Identity-verification pilot plan
A pilot should test the decision and operating system, not merely demonstrate that a vendor SDK can return a pass. Predefine users, evidence, attacks, privacy, fallback, metrics and stop conditions before processing live applicants.
A pilot does not suspend Irish/EU data protection, security or sector obligations. Use synthetic or controlled data until governance permits a limited real-user test.
For: project owners, identity product, fraud, privacy, security and operations teams. This is independent information, not legal, compliance or security advice.
Pilot charter
- Use case, decision owner and business hypothesis.
- Population, documents, devices and channels.
- Applicable rules and approved data flow.
- Methods, vendor version and configuration.
- Duration, volume and decision authority.
Test set
- Representative legitimate users and edge cases.
- Unsupported, expired, damaged and foreign evidence.
- Presentation, injection, replay and duplicate attempts.
- Low connectivity, older devices and accessibility needs.
- Manual review, recovery, provider outage and deletion.
Success measures
Set target ranges for completion, time, failure, false outcomes, fraud, manual review, fallback, appeal, cost and privacy/security exceptions. Segment carefully enough to find unequal outcomes without collecting unnecessary sensitive data.
Stop conditions
- Material unmitigated fraud bypass.
- Unapproved data use, retention or transfer.
- Disproportionate legitimate-user exclusion.
- Missing incident or deletion evidence.
- Scope/version changes invalidating test results.
Go/no-go record
Record results, limitations, residual risks, required changes and accountable approval. A successful pilot supports a controlled production decision; it does not prove future performance without monitoring.
Evidence and limits
MyID separates enacted rules, official implementation material, testing and vendor claims. A source can establish what its publisher says; it does not prove that every product, deployment or interpretation works as claimed. Where Irish implementation remains unsettled, this page says so.
- NIST SP 800-63A-4 identity proofing
- ENISA Remote Identity Proofing: Attacks and Countermeasures
- General Data Protection Regulation
Sources checked 22 August 2026. Re-check the linked primary material before making a consequential decision.
Next useful pages
Follow the Irish evidence
Get the business briefing when Irish wallet, verification and age-assurance evidence changes.
Join the business briefing