All posts

Compliance And Jurisdiction15 min read

Understanding digital identity verification methods for notarial acts across jurisdictions

Four digital identity verification methods, three assurance levels, and the jurisdictional rules that govern each. A practical guide for notaries who need to match verification rigor to statute.

By Self Service Notary

Digital identity verification methods for notary work span four core techniques: credential analysis, knowledge-based authentication, biometric liveness detection, and documentary evidence capture. Which one a notary uses, and in what combination, depends on the jurisdiction where the act is executed and the assurance level that the local statute demands. A working notary who understands this spectrum can pre-check identity before the appointment and arrive at a file already complete rather than starting from scratch.

The four digital identity verification methods explained

Each method answers a different question about the person in front of you, and most jurisdictions require more than one in combination. The definitions below reflect requirements in state regulations including the Texas administrative code guidance, Florida Statutes Chapter 117, and New York's 19 NYCRR Part 182.

Credential analysis

Credential analysis is an automated, third-party process that evaluates a government-issued ID against public and proprietary data sources to verify its physical, optical, and database validity. The procedure checks visual and embedded security features such as barcodes, holograms, fonts, and machine-readable zones. The notary does not perform this check manually; an independent system does it and reports the result. Under Texas administrative rules, Florida Statutes § 117.201, and 19 NYCRR § 182.2, credential analysis is defined as a procedure conducted by a third party that is independent of both the notary and the signer.

Knowledge-based authentication

Knowledge-based authentication, or KBA, presents the signer with dynamic questions about their personal history that only they should be able to answer. According to the Texas Secretary of State, "Identity proofing is the means by which the principal (signer of a document) affirms their identity. This is done through a third party who uses dynamic knowledge based authentication (KBA)." In Texas, the principal must score at least 80% within two minutes. A second failure triggers a mandatory 24-hour lockout before the signer can retest with the same notary.

Biometric liveness detection

Biometric verification and liveness detection confirm that the individual appearing over communication technology matches the credential photo and is physically active and present at that moment. The process prevents the use of static photographs, pre-recorded video loops, or digital masks. It typically runs during the live session rather than as an upload step, because its purpose is to establish real-time human presence, not just document validity.

Documentary evidence capture

Documentary evidence capture is the simplest method: the signer uploads a photograph or scan of an identity document. It is the baseline from which the other methods build. On its own, a static scan is vulnerable to manipulation and does not confirm that the person who submitted it is the person who will sign. The Virginia Secretary of the Commonwealth and other regulators note that uploaded static scans alone are insufficient for identity determination in remote settings.

What each method actually proves

Documentary capture proves the document exists. Credential analysis proves the document is genuine. KBA proves the person knows details tied to the identity. Biometric liveness proves the person is physically present right now. Jurisdictions that permit remote notarization typically require at least two of these layered together.

How verification rigor levels compare

Identity assurance frameworks define three escalating levels of rigor, each building on the previous one. These levels originate in Commission Implementing Regulation (EU) 2015/1502 under the eIDAS framework, but the conceptual tiers map closely to what US state regulators require in practice.

Assurance levels and what each requires
Assurance levelWhat it requiresWhat it preventsTypical notarial use
LowBasic identification checking without strong anti-spoofing controlsMinimal; vulnerable to forged or borrowed documentsFront-office intake and document onboarding only
SubstantialVerification against authoritative sources, two-factor authentication, controls to decrease identity misuseCasual impersonation and stolen-credential reuseIn-person notarial acts with supplementary digital checks
HighTamper-proof security elements, cryptographic verification of credential chips, biometric validation designed to resist sophisticated attacksState-of-the-art spoofing including deepfakes and replay attacksAuthorized remote online notarization

The jump from low to substantial matters because it separates a document that looks right from a document verified against a trusted data source. The jump from substantial to high matters because it adds biometric matching and tamper-resistant credential reading, which is what makes remote identity proofing defensible when the signer never enters the notary's office. A simple document upload at low assurance does not meet the statutory bar for remote notarization in any US state that authorizes it.

