# IAL2 framework templates solution

> Install the IAL2 framework templates in your Sandbox, pick Doc AI or Strong Only, and learn which steps IAL2 requires and what to change for full compliance.

Source: https://help.withpersona.com/articles/0jfM3U58A4LXRbPumx7FZb/
Section: Solutions > All Solutions & Blueprints > Available in Solutions Library

## Overview

The **IAL2 framework templates** solution gives you a starting point for identity proofing flows aligned with NIST Identity Assurance Level 2 (IAL2). It routes each person through the shortest pathway their documents allow, from a single scan of a REAL ID to a passport chip read.

⚠️

The IAL2 framework templates are **aligned with IAL2, but they are not fully IAL2 compliant out of the box.** Two of the four pathways need changes before they meet IAL2. See [Making the flow fully IAL2 compliant](#making-the-flow-fully-ial2-compliant). You are responsible for deciding whether your implementation meets your requirements.

Every step below is labelled one of two ways:

- **Required by IAL2:** the NIST specification asks for it.
- **Persona addition:** Persona includes it to raise pass rates or reduce fraud. The standard does not ask for it.

For background on IAL2 itself, see [IAL2 identity proofing with Persona](https://help.withpersona.com/articles/QC1OAt4zLihlELoVNJ5jmK/).

## What's included

Adding the solution installs 49 objects into your Sandbox:

- **2 Inquiry Templates**
  - **[Verified] IAL2 Framework Doc AI**
  - **[Verified] IAL2 Framework Strong Only**
- **18 Verification Templates**, covering Government ID, Selfie, Document, Database, AAMVA, Phone and Email Verifications
- **28 Workflows** that run the flow's routing and decisions
- **1 Account Type**

When you add the solution, the Dashboard asks you to confirm **enhanced pricing** for both Inquiry Templates.

## Doc AI or Strong Only: which template to use

The two Inquiry Templates differ in one thing: whether they accept FAIR evidence, such as a bank statement or utility bill.

| Template                                  | Pathways    | Pick it when                                                                                                                                                                   |
| ----------------------------------------- | ----------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **[Verified] IAL2 Framework Doc AI**      | All four    | You accept FAIR evidence. People who do not have two STRONG documents can add a bank statement and a utility bill, read with [Document AI](https://help.withpersona.com/articles/GB3qI5b3fH7IHulsQUhVHK/). |
| **[Verified] IAL2 Framework Strong Only** | First three | You accept only STRONG or SUPERIOR evidence. A person who would need FAIR documents ends in a failed Inquiry.                                                                  |

## The four pathways

The flow picks a pathway from the documents the person presents.

| Pathway                                               | Evidence                            | Steps                                                                                      | Meets IAL2 out of the box?                                       |
| ----------------------------------------------------- | ----------------------------------- | ------------------------------------------------------------------------------------------ | ---------------------------------------------------------------- |
| **1. REAL ID and AAMVA**                              | 1 STRONG, validated with the issuer | US driver's license or state ID, AAMVA Verification, Selfie Verification                   | Yes                                                              |
| **2. Passport with NFC chip**                         | 1 SUPERIOR                          | Passport, NFC chip read, Selfie Verification, US Database Verification                     | Yes                                                              |
| **3. Passport and driver's license or ID**            | 2 STRONG                            | Driver's license or ID, passport, Selfie Verification, US Database Verification            | **No.** Needs changes for full compliance.                       |
| **4. Government ID, bank statement and utility bill** | 1 STRONG and 2 FAIR                 | Government ID, Selfie Verification, US Database Verification, bank statement, utility bill | **No.** Needs changes for full compliance. Doc AI template only. |

Pathways 3 and 4 accept documents that cannot be checked with their issuer, such as a non-US license, a license from a state outside AAMVA's service, or a passport without a chip read. The template treats these as STRONG after a US Database Verification of name, date of birth and address, which keeps more people moving through the flow. IAL2 asks for STRONG evidence to be confirmed with the **issuing source**, so a general database check is not enough for full compliance.

