Britain's Approach
52.0 What this chapter gives you#
- You will be able to explain what the Identity Cards Act 2006 actually created, name the register at its centre, and say precisely how and when it was destroyed.
- You will be able to describe the design of GOV.UK Verify, quote the National Audit Office’s figures for its cost and its users, and give the real reasons it ended.
- You will be able to explain how GOV.UK One Login is built, name the two vocabularies it uses to describe authentication and identity confidence, and state its rollout position as of August 2026.
- You will be able to say what the UK trust framework is, what certification involves, who accredits the certifiers, and how many services were on the register in August 2026.
- You will be able to point to the exact statute and sections that give digital identity checking a legal footing in the United Kingdom, and say which of those sections are in force and which are not.
- You will be able to walk through a digital right to work check end to end, name the legal protection the employer is buying, and state what happens to someone who has no passport.
- You will be able to explain how criminal record checking uses digital identity, and why it demands a higher standard of proof than logging in to a government website.
- You will be able to set out the 2025 and 2026 digital ID policy with dates: what was announced, what was abandoned, what was consulted on and what had not happened by August 2026.
- You will be able to compare the British, Indian and European approaches on three explicit axes without caricaturing any of them.
- You will be able to judge, from evidence rather than slogan, whether Britain has no identity system or simply an unusual one.
Britain is the country that decided not to have an identity card, and then spent twenty years building the machinery of identity anyway. That contradiction is the whole subject of this chapter, and it is not hypocrisy. It is the result of a political settlement that ruled out one specific thing, a card issued by the state and backed by a state register of the population, while leaving everything else on the table.
What grew in the space left behind is unlike anything in India or in the European Union. The state does not issue you an identity credential that private companies must accept. Instead it writes a rulebook, appoints independent auditors to check companies against it, publishes a list of those that pass, and then, in a few legally sensitive situations, requires that a digital check be done by a company on that list. Identity in Britain is a regulated market with a government standards body at the top of it. That is the thesis of this chapter.
A second story runs alongside, and by 2026 the two had begun to collide. Government itself needed a way for people to sign in and prove who they are, tried once and failed expensively, tried again and succeeded, and then, in September 2025, a Prime Minister announced a compulsory national digital identity. Within four months the compulsion was gone. What remains is a voluntary government credential, a mandatory move to digital right to work checking, a certified private market of sixty-odd services, and a bill announced but not yet introduced when this chapter was written.
We will go through all of it with the real numbers: the fifteen thousand cards cancelled without refund, the 3.6 million people who signed up to a system that expected 25 million, the 48 per cent that should have been 90 per cent, the 2,984,191 signatures on a petition, and the sixty-three certified services on a public register anybody can read this afternoon. Where something was still unsettled in August 2026, we date the sentence rather than pretend.
The plain version#
The card that was printed and then shredded#
Start with the thing that did not happen.
In 2006 the British Parliament passed a law to create a national identity card. The card itself was the visible part, a plastic rectangle with your photograph on it. The important part was invisible: a government database, called the National Identity Register, holding a record for every person, with the facts about them and a list of every time somebody had checked those facts. The card was only a pointer into that database. The database was the system.
Enrolment began slowly. From late 2009 you could pay thirty pounds and get a card. About fifteen thousand people did.
In May 2010 a new government took office having promised to abolish the scheme, and it did so with unusual speed. A short new Act repealed the old one. It said that no more cards would be issued from the day the Act was passed. It said that every card already in people’s wallets would be treated as cancelled one month later. And it said that all the information recorded in the register had to be destroyed within two months. The register was wiped. Nobody who had paid thirty pounds got their thirty pounds back.
That is a strange thing for a country to do, and it left a mark. For fifteen years afterwards, any British minister proposing anything that looked like a national identity system had to explain why it was not that. This is the single most useful fact for understanding everything that followed.
Two different ways to answer “who are you?”#
Here is the idea that separates Britain from most other countries, and it is simple once you see it.
Imagine you need to prove to a landlord that you are you. There are two ways a country can arrange this.
In the first way, the state keeps a book with everybody’s details in it. You are given a number. The landlord types your number into a machine, the machine asks the state’s book, and the book says yes or no. The state is the answer. This is the model India built, and chapter 50 describes it properly.
In the second way, there is no state book of everybody. Instead there are companies whose business is checking people. You take your passport to one of them, it looks at the passport, looks at your face, satisfies itself that the two match and that the passport is genuine, and then tells the landlord that it has done this and is confident. The company is the answer, and the state’s role is only to say which companies are good enough to be believed.
Britain chose the second way. Not by accident, and not quietly: after 2010 it was the only way left open.
The obvious question is what stops a company being sloppy, or lying, or being a fraud itself. That is exactly the problem the British system exists to solve, and its answer is the subject of the next two parts.
The rulebook, the auditor and the list#
Imagine you want to open a restaurant. The government does not cook your food. It writes rules about kitchens, sends an inspector, and publishes a rating you must display in the window. Customers do not have to understand food hygiene. They look at the rating. The British approach to identity is that, applied to identity checking.
The government writes a rulebook. It covers how strong the evidence must be, how you must store the data, what you must do if someone is defrauded, and whether your service works for a blind user or a person without a smartphone.
The government does not do the checking of companies against the rulebook. Independent audit firms do that. Those audit firms are themselves checked, by a national body whose whole job is accrediting auditors, and then approved by the government office that owns the rulebook. So there is a chain: the rulebook, the auditors who are accredited to apply it, and the companies the auditors certify.
The companies that pass go on a public list. Anybody can read that list, today, and see which company was certified, when, for what, and when their certificate expires. From September 2026 those companies may also display a government trust mark, which is the sticker in the restaurant window.
That is the whole architecture. A rulebook, an audit chain and a public list. No national database of people anywhere in it.
