Join our Newsletter — 33% off our NHI Course

How should DMVs implement online identity proofing without making access harder for legitimate users?

DMVs should treat online identity proofing as a balance of assurance, usability, and privacy. The first step is to define the risk level of each transaction, then use verification methods that confirm the person is real, present, and authenticating in the moment. Strong identity checks should be paired with accessibility, fraud resistance, and clear user journeys so digital services remain usable.

How to Keep Assurance High Without Turning Proofing Into a Dead End

DMVs should treat online identity proofing as a risk-tiered service, not a single gate for every transaction. Low-risk requests can use lighter checks, while higher-risk actions need stronger evidence that the applicant is real, present, and controlling the session in the moment. That approach protects the state from fraud without forcing every legitimate user through the same friction.

A useful way to design the experience is to separate proofing strength from service usability. The proofing flow should ask for only the evidence needed for the specific transaction, and it should make the next step obvious, recoverable, and accessible. If a user fails, the system should explain what went wrong and let them continue through a supported path rather than leaving them stranded.

For the strongest assurance, DMVs should combine document validation, liveness checks, and transaction-aware step-up controls. The point is not to stack every possible control everywhere, but to match the method to the fraud impact. Identity Proofing and KYC Guide is a useful reference for the balance between assurance levels, document checks, and presentation-attack resistance.

Where Legitimate Users Get Stuck

Legitimate users usually do not struggle because they lack intent, they struggle because the proofing process is brittle. Common failure points include poor image capture, inaccessible interfaces, unclear retry instructions, timeout-heavy flows, and verification methods that do not work well for users with disabilities, older devices, or unstable connectivity. If the process is harder than the transaction justifies, completion rates fall and service desks absorb the fallout.

DMVs should expect that some users will need alternates such as assisted verification, in-person fallback, or deferred completion for edge cases. The design goal is graceful degradation, not one perfect digital path for every person. Transaction design also matters: if a user is only changing a mailing address, the proofing burden should be materially lower than if they are replacing a credential or recovering an account.

Good UX here is not cosmetic. It is a control that reduces avoidable abandonment, repeat submissions, and support-driven workarounds that can create new fraud opportunities. The most effective systems make the secure path the easiest path for the majority of users while preserving a clearly defined escalation path for higher-risk cases.

Identity and access design guidance is also relevant because proofing depends on how the DMV binds a person to an account and how it handles authentication after enrollment. Customer IAM (CIAM) Guide and IAM and IGA Basics both reinforce the need to keep authentication, recovery, and access governance aligned with user experience.

What a DMV Should Measure and Tune

DMVs should measure proofing as an operational funnel, not just as a security control. The important signals are completion rate, abandonment rate, manual review rate, false rejection rate, fraud capture rate, average time to complete, and the share of cases routed to fallback channels. Those metrics tell you whether the process is actually balanced or merely strict.

When false rejections rise, the first question should be whether the control is too coarse for the transaction type, the population, or the device conditions being used. When fraud rises, the question should be whether the proofing method is strong enough for the risk tier, whether attackers are bypassing the session, or whether recovery paths are easier to abuse than the main flow.

Program governance matters as much as the proofing tool itself. Teams should review proofing outcomes by transaction type, demographic segment, and channel so they can spot disproportionate friction or weak spots. Access Reviews and Certification Guide is helpful for the broader governance lesson, the control should be continuously tuned from real outcomes, not left as a one-time policy decision.

Risk and Threat Considerations

Online proofing creates two opposite risks at once, fraud if the checks are too weak, and exclusion if they are too strict or brittle. The threat is not only impersonation, but also abuse of weak recovery paths, bot-driven enrollment attempts, and session manipulation that makes a legitimate person look untrusted or a fraudulent one look verified.

Failure mechanism: A DMV either over-trusts a low-assurance signal or forces a control stack that real users cannot reliably complete, so attackers exploit gaps while legitimate users fall out of the process.

Impact: Weak proofing can enable identity fraud, account takeover, or fraudulent credential issuance, while excessive friction drives abandonment, support cost, and unsafe workarounds that undermine the digital service.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, OWASP ASVS and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 IA-8 — Identification and Authentication (Non-Organizational Users) DMV online proofing concerns external users seeking state services.
IA-12 — Identity Proofing The question is explicitly about online identity proofing for citizens.
AC-7 — Unsuccessful Logon Attempts Repeated failed proofing attempts need throttling and safe recovery paths.
Recommendation — Apply IA-8 to authenticate external applicants before granting online access or issuing credentials. Use IA-12 to set proofing strength by transaction risk and evidence quality. Limit repeated failures and route users to controlled recovery when proofing attempts keep failing.
OWASP ASVS V6 — Authentication Identity proofing feeds the authentication journey that follows enrollment.
Recommendation — Verify that authentication strength and recovery paths align with the proofing assurance level.
NIST SP 800-63 IAL2 — Identity Assurance Level 2 Online DMV proofing commonly maps to assurance levels for remote identity verification.
Recommendation — Set the required assurance level by transaction risk and accept only evidence that meets it.

Practitioner Guidance

What to prioritise: Start with transaction risk classification, then define which proofing method is acceptable for each risk tier. If every transaction gets the same proofing burden, the program will either be too weak to stop fraud or too strict to be usable.

What to verify: Verify that the flow works on real devices, supports accessibility needs, and has a clear recovery path when verification fails. A proofing design is not production-ready until a legitimate user can complete it without hidden dependencies or repeated manual intervention.

Decision rule: If the request can create or change a high-value credential or credential-equivalent status, require stronger proofing and tighter step-up controls; if it is a lower-risk service request, minimise friction and preserve a supported fallback channel.

Practitioner takeaway: The right DMV proofing model is risk-based and recovery-aware, because the goal is not maximum friction, it is the lowest-friction process that still resists fraud at the chosen assurance level.