## Each step, labelled

Every pathway starts with a one-time code.

| Step                                            | Label            | Why                                                                                                          |
| ----------------------------------------------- | ---------------- | ------------------------------------------------------------------------------------------------------------ |
| One-time code at the start of the flow          | Required by IAL2 | Revision 3 asks for an enrollment code to confirm the person's contact details.                              |
| Sending that code by email, with phone optional | Persona addition | NIST asks for a code, not a channel. Email changes less often than a phone number.                           |
| Native mobile flow                              | Persona addition | Needed for barcode capture and NFC, not by NIST. See [Mobile, NFC and email 2FA](#mobile-nfc-and-email-2fa). |

### Pathway 1: REAL ID and AAMVA

| Step                                                               | Label            | Why                                                                                                            |
| ------------------------------------------------------------------ | ---------------- | -------------------------------------------------------------------------------------------------------------- |
| Government ID: US driver's license or state ID from an AAMVA state | Required by IAL2 | Collects STRONG evidence.                                                                                      |
| The ID must be a REAL ID, with the barcode on the back scanned     | Persona addition | NIST does not name REAL ID. The template uses it as its marker for STRONG, and reads the barcode to detect it. |
| AAMVA Verification                                                 | Required by IAL2 | Confirms the license details with the issuing state.                                                           |
| Selfie Verification                                                | Required by IAL2 | Confirms the person owns the ID, by comparing a live selfie with the ID photo.                                 |

### Pathway 2: Passport with NFC chip

| Step                                                    | Label            | Why                                                                                                           |
| ------------------------------------------------------- | ---------------- | ------------------------------------------------------------------------------------------------------------- |
| Government ID: passport                                 | Required by IAL2 | Collects the evidence.                                                                                        |
| NFC chip read, with PKI validation as a required check  | Required by IAL2 | Validating the chip's signature makes the passport SUPERIOR evidence. Keep this check required, not optional. |
| Selfie Verification                                     | Required by IAL2 | Confirms the person owns the passport.                                                                        |
| US Database Verification (name, date of birth, address) | Persona addition | IAL2 does not need it when the chip is validated. It adds a further check of the person's details.            |

### Pathway 3: Passport and driver's license or ID

| Step                                  | Label            | Why                                                                                                                   |
| ------------------------------------- | ---------------- | --------------------------------------------------------------------------------------------------------------------- |
| Government ID: driver's license or ID | Required by IAL2 | First piece of STRONG evidence. It can be non-US, from a state outside AAMVA's service, or not a REAL ID.             |
| Government ID: passport               | Required by IAL2 | Second piece of STRONG evidence.                                                                                      |
| Selfie Verification                   | Required by IAL2 | Confirms the person owns the evidence.                                                                                |
| US Database Verification              | Persona addition | Stands in for an issuer check so more documents are accepted. It does not replace validation with the issuing source. |

### Pathway 4: Government ID, bank statement and utility bill (Doc AI template only)

| Step                                                           | Label            | Why                                                                                            |
| -------------------------------------------------------------- | ---------------- | ---------------------------------------------------------------------------------------------- |
| Government ID: passport, driver's license or ID                | Required by IAL2 | The STRONG evidence. It can be non-US, from a state outside AAMVA's service, or not a REAL ID. |
| Selfie Verification                                            | Required by IAL2 | Confirms the person owns the ID.                                                               |
| US Database Verification                                       | Persona addition | Stands in for an issuer check so more IDs are accepted.                                        |
| Bank statement from the last 90 days, showing name and address | Required by IAL2 | The FAIR evidence.                                                                             |
| Utility bill from the last 90 days, showing name and address   | Persona addition | IAL2 needs one FAIR document. The second adds assurance.                                       |

The Government ID and Selfie Verifications in every pathway also run Persona's fraud and quality checks, such as injection detection. Those checks are a **Persona addition**. The liveness check in the Selfie Verification is also expected by IAL2's biometric option.

