Skip to content

Evidence request lists

ISO/IEC 29115:2023 - Entity Authentication Assurance Framework

Evidence request list. 41 controls, 41 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Audit

ISO29115-10.1
Audit and Accountability

Maintain audit trails for enrolment, credential lifecycle, and authentication events with integrity protection.

Artefacts an auditor will ask for
  • audit log inventory
  • log integrity controls (signing, WORM)
  • retention schedule
  • audit log review records
Where this commonly fails
  • logs not integrity protected
  • retention shorter than incident detection window
  • logs not reviewed proactively
ISO29115-10.2
Independent Assessment

Subject CSP and RA operations to independent assessment confirming claimed LoA is supported by controls.

Artefacts an auditor will ask for
  • independent assessment reports
  • assessor qualifications
  • scope definitions
  • corrective action plans
Where this commonly fails
  • assessor not independent
  • scope excludes critical processes
  • findings not closed before next assessment

Authentication

ISO29115-7.1
Authentication Protocol Requirements

Use authentication protocols resistant to relevant threats including replay, eavesdropping, and man in the middle.

Artefacts an auditor will ask for
  • protocol selection rationale
  • threat resistance matrix
  • channel binding evidence
  • protocol version inventory
Where this commonly fails
  • legacy protocols still active
  • channel binding absent
  • no MitM protection for LoA 3 and above
ISO29115-7.2
Multi Factor Authentication

Require multi factor authentication at LoA 3 and 4 combining factors from different categories (knowledge, possession, inherence).

Artefacts an auditor will ask for
  • MFA enforcement configurations
  • factor diversity verification
  • bypass exception register
  • step up authentication logs
Where this commonly fails
  • two factors from same category (two knowledge)
  • MFA bypass for help desk too broad
  • step up not used for risky actions
ISO29115-7.3
Session Management

Manage authenticated sessions with binding to authenticator, timeout, and reauthentication for sensitive actions.

Artefacts an auditor will ask for
  • session policy
  • session token security analysis
  • timeout configurations
  • reauthentication trigger list
Where this commonly fails
  • session tokens long lived without binding
  • no reauthentication for privilege changes
  • logout incomplete

Clause 1-4: Framework Introduction

29115-1
Scope

Framework for managing entity authentication assurance in a given context

Artefacts an auditor will ask for
  • Identity proofing procedure
  • Credential issuance and revocation log
  • Authentication assurance level mapping
  • Federation and assertion configuration records
  • Threat assessment for authentication flows
Where this commonly fails
  • Identity proofing relies on single attribute checks
  • Credential revocation not timely
  • LoA selection not risk-based
  • Federation assertions lack signing and replay protection
29115-3
Terms and definitions

Terms related to entity authentication, levels of assurance, credential service providers, and authentication factors

Artefacts an auditor will ask for
  • Identity proofing procedure
  • Credential issuance and revocation log
  • Authentication assurance level mapping
  • Federation and assertion configuration records
  • Threat assessment for authentication flows
Where this commonly fails
  • Identity proofing relies on single attribute checks
  • Credential revocation not timely
  • LoA selection not risk-based
  • Federation assertions lack signing and replay protection
29115-4
Abbreviations

Abbreviations used in the entity authentication assurance framework

Artefacts an auditor will ask for
  • Identity proofing procedure
  • Credential issuance and revocation log
  • Authentication assurance level mapping
  • Federation and assertion configuration records
  • Threat assessment for authentication flows
Where this commonly fails
  • Identity proofing relies on single attribute checks
  • Credential revocation not timely
  • LoA selection not risk-based
  • Federation assertions lack signing and replay protection

Clause 10: Criteria and Controls for Levels of Assurance

29115-10.1
Enrollment and identity proofing criteria

Criteria for identity proofing at each LoA including evidence requirements and verification methods

Artefacts an auditor will ask for
  • Identity proofing procedure
  • Credential issuance and revocation log
  • Authentication assurance level mapping
  • Federation and assertion configuration records
  • Threat assessment for authentication flows
Where this commonly fails
  • Identity proofing relies on single attribute checks
  • Credential revocation not timely
  • LoA selection not risk-based
  • Federation assertions lack signing and replay protection
29115-10.2
Credential management criteria

Criteria for credential issuance, renewal, revocation, and storage at each LoA

Artefacts an auditor will ask for
  • Identity proofing procedure
  • Credential issuance and revocation log
  • Authentication assurance level mapping
  • Federation and assertion configuration records
  • Threat assessment for authentication flows
Where this commonly fails
  • Identity proofing relies on single attribute checks
  • Credential revocation not timely
  • LoA selection not risk-based
  • Federation assertions lack signing and replay protection
29115-10.3
Entity authentication criteria

