Current Region:
Global

Definitions

Age verification

This is a subset of Age Assurance, providing higher levels of confidence in the age (e.g. 13) or age-range (25+, <17) of a user.

+

Age estimation

This is also a subset of Age Assurance, but providing lower levels of confidence in the age or age-range of a user, often relying on artificial intelligence and machine learning techniques.

Age INFERENCE

This is also a subset of Age Assurance, but providing lower levels of confidence in the age or age-range of a user, relying on methods that imply the age of a user.

=

Age assurance

This is a broader term, which includes age verification as well as methods for age estimation and age inference.

Age Verification

A UK government official describes Age Verification as "the gold standard of Age Assurance."

The British Standards Institution (BSI) defined it in 2018 as:

2.1.8 age verification
determination of an individual’s age involving a full identity verification process

(Source: ISO 27566, see below)

This definition, however, has been overtaken by technology, with methods of age verification now available that do not require full identity verification processes to be repeated.

Typically, Age Verification is confirming age or age-range to a sufficient standard to comply with laws and regulations that specify a particular minimum age which must be checked exactly e.g. 21, 18 or 13.

Age Estimation

Age Estimation methods will typically only indicate a likely age range with a lower level of statistical certainty than Age Verification.

Examples of lower level age estimation techniques given by the UK Government so far typically include the use of artificial intelligence.

But...

High levels of confidence in age-ranges are still possible using Age Estimation. For example, facial analysis can provide a very high level of confidence that a user is over 18, if the software tests for an age above that e.g. 23. Systems can be audited to demonstrate they would correctly confirm a user was over 18 99.99% of the time, if they only confirmed this when the software's estimate indicated the user appeared to be over 23. (This is a far higher standard of accuracy than a human estimating the age of a customer in person, so satisfies regulators in most situations.)

What is NOT Age Assurance?

Age Assurance does not include very simple methods such as ticking / checking a box to confirm age ("Click to confirm you are over 18") or entering a date of birth. These data points could, however, be used in conjunction with other methods that would provide additional evidence to confirm age to a required level of confidence.

Age check / age assessment

A general term for a process used to determine, estimate, infer or establish a person's age, age range or whether they meet a specified age threshold. When greater precision is required, specific methods are referred to as age assurance, age verification, age estimation or age inference.

Source: ISO/IEC 27566-1:2025

Age attribute

Information about a person relating to their age. An age attribute may express an age, date of birth, age range or whether a person is above or below a specified age threshold.

Source: General explanatory term / UK DVS Trust Framework 1.0

Proof of age

Evidence that enables a relying party to establish that a person has attained a particular age or meets an age-related requirement. Proof of age does not necessarily require disclosure of the person's identity, date of birth or other unnecessary personal information.

Source: AVPA definition

Age assurance

A set of processes, methods, technologies, policies and controls used to verify, estimate, infer or establish a person's age, age range or whether they meet a specified age threshold, thereby enabling an organization to make an age-related eligibility decision with some degree of certainty.

Source: ISO/IEC 27566-1:2025

Age verification

Confirmation of age through calculation of the difference between a verified date of birth (or year) and a reference date, typically relying on authoritative credentials such as passports, identity cards, driving licences or digitally issued equivalents.

Source: ISO/IEC 27566-1:2025

Age estimation

A method of age determination performed using inherent features or characteristics to estimate a person's age or age range. Common methods include facial age estimation using computer vision and artificial intelligence applied to photographs.

Source: ISO/IEC 27566-1:2025

Age inference

A method of determining an individual's likely age or age range based on verifiable contextual, behavioral, transactional or environmental signals, rather than biometric data or identity documents. Examples include school enrollment records, financial transactions, account age, content engagement patterns, or participation in age-specific activities.

Source: ISO/IEC 27566-1:2025

Highly Effective Age Assurance (HEAA)

Age assurance that meets Ofcom's statutory criteria for being highly effective for the purposes of the UK Online Safety Act. To qualify as highly effective, an age assurance method must be technically accurate, robust, reliable, fair, and easy to use for all users. Methods based solely on users self-declaring their age do not constitute highly effective age assurance.

Source: Ofcom / UK Online Safety Act

Age Assurance Provider

An organisation that provides one or more age assurance methods or services, which may include age verification, age estimation, age inference or combinations of methods.

Source: AVPA definition

Digital Verification Service (DVS)

A digital service that is provided at the request of an individual and involves: (a) verification of identity or other information about that individual; (b) verification of information about another person with whom the individual has a connection; or (c) verification of information about a thing connected with the individual. DVS are governed by the UK Digital Verification Services Trust Framework.

Source: Data (Use and Access) Act 2025 / UK DVS Trust Framework 1.0

Attribute Service Provider

A provider that creates, checks or shares attributes about a user, such as an age attribute, in accordance with the requirements applying to that role under the UK DVS Trust Framework. ASPs verify, manage and facilitate the sharing of user attributes with relying parties and other framework participants.

