Audit an existing identity proofing integration and replace KBA with compliant NIST 800-63A-4 alternatives

domain: pages.nist.gov · 6 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Inventory all identity proofing touchpoints in the application: locate any step that uses static or dynamic KBA questions (mother's maiden name, street address history, previous vehicle) as a verification or authentication factor.
  2. Classify each KBA use: authentication-step KBA is entirely prohibited under NIST 800-63B-4; proofing-step KBA is only permitted as a single Fair-level evidence supplement for identity resolution, not as the primary verification binding.
  3. Replace authentication-step KBA with a FIDO2 passkey, OTP (TOTP or SMS), or push authenticator to achieve AAL2; document the authenticator type and assurance level in the system security plan.
  4. For remote IAL2 proofing, replace KBA-based identity binding with biometric comparison: capture a selfie, run a face match against the document portrait, and run liveness/PAD detection; this combination satisfies the binding requirement in 800-63A-4.
  5. Update the Digital Identity Acceptance Statement or equivalent documentation to reflect the new xAL configuration and the evidence strength for each proofing pathway.
  6. Conduct a regression test with edge-case users (hyphenated names, non-Latin characters, thin-file individuals) to confirm the replacement proofing path does not introduce unacceptable failure rates.

Known gotchas

Related routes

Implement remote IAL2 identity proofing evidence collection and validation per NIST 800-63A-4
pages.nist.gov · 6 steps · unrated
Configure Knowledge-Based Authentication (KBA) as a recipient identity-verification method on a DocuSign envelope
developers.docusign.com · 5 steps · unrated
Configure an identity proofing flow's evidence requirements to meet NIST SP 800-63-4 IAL2 for a regulated onboarding product
pages.nist.gov · 5 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans