ETSI TS 119 461 is a technical specification by the European Telecommunications Standards Institute that sets policy and security requirements for identity proofing performed as part of a trust service.
Identity proofing establishes, with a required degree of reliability, that an applicant’s claimed identity is correct. The process may involve identity documents, electronic identification, trusted registers, digital signatures, biometric face comparison and other supporting evidence.
The current published version is ETSI TS 119 461 V2.1.1, issued in February 2025. ETSI is developing a European standard based on it, currently titled ETSI EN 319 461. The July 2026 version is still a draft under review and may change before publication.


ETSI TS 119 461 gives trust service providers and identity proofing service providers a structured way to establish that an applicant is connected to a genuine identity.
The applicant may be a natural person, a legal person or an individual acting on behalf of a legal person. A company representative, for example, may need to prove both their own identity and their authority to act for the organization.
Identity proofing may be carried out directly by a trust service provider. It may also be handled by a specialist identity proofing service provider working as a subcontractor. The trust service provider remains responsible for the trust service in which that proofing component is used.
The distinction matters because identity proofing is not defined by eIDAS as a standalone trust service. It is a component that supports services such as certificate issuance, electronic signatures and electronic attestations of attributes.
The specification is written for trust service environments. Its principles can also inform identity verification in banking, telecommunications, government and other regulated fields. Using it outside its formal scope requires the organization to define the relevant legal context, evidence and assurance requirements.
Identity proofing takes place when an organization needs to establish who an applicant is before issuing an identity, credential, certificate or trusted account.
It differs from authentication. Identity proofing usually happens during enrollment while authentication happens later when the enrolled person returns and proves that they are the legitimate user of the account or credential.
A secure login cannot repair a weak enrollment process. When an impostor successfully registers under another person’s identity, strong authentication may simply protect the fraudulent account from everyone except the impostor.
Identity proofing therefore needs to answer several questions.
The identity must exist. The evidence must be valid. The attributes obtained from that evidence must be accurate enough for the intended purpose. The applicant must be the legitimate holder of the evidence. The organization must also retain enough information to explain and, where required, recheck the decision.
These requirements make identity proofing broader than scanning an identity card or comparing a selfie with a document portrait.
ETSI TS 119 461 divides identity proofing into five common tasks.
The first task is initiation. The service establishes the identity proofing context and begins the applicant’s journey.
The second task is attribute and evidence collection. Attributes may include a name, date of birth, nationality, address or organizational role. Evidence may include an identity document, electronic identity, digital signature, register record or attestation.
The third task is validation. The service checks whether the evidence and the attributes obtained from it are authentic, current and suitable.
The fourth task is binding. The process establishes that the evidence belongs to the person or organization applying.
The fifth task is issuing the identity proofing result. The result identifies the level achieved and provides the information required by the trust service receiving it.
The tasks do not always happen in a fixed order. Document capture may collect and validate information at the same time. A process may also be synchronous or asynchronous. Some evidence can be checked after the original user session has ended.
ETSI TS 119 461 defines two Levels of Identity Proofing known as Baseline and Extended.
Each level represents a set of requirements for evidence collection, validation, binding, risk management and operation.
Baseline is the general purpose level. It applies where identity proofing supports ordinary trust service use and the consequences of an incorrect decision are contained. Extended, on the other hand, is intended for situations requiring stronger assurance. It is relevant to qualified certificates and qualified electronic attestations of attributes under the amended eIDAS framework.
The levels should not be treated as simple product labels. A service does not reach Extended level merely by enabling an additional biometric check. The achieved level depends on the complete process. Evidence quality, capture security, staff procedures, attack resistance, audit records and handling of exceptions all contribute to the result.
The identity proofing context determines which level is required. This context may be influenced by legislation, the type of trust service, accepted documents, transaction risk and the consequences of an incorrect identity decision.
No. A Level of Identity Proofing under ETSI TS 119 461 describes the result of the broader identity proofing process. An eIDAS Level of Assurance describes the assurance associated with an electronic identification means. The recognized levels are low, substantial and high.
An existing electronic identification means can be used as evidence within an ETSI identity proofing route. For a route targeting Baseline identity proofing, the specification requires an accepted electronic identification means to provide at least assurance equivalent to eIDAS substantial. For a route targeting Extended identity proofing, the electronic identification means must provide assurance equivalent to eIDAS high.
The specification also allows an identity established through an electronic identification means at substantial level to be enhanced from Baseline to Extended through additional proofing.
These terms should not be used interchangeably. An electronic identity’s assurance level is one input to the process. The Level of Identity Proofing describes the final proofing outcome.
The specification distinguishes authoritative evidence from supplementary evidence.
Authoritative evidence is the primary basis for proving an identity. A passport, national identity card, recognized electronic identity or trusted register may serve this role when accepted by the identity proofing context.
Supplementary evidence strengthens or completes the process. It may include another document, a register lookup, a digital signature, an electronic attestation or proof that the applicant controls a bank account, phone number or email address.