The government’s own front door#
Separately from all that, the government had a plumbing problem of its own.
If you have ever tried to use a government website, you will know that each part of government used to have its own account. Tax had one. Vehicle licensing had another. Passports had a third. You collected logins the way you collect loyalty cards, and none of them knew about the others.
So government built one front door for itself, called GOV.UK One Login. You make one account with an email address and a password, you add a second factor so that a stolen password alone is not enough, and that account then works across government services as they move onto it. If a service needs to know not merely that you can log in but that you really are a particular person, there is a second stage: you prove your identity once, usually by scanning your passport or driving licence with your phone and letting the app match your face against the photograph, and afterwards that proof can be reused.
It is worth being clear about what this is and is not. It is a way to sign in to government, and to prove to government who you are. It is not a card. It is not a register of the population. It does not decide whether a shop may sell you wine.
There was an earlier attempt at exactly this job, called GOV.UK Verify, which was built differently and did not work. Understanding why it failed is one of the most instructive things in this chapter, and we come to it in the technical half.
Where the law makes you prove it#
In most of British life nobody can make you prove your identity. There are three places where the law effectively does, and they are the places where the certified market really operates.
The first is employment. An employer who takes on somebody with no right to work in the United Kingdom can be fined, heavily. The employer can protect itself by making a proper check before the person starts, and keeping the evidence. This protection is the reason right to work checking exists at all, and it is why employers are willing to pay for it.
The second is renting. In England, a landlord letting to somebody with no right to rent can be fined, on the same logic.
The third is trust in vulnerable settings. If you are going to work with children or with adults who need care, somebody will run a criminal record check on you, and that check has to be attached to the right person. Getting the identity wrong here is not a paperwork error, it is a child protection failure.
In all three of these, since 2022, you have been allowed to do the identity part digitally rather than by handing over paper documents in a room, provided the digital check is done by a company on the government’s list. That is the join between the rulebook and real life. Without those three legal duties, the certified market would have very few paying customers.
One person, one Monday#
Let us make this concrete and keep the same person for the rest of the chapter.
Priya Nair is a British citizen, born on 3 May 1999, living in Leeds. She has been offered a job as a care assistant at a residential home, starting on Monday 5 October 2026. Three separate identity events have to happen before she can start.
Her employer must satisfy itself that she has the right to work in the United Kingdom. Priya is British, so the answer is obviously yes, but “obviously” is not a defence if an inspector calls. The employer needs evidence, gathered in a prescribed way, kept on file.
Her employer must also obtain an enhanced criminal record check, because the job involves caring for adults at risk. That check will search police records and a list of people barred from that kind of work, and the results are worthless unless the check is firmly attached to Priya rather than to somebody using her name.
And Priya is moving to Leeds for the job, so a letting agent will separately check that she has the right to rent.
In the old world, all three meant photocopying her passport three times in three offices. In the world this chapter describes, Priya scans her passport with her phone, takes a short video of her face, and a certified company performs an identity check that can, done to the right standard, serve more than one of those purposes at once. The employer receives a result and a record it can keep. And no national register of Priya is created anywhere in the process, because there is none to create.
That is the promise. Now we have to be honest about which parts of it are true, which parts are true only in certain conditions, and which parts are not true at all.
Where the plain version stops being true#
“Britain has no identity system” is simply false#
The most common thing said about British identity, by British people, is that we do not have one. It is wrong.
Britain has a passport, held by about 86.5 per cent of people in England and Wales, since the census recorded 13.5 per cent without a valid one. Britain has a photographic driving licence, a National Insurance number issued to everybody, an NHS number for everybody registered with a doctor in England, and a Unique Taxpayer Reference for anybody who files a tax return. Since 2023 photographic identification has been required to vote in person in Great Britain. And following a rollout that began in 2024, most residents who are not British citizens now hold their immigration status as an online record, proved by generating a code for the person asking.
The honest version: Britain does not have a single, universal, state-issued identity credential. It has many partial ones, each tied to a purpose, none of them covering everybody, and no single number that joins them. That is a different claim, and it has real consequences: the gaps in coverage fall on the poorest, and the absence of a join is a privacy protection and an administrative cost at the same time.
A trust framework is a set of rules, not a piece of technology#
It is tempting to imagine the trust framework as a system you plug into. It is not. It is a document. The rules in it are outcome-based on purpose: they tell a provider what must be true of its service, not which software to use.
That is a deliberate and defensible choice, because prescribing technology in a rulebook freezes the market at the moment the rulebook was written. It also has a cost. Two certified services can be built entirely differently, expose different interfaces, and offer no interoperability with each other at all. Certification tells a relying party that a service is trustworthy. It does not tell them it will be easy to integrate, and it does not mean two certified services can hand credentials to each other.
Certification is a photograph, not a video#
Being on the list means an independent auditor checked a service against the rules and issued a certificate, normally valid for three years with audits in between.
Three honest limits follow. First, a certificate covers a named service, not a company: a firm can have one certified product and five uncertified ones, and may not imply otherwise. Second, certified services depend on other services, and if a supplier’s certification lapses, the customer’s certification can fall over with it. This is not hypothetical. GOV.UK One Login itself was temporarily removed from the register when a biometric supplier allowed its certification to lapse, and was reported in January 2026 to have regained certification after re-audit. Third, certification says a service met the rules on audit day. It cannot promise that nothing has gone wrong since.
The market only works if you have a passport#
Here is the sharpest limit in the whole British design, and it is not technical. A digital right to work check for a British or Irish citizen requires a valid British or Irish passport, or an Irish passport card. There is no other document that will do. If you do not have one, the digital route is closed to you and your employer must fall back to examining physical documents in person.
The scale of this is known. Evidence to the Home Affairs Committee in 2026 drew on census figures showing that 5.2 per cent of the working age population in England and Wales held no valid passport, rising to 13.5 per cent of the whole population, with sharp regional variation: 7.6 per cent of working age people in the North East against 2.2 per cent in London, and 17.7 per cent of people in Scotland holding none at all.