80% Minimum KBA passing score for a principal under Texas online notary rules Texas Secretary of State

Jurisdictional acceptance: where each method applies

Notary identity verification requirements differ sharply between common law and civil law systems. A notary must confirm their own authorisation before relying on any digital method, because what a statute permits in one jurisdiction it may prohibit in another.

United States: state-by-state authorization

In the US, remote online notarization is only permitted where that state authorises it and only where the notary has confirmed their own authorisation. Texas, Florida, and New York each mandate multi-factor identity proofing combining credential analysis with KBA or biometric verification. Texas Government Code Chapter 406 requires third-party credential analysis and dynamic KBA with a minimum 80% passing score. Florida Statutes § 117.201 require credential analysis of government IDs and identity proofing through KBA or biometric verification. New York's 19 NYCRR § 182.5 mandates identity verification through communication technology, third-party credential analysis, and identity proofing, unless the principal is personally known to the electronic notary.

California occupies a distinct category. Although the state enacted the Online Notarization Act (SB 696) in 2023, the California Secretary of State confirms that California notaries cannot perform remote online notarizations until the Secretary of State completes the Notary Automation Project 2.0 or reaches January 1, 2030, whichever is earlier. Until then, California law requires personal physical appearance for acknowledgments and jurats. As the Secretary of State states: "A video image or other form of non-physical representation is not a personal appearance in front of a notary public under current California State law." The California Notary customer alerts page carries current status updates.

Check your state's current authorization

The National Association of Secretaries of State maintains a directory of remote electronic notarization standards and initiatives covering every state that has enacted or is considering enabling legislation. Confirm your commission authorizes the act before you book a remote session.

European Union: front-end intake, reserved notarial acts

In the EU, the notarial act stays in the notary's office and what a client can prepare is intake, identity and signing. Under Directive (EU) 2019/1151, clients can complete preparatory intake, electronic identification, and qualified electronic signatures remotely. However, the drawing up and attestation of authentic notarial deeds remain subject to Member State jurisdiction. Member States may require physical presence on a case-by-case basis where justified by public interest reasons, such as verifying legal capacity or avoiding identity misuse. Digital identity tools in the EU support the front end; they do not relocate the notarial act itself.

United Kingdom: faculty rules govern digital identity checks

The UK is subject to faculty rules. Under the Notaries Practice Rules 2019 and the Faculty Office's Standard for Verifying Identity Using Digital Checks, notaries may use digital identity tools that read cryptographic chips and conduct liveness checks. The regulator is explicit that the notary's responsibility is non-delegable. The Faculty Office of the Archbishop of Canterbury states: "It may be possible to make use of digital tools to assist with checking the identity documents of a remote appearer. However, the notary remains solely responsible for the identification of a remote appearer." Uploaded static scans alone are deemed vulnerable to manipulation. The notary must assess capacity and freedom from duress regardless of what digital tools report.

Hong Kong and the UAE: front office only

Hong Kong and the UAE require front office only. In Hong Kong, notaries appointed by the High Court under the Legal Practitioners Ordinance (Cap. 159) require personal attendance for formal notarial certification. Digital tools are confined to front-office KYC and document onboarding. In the UAE, under Federal Decree-Law No. 20 of 2022, electronic notarization is permitted only through sanctioned government portals where preliminary identity verification and document drafting precede real-time interactive notarial video attestation. In both jurisdictions, digital verification prepares the file but does not replace the notary's in-person or portal-mediated attestation.

