Identity account recovery controls
Recovery is a second identity-proofing system. If a password reset, SIM change or support call can replace a strongly verified account owner, the original onboarding assurance no longer protects the account.
There is no universal Irish recovery flow. Organisations should align recovery strength with account risk, authenticators, available evidence and user-accessibility needs.
For: identity security, customer support, fraud, product and privacy teams. This is independent information, not legal, compliance or security advice.
Recovery triggers
- Lost or replaced phone.
- Lost authenticator or passkey.
- Email, number, name or address change.
- Suspected account takeover.
- Wallet or credential replacement.
- User unable to complete the original proofing method.
Layer the decision
- Identify account value and requested change.
- Use remaining bound authenticators where safe.
- Check recent device, session and behavioural risk.
- Require step-up or re-proofing for material risk.
- Delay or notify through an independent validated channel.
- Log support intervention and permit rapid challenge.
Avoid weak knowledge checks
Static personal facts are often available to attackers and should not be treated as strong evidence of control. Support staff should not bypass controls because an attacker sounds convincing or knows account history.
Accessible recovery
People change numbers, lose documents, replace devices and may be unable to repeat a biometric process. Provide secure attended alternatives, trusted-referee patterns where appropriate, clear escalation and a route to contest a lockout.
Evidence and limits
MyID separates enacted rules, official implementation material, testing and vendor claims. A source can establish what its publisher says; it does not prove that every product, deployment or interpretation works as claimed. Where Irish implementation remains unsettled, this page says so.
- NIST SP 800-63A-4 identity proofing
- ENISA Remote Identity Proofing: Attacks and Countermeasures
- General Data Protection Regulation
Sources checked 22 August 2026. Re-check the linked primary material before making a consequential decision.
Next useful pages
Follow the Irish evidence
Get the business briefing when Irish wallet, verification and age-assurance evidence changes.
Join the business briefing