Home Office guidance is explicit that employers must not treat people without a passport less favourably. That instruction is necessary because the incentive runs the other way: the digital route is faster and cheaper for the employer, and the person who cannot use it is more trouble to hire.
One Login is not a national identity card, and the argument about that is real#
Supporters point out that One Login has no card, holds no population register, and exists to let you sign in to government services you were already entitled to use. Critics point out that a single government account, reused across every department, proved to a documented standard, is functionally a national identity system even if nobody calls it one, and that the difference between “an account for government services” and “an identity” narrows every time another service is added.
Both descriptions are accurate about different things, and the disagreement is about what happens next rather than about what exists today. The safeguard the Home Affairs Committee recommended in May 2026 was procedural rather than technical: that adding new services to a government digital identity should require parliamentary approval, so that expansion is a staircase with votes on each step rather than a slope.
“Voluntary” is doing a lot of work#
By August 2026 the government’s position was that its digital ID would be voluntary, and that digital right to work checks would be mandatory. Both halves of that sentence are true, and together they are slipperier than either alone.
If digital checking becomes compulsory for employers, and the digital route for a British citizen requires a passport or a government digital ID, then a citizen with neither has a problem that the word “voluntary” does not describe. The Home Affairs Committee said this plainly, noting that the implication that it may become necessary for a British citizen to hold a passport or a digital ID in order to work had not been highlighted by the government and was not specifically asked about in its consultation.
The government is now both referee and player#
For fifteen years the British state’s role was to write rules for a private identity market. Since 2022 it has also run a large identity service of its own, and since 2025 it has proposed to issue a credential to every adult who wants one.
The industry noticed. The trade body for age check providers told the committee it was “baffled” that government proposed a state-run copy of what the private sector already provided, and the chair of the association of digital verification professionals said the announcement had “poisoned the well”. The government’s own figures put the sector at around two billion pounds a year to the UK economy.
The tension has no clean resolution. The state has a legitimate interest in identifying its own users without paying a private toll on every transaction, and the market has a legitimate complaint that the referee has entered the game. Watch what the forthcoming legislation says about which checks the government’s own credential may be used for, because that is where this will be settled.
The technical version#
What the Identity Cards Act 2006 actually built#
The Identity Cards Act 2006, chapter 15 of that year’s statutes, received Royal Assent on 30 March 2006 after one of the longest parliamentary fights of the period. Its long title is worth reading, because it describes an architecture rather than a card: an Act “to make provision for a national scheme of registration of individuals and for the issue of cards capable of being used for identifying registered individuals”, plus offences for possessing identity documents you are not entitled to, plus provision to help verify information given with passport applications.
The register came first in the Act and first in the design. The scheme’s centre was the National Identity Register, a database of registrable facts about individuals, each holder receiving a National Identity Registration Number. The Act’s own part headings tell you what kind of system it was: registration, ID cards, maintaining accuracy of the register, provision of information from the register for verification purposes, required identity checks, supervision, offences, civil penalties, fees and charges, and provisions relating to passports.
Two features caused most of the political trouble. The register recorded not only your details but an audit trail of when they had been provided to somebody else, which critics called a record of your life kept by the state. And the scheme was linked to passports, so that applying for a passport would eventually enrol you.
Costs were contested from the beginning and never settled. The government’s published estimate was of the order of 5.9 billion pounds over ten years. The 2005 LSE Identity Project report put the ten-year cost between 10.6 billion and 19.2 billion pounds, with a median around 14.5 billion. Neither figure was ever tested against a completed rollout, because the rollout never completed.
Cards went on sale from late 2009. By May 2010, when the government changed, about 15,000 were in circulation.
The repeal, clause by clause#
The Identity Documents Act 2010, chapter 40, received Royal Assent on 21 December 2010. Its long title is a single line: an Act to make provision for and in connection with the repeal of the Identity Cards Act 2006.
The operative sections are short and worth knowing precisely, because the speed of them is the political point.
Identity Documents Act 2010 (c. 40)
Royal Assent: 21 December 2010
s.1 Repeal of Identity Cards Act 2006
s.2 Cancellation of ID cards etc
(1) no ID cards issued on or after the day
the Act is passed
(2) all valid cards treated as cancelled at
the end of one month from that day
(3) Secretary of State must write to holders
s.3 Destruction of information recorded in the
National Identity Register, before the end
of two months beginning with the day the
Act is passed
s.4 Possession of false identity documents etc
with improper intention
s.6 Possession without reasonable excuse
s.10 Verifying information provided with passport
applications etc
One month from 21 December 2010 put card cancellation on 21 January 2011. Two months put destruction of the register in February 2011. No provision was made for refunding the thirty pound fee, and none was paid.
Three things survived the repeal and are regularly forgotten. The criminal offences about false identity documents in sections 4 to 6 were kept, so the law about fake papers did not change. Section 10 kept a power to verify information given with passport applications. And identity documents for foreign nationals, issued under separate immigration legislation, continued and evolved into the online immigration status records non-citizens use today. The repeal abolished the card for British citizens and the register behind it, not identity documents in Britain.
The government’s published savings claim at the time was about 86 million pounds over four years, plus roughly 800 million pounds of maintenance costs over a decade that would otherwise have been recovered through fees.
GOV.UK Verify: an elegant design that nobody used#
Verify was the Government Digital Service’s answer to identity after the register was destroyed, and its design deserves respect even though it failed.
The core idea was that government should not hold the identity data. Instead, certified private companies would verify people, and a government hub would sit between those companies and government departments so that neither side learned more than it needed. The identity provider would not learn which government service you were using. The department would not learn which identity provider you had chosen. Matching you to the department’s own records was done by a separate matching service on the department’s side.