Source: UK DVS Trust Framework 1.0

Identity Service Provider

A provider that verifies a user's identity and may create or provide identity information for use by other participants in the UK DVS Trust Framework ecosystem.

Source: UK DVS Trust Framework 1.0

Relying Party (RP)

An organisation or service that relies upon an age assurance, identity or attribute result when making a decision, such as whether a person may access age-restricted content, goods or services. Relying parties consume information from identity and attribute service providers.

Source: UK DVS Trust Framework 1.0

Holder

The person to whom identity or attribute information relates and who holds or controls a credential or other means of presenting that information. In digital credential systems, the holder is the individual who manages and may present credentials to verifiers.

Source: Credential terminology / ISO/IEC 18013-5

Holder Service Provider

A provider of a user-facing device, service, software or application through which a user can collect, store, view, manage or share identity or attribute information. HSPs are required to share metadata about confidence levels, authentication methods, and credential provenance to help relying parties understand and integrate with their services.

Source: UK DVS Trust Framework 1.0

Orchestration / Orchestration Provider

Orchestration facilitates interactions between participants in an age assurance or digital identity ecosystem, enabling technical integration and interoperability. An orchestration provider may, for example, enable a relying party to obtain appropriate age assurance from multiple providers without requiring separate technical integration with each provider.

Source: AVPA working definition / UK DVS Trust Framework 1.0

Reusable age assurance

An approach in which an age assurance result, credential or attribute established through an earlier process can subsequently be presented or used again, subject to appropriate authentication, validity, security controls and consent mechanisms, without repeating the original age assurance process on every occasion.

Source: AVPA definition

Double-blind age assurance

A privacy-preserving approach designed so that the relying party does not need to know the user's identity and the age assurance provider does not need to know which relying party or service the user is accessing. Each participant receives only the information necessary to perform its function.

Source: AVPA definition

Selective disclosure

An approach that allows only the information required for a particular transaction to be disclosed from a larger set of information, using cryptographic mechanisms such as commitment schemes or zero-knowledge proofs. For example, a person may prove that they are over 18 without disclosing their name or date of birth.

Source: Digital credential standard practice / ISO/IEC 18013-5

Derived credential

A credential or proof created using information established by another trusted credential or source, enabling selected information or attributes to be presented without necessarily presenting the original credential in full. Derived predicates allow issuers to specify rules that holders can use to make cryptographic statements without revealing underlying data.

Source: Credential terminology / ISO/IEC 18013-5

Age token / proof-of-age token

A digital representation of an age assurance result or age attribute, such as confirmation that its holder is over a specified age. Depending on its design, an age token can enable age assurance to be reused or presented without revealing the person's identity or date of birth.

Source: AVPA terminology

Confidence level

An expression of the degree of confidence that can appropriately be placed in an age assurance result, taking account of factors such as the method used, quality of evidence, technical accuracy, controls and processes. Confidence levels are also referred to as "Levels of Assurance" (LoA) in some standards and frameworks.

Source: ISO/IEC 29115 / eIDAS Regulation

Age threshold

A specified age used to determine whether a person meets an age-related requirement, such as 13, 16 or 18. Age assurance can establish whether a person is above or below a threshold without establishing or disclosing their exact age.

Source: General explanatory term

Challenge 25

A retail age-checking policy under which a person attempting to purchase an age-restricted product is asked for acceptable proof of age if they appear to be under 25. Challenge 25 provides a safety margin around the applicable legal minimum age and does not change the legal age for purchasing the product. Adopted by many UK retailers and a legal requirement in Scotland.

Source: Retail of Alcohol Standards Group (RASG) / UK policy

Facial age estimation

An age estimation method that uses computer vision and artificial intelligence to analyse facial features and characteristics to estimate a person's age or age range. Facial age estimation does not necessarily identify the individual or require their face to be compared with an identity document or identity database.

Source: ISO/IEC 27566-1:2025 / Biometric terminology

Permission given by a person with parental responsibility for a child for a specified activity, data processing or service to take place. Under GDPR, parental consent is required for processing the personal data of children under 16 years old (or a lower age down to 13 as set by individual member states). A parental consent process must establish that the person giving consent has the appropriate authority and that the required consent has been knowingly given.

Source: GDPR Article 8

Interoperability

The ability of different age assurance systems, providers, credentials and relying parties to exchange and use age assurance information through common technical standards, semantic definitions and trust arrangements, without requiring bespoke technical integration between every pair of participants. Interoperability is essential for digital identity ecosystems to scale.

Source: AVPA working definition / Digital credential ecosystem terminology

Who defines these terms?

ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) have defined age assurance as a "set of processes and methods used to verify, estimate or infer the age or age range of an individual, enabling organizations to make age-related eligibility decisions with varying degrees of
certainty". 

In additon, the IEEE has published a standard for Best Practice in Age Verification, 2089.1

For  more information on our work developing standards, see here.