Skip to content
Help Center

IAL2 framework templates solution

View Markdown Contact support Contact support 8 min read
On this page

Overview

The IAL2 framework templates solution gives you a starting point for identity proofing flows aligned with NIST Identity Assurance Level 2 (IAL2). It routes each person through the shortest pathway their documents allow, from a single scan of a REAL ID to a passport chip read.

The IAL2 framework templates are aligned with IAL2, but they are not fully IAL2 compliant out of the box. Two of the four pathways need changes before they meet IAL2. See Making the flow fully IAL2 compliant. You are responsible for deciding whether your implementation meets your requirements.

Every step below is labelled one of two ways:

  • Required by IAL2: the NIST specification asks for it.
  • Persona addition: Persona includes it to raise pass rates or reduce fraud. The standard does not ask for it.

For background on IAL2 itself, see IAL2 identity proofing with Persona.

What’s included

Adding the solution installs 49 objects into your Sandbox:

  • 2 Inquiry Templates
    • [Verified] IAL2 Framework Doc AI
    • [Verified] IAL2 Framework Strong Only
  • 18 Verification Templates, covering Government ID, Selfie, Document, Database, AAMVA, Phone and Email Verifications
  • 28 Workflows that run the flow’s routing and decisions
  • 1 Account Type

When you add the solution, the Dashboard asks you to confirm enhanced pricing for both Inquiry Templates.

Doc AI or Strong Only: which template to use

The two Inquiry Templates differ in one thing: whether they accept FAIR evidence, such as a bank statement or utility bill.

TemplatePathwaysPick it when
[Verified] IAL2 Framework Doc AIAll fourYou accept FAIR evidence. People who do not have two STRONG documents can add a bank statement and a utility bill, read with Document AI.
[Verified] IAL2 Framework Strong OnlyFirst threeYou accept only STRONG or SUPERIOR evidence. A person who would need FAIR documents ends in a failed Inquiry.

The four pathways

The flow picks a pathway from the documents the person presents.

PathwayEvidenceStepsMeets IAL2 out of the box?
1. REAL ID and AAMVA1 STRONG, validated with the issuerUS driver’s license or state ID, AAMVA Verification, Selfie VerificationYes
2. Passport with NFC chip1 SUPERIORPassport, NFC chip read, Selfie Verification, US Database VerificationYes
3. Passport and driver’s license or ID2 STRONGDriver’s license or ID, passport, Selfie Verification, US Database VerificationNo. Needs changes for full compliance.
4. Government ID, bank statement and utility bill1 STRONG and 2 FAIRGovernment ID, Selfie Verification, US Database Verification, bank statement, utility billNo. Needs changes for full compliance. Doc AI template only.

Pathways 3 and 4 accept documents that cannot be checked with their issuer, such as a non-US license, a license from a state outside AAMVA’s service, or a passport without a chip read. The template treats these as STRONG after a US Database Verification of name, date of birth and address, which keeps more people moving through the flow. IAL2 asks for STRONG evidence to be confirmed with the issuing source, so a general database check is not enough for full compliance.

Each step, labelled

Every pathway starts with a one-time code.

StepLabelWhy
One-time code at the start of the flowRequired by IAL2Revision 3 asks for an enrollment code to confirm the person’s contact details.
Sending that code by email, with phone optionalPersona additionNIST asks for a code, not a channel. Email changes less often than a phone number.
Native mobile flowPersona additionNeeded for barcode capture and NFC, not by NIST. See Mobile, NFC and email 2FA.

Pathway 1: REAL ID and AAMVA

StepLabelWhy
Government ID: US driver’s license or state ID from an AAMVA stateRequired by IAL2Collects STRONG evidence.
The ID must be a REAL ID, with the barcode on the back scannedPersona additionNIST does not name REAL ID. The template uses it as its marker for STRONG, and reads the barcode to detect it.
AAMVA VerificationRequired by IAL2Confirms the license details with the issuing state.
Selfie VerificationRequired by IAL2Confirms the person owns the ID, by comparing a live selfie with the ID photo.

Pathway 2: Passport with NFC chip

StepLabelWhy
Government ID: passportRequired by IAL2Collects the evidence.
NFC chip read, with PKI validation as a required checkRequired by IAL2Validating the chip’s signature makes the passport SUPERIOR evidence. Keep this check required, not optional.
Selfie VerificationRequired by IAL2Confirms the person owns the passport.
US Database Verification (name, date of birth, address)Persona additionIAL2 does not need it when the chip is validated. It adds a further check of the person’s details.