GOV.UK Verify, simplified
You
|
v
[Department service] --(1) send auth request-->
[Verify hub]
|
(2) you pick a provider
v
[Certified identity
provider, e.g. a
credit bureau or
the Post Office]
|
(3) signed assertion back
v
[Verify hub]
|
(4) assertion to service
v
[Department matching service]
matches you to its own record
The privacy properties of that arrangement were genuinely good. The performance was not.
The National Audit Office investigated and published its report, “Investigation into Verify”, on 5 March 2019 as HC 1926 of Session 2017 to 2019. Its findings are the most useful single set of numbers in British identity policy, and they are worth setting out exactly.
| Verify measure | Target | Actual |
|---|---|---|
| Users by 2020 | 25 million | 3.6m by Feb 2019 |
| Services by Mar 2018 | 46 | 19 |
| Sign-up success rate | 90 per cent | 48 per cent |
| Benefits 2016-17 to 2019-20 | GBP 873m | GBP 217m |
Costs ran the other way. From 2011-12 to September 2018, spending on Verify and its predecessor Identity Assurance Programme was at least 154 million pounds, of which 58 million went to identity providers. The 2016 business case had assumed a cost of 212 million pounds against 873 million pounds of benefits over four years. The benefits estimate was later cut by 75 per cent to 217 million, and the NAO recorded that it had not been able to replicate or validate even that.
The commercial model failed in an instructive way. The plan assumed the price per sign-up would fall as volumes rose. Volumes did not rise, so average prices paid to providers stayed above twenty pounds for each new verification, and the Cabinet Office kept subsidising departments to use it. Most departments then did not pay even the subsidised invoices. HMRC paid 6.7 million pounds; between 2016-17 and 2018-19 no other department paid at all, and the NAO said it was unclear why.
The single most quoted number is about Universal Credit, Verify’s largest customer and the reason it could not simply be switched off. In the NAO’s words, only 38 per cent of Universal Credit claimants could successfully verify their identity online, of the 70 per cent of claimants who attempted to sign up through Verify. The Department for Work and Pensions put 12 million pounds into keeping Verify running to March 2020 while it worked on an improvement plan.
The Infrastructure and Projects Authority reviewed the programme in July 2018 and recommended closing it as quickly as practicable. In October 2018 the Cabinet Office announced that central funding would cease in March 2020, capped at 21.5 million pounds in the meantime, with five commercial identity providers on eighteen-month contracts and an intention that the private sector would take Verify over. That handover did not happen in the form imagined. The service was formally closed in 2023.
There are four reasons for the failure, and only one of them is technology.
The first is that the people who most needed to prove their identity to government were the people the private data industry knew least about: young people, renters, people without credit histories, people who had moved recently. Verification leaned on records held by credit reference agencies, and a thin file meant a failed check. The 48 per cent success rate is that fact in one number.
The second is that departments already had a working alternative, the Government Gateway, and were not compelled to move. A platform whose value depends on adoption cannot be optional for the organizations whose adoption it needs.
The third is the commercial model. Paying over twenty pounds per verification, where nobody was reaching the volumes that would bring the price down, is not a business, it is a subsidy waiting to be withdrawn.
The fourth is the privacy design itself, and this is the uncomfortable one. Because the hub deliberately prevented the department from learning who had verified you, each department needed its own matching service to attach the verified identity to its own records, and matching turned out to be hard, expensive and error-prone. A design that protects the citizen from the state’s own joining-up will cost the state more to operate. That is a genuine trade-off, not a mistake, but somebody has to be willing to pay for it and nobody was.
GOV.UK One Login: the design that replaced it#
One Login is Verify’s successor and is built on opposite instincts. Government runs the identity checking itself, using commercial suppliers underneath, and the account is government’s own rather than a broker between the citizen and a private provider.
Technically it is an OpenID Connect provider. A relying party service registers, generates a key pair, and sends an authorization request to the standard endpoint, signing the request object with its private key. The two things a British integrator has to understand are the vocabularies used to say how strongly the user was authenticated and how strongly their identity was proved. Both come from RFC 8485, the Vectors of Trust specification, and the values are these.
| Vector | Meaning | Notes |
|---|---|---|
| Cl | Credential low | Username and password |
| Cl.Cm | Credential medium | Password plus 2FA |
| P0 | No identity proving | Default |
| P1 | Low identity confidence | Requires Cl.Cm |
| P2 | Medium identity confidence | Requires Cl.Cm |
A request that wants a signed-in user who has also proved their identity to medium confidence therefore asks for Cl.Cm.P2. Asking for identity confidence at all requires the medium authentication level; a service that only asks for Cl cannot request identity attributes.
GET /authorize
?response_type=code
&scope=openid+email+phone
&client_id=<your client id>
&state=<opaque value>
&redirect_uri=<your callback>
&nonce=<single use value>
&vtr=["Cl.Cm.P2"]
&claims={"userinfo":{
"https://vocab.account.gov.uk/v1/coreIdentityJWT":
null}}
If identity proving succeeds, the service always receives the user’s name, date of birth and the level of identity confidence achieved, carried in a separately signed core identity claim rather than as loose fields. It may additionally request the user’s postal addresses for the last three years, and the passport or driving licence details used, and it may be asked to justify why it needs them. From the sign-in half it receives a unique identifier for the user, an email address, and a phone number where one was used for the second factor.
As of August 2026 the service publicly states that it provides a medium level of confidence and plans to offer low and high in future. This matters more than it sounds, and we return to it when we reach criminal record checks.
The rollout is the part that changed most between 2024 and 2026. In November 2024 the Government Digital Service celebrated a fiftieth service and published figures stated as “over 3 million One Login accounts have been created”, “over 6.2 million identities issued”, “over 8.8 million downloads of our ID check app” and 50 services onboarded. The first two sit oddly together and the post does not explain the difference, so treat them as published rather than as reconciled. By mid-January 2026, figures attributed to the Government Digital Service put One Login at 13 million registered users across 120 public services.
