Reading Time: 3 minutes

Asked and Answered in InCommon’s First Identity Proofing Accelerator 

From February to April 2026, faces sat in individual boxes, each interested in one of research and education’s most pressing topics: identity proofing. 

These faces belonged to IT leaders and practitioners at 12 universities who were participating in the pilot cohort of InCommon’s Identity Proofing Accelerator. The Identity Proofing Accelerator is a collaborative program designed to help institutions strengthen identity verification and reduce fraud risk ahead of the 2027 federal deadline enforced by agencies such as the National Institutes of Health and the Department of Education. 

The learning was plentiful, with each institution determining the current state of identity proofing on their campuses, the opportunities and challenges they face, and the language necessary to communicate the need for change. Several participants cited the accelerator as highly engaging, valuable, timely, and intentionally structured. 

Based on what we’ve heard, we have compiled high-value questions from members of our cohort and insights that will move you closer to strengthening identity assurance at your own institution:

1. Why is identity proofing not a technology upgrade?

Technology alone will not solve an issue that spans across institutional processes, risk, and decision-making. Identity proofing affects how campuses verify people, protect systems, and reduce fraud incidents. That means it takes more than a single tool or team to implement identity proofing effectively. Identity proofing stretches across the entire organization and involves stakeholders outside of information technology (IT). 

This process involves departments such as human resources and teams responsible for onboarding a new collaborator to use sensitive research data. Identity proofing also extends to processes such as campus card issuance and responding to student help desk queries.

Institutions make more progress when they treat identity proofing as an organizational priority rather than a standalone IT rollout.

2. Who needs to be involved in identity proofing at your institution?

IT may help drive the work, but IT cannot be the sole owner. Identity proofing decisions often affect the registrar’s office, financial aid, compliance, security, student services, and senior leadership. 

These stakeholders have separate but interconnected data sets and must protect the areas and business processes that are specific to their departments. 

Even though each department may have a different use case, strong identity assurance requires partnership and interdependence across campus, understanding how identity verification is conducted at the start and the steps needed to grant users higher levels of access when permitted to more sensitive data. 

Bringing these stakeholders together early helps institutions move faster, identify process gaps sooner, and build the support needed to build sustainable best practices.

3. Why do relationships matter so much in identity proofing?

Identity proofing depends on coordination, and coordination relies on trust. 

Consider how two different institutions could fare when implementing a shared verification record. One succeeds because their fraud, legal, and IAM teams meet regularly and align on risk thresholds even when their incentives differ. Another may stall because those same functions operate in silos and cannot agree on what the system should capture or who owns the data. 

Frameworks and tools are important, but progress happens when teams are willing to collaborate, share risk, and problem-solve together. 

Strong internal relationships and peer learning across institutions help sustain the work long after the first phase begins.

4. Is identity proofing something institutions can ever “finish”?

No, identity proofing is not a project. Identity proofing does not have a set end date. This is a long game. 

Threats evolve, institutional needs shift, and processes must be revisited over time. The institutions best positioned for success are those that treat identity proofing as an ongoing practice that requires regular evaluation, adjustment, and improvement.

5. How can institutions determine the right identity proofing approach?


There is no one-size-fits-all solution. The right approach depends on an institution’s specific risk profile, business needs, and areas of vulnerability. 

A useful starting point is to ask the following questions: 
What are we trying to protect? 
Where are we most vulnerable? 
Which users, systems, or workflows carry the most risk? 

For example, access to financial aid disbursement carries higher stakes than access to the campus events calendar. 

An IT help desk account capable of resetting passwords and unlocking accounts across the institution could be a high-value target.

Answering the questions above helps institutions choose an approach with solutions tailored to their specific environments.


Move From Questions to Stronger Identity Assurance

Whether your institution is just beginning or already hard at work, the next Identity Proofing Accelerator can help you assess where you are, chart a clear roadmap, and immediately put effective practices to use.

Because identity proofing is not “just an IT problem” and touches the people, policies, systems, and services that shape access across the institution, we encourage participation from researchers, student services, help desks, registrars, compliance teams, financial aid, and other campus partners.

Complete our interest form to stay ahead of the next registration window and be first in line to secure your institution’s spot in the next cohort. 

InCommon logo in orange