Moving beyond checklists to living digital identity risk management

Tatiana Maksimova / Getty Images
COMMENTARY | The era of static checklists is over. The future belongs to living, adaptive digital identity programs.
The federal government is racing to deliver secure, seamless digital services to millions of Americans, from veterans seeking healthcare to citizens accessing benefits. Yet our digital identity systems too often rely on outdated frameworks that treat security as a one-time checkbox exercise.
The National Institute of Standards and Technology’s Special Publication 800-63-4 changes that. Released this year, it marks a doctrinal shift from static compliance to a dynamic, holistic Digital Identity Risk Management (DIRM) process.
As someone leading ICAM efforts at the Department of Health and Human Services and co-chairing related working groups, I believe agencies that treat this update as “just another revision” will fall behind. Those that lean in will build identity systems that are more secure, equitable and user-friendly in an era of sophisticated threats and rising public expectations.
The previous version, SP 800-63-3, served us well by establishing risk-based assurance levels (IAL, AAL and FAL). But the digital landscape has evolved dramatically. Phishing attacks have grown more targeted, synthetic identity fraud proliferates and users demand frictionless experiences across devices.
SP 800-63-4 responds with a five-step DIRM lifecycle: Define the online service, conduct impact assessments, select initial assurance levels, tailor controls and — most importantly — continuously evaluate and improve. This is not incremental; it embeds privacy, customer experience and threat resistance into every decision.
A core advancement is the raised bar for Identity Assurance Levels (IAL). IAL1 no longer tolerates purely self-asserted identities. Even at the lowest level, agencies must validate core attributes against authoritative or credible sources to counter bots and synthetic fraud.
For higher assurance, IAL3 now requires attended sessions with biometric collection. Critically, the standard introduces “No IAL” for services where proofing adds no value — preventing unnecessary data collection and aligning with privacy principles. This flexibility, guided by DIRM’s tailoring step, lets agencies avoid over-provisioning security that harms usability or under-provisioning that invites risk.
Authentication Assurance Levels (AAL) see equally pragmatic evolution. Phishing resistance moves from AAL3 specialty to a requirement offered at AAL2 and mandated at AAL3. Modern authenticators like FIDO2 passkeys and non-exportable keys in secure elements become central, while session management relaxes appropriately (e.g., longer timeouts with device-bound credentials) to reduce user fatigue.
These changes directly support Executive Order 13681’s MFA push and Zero Trust architectures without sacrificing security. Agencies can now inventory authenticators, conduct gap analyses and phase in phishing-resistant options — practical steps that deliver measurable risk reduction.
Federation Assurance Levels (FAL) similarly adapt to modern models, including subscriber-controlled wallets. The emphasis on performance metrics, redress processes and AI/ML governance stands out. Organizations must now document AI use in proofing or fraud detection, assess risks per the NIST AI RMF and ensure human oversight for redress. No longer can automated systems operate as black boxes. Users denied access deserve transparent, trackable paths to resolution — essential for equity and public trust.
The new Digital Identity Acceptance Statement (DIAS) serves as the capstone: a living record of impact assessments, tailoring decisions, compensating controls and monitoring plans. Paired with the GSA DIRA Playbook, it turns DIRM from abstract framework into operational reality.
For federal leaders, the benefits are clear. At HHS, expanding FedHub as a government-wide identity hub demands this risk-based agility. Services supporting veterans, healthcare data exchange via CARIN Alliance, or public benefits require tailored assurance that balances security with accessibility. Rigid checklists lead to either abandoned enrollments (hurting mission delivery) or unaddressed threats (risking breaches).
DIRM’s continuous evaluation — tracking pass/fail rates, abandonment, fraud indicators and redress requests — enables data-driven iteration. This is how we achieve “inclusive security”: strong enough to protect sensitive PII, flexible enough for diverse populations.
Implementation will require effort. Cross-functional teams (IT, privacy, CX, legal) must reassess services, update DIAS documents, inventory authenticators and build redress mechanisms. Agencies should prioritize high-impact systems first, leveraging existing investments in PIV/CAC, ID.me, Login.gov and emerging tools. The ATARC Identity Management Working Group’s new Implementation Guide — developed collaboratively with government and industry experts — provides practical checklists, roadmaps, gap analyses and templates to accelerate this transition.
Critics may worry about added bureaucracy. But DIRM reduces it by enabling risk-based tailoring instead of uniform mandates. It aligns identity programs with broader FISMA, RMF and Zero Trust initiatives while preparing for subscriber wallets and advanced biometrics. Ignoring the update risks non-compliance, poor user experiences and vulnerability to evolving threats.
The federal government has invested billions in digital transformation. NIST SP 800-63-4 ensures those investments deliver trustworthy, resilient identity foundations. I urge CIOs, ICAM leaders and program managers to adopt the DIRM process now. Read the standard, use the implementation resources and produce DIAS documents that demonstrate thoughtful risk management. Our citizens — veterans, patients and taxpayers — deserve identity systems as modern and responsive as the services they access.
The era of static checklists is over. The future belongs to living, adaptive digital identity programs. Let’s lead that transition together.
Adam McBride is the ICAM/IdAM Program Manager for the Department of Health and Human Services (HHS) and co-chair of the ATARC Identity Management Working Group. He has over fifteen years of experience in government and a retired Master Sargeant, US Army.