Two migrations mark the change of scale. Companies House completed its move on 13 October 2025, after which its filing service could not be used without One Login. HMRC, by far the largest set of personal accounts in British government, went into public beta on 9 February 2026 for a proportion of first-time users, with existing Government Gateway users to follow. The stated destination is that One Login replaces every other way of signing in on GOV.UK.
Inclusion work is part of the design rather than an afterthought, and is one of the clearest lessons taken from Verify. A face-to-face route through Post Office branches opened in October 2023 for people who cannot or will not complete the check on a phone, a contact centre opened at the same time, and the range of acceptable evidence was widened to include documents such as biometric residence permits and knowledge-based questions.
GPG 45, and the arithmetic behind “medium confidence”#
British identity assurance has a specific vocabulary, and it is worth learning because it is used identically by government and by the certified market.
Two guidance documents do the work. Good Practice Guide 44 covers authentication, that is, how confident you are that the person signing in now is the same person who set the account up. Good Practice Guide 45, published as “How to prove and verify someone’s identity”, covers identity proving, that is, how confident you are that the claimed identity is real and belongs to the person in front of you.
GPG 45 does not have levels in the simple sense. It scores five separate things and then defines named combinations. The five are the strength of the evidence, its validity, the activity history attached to the identity, the counter-fraud checks performed, and the verification that the evidence belongs to the person presenting it. A named combination is called an identity profile, and profiles map to four levels of confidence: low, medium, high and very high.
The medium profiles that use a single piece of evidence show the arithmetic clearly.
| Profile | Strength / validity | Fraud / verification |
|---|---|---|
| M1A | 4 / 2 | 1 / 2 |
| M1B | 3 / 2 | 2 / 2, activity 1 |
| M1C | 3 / 3 | none / 3 |
| M1D | 2 / 2 | 1 / 3, activity 2 |
Read M1A and M1B against a real document. A current British passport, chip read and checked, is the strongest ordinary evidence available, so a single passport with a good face match can reach M1A. A weaker document requires either better verification, or activity history showing the identity has been in use over time, or stronger counter-fraud checking, to reach the same medium level by a different route. That is why the profiles exist: they are alternative ways to buy the same confidence with different evidence.
For completeness, the recognized profiles are grouped as L1A to L3A at low confidence, M1A to M3A at medium, H1A to H3A at high, and V1A to V3A at very high.
One Login’s own certification is against the identity service provider role at medium confidence, using profiles M1A and M1B, with a certificate that on the reporting available expires on 30 October 2026. A practitioner should note the consequence: One Login as of August 2026 can be the identity layer for services that need medium confidence, and cannot be the identity layer for anything requiring high.
The trust framework: roles, rules, certification and the register#
The rulebook has a long publication history, and getting the versions right matters because certification is always against a named version.
| Version | Published | Status note |
|---|---|---|
| alpha | 11 Feb 2021 | Prototype, DCMS |
| alpha v2 (0.2) | Aug 2021 | Certification approach added |
| beta | 13 Jun 2022 | Updated July 2023 |
| gamma (0.4) | 26 Jun 2025 | Non-statutory |
| gamma (0.4) | 1 Dec 2025 | Statutory version |
| 1.0 pre-release | 3 Mar 2026 | For business readiness |
| 1.0 final | 9 Jun 2026 | In force expected 1 Sep 2026 |
The 1.0 publication is also a renaming. Every earlier version was called the UK digital identity and attributes trust framework. The 1.0 version is called the UK digital verification services trust framework, to match the term the statute uses. Practitioners will meet both names for years; they are the same document at different versions.
The framework is maintained by the Office for Digital Identities and Attributes, known as OfDIA, which sits inside the Department for Science, Innovation and Technology. Its rules are grounded in six published principles: privacy, transparency, inclusivity, interoperability, proportionality and good governance.
There are five certifiable roles, and a service must perform at least one of them.
| Role | What it does |
|---|---|
| Identity service provider | Checks a user’s identity |
| Attribute service provider | Collects and checks attributes |
| Holder service provider | Holds identity over time |
| Orchestration service provider | Orchestrates the participants |
| Component service provider | Supplies part of a process |
Identity, attribute, holder and orchestration roles may be held concurrently by a single service in any combination. A component service may not hold any other role concurrently, and must be certified separately, so that customers can see exactly what has been certified.
Certification runs through conformity assessment bodies. A conformity assessment body must be accredited to ISO 17065 by the United Kingdom Accreditation Service and approved by OfDIA to certify against the framework. A certificate is normally valid for three years, subject to surveillance audits, and OfDIA may require an uplift to a newer publication sooner than three years. Where there is suspicion that the rules are not being followed, the investigation is launched by the conformity assessment body the provider contracted with, not by the government.
The transition arrangements for 1.0 show how a live certification regime handles a version change. From the coming into force date, expected to be 1 September 2026, a provider not already certified can only certify against 1.0. Holders of gamma certificates may apply for new gamma certification only in narrow circumstances, including where they apply within fifteen months of that date and before their existing certificate expires. All gamma certificates cease to count once twenty-seven months have elapsed from that date, or when the service uplifts, or when the certificate expires, whichever comes first. A “delta uplift” route allows an already certified provider to be audited only against the rules that changed.
The public register is the visible end of all this. It is maintained under section 32 of the Data (Use and Access) Act 2025 and can be read by anybody. As of 12 August 2026 it listed 63 certified services, filterable by role, by trust framework version and by the three supplementary codes for right to work, right to rent and Disclosure and Barring Service checks. Individual entries carry certification and expiry dates: to take three from that day’s listing, Amiqus ID was certified on 3 August 2026 with expiry 10 August 2029; a Deloitte service called Go Verify was certified on 21 July 2026 for the right to work code; and Signicat’s ReadID held orchestration and component roles from 29 June 2026.
