PR.AA-02.198
Does your organization verify individuals' identities during enrollment using government-issued credentials?
Explanation
This question assesses whether your organization validates the true identity of users during initial account creation or enrollment by requiring government-issued identification documents like passports, driver's licenses, or national ID cards. This verification process helps prevent identity fraud, account takeovers, and ensures only legitimate users gain access to your systems and services. Evidence of compliance could include documented identity verification procedures, screenshots of identity verification prompts in your enrollment workflow, audit logs showing identity verification steps completed, or contracts with third-party identity verification service providers.
Implementation Example
Verify a person's claimed identity at enrollment time using government-issued identity credentials (e.g., passport, visa, driver's license)
ID: PR.AA-02.198
Context
- Function
- PR: PROTECT
- Category
- PR.AA: Identity Management, Authentication, and Access Control
- Sub-Category
- Identities are proofed and bound to credentials based on the context of interactions

