Most businesses treat standards compliance as a cost. Sebastian Elfors, Chief Security Officer at IDnow Trust Services and active contributor to ETSI and CEN working groups, argues it could be the opposite, if businesses only knew how to use them.
I have spent much of my working life attending standardisation meetings that many in the identity verification industry may not know take place.
They are long, detailed, sometimes contentious discussions between technical experts, regulators, national standards bodies and industry representatives who are all trying to agree, in precise and unambiguous language, what ‘compliant’ means for a given technology or process. The output is a document that most businesses will only encounter as a compliance checkbox, if they encounter it at all.
Despite all this, it is incredibly inspiring to be working with some of Europe’s best experts to develop the standards that will ultimately define the upcoming EUDI Wallet eco-system.
Here, I explain some of the most important technical standards that are working tirelessly in the background [much like me!] to lay the groundwork for the future of identity verification.
Sebastian Elfors, Chief Security Officer, IDnow Trust Services
What ETSI 119 461 Actually Certifies
ETSI TS 119 461 is the European technical standard for identity proofing, which means it’s the process by which a person’s identity is established and verified before a qualified trust service is issued. Version 2.1.1, which IDnow is certified against, specifies the requirements for identity proofing processes in terms of the countermeasures that must be in place against the attack vectors that exist.
This is the standard’s most important characteristic, and the one most misunderstood. ETSI 119 461 does not simply say “verify that the document is genuine and the face matches.” It specifies, at a technical level, what the verification process must be able to resist, including:
Presentation Attacks, in which a fraudster presents a photograph, mask or deepfake video instead of a live face.
Injection Attacks, in which a fraudulent video stream is injected into the verification process at the software level, bypassing the device’s physical camera.
Document Fraud typologies, including counterfeit documents, altered genuine documents, and fraudulently obtained genuine documents.
Certification against ETSI 119 461 v2.1.1 means that an identity proofing process has been assessed against all the above, and that the countermeasures in place meet the standard’s requirements.
An identity proofing process that has been certified against this standard verifies that is has been independently assessed against the threat landscape as it currently exists. Plus, as the standard evolves and as new attack vectors emerge, the certification requirements update accordingly.

EUDI Wallet Consumer Survey
Download ‘The Identity Gap’ to discover what 2,000 European consumers really think about the EUDI Wallet, and what it means for banks, telcos, governments, and every organisation building their identity verification stack.
The ETSI Standards Shaping the Next Phase of Digital Identity
While ETSI TS 119 461 defines the requirements for identity proofing, a cluster of newer ETSI standards is now shaping the next phase of digital identity in Europe, specifically within the EUDI Wallet ecosystem and the issuance of Qualified Electronic Attestations of Attributes (QEAAs).
ETSI TS 119 471 sets out the policy requirements that a Qualified Trust Service Provider must meet when issuing QEAAs, and the attestations that will underpin attribute-based credentials in the EUDI Wallet. It defines the governance framework within which QTSP operations must sit, covering everything from registration and issuance policies to revocation and audit obligations. ETSI TS 119 472-3 goes a level deeper, specifying the technical requirements for the actual issuance protocol: how a QEAA is generated, bound to a wallet, and delivered to the end user in a way that preserves the integrity of the underlying identity verification.
ETSI TS 119 478 addresses access to authentic sources, which refers to the authoritative data repositories (such as population registers or official databases) from which identity attributes are drawn before being attested in a QEAA. This standard defines what it means for a source to be considered authentic and how the link between the source data and the issued attestation must be maintained and auditable.
Meanwhile, ETSI TS 119 476-3 covers Wallet Unit Attestation: the mechanism by which a wallet instance i and key storage tself is certified as trustworthy before it is permitted to receive and hold QEAAs. The fact that a QEAA is only as reliable as the EUDI Wallet environment it lives in, and this standard defines the bar that wallet providers must meet is a critical but often overlooked layer of the trust chain. Taken together, these four ETSI standards define the full trust chain for QEAA issuance: from the policies governing QTSPs, through the issuance process itself, to the authenticity of the underlying data sources and the integrity of the wallet environment receiving the credential.
For businesses that will be accepting EUDI Wallet credentials, understanding these standards matters because they collectively define the bar for the credentials they will be accepting.
Sebastian Elfors, Chief Security Officer, IDnow Trust Services
A QEAA issued by a provider operating in compliance with ETSI TS 119 471 and 119 472-3, drawing on authentic sources as defined by ETSI TS 119 478, and delivered into a wallet attested under ETSI TS 119 476-3, carries a level of assurance that a credential from a non-conformant provider simply does not.
