| Layer | What you can state | What is still unresolved |
|---|---|---|
| Capture | The submitted content can be read | Whether it faithfully represents an original |
| Consistency | The fields satisfy the rules checked | Whether the source is genuine |
| Authenticity | The document's origin and integrity are supported by appropriate evidence | Whether the presenter is its rightful holder |
| Holder binding | Appropriate evidence connects the presenter to the identity | Whether the identity is eligible for the requested service |
A practical example
Your onboarding form accepts a nine-character string and a date. The values have the right length and calendar format. You have established that the form accepted those values. You have not established that a document exists, that the values were issued, or that they identify the person using the form.
The evidence ladder is an editorial model for documenting conclusions. It is not a certification framework. NIST's identity-proofing guidance separately addresses evidence validation and identity verification, which supports keeping document checks and applicant binding distinct. NIST SP 800-63A-4: identity proofing
Write the result at the right level
| Avoid | Prefer |
|---|---|
| Valid ID | Required fields passed the configured syntax checks |
| Verified person | Presenter-to-evidence check completed under the stated process |
| Fake document | Observed mismatch requires review |
| Secure upload | File accepted under the stated size and type rules |
Attach a method and a scope to every result. A report that says “passed” without saying what was tested is difficult to interpret and easy to misuse. If a tool did not inspect an authenticity signal, it should not imply that the signal was inspected.
Choose a next step
- If the image is unreadable, fix the capture before interpreting a feature.
- If fields are inconsistent, inspect the exact rule and original source of the values.
- If provenance is unresolved, use an approved authenticity process appropriate to the document.
- If holder binding is unresolved, follow the applicable identity-proofing process.