Evaluations of IAL3 vendors are usually built around the machinery: evidence validation, biometric matching, audit records, throughput, and price. The experience of the person being verified often receives less weight on the scorecard, even though a poor rollout creates work for HR, security, the help desk, managers, and employees themselves.
At Trust Swiftly, we work closely with human resources teams to implement and operate IAL3 programs. When the rollout is opaque, employees begin their appointments with reasonable questions about their documents, biometrics, and privacy. When they know why the verification is happening, what they need to bring, and what will happen to their information, they arrive ready to complete it.
This is not only a service-design preference. NIST SP 800-63A-4's customer experience guidance recommends preparing users in advance, explaining what data will be collected and where it will be stored, offering scheduling and rescheduling for attended sessions, testing each step with representative users, and providing clear ways to get help. Those recommendations address the same problems that make attended sessions run long.
Preparation Changes the Workload
Across thousands of IAL3 sessions, Trust Swiftly's session statistics show that employees who arrive wary typically take about 50% longer than employees who understand the process and are comfortable proceeding. More time goes toward answering questions, repeating instructions, and helping the employee confirm that a document or biometric capture was completed correctly.
None of that is a character flaw. Every business has a different baseline familiarity with identity processes, and an identity document is exactly the kind of sensitive object that puts some people on high alert the moment they are asked for it. For most employees this is the first high-assurance proofing of their lives. If nobody has told them what will be collected, who reviews it, and what happens to it afterward, alertness is the rational response.
The cost is operational as well as personal. Longer sessions, repeat attempts, and support tickets add up quickly across a workforce. We therefore treat employee preparation as part of the verification workflow, not as a courtesy added after the technical work is finished.
What Puts People at Ease
A familiar location that still meets the standard. Under the current NIST IAL3 requirements, proofing is delivered as on-site attended. The proofing agent may be in the same room or participate remotely through a CSP-controlled kiosk or device. Trust Swiftly supports both co-located and kiosk-based models. With the required Trust Swiftly-controlled equipment and deployment safeguards, the controlled setting can be established in an employee's home office, a reserved room at work, or a dedicated kiosk. For concentrated events, an on-site agent brings the equipment and conducts the session in person.

Scheduling the employee controls. A verification placed on someone's calendar without input can collide with shift work, deadlines, or personal obligations. Employees can choose a suitable time and reschedule when something changes. Offices with steady volume can also run express walk-in flows with a virtual queue so employees are not left waiting in a hallway with identity documents in hand.
Early, complete communication. Before the session, every employee should know what will be collected, why it is needed, who can access it, and what will happen after the session. Recording is configurable: some organizations require a session recording, while others choose not to record. When a session will be recorded, the employee is notified and provides consent before recording begins. Retention and deletion are also configurable, and many programs define a short retention period measured in days. The employee should also know what happens after an incomplete session and how to ask for help or dispute a proofing event.
Accessibility built into the session. Accessibility needs should be identified before the appointment so the right support is ready. Trust Swiftly can provide options such as closed captioning for employees who are deaf or hard of hearing, while the live proofing agent provides step-by-step assistance throughout the session. These options improve access without changing the IAL3 verification requirements.
Handle Exceptions Without Lowering the Bar
IAL3 requirements do not change because someone forgot a document, positioned a passport incorrectly, or moved out of frame. The workflow can, however, distinguish an incomplete session from suspected fraud. An employee who needs the correct evidence can pause and reschedule; someone having trouble with a capture can receive clear instructions and try again. Evidence that does not validate, a biometric mismatch, or signs of off-camera coaching require escalation and review. The pass criteria remain fixed, but the response to each problem does not have to be identical.
It Is Not a Clearance Interview
Employees who have interviewed at national security agencies or completed a security-clearance process sometimes expect IAL3 to involve similar questioning. IAL3 doesn't need to be completed in a windowless room that puts individuals in an uncomfortable environment. Some of the most successful intelligence operations throughout history have been done in the open without the individual knowing the wiser.
IAL3 is identity proofing, not a personnel investigation. It validates qualifying identity evidence, verifies that the evidence belongs to the person presenting it, collects the required biometric sample, and completes attended authenticator binding. It does not investigate the employee's history, associations, habits such as alcohol usage or finances. NIST SP 800-63A-4 states that knowledge-based verification or authentication must not be used for identity verification. Explaining that distinction before the appointment prevents an avoidable misunderstanding.
A Calm Process Reduces Noise
Clear instructions reduce ordinary user errors. That gives the proofing agent more room to concentrate on objective risk signals: evidence that does not validate, a biometric mismatch, signs of manipulation or coercion, off-camera coaching, or actions that are not visible during the attended session.
An experienced bad actor may appear completely calm. Demeanor is not a security control and should not be treated as one. Identity proofing also cannot determine whether a correctly identified employee has malicious intent. What it can do is help identify impersonation, proxy applicants, coaching, and coercion before an authenticator is issued. A comfortable process improves the employee experience and makes those objective impersonation and proxy risks easier to investigate.
Pilot With a Small Group, Then Adjust Quickly
Start with a small, representative group before deploying IAL3 across the workforce. Include different locations, job types, shift patterns, levels of technical familiarity, and accessibility needs. A pilot may uncover an announcement email that looks like phishing, an unclear checklist item, a scheduling window that conflicts with a shift, or a document requirement that causes problems for an employee with a recent name change.
Measure the pilot as well as discussing it. Useful measures include first-attempt completion rate, completion time, abandonment, reschedules, failures by proofing step, and help-desk contacts. Keep usability failures separate from suspected fraud, and compare results by location and workflow so an overall average does not hide a recurring problem. These measures align with the continuous-evaluation metrics recommended by NIST.

Before the wider rollout, establish who can update communication templates, evidence checklists, scheduling windows, retention settings, and accessibility options, along with the expected turnaround time for each change. The pilot is valuable only if its findings can be acted on.
The Checks and the Experience Both Matter
NIST specifies the technical and procedural controls for IAL3 and also addresses the experience of the people completing them. A strong program implements both: qualifying evidence and biometrics, an attended and controlled setting, clear privacy choices, practical scheduling, accessible support, consistent exception handling, and continuous measurement. That is how an organization maintains the IAL3 standard without adding avoidable friction for its employees.
Explore our turnkey IAL3 verification solution, read our guide to choosing an IAL3 solution, or talk to us about designing an IAL3 program built around your employees.