  • 2014-07-23Regulation (EU) No 910/2014 (eIDAS) adopted, creating the legal framework for electronic identification and trust services across EU Member States
  • 2017-06-01Texas enacts Subchapter C, Chapter 406 of the Texas Government Code, authorizing commissioned online notaries
  • 2019-06-07Florida enacts HB 409, codified in Chapter 117 Part II, effective January 1, 2020
  • 2022-09-26UAE promulgates Federal Decree-Law No. 20/2022 on the Regulation of the Notary Public Profession
  • 2023-01-25New York adopts 19 NYCRR Part 182, establishing electronic notarization and 10-year record retention
  • 2023-09-30California enacts SB 696, scheduling remote online notarization implementation ending on or before January 1, 2030
  • 2026-06-26Faculty Office issues the Standard for Verifying Identity Using Digital Checks for English notaries

How digital verification changes remote versus in-person work

For authorized remote sessions, remote online notarization identity proofing is the gatekeeper. The notary cannot eyeball an ID across a desk, so the statute substitutes layered digital proof: credential analysis confirms the document, KBA confirms the person's knowledge, and biometric liveness confirms their physical presence at the session. The notary reviews the results before the session opens, which means the identity question is answered before the signer appears on screen.

For traditional in-person appointments, digital verification shifts from a statutory requirement to a workflow advantage. A client who completes an ID pre-check, uploads their document, and books a slot ahead of time arrives with the file already assembled. The notary opens a completed record, confirms the identity in person as required, and moves directly to execution. The repetitive administrative work, the hand-checking of IDs at the counter, and the document chasing that fragments a notary's day all happen upstream of the appointment.

The practical difference is clear: in a remote session the digital verification is the identity proofing the statute requires. In an in-person session it is a preparatory step that lets the notary start from a complete file rather than a blank one.

Security and privacy considerations for notarial records

Notarial records created through digital verification carry the same liability as those created on paper, and the retention obligations are statutory. The rules vary by jurisdiction, sometimes significantly.

Statutory retention periods for electronic notarial records
JurisdictionMinimum retentionWhat is retainedSource
Texas5 yearsElectronic journal entries and audio-visual recordingsTexas Government Code § 406.108(c)
Florida10 yearsElectronic journals and session recordingsFlorida Statutes § 117.245(4)
New York10 yearsElectronic notarial act records and video/audio recordings19 NYCRR § 182.9

In the UK and EU, notarial data retention must comply with UK GDPR and Regulation (EU) 2016/679, balancing statutory notarial evidence requirements against data minimization principles. The notary holds personal data, biometric data, and session recordings, all of which are sensitive. Four principles apply regardless of jurisdiction:

  • Data minimization: collect only what the statute requires for identity proofing and journal entry. Do not retain credential images longer than the retention period demands.
  • Encryption at rest: session recordings and journal entries must be stored in a form that is unreadable without authorization, using standard protective measures rather than any named algorithm.
  • Tamper-evident storage: journal entries should be sealed in a way that makes any later alteration detectable.
  • Retention limits: delete or archive on the schedule your jurisdiction sets. Holding records longer than required increases exposure without adding evidentiary value.

The notary's liability for client data is personal and non-delegable. A third-party system can perform credential analysis, but if it fails or stores data insecurely, the notary's commission and register are the ones at risk. Verifying that your verification tools meet the assurance level your jurisdiction requires is part of the job, not a feature you can assume.

Moving verification upstream to streamline the act

The administrative burden of a notarial practice is not the notarial act itself. It is everything that happens before it: intake forms, ID checking, document collection, scheduling, payment, and the back-and-forth that fragments a working day. Moving identity verification upstream means the client completes intake, ID pre-check, booking, payment, and signing before the session begins. The notary opens a file already complete, reviews it, and presses one button to execute the act.

This works for both remote and in-person appointments. A client who arrives with a verified identity, a booked slot, and a paid fee needs the notary to confirm and execute, not to start from scratch. Notary client intake verification that runs ahead of the appointment lets a small practice serve more clients without adding staff. The notary's time goes to the acts that require judgment, not to chasing documents.

