Overview
ISO/IEC TS 29003:2018 - Identity proofing provides guidelines for proving the identity of a natural person and specifies levels of identity proofing (LoIP) and the requirements to achieve them. Applicable to identity management systems, the technical specification supports interoperable, auditable identity verification processes that enable federated trust across digital services, supply chains and cross‑border scenarios.
Key topics and technical requirements
- Identity proofing process: Steps to collect proofing information, verify identifying attributes, achieve the required LoIP and bind the subject to the claimed identity. Channels include in‑person, online and telephone applications.
- Proofing information & attributes: Distinguishes identifying attributes (e.g., name, date of birth, national identifier, biometrics, address) from supporting attributes used to corroborate identity.
- Evidence of identity (EOI): Defines types of evidence used during proofing and their expected consistency with application data.
- Authoritative evidence: Information managed by an authoritative party (e.g., civil registry) and treated as a primary source.
- Corroborative evidence: Secondary sources that can mitigate residual risk when authoritative evidence is unavailable.
- Levels of identity proofing (LoIP): The specification defines different assurance levels and the requirements to meet them (policy, evidence strength, binding methods).
- Policy and governance: Requires documenting an identity proofing policy (proofing policy maker), defining context and boundaries, and recording enrolment/outcomes.
- Fraud awareness: Informative annexes provide examples of evidence and recommendations on contra‑indications and fraud detection.
Applications and who uses it
ISO/IEC TS 29003:2018 is intended for organizations that perform or rely on identity proofing:
- Government agencies (civil registries, e‑government enrolment)
- Identity providers (IdPs) and federated authentication systems
- Financial institutions, insurance and payment service providers
- Telecommunications and utilities onboarding customers
- Service providers issuing credentials (digital certificates, access tokens)
- IT security and identity governance teams building enrolment and identity lifecycle controls
Use cases include digital onboarding, credential issuance, KYC (know your customer) processes, federated single sign‑on and cross‑domain trust frameworks.
Related standards
- ISO/IEC 24760 series - general identity management framework and lifecycle
- ISO/IEC 29115 - entity authentication assurance (complements LoIP definitions)
These standards together support end‑to‑end identity management, from proofing and enrolment to authentication and lifecycle management.
Keywords: ISO/IEC TS 29003:2018, identity proofing, evidence of identity, authoritative evidence, corroborative evidence, identity management, levels of identity proofing, enrolment, identity verification, LoIP.