## Mobile, NFC and email 2FA

| Setting              | What the template does                                                                                                                                          | Label                                                                                |
| -------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------ |
| **Native mobile**    | The flow runs in the [native mobile experience](https://help.withpersona.com/articles/2YEOllyeCf2gVzgoSlfqld/). On iPhone it opens as an App Clip, so people do not need to install an app. | Persona addition. Barcode capture is hard on a webcam and NFC only works on a phone. |
| **NFC chip reading** | Reads the chip in a passport and validates its signature. See [Collecting Passports and other IDs using NFC](https://help.withpersona.com/articles/1iu1Fak8y9RiOE2FddXrHJ/).                | Required by IAL2 for the SUPERIOR pathway.                                           |
| **Email 2FA**        | Sends a one-time code by email at the start of the flow. Phone is available as an option. See [Email (2FA) Verification](https://help.withpersona.com/articles/2FauPy2tquCwnyeMjtpVly/).    | The code is required by IAL2. Choosing email is a Persona addition.                  |

## Add the solution to your Sandbox

1.  In the Dashboard, [switch into](https://help.withpersona.com/articles/1IKpaNpGCG2E8ksAjZQYLx/) your Sandbox environment.
2.  Select **Home** in the navigation bar.
3.  On the Home page, click **Explore all solutions**.
4.  Find **IAL2 framework templates**, then click **Add to sandbox**.
5.  Confirm enhanced pricing for the two Inquiry Templates when the Dashboard asks.
6.  Click the solution to see its setup checklist.

The setup checklist walks you through four steps:

1.  Choose **[Verified] IAL2 Framework Doc AI** or **[Verified] IAL2 Framework Strong Only**, depending on whether you accept FAIR evidence.
2.  If you are legally required to meet IAL2, apply the changes in [Making the flow fully IAL2 compliant](#making-the-flow-fully-ial2-compliant).
3.  Optionally, apply a theme to match your brand.
4.  Publish the template, then point your Workflows and API integrations at it.

For more on adding and customizing a solution, see [Add a solution](https://help.withpersona.com/articles/67J7FurQtIgwxkWWvUropu/). Test the flow before you go live, using [Testing your Inquiry Template](https://help.withpersona.com/articles/1az3sGqpcW5Zrne9I7lm49/).

## Making the flow fully IAL2 compliant

To be fully compliant, every piece of STRONG evidence must be confirmed with its issuing or an authoritative source. These changes close the gaps in pathways 3 and 4.

| Document                                                                 | Counts as                                                                                                                   | What to change                                                                                                                                                                                           |
| ------------------------------------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Non-US driver's license or ID**                                        | STRONG only if Persona can check it against an issuing or authoritative source in that country. Otherwise FAIR.             | Pick one: accept only US licenses and IDs from AAMVA states; add an international Database Verification for each country you accept; or count these documents as FAIR and require other STRONG evidence. |
| **US REAL ID from a state outside AAMVA's service**                      | Open to interpretation. The REAL ID designation makes STRONG defensible, but the details cannot be checked with the issuer. | For full compliance, count it as FAIR.                                                                                                                                                                   |
| **US license or ID from a state outside AAMVA's service, not a REAL ID** | FAIR only.                                                                                                                  | Count it as FAIR, and require other STRONG evidence.                                                                                                                                                     |

Also confirm that the NFC chip's PKI validation stays a **required** check in pathway 2. The pathway relies on that check to treat the passport as SUPERIOR evidence.

☝️

Persona provides the components for an IAL2 flow. Your compliance team decides whether your configuration meets your obligations.

## Settings that need a Persona teammate

Most of the solution is self-serve. Two things may need your Persona account team:

- **Phone 2FA service.** The Phone Verification's delivery service cannot be set from the Dashboard, so a Persona teammate finishes it if you want to offer phone codes. Email 2FA, the default, works without this.
- **Enhanced pricing.** The Inquiry Templates use enhanced pricing. If you are unsure what that means for your contract, check with your account team before you go live.

## TEFCA

If you are a TEFCA Individual Access Services provider, use the separate **TEFCA** solution instead. It installs **[Verified] TEFCA IAL2** with an OIDC Authentication Template, adds patient matching fields, and is stricter about which licenses it accepts. See [TEFCA Individual Access Services (IAS)](https://help.withpersona.com/articles/ARLLoIOGw9P5nGlnC53uc/).

To learn more or request access, [let us know](https://app.withpersona.com/dashboard/contact-us?category=sales). We're happy to help.