The newest addition is a mark rather than a rule. Providers certified against 1.0 may, for the first time, display a trust mark called UK CertifID, licensed by the Secretary of State and issued by OfDIA on their behalf. Its use is optional. It is the sticker in the restaurant window, letting a member of the public recognize a certified service without reading a register.
Three changes in 1.0 are worth a practitioner’s attention. Holder service providers must now share metadata about identity confidence, authentication methods, provenance and binding to the user, so that a relying party can understand a credential it did not issue. Orchestration providers must be able to confirm whether the services they orchestrate are on the register, against a cached copy or the live register, anticipating a programmatic interface to it. And the prohibition on processing identity and attribute data for certain purposes was extended to metadata about that data, on the reasoning that metadata can reveal as much as the data.
The statutory footing: the Data (Use and Access) Act 2025#
Until 2025 the entire British trust framework had no statutory basis. It was a voluntary scheme with real commercial consequences and no Act behind it. That changed with the Data (Use and Access) Act 2025, chapter 18, which received Royal Assent on 19 June 2025.
Part 2 of that Act, sections 27 to 55, is the digital verification services regime. The structure is straightforward once you see the pattern: the Secretary of State prepares and publishes a framework, may add supplementary codes for particular uses, must maintain a public register of providers certified against it, has powers to refuse or remove registration, may license a trust mark, and must report on how the whole thing is working.
| Section | Provision |
|---|---|
| 28 | DVS trust framework |
| 29, 30 | Supplementary codes |
| 31 | Review, consulting the ICO |
| 32 to 44 | The register and its entries |
| 45 to 49 | Public authority gateway |
| 50 | Trust mark licensing |
| 53 | Report on Part 2 |
| 55 | Powers on identity checks |
Most of Part 2 was commenced on 1 December 2025 by the Commencement No. 4 Regulations. The exception matters: sections 45 to 48, which allow public authorities to disclose information to registered providers, were held back, and a code of practice under section 49 is to be prepared before those powers go live. In plain terms, the legal plumbing that would let a government department confirm a fact about you directly to a certified private checker existed on paper from June 2025 but was not switched on as of August 2026.
Section 31 requires consultation with the Information Commissioner’s Office and other appropriate stakeholders when the framework is prepared or revised, which is why the framework’s own text records that it was consulted on through written surveys and working groups.
Right to work: how the IDSP model works in practice#
Right to work checking is the largest real use of the certified market, and its mechanics repay careful reading.
The employer’s motivation is a legal defence. Carrying out a prescribed check before employment begins, and keeping the evidence, gives the employer a statutory excuse against liability if the person turns out to have no right to work. Without it the employer faces a civil penalty of up to 60,000 pounds per illegal worker, and criminal liability where the employment was knowing.
There are three routes, and choosing the wrong one destroys the excuse.
| Route | For whom | Mechanism |
|---|---|---|
| Manual | Anyone with listed documents | Examine originals in person |
| Online service | Holders of eVisas | Share code plus checking |
| Digital via provider | British and Irish passports | IDVT by certified service |
The digital route opened on 6 April 2022 and uses Identity Document Validation Technology, universally abbreviated to IDVT, performed by what the Home Office called an Identity Service Provider and what the statute now calls a digital verification service. The scope is narrow and precise: British or Irish citizens holding a valid passport, or an Irish passport card. The guidance is explicit that using a provider for a manual document check, or for a check through the Home Office online service, does not give a statutory excuse. The provider does the identity part; the employer must still carry out its own likeness check against the person who turns up, and must keep the output for the duration of employment and for two further years.
That last obligation is one employers routinely get wrong. The Home Office’s own survey found that 37 per cent of micro and small employers kept records only for the length of employment rather than the required two years afterwards.
Volumes tell you how the market is really distributed. A Home Office survey of employers in September 2024 found that 79 per cent of employers conducted manual right to work checks, 37 per cent used the Home Office online service for eVisa holders, and 23 per cent used digital verification providers. The Association of Digital Verification Professionals told Parliament its members perform about five million right to work checks in the United Kingdom each year. On the eVisa side, the Home Office told the Home Affairs Committee that in February 2026 alone, eight million eVisas were checked through online services, against five million eVisa accounts registered by January 2026.
The current published guidance for employers is dated 26 June 2025. A draft version dated 16 July 2026 was published ahead of a significant change: section 48 of the Border Security, Asylum and Immigration Act 2025 comes into force on 1 October 2026 and extends right to work duties beyond employees to gig economy workers, individual subcontractors and people engaged through online matching platforms, with the same penalty exposure. Any statement in this section about who must check whom should therefore be read as correct for August 2026 and due to widen in October.
Now put Priya through it. She is British and holds a current passport. Her employer sends her a link from a service on the register that carries the right to work supplementary code. She photographs the passport’s data page and lets the app read the chip, which cryptographically proves the passport data has not been altered. She records a short video for the liveness and face match. The provider scores this against GPG 45, reaching a medium confidence profile with the passport as strong evidence, and returns a result and an identity document validation report to the employer. On her first morning the manager checks that Priya’s face matches the photograph in that report. The employer files the report, dated before her start date, and keeps it until October 2028. That file is the statutory excuse.
Right to rent, and criminal record checks#
The same machinery, with different parameters, serves two other statutory duties.
Right to rent applies in England. Landlords and agents may use a certified provider for the same narrow category, British and Irish citizens with valid passports, on the same basis and with the same warning against treating others less favourably. Penalties were sharpened on 13 February 2024, when maximum civil penalties for a first breach rose from 80 pounds per lodger and 1,000 pounds per occupier to 5,000 pounds per lodger and 10,000 pounds per occupier, and for repeat breaches to 10,000 pounds per lodger and 20,000 pounds per occupier.
