\/li>\n<li>the approved method for confirming it belongs to the applicant; and<\/li>\n<li>the fallback when the evidence cannot be validated.<\/li>\n<\/ul>\n<h3>4. Check the process, not just the document<\/h3>\n<p>Train staff to follow the approved steps consistently. If the process depends on specialist equipment, an authoritative data source, or a digital-verification method, confirm that it is available before telling customers that the evidence is accepted.<\/p>\n<h3>5. Provide an alternative route<\/h3>\n<p>Document how staff handle people whose evidence is unavailable, does not match current details, or cannot be validated. NIST discusses exception handling, trusted referees, applicant references, and process assistance as possible parts of an inclusive identity-proofing design. Whether those options are suitable depends on the service.<\/p>\n<h3>6. Collect only what is needed<\/h3>\n<p>NIST expects identity-proofing services to use privacy-enhancing principles such as data minimization. Avoid collecting an extra document or attribute merely because it might be useful later. Record what is required, why it is required, who can access it, and when it should be deleted.<\/p>\n<h3>7. Give customers clear instructions<\/h3>\n<p>Tell customers which evidence your specific process accepts and how to submit it through the approved secure channel. Explain that requirements can vary and provide a contact route for questions or alternative arrangements. Do not ask customers to send sensitive documents through an unapproved channel.<\/p>\n<h2>Questions to ask an identity-verification provider<\/h2>\n<p>Before choosing or configuring a provider, ask:<\/p>\n<ul>\n<li>Which evidence types and issuing locations are supported?<\/li>\n<li>How is each evidence type validated?<\/li>\n<li>How does the process confirm that the evidence belongs to the person presenting it?<\/li>\n<li>Which steps are automated, and which involve trained staff?<\/li>\n<li>What happens when a person cannot use the standard evidence route?<\/li>\n<li>What data is collected, where is it processed, who can access it, and when is it deleted?<\/li>\n<li>How are changes to supported evidence communicated?<\/li>\n<li>What records are available for review when a decision is questioned?<\/li>\n<\/ul>\n<p>Record the answers in your own policy. Do not rely on a general marketing statement when a specific document, country, or workflow matters.<\/p>\n<h2>Frequently asked questions<\/h2>\n<h3>Is a passport always required?<\/h3>\n<p>No. A passport is one example of identity evidence. The accepted evidence should match the service, required confidence, user population, and available validation process.<\/p>\n<h3>Is one photo ID always enough?<\/h3>\n<p>Not necessarily. A process may require another evidence item, additional attributes, or a stronger validation and verification method. The required combination depends on the process design and applicable rules.<\/p>\n<h3>Can a business accept an expired document?<\/h3>\n<p>Do not apply a blanket answer. The service must define what \u201cvalid\u201d means for its purpose and how expiry affects acceptance. Check the applicable rule, issuing source, and provider policy before giving customers an answer.<\/p>\n<h3>What if a customer does not have the standard evidence?<\/h3>\n<p>Use the documented exception path rather than making an improvised decision. If no alternative is available, explain that clearly and tell the customer where to ask for help.<\/p>\n<h2>The main takeaway<\/h2>\n<p>The right question is not only \u201cWhich document should we collect?\u201d It is \u201cWhat evidence is appropriate, how will we validate it, how will we confirm it belongs to this person, and what will we do when the standard route does not work?\u201d<\/p>\n<p>Build the checklist around those questions, document the answers, and review the policy whenever the service, risk, provider, or applicable rules change.<\/p>\n<h2>Primary sources<\/h2>\n<p>1. <a href=\"https:\/\/pages.nist.gov\/800-63-4\/sp800-63a.html\" rel=\"noopener noreferrer\">NIST SP 800-63A \u2014 Identity Proofing and Enrollment<\/a>, accessed August 11, 2026. 2. <a href=\"https:\/\/pages.nist.gov\/800-63-4\/sp800-63a\/evidence\/\" rel=\"noopener noreferrer\">NIST SP 800-63A Appendix A \u2014 Identity Evidence Examples by Strength<\/a>, accessed August 11, 2026. 3. <a href=\"https:\/\/www.gov.uk\/government\/publications\/identity-proofing-and-verification-of-an-individual\" rel=\"noopener noreferrer\">UK Cabinet Office and Government Digital Service \u2014 How to prove and verify someone&#039;s identity (GPG 45)<\/a>, last updated November 14, 2024; accessed August 11, 2026.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A plain-language guide to common identity-evidence categories, validation and verification steps, exception paths, and a practical preparation checklist based on current NIST and UK government guidance.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-5","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/instantid.io\/blog\/wp-json\/wp\/v2\/posts\/5","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/instantid.io\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/instantid.io\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/instantid.io\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/instantid.io\/blog\/wp-json\/wp\/v2\/comments?post=5"}],"version-history":[{"count":1,"href":"https:\/\/instantid.io\/blog\/wp-json\/wp\/v2\/posts\/5\/revisions"}],"predecessor-version":[{"id":6,"href":"https:\/\/instantid.io\/blog\/wp-json\/wp\/v2\/posts\/5\/revisions\/6"}],"wp:attachment":[{"href":"https:\/\/instantid.io\/blog\/wp-json\/wp\/v2\/media?parent=5"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/instantid.io\/blog\/wp-json\/wp\/v2\/categories?post=5"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/instantid.io\/blog\/wp-json\/wp\/v2\/tags?post=5"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}