I’m researching Virginia remote/electronic notarization identity proofing and would appreciate law-focused input.
Virginia materials discuss identity assurance methods including personal knowledge, antecedent proofing, credential analysis, KBA under the current law, and the phrase:
“valid digital certificate accessed by biometric data”
My question is narrow: does that phrase mean the signer must already have some certificate-backed credential, such as an X.509/PIV/PIV-I/smart-card type credential, where biometric data is used to access or authenticate the certificate? Or do Virginia notaries/vendors understand it to include ordinary platform workflows such as ID upload, selfie capture, liveness, or face match?
I am not asking whether biometric fraud controls are useful. They may be. I’m asking what statutory identity method the notary is actually relying on, especially for unknown remote signers and for acts before Virginia’s July 1, 2024 KBA change.
If anyone has Virginia statutory text, handbook language, administrative guidance, platform instructions, or real-world audit/journal wording that maps these workflows to the Virginia identity methods, I’d like to compare sources.
My current concern is that people may be using the word “biometrics” too broadly, collapsing certificate-based identity into ordinary selfie/liveness workflows.
Digital certificate: This is a cryptographic credential (often X.509 or PIV/PIV‑I format) issued by a trusted authority, such as a government or certified vendor, that uniquely identifies the signer and can be used to sign or authenticate electronic documents.
Accessed by biometric data: The certificate is secured and accessed using a biometric factor (e.g., fingerprint, facial recognition) rather than a PIN or password. This is consistent with FIPS 203 and FIPS 201 standards for Personal Identity Verification (PIV) cards and related systems.
Valid: The certificate must be unexpired, issued by an authorized entity, and meet the standards set by the Secretary of the Commonwealth."
Yes thanks. This has been the source of widespread confusion. The law in state of VA reference to "Accessed by biometric data" means that the “Digital certificate” is access by biometric data such as a fingerprint smart card reader. It’s interesting that many years ago the same discussion existed but it then went away.
I’m not a fan of biometrics either, and I agree with your comment: “My current concern is that people may be using the word ‘biometrics’ too broadly, collapsing certificate-based identity into ordinary selfie/liveness workflows.”
Per the site’s own definition:
“Selfie Comparison (also known as biometric verification) is a secure method of identity verification that compares a real-time photo of a signer to the photo on their government-issued ID. This process ensures the person participating in the session matches the identification provided.
As a key component of IAL2-compliant identity verification, Selfie Comparison provides an enhanced layer of security. It may also serve as a secondary verification method if a signer is unable to complete Knowledge-Based Authentication (KBA).”
Which basically means the signer failed the Knowledge-Based Authentication questions, so the system falls back to selfie comparison as a secondary verification method.