MFA Proves It's the Same Person.Verified Identity Proves It's the Right One.
Stolen and synthetic identities are drawing federal student aid. The Department of Education now accepts identity verification performed by a NIST IAL2 compliant entity and requires you to keep the record. QuickLaunch Verified Identity puts that check inside the account claim your students already complete, using the verification provider you already chose.
Bring your own provider · Audit record written automatically
Request a Demo
See your campus through the analytics layer.
Why This Became Urgent
Aid Fraud Became an Identity Problem. Then It Became Your Compliance Problem.
Organized fraud rings learned that an open-enrollment institution will create an account, enroll a student, and disburse aid without ever meeting the person. The Department of Education has called the resulting rate of stolen-identity fraud a threat that imperils the Title IV programs themselves and the response landed on financial aid offices as new, mandatory, manual work.
The relief the Department offered is specific: identity verified by a NIST IAL2 compliant entity counts. That single sentence turned identity proofing from a policy debate into a procurement and orchestration question.
Every applicant is screened
As of April 26, 2026 the FAFSA screens all applicants, and some are asked to photograph a government-issued photo ID inside the form itself.
The requirement reaches backward.
Previously submitted 2026–2027 forms were re-screened, creating new verification requirements for students who had already been offered or had accepted aid.
Third-party IAL2 verification is accepted.
Dear Colleague Letter GEN-25-10 added it as acceptable documentation alongside in-person and live video.
You must keep the receipt.
The institution has to retain the date the identity was verified and the entity that performed the verification..
Fraud has to be reported
Suspected or confirmed misrepresentation goes to the Office of Inspector General, which means the evidence trail matters as much as the check.
The Regulatory Record
How Identity Verification Became a Title IV Requirement
Twelve months of federal action, in the order it happened. Every item below is published guidance, not interpretation.
Federal Student Aid calls stolen-identity fraud a threat to the programs
An electronic announcement states that the rate of fraud through stolen identities has reached a level that imperils the federal student aid programs authorized under Title IV. It expands V4 verification selections, and it introduces the provision that matters most: the Department will consider a student's identity verified if it was verified by an entity compliant with NIST IAL2, provided the institution retains the date and the entity. Federal Student Aid electronic announcement.
Scale becomes visible
The Department reports that focused fraud-detection work identified roughly 150,000 suspect identities in then-current FAFSA forms, all marked for required identity validation by schools before aid could be disbursed, and projected on the order of 125,000 students needing summer verification. Department of Education press release.
NIST SP 800-63-4 becomes the current standard
Revision 4 of the Digital Identity Guidelines supersedes revision 3. Volume 800-63A-4 governs identity proofing and enrollment, and confirms that IAL2 may be delivered remotely and can be satisfied without an automated biometric comparison. National Institute of Standards and Technology.
Dear Colleague Letter GEN-25-10 codifies the new methods
For the 2026–2027 award year the Department updated acceptable documentation for identity verification, adding a live video call as a substitute for the notary statement, and third-party verification satisfying NIST IAL2. In-person remains the preferred method; IAL2 is an accepted alternative. Dear Colleague Letter GEN-25-10.
Every FAFSA applicant is screened, and the net reaches backward
The FAFSA began screening all applicants for identity, with some asked to submit a photo of a government-issued ID before submitting the form. Students who cannot complete it must present identification to the financial aid office before receiving aid. Previously submitted 2026–2027 forms were also re-screened, so new requirements can land on students who were already offered or had accepted aid. Federal Student Aid guidance and institutional advisories.
“The Department will consider a student's identity to be verified if the student's identity was verified by an entity that is compliant with National Institute of Standards and Technology (NIST) Identity Assurance Level 2. In this instance, an institution must retain documentation of the date that the student's identity was verified and the entity that performed the verification.”
— U.S. Department of Education, Federal Student AidWhy It Ranks With MFA
Two Different Questions. Two Different Standards.
NIST does not treat authentication strength and identity confidence as one measurement. It defines them as separate, independently rated components. Most campuses have invested heavily in one of them.
Adaptive MFA
“Is this the same person who set up the account?”
- Blocks stolen and reused credentials at sign-in
- Steps up on risky context: new device, new country, odd hour
- Reaches phishing resistance with passkeys at AAL2
- Protects the account for its entire life
- Already deployed on most campuses
Verified Identity
“Who is that person, actually?”
- Validates government-issued evidence against its issuing source
- Binds a real human to the institutional record at claim time
- Stops a synthetic applicant at the claim, before any credential exists
- Produces the documentation the Department requires you to keep
- The half of the standard most campuses have not deployed
Lifecycle & Security
The Source Decides. The Portal Follows.