Proof of access does not establish identity by itself in every situation. It shows that the applicant controls the item or account being checked. The service must decide what identity attributes can reliably be obtained from that source.
ETSI TS 119 461 requires procedures for resolving discrepancies. A name from a bank record may differ from the name shown on an identity document. The service needs documented rules for determining which evidence has authority and when a case must be reviewed.
A single still image of a physical identity document is not considered sufficient under the current specification for remote proofing to Baseline or Extended level.
The applicant must present the physical document in real time in front of a camera. The process needs to establish that the document is physically present rather than supplied as a prerecorded image or video.
The capture should provide enough visual information to assess the document and its security features. A video sequence may show changes in optical features as the applicant moves the document. Both sides of an identity card may need to be recorded.
The specification requires adequate frame rate, image resolution, sharpness and lighting. It also calls for protection against prerecorded, artificially generated or digitally injected document footage.
This requirement is stricter than many ordinary document upload journeys. A service designed around one static photograph should not be presented as meeting these remote document requirements without further analysis.


The specification does not require automated facial recognition in every use case. Manual face comparison can be used in certain physical or attended remote processes. Automated face biometrics can be used alone or together with manual comparison in other routes.
The specification provides detailed requirements for binding an applicant through face biometrics and manual face verification. It does not provide equivalent detailed use cases for fingerprint, iris or palm biometrics. These modalities are not prohibited, but their use is not specified in the same way.
ETSI TS 119 461 sets specific requirements for biometric injection attack prevention and detection.
For Baseline identity proofing, the injection attack detection technology must be tested by an accredited laboratory to the applicable Substantial level under the referenced injection attack testing specification by the end of 2026. For Extended identity proofing, the corresponding High testing level is required by the same deadline.
The external evaluation must be repeated at least every two years. The provider must also continue updating its protections according to current risk intelligence. Passing one laboratory evaluation does not remove the need to respond to new attack methods.
The specification treats deepfakes as content that can be combined with either a presentation attack or an injection attack. A generated face might be played on a screen in front of the camera. It might instead be inserted directly into the digital capture channel through a virtual camera, modified application, emulator or compromised device.
The process must therefore examine both the content and its origin.
Facial appearance should be checked for signs of artificial generation or manipulation. The capture route should also provide confidence that the incoming video comes from the expected live sensor.
The same concern applies to identity documents. An attacker may generate or alter a document image and inject it into the process. The standard calls for measures able to detect artificially generated or manipulated document content at the relevant attack potential.
Trust service providers are the most direct users. They may apply the framework when issuing qualified certificates, electronic signature credentials and electronic attestations of attributes.
Banks and fintech companies can draw on its controls when designing remote onboarding with a high level of evidential reliability. Telecommunications providers can apply similar principles during regulated subscriber registration. Government agencies may use the framework when issuing digital identities, professional credentials or access to public services.
Education and employment services can use trusted identity proofing before issuing or accepting digital qualifications. Healthcare systems may apply it when a professional or patient identity must be reliably connected with a digital credential.
The formal applicability of ETSI TS 119 461 depends on the service and regulatory context. Its broader value lies in showing how evidence, biometrics, security and auditability can be combined within one identity decision.
Innovatrics Identity Verification technology includes document capture, data extraction, electronic document reading, face verification, liveness detection and video injection detection. These components can support evidence collection, document validation and binding of the applicant to the identity document.
Document capture can guide users toward usable images and video. NFC functionality can read and validate information from supported electronic documents. Face verification can compare the live applicant with the trusted document portrait. Liveness and injection protections address different forms of impersonation and digital substitution.
The technology does not make an entire service compliant by itself. The deployed organization must still define the accepted evidence, applicable Level of Identity Proofing, review procedures, retention policies, risk controls and conformity assessment route.
The starting point should be the purpose of the identity proofing process. Teams need to determine which law and trust service rules apply. They need to choose the required Level of Identity Proofing and the use case through which it will be achieved.
Accepted identity documents and electronic identities must be defined in the identity proofing practice statement. The service should distinguish authoritative evidence from supplementary evidence.
Document capture must reflect whether the document is physical or digital. Remote face capture needs presentation attack detection, manipulated media detection and injection protection. The process needs procedures for uncertain results, inconsistent attributes, unsupported documents and applicants who cannot complete the standard journey.
Evidence retention must support audit needs without exceeding legal and privacy limits. Independent assessment should review the complete service rather than isolated technical modules.
Remote identity verification can look simple to the applicant. Behind the interface, the service must answer difficult questions about evidence, ownership, attack resistance and accountability.
A genuine document may be presented by the wrong person. A realistic face may be generated or replayed. An apparently live camera stream may have been replaced before it reaches the verification engine.
ETSI TS 119 461 brings these risks into one structured identity proofing framework. It defines what must be collected, how evidence should be validated, how an applicant can be bound to that evidence and what proof should remain after the decision.
Its growing role in EU implementing regulations also gives it practical relevance for qualified trust services and European digital identity. The result is not a guarantee that identity fraud becomes impossible. It is a clearer basis for building, testing and assessing a process that another organization can reasonably trust.