What the AMLR RTS Defines — and What it Leaves to Standards
One of the most important things to consider about the Anti-Money Laundering Regulation’s (AMLR) customer due diligence Regulatory Technical Standards is the relationship between the regulation and the technical standards. A good way of thinking about it is the regulation defines obligations and the standards define how those obligations are met.
Article 22(6) of the AMLR specifies that non-face-to-face identity verification must use either electronic identification means at substantial’ or ‘high’ assurance level under eIDAS 2.0, and relevant qualified trust services. The RTS specifies, in more detail, the attributes that those means and services must carry, and the conditions under which simplified or enhanced due diligence applies.
What neither the AMLR nor the RTS specify, because it is not their function, is the precise technical implementation of the verification process. That is the domain of ETSI TS 119 461 and the suite of ETSI standards governing QEAA issuance and wallet attestation. AMLR states to use a method that meets assurance level ‘substantial’ or ‘high’. ETSI 119 461 mandates what a verification process must do to meet that assurance level. The two instruments work together and neither is sufficient without the other.
It is therefore important that businesses treat the regulatory and technical standards as complementary. A business that understands only the regulatory obligation, such as “we must use a method at ‘substantial’ assurance level’ without understanding the technical standard that defines what that means in practice, cannot make an informed assessment of whether their current processes are compliant. So, naturally, a business that understands both is in a materially stronger position.
Why IDnow’s Standards Contributions Matter for Customers
IDnow contributes directly to the development of the standards I have described. I contribute to all ETSI working groups. More specifically, I’ve been the editor of ETSI TR 119 476-1 and ETSI TS 119 476-3.
Being in the room where standards are developed means understanding what the standard says today and why it says it; what attack vectors drove specific requirements; what debates shaped decisions, and what directions the standard is likely to move in as the threat landscape evolves. That understanding feeds directly into product and architecture decisions.
It also means something more practical for customers: when a standard is updated, the IDnow Trust Platform updates to reflect it. The compliance burden of tracking, interpreting and implementing standard changes falls on IDnow, not on the compliance team at the bank or fintech or telecoms operator using the platform. The customer does not need to know the difference between ETSI 119 461 V1.1.1 and v2.1.1 to benefit.
This is what I mean when I say standards are a competitive advantage rather than a cost but only if you know how to use them. A business that is building its own identity verification capability – and using a combination of tools – needs to track standard changes manually and implementing them through its own development cycle. In this sense, keeping up with standards is like a continuous, expensive, and never-quite-finished compliance project.
As the IDnow Trust Platform is maintained by standards contributors, users face none of that overhead. The standards become an asset and a guarantee that the verification methods in use are current, independently assessed, and defensible to any regulator who asks.
The Practical Implication: One Question to Ask Your Vendor
If there is one thing I would recommend that every compliance or technology leader reading this does in the next week, it’s this: ask your identity verification vendor which standards they are certified against, and who in their organisation contributed to writing those standards.
The first question has a straightforward answer. Either a vendor is certified against ETSI 119 461 v2.1.1 by an accredited conformity assessment body, or they are not. Either their identity proofing process has been independently assessed by lab testing against Presentation Attacks, Injection Attacks and document fraud typologies, or it has not.
The second question is more revealing. Standards are not written by regulators in isolation, they are developed through working groups in which industry experts participate, argue and ultimately agree in consensus. A vendor whose technical team contributes to those working groups understands the standards at a depth that a vendor who merely reads the published output does not. That depth shows up in product decisions, in architecture choices, and in how quickly the platform responds when a standard changes.
Standards compliance is the floor, not the ceiling. But it is a floor worth understanding because the difference between a business that understands it and one that treats it as a checkbox is, increasingly, the difference between a business that is ready for 2027 and one that will spend 2027 catching up.
Interested in more ‘Lessons From’ our subject matter experts? Click below!
- Former INTERPOL Coordinator, and current Forensic Document Examiner at IDnow, Daniela Djidrovska explains why IDnow offers document fraud training to every customer, regardless of sector.
- Research Scientist in the Biometrics Team at IDnow, Elmokhtar Mohamed Moussa explores the dangers of face verification bias and what steps must be taken to eradicate it.
- Research Scientist at IDnow, Nathan Ramoly explores the dangers of deepfakes and explains how identity verification can help businesses stay one step ahead of the fraudsters and build real trust in a digital world.
- Senior Product Owner at IDnow, Christophe Chaput explains why the steps we took to comply with the European Accessibility Act made our solutions better – for all our customers.
By

Sebastian Elfors
Chief Security Officer at IDnow Trust Services
Connect with Sebastian on LinkedIn
