Asked and Answered in InCommon’s First Identity Proofing Accelerator
From February to April 2026, faces sat in individual boxes, each interested in one of research and education’s most pressing topics: identity proofing.
These faces belonged to IT leaders and practitioners at 12 universities who were participating in the pilot cohort of InCommon’s Identity Proofing Accelerator. The Identity Proofing Accelerator is a collaborative program designed to help institutions strengthen identity verification and reduce fraud risk ahead of the 2027 federal deadline enforced by agencies such as the National Institutes of Health and the Department of Education.
The learning was plentiful, with each institution determining the current state of identity proofing on their campuses, the opportunities and challenges they face, and the language necessary to communicate the need for change. Several participants cited the accelerator as highly engaging, valuable, timely, and intentionally structured.
Based on what we’ve heard, we have compiled high-value questions from members of our cohort and insights that will move you closer to strengthening identity assurance at your own institution:
Technology alone will not solve an issue that spans across institutional processes,
risk, and decision-making. Identity proofing affects how campuses verify people, protect systems, and reduce
fraud incidents. That means it takes more than a single tool or team to implement identity proofing
effectively. Identity proofing stretches across the entire organization and involves stakeholders outside of
information technology (IT).
This process involves departments such as human resources and teams
responsible for onboarding a new collaborator to use sensitive research data. Identity proofing also extends
to processes such as campus card issuance and responding to student help desk queries.
Institutions
make more progress when they treat identity proofing as an organizational priority rather than a standalone
IT rollout.
IT may help drive the work, but IT cannot be the sole owner. Identity proofing
decisions often affect the registrar’s office, financial aid, compliance, security, student services, and
senior leadership.
These stakeholders have separate but interconnected data sets and must protect
the areas and business processes that are specific to their departments.
Even though each department
may have a different use case, strong identity assurance requires partnership and interdependence across
campus, understanding how identity verification is conducted at the start and the steps needed to grant
users higher levels of access when permitted to more sensitive data.
Bringing these stakeholders
together early helps institutions move faster, identify process gaps sooner, and build the support needed to
build sustainable best practices.
Identity proofing depends on coordination, and coordination relies on
trust.
Consider how two different institutions could fare when implementing a shared verification
record. One succeeds because their fraud, legal, and IAM teams meet regularly and align on risk thresholds
even when their incentives differ. Another may stall because those same functions operate in silos and
cannot agree on what the system should capture or who owns the data.
Frameworks and tools are
important, but progress happens when teams are willing to collaborate, share risk, and problem-solve
together.
Strong internal relationships and peer learning across institutions help sustain the work
long after the first phase begins.
No, identity proofing is not a project. Identity proofing does not have a set end
date. This is a long game.
Threats evolve, institutional needs shift, and processes must be
revisited over time. The institutions best positioned for success are those that treat identity proofing as
an ongoing practice that requires regular evaluation, adjustment, and improvement.
There is no one-size-fits-all solution. The right approach depends on an
institution’s specific risk profile, business needs, and areas of vulnerability.
A useful starting
point is to ask the following questions:
– What are we trying to protect?
– Where are
we most vulnerable?
– Which users, systems, or workflows carry the most
risk?
For example, access to financial aid disbursement carries higher stakes than access
to the campus events calendar.
An IT help desk account capable of resetting passwords and unlocking
accounts across the institution could be a high-value target.
Answering the questions above helps
institutions choose an approach with solutions tailored to their specific environments.
Move From Questions to Stronger Identity Assurance
Whether your institution is just beginning or already hard at work, the next Identity Proofing Accelerator can help you assess where you are, chart a clear roadmap, and immediately put effective practices to use.
Because identity proofing is not “just an IT problem” and touches the people, policies, systems, and services that shape access across the institution, we encourage participation from researchers, student services, help desks, registrars, compliance teams, financial aid, and other campus partners.
Complete our interest form to stay ahead of the next registration window and be first in line to secure your institution’s spot in the next cohort.
