Skip to main content

Conforming with the Identification Standards

Use this guidance to learn the types of conformance and the process for getting assessed. Use the tools to gather the evidence needed for assessment.

Conformance and mandates

To conform with each of the Identification Standards, ALL the controls will be met.

Voluntary conformance by any party wishing to follow good practice for contributing to the prevention of identity theft and fraud, will be against the levels indicated by undertaking a risk assessment.

Mandated conformance with the Identification Standards is specified through mechanisms such as contracts, cabinet mandates and legislation. The following mandate currently applies:

Conformance with one or more of the Identification Standards is a requirement for Digital Identity Services Trust Framework (DISTF) accreditation.

Accreditation of digital identity providers and services — Public Service Commission

Types of conformance

Conformance with standards brings consistency and good practice to products and services. It’s a key element to building consumers’ trust in the use of products and services.

There are 3 types of conformance:

Self-assessment

Qualified assessment

Audited assessment

Deciding on a conformance type

The type of assessment being undertaken impacts who is involved and what’s produced at the end of it. The options are:

  • self-assessment — can be done at any time and does not involve an assessor or the formal conformance process
  • qualified assessment — light conformance process that results in informal advice provided by an assessor about the degree to which conformance may be achieved and to what Levels of Assurance
  • audited assessment — robust conformance process that results in an Identification Standards Conformance Certificate being issued.

Schedule an assessment

Contact the Identification Team at idmstandards@gdda.govt.nz to schedule qualified or audited assessments.

The conformance process

The formal conformance process occurs in 3 key stages:

For help at any point throughout these stages contact the Identification Team at idmstandards@gdda.govt.nz.

Stage 1 — Introduction and scoping

The first stage of applying the Identification Standards or seeking conformance is to understand which role and standards are relevant.

Understanding identification roles

There are 3 roles when applying the Identification Standards – Relying Party (RP), Credential Provider (CP) and Facilitation Provider (FP).

Most organisations will be a Relying Party at some point in what they do.

Anyone who enrols Entities (people or otherwise) and creates records or accounts for them is a Relying Party.

Diagram 1: Identification roles and their relationship

Diagram depicting the roles, artefacts and processes that make up identification management.

Detailed description of diagram

This diagram depicts how the elements in identification management work together.

An Entity (for example, a person) wants to get a Credential that they can use to get a service from a Relying Party (for example, an organisation). The Entity goes to a Credential Provider to get an applicable Credential and then either presents their Credential directly to the Relying Party or uses a Facilitation Provider to assist in the presentation.

View larger image (73KB)
Descriptions of the roles, artefacts and their relationships

It’s common to hold more than 1 identification role.

Examples of multiple roles
  • A Credential Provider will also be a Relying Party when they’re enrolling Entities before issuing their own Credential.
  • A Credential Provider will also be a Facilitation Provider if they’re involved in the presentation of their Credentials.
  • A Facilitation Provider can become a Credential Provider if they create their own Credential.

Understand which standards apply

The identification role and the processes being carried out indicate which of the 5 Identification Standards should be applied.

Identification Standards

Table 1 describes the broad identification processes undertaken by each accountable party and the applicable Identification Standards.

Table 1: Which standards to apply when
Accountable parties and processes Applicable standard

Relying Parties enrol Entities by:

  • collecting and verifying information
  • linking the information to the Entities
  • establishing Authenticators to recognise them when they return.

Credential Providers:

  • enrol Entities as a Relying Party
  • issue Credentials for use across multiple contexts
  • establish Authenticators for Credentials.

Facilitation Providers present credentials by:

  • establishing facilitation mechanisms with Authenticators
  • passing information through these to Relying Parties.

Authentication Providers:

  • provide Authenticators and Authentication services to Relying Parties, Credential Providers and Facilitation Providers.

Stage 2 — Providing evidence and being assessed

The second stage involves gathering evidence about how the individual controls in each relevant standard are being applied, and having that evidence assessed to see that all controls are met.

This process is the bulk of work and time, and is an iterative process involving information and communication back and forth with the assessor.

Risk Assessment

Assessing risk is integral to being able to apply the Identification Standards correctly. Risk assessment determines which Levels of Assurance to apply for certain controls.

While any risk assessment process can be used, more information is available in the following guidance:

Assessing identification risk

Identification risk assessment should be done as early as possible and provided to the assessor. The feedback on these will help to ensure that the conformance process is on the right track.

Privacy impact assessment

Products or services using information will need to manage information privacy risks when the information is processed.

The information in scope may be personal information relating to people, or information relating to non-person Entities that is commercially sensitive or require specific security measures (for example, business details of a company, security information of computer infrastructure, the physical location of protected animals).

Documenting information privacy risks and how they will be controlled is a crucial step to build security and privacy by design into the product or service. Doing this early will help design the product or service correctly, prevent expensive rework later in development and contribute to conformance with several identification controls.

