Identity assurance in hiring is the evidence that the person who took your assessment, sat your interview and turns up on payroll are the same human being. It is a separate question from skill measurement. A test can be perfectly valid and still score an impostor: validity licenses an inference about the person who produced the score, and nothing more.
For most of the history of employment testing, that assumption was free. Candidates walked into a room. In cross-border remote hiring it is not free, and the last two years of public enforcement records show what happens when nobody buys it.
A valid score answers the wrong question if the identity is wrong
Every piece of validity evidence you hold — criterion, content, construct — is conditional on the score belonging to the applicant. Break that link and the psychometrics do not degrade gracefully; they become irrelevant. A 92nd-percentile coding score obtained by a proxy is not a noisy estimate of the candidate's ability. It is an estimate of somebody else's ability.
This is why identity assurance is not a security add-on bolted onto assessment. It is a precondition for the claim the assessment makes.
What the public record actually documents
Treat the enforcement filings as process evidence rather than as a news story. They describe, in unusual detail, which hiring controls failed.
- In a coordinated set of actions announced on 30 June 2025, the US Department of Justice described schemes affecting more than 100 US companies, using the stolen identities of more than 80 US persons, and reported searches of 21 premises across 14 states with roughly 200 computers and 29 financial accounts seized (DOJ).
- A January 2025 indictment set out work obtained from at least 64 US companies between April 2018 and August 2024; payments traced from just ten of them exceeded $866,000.
- Recorded Future's Insikt Group tracked one operating cluster that applied to more than 1,100 companies, running 22 fabricated personas and submitting at least 60 applications a day across 10 job platforms (reported August 2026). Security firm Huntress documented the same pattern reaching healthcare, financial services and sales roles — in one case a substituted identity was caught 13 days after onboarding.
The base rate is rising outside organised fraud too. In a Gartner survey of 3,000 job candidates, 6% admitted to interview fraud — either impersonating someone else or having someone pose as them — and Gartner projects that by 2028 one in four candidate profiles worldwide could be fake (HR Dive, August 2025).
None of these are assessment-quality failures. Every one is an identity failure that a well-built assessment then dutifully scored.
Most employers run "controlled" mode and describe it as "supervised"
The International Test Commission's guidelines on computer-based and internet-delivered testing define four administration modes. The distinction is worth memorising, because the gap between two of them is where remote hiring leaks.
- Open — no human supervision and no way to authenticate the test-taker. A public practice test.
- Controlled — no supervision, but access is restricted to identified participants via a one-time username and password. A login is not an identity.
- Supervised (proctored) — direct human supervision of test conditions, with identity checked at the start and the session confirmed as properly completed.
- Managed — high supervision and control of the environment, typically a dedicated centre with vetted staff and standard equipment.
A unique link emailed to a named address is controlled mode. It proves that whoever received the email took the test. Most volume hiring funnels operate here and report results as if they were supervised.
Borrow the identity-proofing ladder instead of inventing one
Hiring teams do not need a bespoke framework. NIST's SP 800-63A-4 digital identity guidelines already grade identity proofing in three levels, and they map onto hiring stages cleanly:
- IAL1 — the process supports the real-world existence of the claimed identity and gives some assurance the applicant is associated with it. Adequate for top-of-funnel sift.
- IAL2 — additional evidence, more rigorous validation, and enhanced checks that the applicant is the rightful owner of the evidence presented. This is the right bar for a scored assessment that drives a reject decision.
- IAL3 — an on-site attended session with a trained proofing agent and collection of at least one biometric. Reserve it for the offer and onboarding step of high-consequence roles.
If a vendor offers face matching or liveness detection, ask what its presentation-attack detection has been tested against. ISO/IEC 30107-3:2023 is the published standard for testing and reporting biometric presentation attack detection; "AI-powered liveness" with no reference to it is a marketing claim, not a measurement. AssessAll's AI proctoring reports an integrity band rather than a pass/fail verdict for the same reason — a band is a signal for a human reviewer to act on, and treating any automated flag as a finding is how fair processes turn unfair.
What changes by the end of 2026
Under Regulation (EU) 2024/1183, every EU member state must make at least one European Digital Identity Wallet available to its citizens, with the deadline falling in late December 2026. Where wallets land, IAL2-equivalent proofing for EU-based candidates becomes cheap and standardised. That is genuinely useful — and it covers a single bloc. For a Manila, Bengaluru, Nairobi or São Paulo pipeline, verification remains something the employer has to design.
The longer-term fix is a credential that carries both halves — who was assessed and how well they performed, signed and re-checkable. That is the argument for Skill Passports over a PDF score report, and it only works if the identity layer underneath it was real at the moment of testing.
An eight-step verification design
- Write down, per role, the consequence of a wrong hire. Set the assurance level from that, not from the job title.
- Keep the sift at IAL1. Over-verifying 4,000 applicants to catch three is a bad trade and costs you real candidates.
- Move the decision-grade assessment to supervised mode. Randomised item delivery is not supervision.
- Check the document at the same session as the face, not weeks earlier in a separate portal.
- Ask vendors for presentation-attack detection results against ISO/IEC 30107-3, and for false-match rates by demographic subgroup.
- Re-verify at onboarding. The Huntress cases show the substitution often happens between offer and first login, not before.
- Log what you checked, when, and who reviewed each flag. Automated integrity signals should never terminate a candidacy unreviewed.
- Minimise and time-limit biometric data. It is special-category data under GDPR Article 9 and sensitive personal data under India's DPDP Act, 2023 — collect the least that answers the question and delete on schedule.
When lighter verification is the right call
For internal moves, in-person roles, low-consequence hires and small pipelines where a manager already knows the candidate, heavy proofing buys nothing and costs completion. Verification friction is not free: every additional step is an opportunity to lose a good applicant, and a false accusation is far more damaging than a missed check. The point is not maximum assurance everywhere. It is deliberate assurance, matched to the decision the score is about to drive.
Takeaway
Your assessment programme already answers "how good is this person?" with reasonable precision. In a remote, cross-border funnel it is worth spending the same design effort on "which person is this?" — because the first answer is worthless without the second.