Built to
The standards behind registers and identity
Identity assurance levels across NIST, TDIF, GPG 45 and eIDAS; consuming the accredited scheme rather than rebuilding it; data minimisation; tell us once; public registers with suppression; natural justice; record integrity; governed entity resolution; statutory clocks.
Assurance levels mapped
What each register requires, in every framework's terms
| NIST 800-63-4 | TDIF / Digital ID Act | GPG 45 | eIDAS 2.0 | Used here for |
|---|---|---|---|---|
| IAL1 | IP1 (self-asserted) / IP1 Plus | Low | Low | Animal registration; public extracts |
| IAL2 | IP2 / IP2 Plus (verified documents, binding) | Medium | Substantial | Business names, associations, practitioners; a subject's own full record |
| IAL3 | IP3 (in-person or biometric binding) | High | High | Reserved for registers the Act names |
Standards
| Standard | Source | Requirement | Where it shows up here |
|---|---|---|---|
| Identity assurance levels | NIST SP 800-63-4 (IAL1/2/3); TDIF and the Digital ID Act 2024 (AU, IP1..IP4); GPG 45 (UK, low/medium/high); eIDAS 2.0 (EU, low/substantial/high); ISO/IEC 29115 | Record the level of assurance reached, how, and when; require only the level the transaction needs. | Every identity carries level and source; each register declares the level it requires; the assessment cites the gap (GL-RG-03). |
| Consume the scheme, don't rebuild it | Digital ID Act 2024 and TDIF accreditation (AU); GOV.UK One Login; EU Digital Identity Wallet | Verify through the accredited scheme with consent; store the assertion, not the documents. | The identity agent calls the scheme only with recorded consent and stores the attributes asserted and the level reached; no document images anywhere (GL-RG-03). |
| Data minimisation and purpose | APP 3, 6 and 11 (AU); GDPR arts 5 and 6; ISO/IEC 27701 | Collect what the register needs, use it for the register's purpose, share by rule. | Public fields are declared per register; a full record needs the subject at IAL2 or a basis the rules allow (GL-RG-06). |
| Tell us once / once-only | Digital Service Standard (AU); GDS Service Standard; EU Single Digital Gateway once-only principle | One identity across services; a change told once propagates with its source. | Identity links MG-01, MG-02, MG-03, MG-04 and MG-05 records; a correction propagates and records where it came from (GL-RG-07). |
| Statutory registers and public access | Register provisions in business names, associations, practitioner and animal legislation; open government policy | A public register with the fields the Act names, kept current, with suppression where safety requires. | `/register-search` shows only the declared public fields; suppressed entries withhold address and contact; only the registrar lifts suppression (GL-RG-05). |
| Natural justice before adverse action | Administrative law; show-cause provisions in registration Acts | Notice of the proposed deregistration or suspension, a chance to respond, a decision by a person with reasons and review rights. | The sweep drafts the grounds and issues show cause; the registrar cannot decide while the period is open without a response (GL-RG-01). |
| Record integrity and history | Public records legislation; ISO 15489 records management; ISO 8000 data quality | Nothing overwritten; every change with before, after, reason, actor and source; evidentiary extracts verifiable. | EntryChange rows for every change (GL-RG-04); certified extracts carry a hash verifiable against the register. |
| Entity resolution as a governed decision | Fellegi-Sunter probabilistic matching; national data-linkage guidelines; ABS data integration principles | Show the matchers and the score; a person confirms before records are merged. | Candidate duplicates are scored and held with their matchers; only the registrar merges (GL-RG-02). |
| Statutory timeframes | Decision periods in registration Acts | Decide within the period; never let a deemed outcome operate by accident. | Every application carries its statutory due date and the overview counts those at risk (GL-RG-08). |
| Accessibility and plain language | WCAG 2.2 AA; ISO 24495-1 | Every screen usable with assistive technology; notices a person can understand. | Interfaces designed against WCAG 2.2 AA with conformance evidenced per deployment; notices written plainly. |