Criteria for authentication mechanisms and protocols at each LoA

Artefacts an auditor will ask for
  • Identity proofing procedure
  • Credential issuance and revocation log
  • Authentication assurance level mapping
  • Federation and assertion configuration records
  • Threat assessment for authentication flows
Where this commonly fails
  • Identity proofing relies on single attribute checks
  • Credential revocation not timely
  • LoA selection not risk-based
  • Federation assertions lack signing and replay protection
29115-10.4
Federation and assertion criteria

Criteria for federation protocols and authentication assertions at each LoA

Artefacts an auditor will ask for
  • Identity proofing procedure
  • Credential issuance and revocation log
  • Authentication assurance level mapping
  • Federation and assertion configuration records
  • Threat assessment for authentication flows
Where this commonly fails
  • Identity proofing relies on single attribute checks
  • Credential revocation not timely
  • LoA selection not risk-based
  • Federation assertions lack signing and replay protection

Clause 11-12: Mapping and Guidance

29115-11
Mapping other authentication schemes

Guidance for mapping other authentication assurance schemes to the four LoAs

Artefacts an auditor will ask for
  • Identity proofing procedure
  • Credential issuance and revocation log
  • Authentication assurance level mapping
  • Federation and assertion configuration records
  • Threat assessment for authentication flows
Where this commonly fails
  • Identity proofing relies on single attribute checks
  • Credential revocation not timely
  • LoA selection not risk-based
  • Federation assertions lack signing and replay protection
29115-12.1
Exchanging authentication results

Guidance for exchanging authentication results that are based on the four LoAs

Artefacts an auditor will ask for
  • Identity proofing procedure
  • Credential issuance and revocation log
  • Authentication assurance level mapping
  • Federation and assertion configuration records
  • Threat assessment for authentication flows
Where this commonly fails
  • Identity proofing relies on single attribute checks
  • Credential revocation not timely
  • LoA selection not risk-based
  • Federation assertions lack signing and replay protection
29115-12.2
Controls for mitigating threats

Guidance on controls that should be used to mitigate authentication threats at each LoA

Artefacts an auditor will ask for
  • Identity proofing procedure
  • Credential issuance and revocation log
  • Authentication assurance level mapping
  • Federation and assertion configuration records
  • Threat assessment for authentication flows
Where this commonly fails
  • Identity proofing relies on single attribute checks
  • Credential revocation not timely
  • LoA selection not risk-based
  • Federation assertions lack signing and replay protection

Clause 5-6: Framework Overview and Context

29115-5.1
Entity authentication assurance framework overview

Overview of the entity authentication assurance framework and its components

Artefacts an auditor will ask for
  • Identity proofing procedure
  • Credential issuance and revocation log
  • Authentication assurance level mapping
  • Federation and assertion configuration records
  • Threat assessment for authentication flows
Where this commonly fails
  • Identity proofing relies on single attribute checks
  • Credential revocation not timely
  • LoA selection not risk-based
  • Federation assertions lack signing and replay protection
29115-5.2
Authentication lifecycle phases

Phases of entity authentication including enrollment, credential management, and authentication

Artefacts an auditor will ask for
  • Identity proofing procedure
  • Credential issuance and revocation log
  • Authentication assurance level mapping
  • Federation and assertion configuration records
  • Threat assessment for authentication flows
Where this commonly fails
  • Identity proofing relies on single attribute checks
  • Credential revocation not timely
  • LoA selection not risk-based
  • Federation assertions lack signing and replay protection
29115-6.1
Authentication context

Factors that determine the required level of authentication assurance in a given context

Artefacts an auditor will ask for
  • Identity proofing procedure
  • Credential issuance and revocation log
  • Authentication assurance level mapping
  • Federation and assertion configuration records
  • Threat assessment for authentication flows
Where this commonly fails
  • Identity proofing relies on single attribute checks
  • Credential revocation not timely
  • LoA selection not risk-based
  • Federation assertions lack signing and replay protection

Clause 7-8: Levels of Assurance

29115-7.1
Level of Assurance 1 (LoA1)

Little or no confidence in the asserted identity; minimal requirements for authentication

Artefacts an auditor will ask for
  • Identity proofing procedure
  • Credential issuance and revocation log
  • Authentication assurance level mapping
  • Federation and assertion configuration records
  • Threat assessment for authentication flows
Where this commonly fails
  • Identity proofing relies on single attribute checks
  • Credential revocation not timely
  • LoA selection not risk-based
  • Federation assertions lack signing and replay protection
29115-7.2
Level of Assurance 2 (LoA2)

Some confidence in the asserted identity; single-factor authentication with basic identity proofing

Artefacts an auditor will ask for
  • Identity proofing procedure
  • Credential issuance and revocation log
  • Authentication assurance level mapping
  • Federation and assertion configuration records
  • Threat assessment for authentication flows
Where this commonly fails
  • Identity proofing relies on single attribute checks
  • Credential revocation not timely
  • LoA selection not risk-based
  • Federation assertions lack signing and replay protection
29115-7.3
Level of Assurance 3 (LoA3)