Criminal record checking is more demanding, and is the clearest illustration of why levels of confidence exist.
The Disclosure and Barring Service issues basic, standard, enhanced and enhanced-with-barred-lists certificates. Its digital identity verification guidance permits identity checking by a digital verification service certified against a current publication of both the trust framework and the DBS supplementary code, by an approved conformity assessment body. The confidence requirements differ by check type: a minimum of medium confidence for a basic check, and a minimum of high confidence for standard, enhanced and enhanced-with-barred-lists checks. The guidance was updated on 10 July 2026, and the underlying ID checking guidelines for standard and enhanced applications have applied since 22 April 2025.
Two further requirements often catch people out. The applicant must declare at least five years of address history to the organization processing the check. And if the current address is not verified by the digital verification service itself, it must be verified within 90 days. Records must be kept for a minimum of two years.
Follow Priya again. Her care home job needs an enhanced check with barred lists, so the identity part must reach high confidence, not medium. Her single chip-read passport reached a medium profile, which is enough for right to work but not enough here. The provider must add evidence: a second document, or a validated activity history showing the identity in use over time, or stronger counter-fraud checking, until a high profile is met. This is precisely why One Login, providing medium confidence as of August 2026, cannot today be the identity layer for an enhanced DBS check, and why the private certified market is not merely a duplicate of the government service.
The policy turn of 2025 and 2026#
Everything above was built slowly, by officials, over fifteen years. What happened next was fast, and it happened in public.
| Date | Event |
|---|---|
| 26 Sep 2025 | PM announces digital ID |
| 13 Oct 2025 | To be built inside government |
| Nov 2025 | OBR costs it at GBP 1.8bn |
| 15 Jan 2026 | Mandatory element abandoned |
| 10 Mar 2026 | Consultation published |
| 5 May 2026 | Consultation closes |
| 13 May 2026 | Bill in King’s Speech |
| 20 May 2026 | Home Affairs Committee reports |
On 26 September 2025 the Prime Minister announced that a digital ID would be introduced by the end of the Parliament and would be mandatory for right to work checks. The announcement followed a paper by the think tank Labour Together proposing a mandatory “BritCard”, a letter from around forty backbench MPs in April 2025, and a visit by the then Chancellor of the Duchy of Lancaster to Estonia in August 2025.
The reaction was severe. An e-petition against introduction attracted 2,984,191 signatures, among the most-signed petitions ever recorded. Polling moved sharply: More in Common found 53 per cent support for digital ID in November 2024 and 31 per cent support for the government’s mandatory proposal by September 2025 with 32 per cent strongly opposed, and Ipsos found support for a national ID card scheme falling from 57 per cent in July 2025 to 32 per cent by February 2026. The First Minister of Scotland and the First Minister and Deputy First Minister of Northern Ireland criticized the scheme, and no opposition party supported it. Officials reportedly raised compatibility with the Common Travel Area with Ireland, which a Home Office minister later confirmed had been “a concern that was raised in meetings”.
On 13 October 2025 the Secretary of State for Science, Innovation and Technology told the Commons that the digital ID was expected to be designed and built within government. In November 2025 the Office for Budget Responsibility estimated the cost at 1.8 billion pounds across 2026-27 to 2028-29 and noted that no funding had been identified; Number 10 rejected the estimate and said costs to 2028-29 would be met from existing budgets, while conceding it did not yet have its own estimate.
On 15 January 2026 the then Parliamentary Secretary in the Cabinet Office told the Commons that a government-issued digital ID would no longer be mandatory for right to work checks, while digital right to work checks themselves would still become mandatory by the end of the Parliament. That is the pivot on which current policy stands: the checking becomes compulsory, the credential does not.
A consultation was published on 10 March 2026 and closed at 12:30 on 5 May 2026, accompanied by a People’s Panel on Digital ID of 120 people meeting to deliberate on the proposals, and by British Sign Language and Easy Read versions. The consultation states that the digital ID will be free, that there will be no legal obligation to have it, and that access to public services will not depend on holding it, while also indicating that the range of acceptable evidence for right to work checks will be narrowed.
The King’s Speech of 13 May 2026 named a Digital Access to Services Bill, described as bringing forward powers to deliver a voluntary digital ID scheme for access to public services, setting out what the credential will contain and how it may be issued, maintained, stored and verified. When the parliamentary bills register was checked in mid-August 2026, no bill of that name had yet been introduced. [UNVERIFIED: whether the Digital Access to Services Bill was introduced in Parliament between mid-August 2026 and publication, and whether the government’s response to the March 2026 consultation had been published by then]
The Home Affairs Committee published “Mandatory to manageable: the government’s plans for digital ID” as HC 986 on 20 May 2026. Its verdict on process was blunt: the announcement was “rushed, poorly thought through”, the policy had been developed “back-to-front”, and the committee was “sceptical that digital ID will be any different” from previous government digital transformation programmes. It recommended a costed roadmap, engagement with the public specifically on what documents will be needed to work, and statutory safeguards so that future expansion requires parliamentary approval, describing the ambition as “not a slippery slope, rather a staircase”.
GOV.UK Wallet, briefly#
Running alongside the policy argument is a quieter engineering programme. The Government Digital Service has built a wallet inside the GOV.UK One Login app to hold government-issued credentials. The digital HM Armed Forces Veteran Card went live in October 2025 and had been added by more than 15,000 veterans by January 2026. Private testing of a digital driving licence with the Driver and Vehicle Licensing Agency began in December 2025, with wider rollout planned during 2026.
The engineering problem GDS names is the interesting one. A physical licence has security features you can see; a digital credential does not, so checking must be programmatic, with the checker’s software validating the credential’s signature with the holder’s consent. That is a signed document replacing a database lookup, and chapter 53 handles it properly.