Because RTDS runs independent of login, lifecycle is enforced by the system of record not by whether someone happens to sign in. Joiners get accounts before they arrive, movers get updated access as their record changes, and leavers lose access when the source says so.
| Verification Provider | NIST IAL2 Standing | Higher-Education Practice |
|---|---|---|
| ID.me | Kantara-approved First credential service provider approved conformant to NIST SP 800-63-3 at IAL2 and AAL2, 2018 |
Published community-college deployments verifying students at IAL2 |
| Persona | Kantara-certified States Kantara certification and IAL2-aligned verification |
Dedicated higher-education practice covering aid fraud and account recovery |
| Socure | States IAL2 Real-time identity proofing and fraud scoring |
Higher-education practice focused on aid and refund fraud |
| Nametag | States IAL2 Deepfake-resistant verification engine |
Purpose-built for student aid applicant verification and help-desk identity |
| VerifiNow | States IAL2 Remote proofing with FSA-oriented audit output |
Ghost-student detection and Title IV disbursement workflows |
How to read this table. The Department's requirement is that verification be performed by an entity compliant with NIST IAL2. The Kantara Initiative operates the recognized conformity-assessment program against NIST SP 800-63, so a Kantara approval is independent evidence of conformance; the remaining entries reflect each provider's own published IAL2 positioning. The Kantara approval listed here was granted against SP 800-63-3, which revision 4 superseded on August 1, 2025 — confirm current standing and revision with your provider during procurement. Listing is market context for institutions evaluating options, not a QuickLaunch endorsement or a reseller relationship. If your provider is not listed and meets IAL2, QuickLaunch can orchestrate it.
Inside the Claim Flow
One New Step in a Flow Your Students Already Complete
QuickLaunch Account Activation already walks every new student from invited, to verified, to secured, to live. Verified Identity is what the word verified becomes when the Department wants proof.
The student starts their claim
The account already exists. Enrollment posted, it was created in Active Directory, and the invitation to claim it went to the student. They open the same self-service claim experience they would have used anyway — nothing new to learn, no separate portal, no second set of instructions from the aid office.
QuickLaunch decides whether proofing is required
Policy lives with the institution, evaluated per person: everyone, first-time aid applicants only, students flagged for V4 or V5, a specific cohort or program, or a risk signal on the claim itself. Students who do not need proofing never see it.
Your provider runs the verification
QuickLaunch opens a verification session with your IAL2 provider, carrying a reference that binds the session to this student's institutional identity, and hands off to the provider's hosted experience by single-use link. The student presents evidence to the provider, never to a staff inbox.
In-person and live video paths remain available for students who need them.
The result comes back authoritatively
QuickLaunch does not trust the browser. The outcome is confirmed server-to-server with the provider and normalized to a single institutional vocabulary: verified, failed, needs review, abandoned, or provider error. A provider outage routes to an operational queue, never to a false rejection of a real student.
The assurance record is written
Date of verification, the entity that performed it, the outcome, and the identity it is bound to, recorded against the student the moment the result lands. This is the documentation the Department asks institutions to retain, created as a by-product of the flow rather than as an afterthought.
The account is handed over, and MFA is enrolled
A proven student finishes the claim and sets their own credentials — no temporary password is ever issued, so there is nothing sitting in an inbox to phish. They enroll multi-factor authentication or a passkey and walk into single sign-on across campus. Both halves of the standard are satisfied before the account is ever used: the right person, and from now on, the same person.
Watch
Ninety Seconds: The Student Who Isn't Read
Two applicants claim an account on the same morning. Only one of them exists. Watch where the difference gets caught.
Audit Readiness
The Record the Department Asks You to Keep
Guidance is unusually specific about documentation. When identity is verified by a third party, the institution must retain the date the verification happened and the entity that performed it. Institutions must also preserve identification documentation, and report suspected misrepresentation to the Office of Inspector General.
That is a records problem, and records problems are where compliance programs actually fail. A verification that happened but cannot be evidenced is, to an auditor, a verification that did not happen.
QuickLaunch writes the assurance record as part of the transaction and keeps it attached to the identity for the life of the account. Because it lives in the identity platform rather than in a vendor's console or someone's inbox, it is reportable next to everything else you already track: who claimed, when, from where, with which factors, and now with which verification.
Aid officers get a queue instead of an errand. Completed verifications arrive with their evidence already recorded, so staff attention goes to genuine exceptions: the students who need a video call, a trusted referee, or a second attempt.
Assurance Record
- Verified On · required
- The date verification completed
- Verified By · required
- The NIST IAL2 entity that performed it
- Assurance Level
- IAL2
- Method
- Remote, live video, or in person
- Outcome
- Verified, failed, or referred for review
- Bound Identity
- The institutional person record
- Reference
- Provider session identifier for lookup
Results Across the Network
The Numbers Institutions See
FAQ
Frequently Asked Questions
The Student Identity Journey
Verified Identity is the gate in front of the journey the moment a real person becomes a campus identity.
Case Studies
Institutions Already on One Login
55,000+ FTE · <2 Months
Community College of Baltimore County
Centralized SSO across 100+ service providers with guided self-service account claim cutting a 1,000-reset-a-day help desk by nearly 95%.
SSO + MFA
Texas A&M International University
Single sign-on and multi-factor authentication across the campus application portfolio, with self-service reset taking onboarding off the help-desk queue.
Passwordless Onboarding
University of Houston-Clear Lake
First-time account claim with no temporary passwords and SSO for students, faculty, and staff branded end to end to the institution.
Ready for a Portal That Always
Reflects the Source of Truth?
Users, groups, and memberships synced from your directory validated, audited, and in place before the first login.