High confidence in the asserted identity; multi-factor authentication with strong identity proofing

Artefacts an auditor will ask for
  • Identity proofing procedure
  • Credential issuance and revocation log
  • Authentication assurance level mapping
  • Federation and assertion configuration records
  • Threat assessment for authentication flows
Where this commonly fails
  • Identity proofing relies on single attribute checks
  • Credential revocation not timely
  • LoA selection not risk-based
  • Federation assertions lack signing and replay protection
29115-7.4
Level of Assurance 4 (LoA4)

Very high confidence in the asserted identity; hard cryptographic token required with in-person identity proofing

Artefacts an auditor will ask for
  • Identity proofing procedure
  • Credential issuance and revocation log
  • Authentication assurance level mapping
  • Federation and assertion configuration records
  • Threat assessment for authentication flows
Where this commonly fails
  • Identity proofing relies on single attribute checks
  • Credential revocation not timely
  • LoA selection not risk-based
  • Federation assertions lack signing and replay protection

Clause 9: Threats to Authentication

29115-9.1
Threat analysis overview

Overview of threats to the entity authentication process across all phases

Artefacts an auditor will ask for
  • Identity proofing procedure
  • Credential issuance and revocation log
  • Authentication assurance level mapping
  • Federation and assertion configuration records
  • Threat assessment for authentication flows
Where this commonly fails
  • Identity proofing relies on single attribute checks
  • Credential revocation not timely
  • LoA selection not risk-based
  • Federation assertions lack signing and replay protection
29115-9.2
Enrollment and identity proofing threats

Threats during the enrollment and identity proofing phase including impersonation and forgery

Artefacts an auditor will ask for
  • Identity proofing procedure
  • Credential issuance and revocation log
  • Authentication assurance level mapping
  • Federation and assertion configuration records
  • Threat assessment for authentication flows
Where this commonly fails
  • Identity proofing relies on single attribute checks
  • Credential revocation not timely
  • LoA selection not risk-based
  • Federation assertions lack signing and replay protection
29115-9.3
Credential management threats

Threats to credential issuance, storage, and revocation including credential theft and compromise

Artefacts an auditor will ask for
  • Identity proofing procedure
  • Credential issuance and revocation log
  • Authentication assurance level mapping
  • Federation and assertion configuration records
  • Threat assessment for authentication flows
Where this commonly fails
  • Identity proofing relies on single attribute checks
  • Credential revocation not timely
  • LoA selection not risk-based
  • Federation assertions lack signing and replay protection
29115-9.4
Authentication mechanism threats

Threats during the authentication event including replay attacks, man-in-the-middle, and session hijacking

Artefacts an auditor will ask for
  • Identity proofing procedure
  • Credential issuance and revocation log
  • Authentication assurance level mapping
  • Federation and assertion configuration records
  • Threat assessment for authentication flows
Where this commonly fails
  • Identity proofing relies on single attribute checks
  • Credential revocation not timely
  • LoA selection not risk-based
  • Federation assertions lack signing and replay protection

Credential Management

ISO29115-6.1
Credential Lifecycle Management

Manage credentials through issuance, renewal, suspension, revocation, and destruction with LoA appropriate controls.

Artefacts an auditor will ask for
  • lifecycle policy
  • renewal procedures
  • revocation logs
  • destruction evidence
Where this commonly fails
  • revocation latency excessive
  • destruction unverified for hardware tokens
  • renewal does not reverify identity
ISO29115-6.2
Authenticator Binding

Bind authenticators to the identity established during enrolment with integrity protected records.

Artefacts an auditor will ask for
  • binding records
  • rebinding procedures for lost authenticators
  • binding integrity controls
  • audit trail of binding events
Where this commonly fails
  • rebinding does not require reproofing
  • binding records mutable
  • no detection of unbound authenticator use

Enrolment

ISO29115-5.2
Enrolment Phase Controls

Apply enrolment controls including identity proofing and credential issuance proportionate to required LoA.

Artefacts an auditor will ask for
  • enrolment procedures by LoA
  • identity proofing evidence retention policy
  • credential issuance logs
  • registration authority approvals
Where this commonly fails
  • LoA 3 enrolment performed remotely without compensating controls
  • evidence retention shorter than credential lifetime
  • RA training not refreshed

Federation

ISO29115-11.1
Cross LoA Federation

When federating identities across providers, ensure LoA is preserved or appropriately downgraded with relying party awareness.