What moving verification upstream gains

  • The notary reviews a completed file, not a pile of loose documents
  • Identity issues surface before the appointment, not during it
  • Clients book, pay, and sign through a single portal, eliminating phone tag
  • Session time goes to execution and witnessing, not administration

What to watch for

  • Digital verification does not replace the notary's personal responsibility for identity
  • Retention and storage obligations apply to digitally captured identity data
  • The assurance level must match what your jurisdiction's statute requires

Choosing the right verification method for your practice

Start with your jurisdiction. If your state authorizes remote online notarization, read the statute to see which methods it mandates. Texas requires credential analysis plus KBA with an 80% passing score. Florida requires credential analysis plus KBA or biometric verification. New York requires communication technology, third-party credential analysis, and identity proofing. California does not authorize remote notarization at all until its system is operational. Match your verification to the statute, not to what a system offers.

Next, consider your client base. If your clients are local and appear in person, a low-assurance document capture for intake plus your in-person identity check at the appointment may be sufficient. If you serve clients across distances or handle high-value transactions, substantial or high assurance is what the statute and the risk profile demand. Notarial jurisdiction compliance is worth reviewing closely if your practice spans state lines.

Do not over-engineer. A practice that handles routine acknowledgments for walk-in clients does not need high-assurance biometric liveness for every appointment. A practice that handles remote real estate closings does. The verification method should fit the act, the jurisdiction, and the client. Anything beyond what the statute requires adds cost and friction without adding legal protection.

Key points before you adopt a verification method

  • Confirm your jurisdiction authorizes the method before relying on it for any notarial act
  • Layer at least two methods for remote sessions: document validity plus person presence
  • Match the assurance level to the act, not to what the platform offers by default
  • Retention obligations for digital identity data are statutory and non-delegable

Preparing your practice for verified client intake

A client portal lets the notary's clients complete intake, identity verification, booking, e-signing, tamper-evident sealing, e-journals, and payments directly to the notary's account before the session. The notary reviews a completed file, confirms identity as required, and executes the act. This is the practical endpoint of understanding digital identity verification methods: a workflow where the administrative work is done upstream and the notary's judgment is reserved for the act itself. The client intake automation guide describes how the page handles each of those steps from ID pre-check through payment.

Frequently asked questions

What is credential analysis for notaries?

Credential analysis is an automated, third-party process that evaluates a government-issued ID against public and proprietary data sources to verify its physical, optical, and database validity. The notary does not perform the check manually; an independent system does it and reports the result. Texas, Florida, and New York all require it for authorized remote online notarization.

Can a notary accept a scanned ID instead of using credential analysis?

A static scan alone is insufficient for remote notarization in jurisdictions that authorize it. Documentary evidence capture proves the document exists but does not confirm that the person who submitted it is the person who will sign. Regulators including the Faculty Office of the Archbishop of Canterbury note that uploaded static scans alone are vulnerable to manipulation.

Is remote online notarization legal in every US state?

No. In the US, remote online notarization is only permitted where that state authorises it and only where the notary has confirmed their own authorisation. California, for example, enacted enabling legislation in 2023 but the California Secretary of State confirms that remote notarization cannot begin until the state's system is operational or January 1, 2030, whichever is earlier. The National Association of Secretaries of State maintains a directory of state standards.

What KBA passing score does Texas require?

Texas requires the principal to score at least 80% on dynamic knowledge-based authentication within two minutes. A second failure triggers a mandatory 24-hour lockout before the signer can retest with the same notary.

Can digital identity verification replace the notary's personal responsibility?

No. In every jurisdiction covered here, the notary's responsibility for identity verification is non-delegable. A third-party system can perform credential analysis, but the notary's commission and register are at risk if the system fails or stores data insecurely. The Faculty Office of the Archbishop of Canterbury states: "the notary remains solely responsible for the identification of a remote appearer."

How long must a notary retain electronic notarial records?

Retention periods vary by jurisdiction. Texas requires 5 years under Texas Government Code § 406.108(c). Florida requires 10 years under Florida Statutes § 117.245(4). New York requires 10 years under 19 NYCRR § 182.9. Check your jurisdiction's statute for the specific obligation that applies to your commission.

ShareXLinkedIn