How remote identity proofing should be engineered toward the NIST SP 800-63-4 model — evidence validation, document authentication, presentation-attack detection, biometric matching, and demographic differential performance — and what remains a measured, not designed, claim.