SDK docs · record/01

Decision record — the assurance vocabulary

Accepted in August 2026: MintID’s four assurance grades are its own contract, anchored on the eIDAS levels and squared with ISO/IEC 29115, with recency reported as a separate freshness band. The options, the comparison, and why the hybrid was chosen.

Context

Status: Accepted (August 2026) · first recorded in July 2026 as an open decision · depends on the specification’s assurance-grade and issuer-conduct rules

Issuers turn authenticated identity checks into one assurance grade, A1 to A4. Something must say, normatively, which evidence suffices for which grade. Two issuers grading the same evidence differently — or one grading A3 on evidence the ecosystem would call basic — would undermine exactly the trust the grades exist to carry.

The choice shapes conformance testing, issuer onboarding and how regulators read a MintID grade. It does not touch chain state or consensus, which is why it could stay open while the provider-neutral KYC interface was being built.

The two options

Option A — a bespoke MintID vocabulary

MintID defines its own evidence requirements: for each grade, the required check types, evidence classes and review cadence, versioned with the protocol.

  • Pros: full control over the semantics; an exact fit for four grades; no dependence on an external body’s revision cycle; conformance tests derived directly from our own text.
  • Cons: the authoring and maintenance burden is ours; every provider and issuer maps onto our vocabulary without ecosystem tooling; regulators and partner institutions must be taught what a MintID grade means; audit defensibility rests on our own documentation alone.

Option B — adopt an external framework wholesale

A1–A4 are defined purely as mappings onto an established framework — candidates included OpenID Connect for Identity Assurance, the eIDAS levels (low, substantial, high) and NIST SP 800-63 (IAL1–3).

  • Pros: regulator and institutional legibility for free; providers already describe their checks in these vocabularies; external audit can lean on established criteria; less text to maintain.
  • Cons: none of these frameworks has four levels, so any mapping onto A1–A4 is partial; revisions happen outside our control; each framework carries a jurisdictional flavour; and some assumptions — such as verifier-side attribute visibility — do not fit a credential presented in zero knowledge.
A: bespokeB: external framework
Fit to four gradesexactpartial (three-level frameworks)
Regulator and partner legibilitymust be builtlargely inherited
Provider-mapping efforthigher (our vocabulary)lower (their native vocabulary)
Revision controloursan external body’s
Jurisdiction neutralityyesflavoured by the chosen framework
Maintenance burdenauthoringtracking plus glue

A hybrid — MintID’s own four-grade contract, anchored on external levels — was recorded at the time as a variant of A. It is where the decision landed.

Decision: the hybrid

MintID keeps its own four-grade contract — grades are decided by the issuer from enumerated, authenticated checks, within the grades the council allows it — and anchors the grades on the eIDAS assurance levels, squared with ISO/IEC 29115. The grade meanings are unchanged; the external columns are mappings, not redefinitions.

GradeeIDASISO/IEC 29115NIST SP 800-63AML posture
A1lowLoA2IAL1customer due diligence
A2substantialLoA3IAL2due diligence with biometric liveness (ETSI TS 119 461 baseline proofing)
A3substantial + enhanced due diligenceLoA3⁺IAL2 + EDDscreening: sanctions, PEP, adverse media
A4highLoA4IAL3qualified identity proofing (ETSI extended proofing, a notified eID at high, the EU Digital Identity Wallet)

Freshness is a second dimension, not a grade. The issuer holds a freshness band — F4 under 30 days, F3 under 90, F2 under 180, F1 under 365 — published as a band and never as a date, so that it cannot become a linkable timestamp.

Why. eIDAS is what Europe’s regulators, the EU Digital Identity Wallet and qualified trust-service proofing use first, and the EU AML Regulation points to it; ISO/IEC 29115 supplies the four-level backbone; and every framework reviewed tiers identity proofing by strength, while none attaches a validity period to a level — which is why validity moved out of the grade. The first issuer implementation informed the choice, and the provider-neutral KYC interface did not change.

Consequences

The issuer-side KYC policy that applies the grades — requirements per type of operator (person or organisation), evidence reuse within the AML envelope, overdue re-verification handled as suspension rather than revocation, and consent withdrawal revoking everything it backed — is implemented behind the provider-neutral interface and awaits counsel sign-off. Until then, the first issuer works with a simulated KYC provider only.

For verifiers nothing changes on the wire: a presentation still proves grade ≥ G and, separately, freshness ≥ F — never a level or a date.