Pathway 3: Passport and driver’s license or ID

StepLabelWhy
Government ID: driver’s license or IDRequired by IAL2First piece of STRONG evidence. It can be non-US, from a state outside AAMVA’s service, or not a REAL ID.
Government ID: passportRequired by IAL2Second piece of STRONG evidence.
Selfie VerificationRequired by IAL2Confirms the person owns the evidence.
US Database VerificationPersona additionStands in for an issuer check so more documents are accepted. It does not replace validation with the issuing source.

Pathway 4: Government ID, bank statement and utility bill (Doc AI template only)

StepLabelWhy
Government ID: passport, driver’s license or IDRequired by IAL2The STRONG evidence. It can be non-US, from a state outside AAMVA’s service, or not a REAL ID.
Selfie VerificationRequired by IAL2Confirms the person owns the ID.
US Database VerificationPersona additionStands in for an issuer check so more IDs are accepted.
Bank statement from the last 90 days, showing name and addressRequired by IAL2The FAIR evidence.
Utility bill from the last 90 days, showing name and addressPersona additionIAL2 needs one FAIR document. The second adds assurance.

The Government ID and Selfie Verifications in every pathway also run Persona’s fraud and quality checks, such as injection detection. Those checks are a Persona addition. The liveness check in the Selfie Verification is also expected by IAL2’s biometric option.

Mobile, NFC and email 2FA

SettingWhat the template doesLabel
Native mobileThe flow runs in the native mobile experience. On iPhone it opens as an App Clip, so people do not need to install an app.Persona addition. Barcode capture is hard on a webcam and NFC only works on a phone.
NFC chip readingReads the chip in a passport and validates its signature. See Collecting Passports and other IDs using NFC.Required by IAL2 for the SUPERIOR pathway.
Email 2FASends a one-time code by email at the start of the flow. Phone is available as an option. See Email (2FA) Verification.The code is required by IAL2. Choosing email is a Persona addition.

Add the solution to your Sandbox

  1. In the Dashboard, switch into your Sandbox environment.
  2. Select Home in the navigation bar.
  3. On the Home page, click Explore all solutions.
  4. Find IAL2 framework templates, then click Add to sandbox.
  5. Confirm enhanced pricing for the two Inquiry Templates when the Dashboard asks.
  6. Click the solution to see its setup checklist.

The setup checklist walks you through four steps:

  1. Choose [Verified] IAL2 Framework Doc AI or [Verified] IAL2 Framework Strong Only, depending on whether you accept FAIR evidence.
  2. If you are legally required to meet IAL2, apply the changes in Making the flow fully IAL2 compliant.
  3. Optionally, apply a theme to match your brand.
  4. Publish the template, then point your Workflows and API integrations at it.

For more on adding and customizing a solution, see Add a solution. Test the flow before you go live, using Testing your Inquiry Template.

Making the flow fully IAL2 compliant

To be fully compliant, every piece of STRONG evidence must be confirmed with its issuing or an authoritative source. These changes close the gaps in pathways 3 and 4.

DocumentCounts asWhat to change
Non-US driver’s license or IDSTRONG only if Persona can check it against an issuing or authoritative source in that country. Otherwise FAIR.Pick one: accept only US licenses and IDs from AAMVA states; add an international Database Verification for each country you accept; or count these documents as FAIR and require other STRONG evidence.
US REAL ID from a state outside AAMVA’s serviceOpen to interpretation. The REAL ID designation makes STRONG defensible, but the details cannot be checked with the issuer.For full compliance, count it as FAIR.
US license or ID from a state outside AAMVA’s service, not a REAL IDFAIR only.Count it as FAIR, and require other STRONG evidence.

Also confirm that the NFC chip’s PKI validation stays a required check in pathway 2. The pathway relies on that check to treat the passport as SUPERIOR evidence.

Persona provides the components for an IAL2 flow. Your compliance team decides whether your configuration meets your obligations.

Settings that need a Persona teammate

Most of the solution is self-serve. Two things may need your Persona account team:

  • Phone 2FA service. The Phone Verification’s delivery service cannot be set from the Dashboard, so a Persona teammate finishes it if you want to offer phone codes. Email 2FA, the default, works without this.
  • Enhanced pricing. The Inquiry Templates use enhanced pricing. If you are unsure what that means for your contract, check with your account team before you go live.

TEFCA

If you are a TEFCA Individual Access Services provider, use the separate TEFCA solution instead. It installs [Verified] TEFCA IAL2 with an OIDC Authentication Template, adds patient matching fields, and is stricter about which licenses it accepts. See TEFCA Individual Access Services (IAS).

To learn more or request access, let us know. We're happy to help.

Was this page helpful?If something is missing, let us know and we will take a look.
Thanks for the feedback. It helps us improve these docs.