Artefacts an auditor will ask for
  • federation agreements
  • LoA mapping between providers
  • assertion content specifications
  • relying party LoA awareness mechanism
Where this commonly fails
  • LoA elevated in transit (federation claims higher than source)
  • assertion does not convey LoA
  • RP cannot distinguish LoAs
ISO29115-11.2
Privacy in Authentication

Apply privacy controls to authentication including minimal attribute disclosure and pseudonymisation where appropriate.

Artefacts an auditor will ask for
  • attribute minimisation policy
  • pseudonymous identifier use
  • PII disclosure in assertions audit
  • consent for attribute release
Where this commonly fails
  • full identity disclosed when pseudonymous sufficient
  • no consent for attribute release
  • logs reveal PII across RPs

Foundation

ISO29115-5.1
Authentication Assurance Level Selection

Determine required Level of Assurance (LoA 1 to 4) based on risk analysis of authentication failure consequences.

Artefacts an auditor will ask for
  • risk assessment per relying service
  • LoA determination matrix
  • consequence categories table
  • selection justification document
Where this commonly fails
  • LoA selected by IT preference not risk
  • consequence categories ignore non financial harm
  • no periodic LoA reconfirmation

Identity Proofing

ISO29115-5.3
Identity Proofing at LoA 1

LoA 1 self assertion of identity is sufficient with no verification required of asserted attributes.

Artefacts an auditor will ask for
  • LoA 1 use case justifications
  • self assertion capture mechanisms
  • limitations notice to relying parties
  • LoA 1 service inventory
Where this commonly fails
  • LoA 1 used for higher consequence transactions
  • relying parties unaware of LoA limitations
  • no escalation path to higher LoA
ISO29115-5.4
Identity Proofing at LoA 2

LoA 2 requires verification of at least one valid identity evidence with single factor authentication.

Artefacts an auditor will ask for
  • acceptable evidence list for LoA 2
  • verification logs
  • evidence validation methods (issuer verification)
  • fraud detection results
Where this commonly fails
  • evidence accepted without issuer verification
  • fraud detection limited to format checks
  • no liveness for remote proofing
ISO29115-5.5
Identity Proofing at LoA 3

LoA 3 requires two strong identity evidences verified against authoritative sources plus multi factor authentication.

Artefacts an auditor will ask for
  • LoA 3 evidence requirements
  • authoritative source verification logs
  • biometric or in person checks
  • MFA enrolment records
Where this commonly fails
  • only one strong evidence verified
  • authoritative source replaced with commercial database
  • MFA enrolment over single channel
ISO29115-5.6
Identity Proofing at LoA 4

LoA 4 requires in person proofing or equivalent, multiple strong evidences, and hardware based credentials.

Artefacts an auditor will ask for
  • in person proofing records
  • hardware token issuance logs
  • trusted referee procedures if remote
  • tamper evident credential storage
Where this commonly fails
  • in person waived without equivalence analysis
  • hardware tokens shipped insecurely
  • trusted referee training absent

Operations

ISO29115-12.1
Documented Operating Procedures

Document operating procedures for all authentication services including incident response and exception handling.

Artefacts an auditor will ask for
  • procedures library
  • incident playbooks
  • exception handling workflows
  • version control records
Where this commonly fails
  • procedures tribal knowledge
  • incident playbooks untested
  • exceptions not logged

Provider Assurance

ISO29115-8.1
Credential Service Provider Assurance

Credential Service Providers demonstrate operational, technical, and management assurance commensurate with offered LoA.

Artefacts an auditor will ask for
  • CSP audit reports
  • operational procedures
  • management commitment evidence
  • personnel screening records
Where this commonly fails
  • CSP self attestation not externally audited
  • personnel screening waived for contractors
  • operational procedures outdated
ISO29115-8.2
Registration Authority Operations

Registration Authorities operate with documented procedures, trained personnel, and audit trails for enrolment decisions.

Artefacts an auditor will ask for
  • RA procedures manual
  • RA training records
  • enrolment decision logs
  • RA audit reports
Where this commonly fails
  • RA decisions not logged with reasoning
  • RA training one off (no refresh)
  • no four eyes for LoA 4 enrolment

Threats

ISO29115-9.1
Threat Mitigation Mapping

Map authentication threats to mitigations across enrolment, credential management, and authentication phases.

Artefacts an auditor will ask for
  • threat catalogue
  • threat to control mapping
  • residual threat acceptance
  • threat update process
Where this commonly fails
  • catalogue not refreshed for credential stuffing or SIM swap
  • mappings high level not specific
  • residual threats not formally accepted
ISO29115-9.2
Fraud Detection and Response

Detect authentication fraud through anomaly monitoring and respond with credential actions and investigation.

Artefacts an auditor will ask for
  • fraud detection rules
  • anomaly monitoring dashboard
  • investigation procedures
  • fraud reporting metrics
Where this commonly fails
  • fraud rules static for years
  • no behavioural analytics
  • investigation outcomes not fed back to rules
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.