Join our Newsletter — 33% off our NHI Course

Attestation-Only Model

An attestation-only model retains only the minimum evidence needed to support the identity decision and destroys raw verification data after a short period. It reduces privacy exposure, but it must still preserve enough assurance for the workforce use case and the associated risk level.

What the attestation-only model is designed to preserve

An attestation-only model keeps just enough evidence to justify the identity decision, then deletes the raw verification material quickly. The core idea is not to eliminate assurance, but to retain only the minimum proof needed for the use case and its risk profile.

This model is usually chosen when the organisation wants to reduce exposure of source data, such as biometrics or other verification artefacts, while still being able to show that the original decision was made on a defensible basis. The retention boundary is therefore part privacy control, part assurance design.

How attestation differs from full verification retention

In a fuller retention model, the system may keep raw documents, images, or other verification inputs so they can be rechecked later. In an attestation-only model, those inputs are discarded after validation and replaced by a smaller record, typically a result, reference, or proof that the check occurred.

That difference matters because the retained artefact is no longer the evidence itself, but a statement about the evidence. The model depends on the strength of the original verification process, the integrity of the attestation record, and the organisation’s ability to explain why the retained record is sufficient for the decision it supports.

The approach is often aligned with privacy-by-design thinking because it reduces the volume and sensitivity of stored data. At the same time, it creates a dependency on process quality: if the original check was weak, the organisation cannot recover confidence later from data it no longer holds.

Where the assurance boundary can break down

An attestation-only approach is strongest when the decision is low to moderate risk and the organisation can tolerate limited post-event revalidation. It is weaker when later disputes, regulatory reviews, or fraud investigations may require the original artefacts rather than a summary of them.

The practical question is whether the retained attestation can support the full lifecycle of the identity decision, including audit, dispute handling, and risk review. If it cannot, the model may still be privacy-preserving, but it may no longer be operationally sufficient.

For workforce identity use cases, the evidence threshold should reflect the access being granted. A low-friction onboarding flow may justify minimal retention, while higher-risk access decisions need a stronger retained assurance trail even if the raw data itself is not kept.

When practitioners should use it

Why practitioners should care: The attestation-only model is a deliberate trade-off between privacy exposure and later revalidation ability. It is most useful when the organisation wants to minimise stored sensitive material without weakening the original identity decision beyond what the use case can tolerate.

Common misunderstanding: minimal retention does not mean minimal assurance. The retained record still has to prove that the verification process was trustworthy enough for the business risk involved, otherwise the model only hides evidence rather than governing it.

Practitioner takeaway: Use attestation-only retention when the decision can be safely supported by a short-lived proof trail, and avoid it where future challenge, fraud review, or high-assurance rechecking is likely to matter.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63 and NIST SP 800-53 Rev 5 set the technical controls, while GDPR defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-63 Digital Identity Guidelines Defines identity assurance and evidence handling for identity decisions.
Recommendation — Choose an assurance level that matches the retained evidence and the workforce risk.
GDPR A.5.1 — Purpose limitation Supports collecting and retaining only the evidence needed for the identity purpose.
A.5.2 — Data minimisation Directly supports deleting raw verification data after a short, justified period.
Recommendation — Limit retained verification data to what is necessary for the stated identity purpose. Minimise retained verification artefacts and delete raw data once attestation is established.
NIST SP 800-53 Rev 5 IA-2 — Identification and Authentication (Organizational Users) Covers user identity verification and the assurance behind access decisions.
IA-5 — Authenticator Management Supports lifecycle handling of proof material and related authenticators.
Recommendation — Match user authentication strength to the assurance needed for the access decision. Control the lifecycle of retained evidence and authenticators so obsolete material is removed promptly.