Completing information privacy risk assessments early, such as a Privacy Impact Assessment, helps to guide the development of a product or service. These assessments should also be provided to the assessor as soon as available.

For Privacy Impact Assessments regarding people, the Office of the Privacy Commissioner has guidance on how to complete these and a template to work through the privacy impacts for the product or service being assessed.

Privacy Impact Assessments — Office of the Privacy Commissioner

For non-person Entities, a similar document should be created. It could use many of the same Information Privacy Principles as these are still relevant to non-person Entities.

Applying the relevant standard controls

Applying the controls in each of the relevant standards is the main part of the journey to conformance.

Meeting certain Levels of Assurance can mean changes need to be made to some systems and processes. These may not be easy or fast to implement. If the planned Levels of Assurance cannot be met, decisions will need to be made about the impact of meeting a lower level of assurance.

Levels of Assurance

If the target Levels of Assurance are unable to be met, options include:

  • carrying out additional work to reach the target Levels of Assurance; or
  • electing to operate at lower Levels of Assurance.

The latter option does not prevent continuing to work on the aspects that need improvement and seeking reassessment later.

Contact the Identification Team for advice at idmstandards@gdda.govt.nz on different options.

Each of the Identification Standards has an implementation guide which provides more information about how to apply the controls and examples.

Identification Standards

Documenting evidence for assessment

There are 3 options for documenting evidence for assessment.

1. Notating existing documents

Where the evidence for assessment is in existing documentation, clear cross-referencing to the controls in the Identification Standards is essential. Examples of clear cross-referencing include:

  • annotating text with comments that reference the control number being met
  • combining information together under headers or sub-headers that reference the control number
  • providing a table listing each relevant control and a reference to the section and page number where the evidence of the control being met is documented.

Any information that’s not to be disclosed for the conformance process can be redacted or removed.

2. Creating new bespoke documents

Organisations may wish to extract the relevant information into new documents. If a new document is created, the new document can use the cross-referencing techniques in the section above to evidence how controls are being met.

3. Using our checklists

A series of checklists are available to help with collating evidence. They outline the types of evidence that is needed, list each of the controls and provide space to write how each control is being met.

Where a qualified assessment was requested, the assessor will not need the detailed documentation used for a full audit. The level of documentation needed for the lighter assessment will be discussed when scheduling an assessment.

You do not need to have all documentation complete for assessment to commence. Documents can be sent progressively, for early feedback on progress.

Being assessed

The assessment process begins when a document or evidence is submitted to the assessor for assessment. An early draft of a document can be sent for feedback before formal assessment begins, if this is made clear to the assessor beforehand.

Documents and evidence will include risk assessments, privacy impact assessments, functional and design documents, checklists or any other documents that describe how the controls are being met.

The assessor will review the evidence as it is submitted and provide progress updates and feedback.

The assessor may require additional information about the service or product being assessed, such as further evidence about how the controls are being met or levels of assurance. Swift responses to requests for more information will ensure that the assessment continues to progress.

Stage 3 — Demonstration and assessment outcome

The third stage involves a demonstration of the service to the assessor and the outcomes from the assessment and demonstration.

If a self-assessment is being undertaken, this stage is not needed.

Doing a demonstration

To confirm that the identification processes within a product or service operate according to the documentation provided, the assessor will request a physical demonstration.

The demonstration will show the lifecycle of the product or service from beginning to end. The assessor will ask for specific aspects of the product and service to be demonstrated.

Examples of what a demonstration will show include:

  • the information collection and binding processes
  • if the product is a credential, how the credential is issued, revoked and cancelled
  • metadata generated by the product or service the collateral and location of where levels of assurance are declared.

Assessment outcome

At the end of the assessment process the organisation being assessed will have an opportunity to discuss the assessment before one of the following final documents is issued.

Advice
Certificate

Re-conformance

Both advice and conformance certificate are issued at a point in time. There are several things that may make it necessary to apply for re-conformance:

Certificate expiry

Change made to a product or service

Changes to the Identification Standards

Outcome of a complaint

We’re here to help

For all enquiries, requests, and assessment booking, please contact the Identification Team at the Government Digital Delivery Agency (GDDA) at idmstandards@gdda.govt.nz.

In addition to advice on conformance, we can also help with the following aspects:

  • Reviewing identification risk assessments and suggesting improvements
  • Interpreting and applying the Identification Standard controls
  • Suggesting alternative ways to design processes
  • Advising on options if controls cannot be met.

The Identification Team also provides training and clinics to help develop identification capability. It’s strongly recommended that people seeking conformance undertake the training.

Training and clinics

Utility links and page information

Was this page helpful?
Thanks, do you want to tell us more?

Do not enter personal information. All fields are optional.

Last updated