Three axes against India and Europe#
Comparisons between national identity programmes usually collapse into slogans. Three axes make the differences precise.
| Axis | UK | India / EU |
|---|---|---|
| Who issues identity | Certified firms | State / state wallets |
| What law compels | The check | Use / acceptance |
| Where data rests | With providers | Central / holder |
The first axis is who issues the identity. In India the state issues one identifier to every resident and holds the biometrics behind it, with roughly 1.43 billion numbers issued; chapter 50 covers that programme. In the European Union, Regulation (EU) 2024/1183 obliges each member state to provide at least one wallet, with the deadline of 24 December 2026; chapter 51 covers it. In the United Kingdom the identity is issued by whichever certified private service the person or the relying party chose, and until the Digital Access to Services Bill passes there is no state-issued citizen credential at all beyond the passport and the driving licence.
The second axis is what the law actually compels. India’s Aadhaar Act compels use in a defined way, by permitting authorities to require the number as a condition of subsidies and benefits drawn from public funds. Europe compels acceptance: member states must accept wallets where their public services require electronic identification, and designated very large online platforms must accept them on request. Britain compels neither the holding nor the accepting of an identity credential. It compels the check: an employer must check right to work to get its statutory excuse, a landlord must check right to rent, and from the end of this Parliament the government intends that the check must be digital. Compulsion lands on the organization, not on the individual, and that is the most distinctive feature of the British model.
The third axis is where the data rests and who pays. India’s model queries a central repository. Europe’s model puts issuer-signed credentials in the holder’s own wallet on the holder’s own device. Britain’s data sits with the certified provider that performed the check and with the relying party that bought it, and the relying party pays: right to work checking is a business cost of employers, not a public service. The consequence is a market of about two billion pounds a year by the government’s own estimate, and a system whose coverage follows commercial demand rather than population need, which is why a person without a passport can fall outside it entirely.
There is a fourth difference that is not an axis but a temperament. India built, then litigated. Europe legislated, then built. Britain abolished, let a market grow, then legislated to describe the market it already had: the Data (Use and Access) Act 2025 did not create the trust framework, it gave statutory footing to something four years old. Practice first and law afterwards explains both the system’s pragmatism and its gaps.
What Britain actually bought#
What worked: the certification regime is real, independently audited, publicly listed and used in legally consequential situations every day. The supplementary codes give a narrow, checkable definition of what a provider must do for a specific statutory purpose, which is more than most countries’ frameworks manage. One Login, after a decade of failure, is at population scale.
What did not: 154 million pounds went into Verify and its predecessor for 3.6 million users and a 48 per cent success rate. The certified market reaches only those with the right passport. The statutory information gateway that would let public authorities confirm facts to certified providers, the piece that would most improve inclusion, was still not switched on in August 2026. And the government’s own 2025 announcement, by the finding of a select committee, damaged public support for the thing it was trying to introduce. Whether “voluntary credential, mandatory check” survives contact with the people who have no passport is the question to watch, and no specification will answer it.
52.98 Common wrong ideas#
Wrong: Britain rejected identity cards, so Britain has no national identity infrastructure. Right: Britain abolished one specific thing in 2010, a state-issued card backed by a population register, and then built a certified market of identity providers, a government single sign-on with identity proving used by 13 million people by January 2026, and a statutory trust framework under Part 2 of the Data (Use and Access) Act 2025.
Wrong: The Identity Cards Act 2006 was repealed because the cards were unpopular. Right: The cards were part of the objection, but the Identity Documents Act 2010 was written around the register: section 3 required all information in the National Identity Register to be destroyed within two months of Royal Assent on 21 December 2010, which is a statement about databases rather than about plastic.
Wrong: GOV.UK Verify failed because the technology did not work. Right: The Infrastructure and Projects Authority noted in 2017 that the platform was an innovative technical success performing to specification; it failed on take-up, on a commercial model that kept prices above twenty pounds per verification, on departments having alternatives, and on verification methods that could not confirm people with thin credit files, producing a 48 per cent success rate against a 90 per cent target.
Wrong: GOV.UK One Login is a national identity card in software. Right: It is an OpenID Connect provider that lets you sign in to government services and, optionally, prove your identity to medium confidence for reuse across those services; it issues no credential to be shown to a shop, and holds no register of the population, though critics reasonably argue that a single reusable government identity acquires the properties of one as more services join, which is why the Home Affairs Committee recommended parliamentary approval for each expansion.
Wrong: Being on the government’s register means a company is approved by the government. Right: It means an independent conformity assessment body, accredited to ISO 17065 by the United Kingdom Accreditation Service and approved by OfDIA, certified a named service against a named version of the trust framework, usually for three years with surveillance audits, and the certificate covers that service alone and not the company.
Wrong: Any certified provider can do any statutory check. Right: The trust framework certification is the base, and separate supplementary codes govern right to work, right to rent and Disclosure and Barring Service checks, so the register is filterable by code, and the confidence required differs by purpose: a minimum of medium confidence for a basic DBS check and a minimum of high for standard and enhanced ones.
Wrong: Digital right to work checks are available to everybody in Britain. Right: For British and Irish citizens the digital route requires a valid British or Irish passport or an Irish passport card, with no substitute permitted, so the 5.2 per cent of working age people in England and Wales without a valid passport must use a manual document check, and employers are instructed not to treat them less favourably.
Wrong: The government abandoned digital ID in January 2026. Right: It abandoned compulsion, not the programme: the statement of 15 January 2026 kept the plan to make digital right to work checks mandatory by the end of the Parliament while dropping the requirement to use a government-issued digital ID for them, a consultation ran from 10 March to 5 May 2026, and a Digital Access to Services Bill for a voluntary scheme was announced in the King’s Speech of 13 May 2026.
Wrong: The trust framework tells providers which technology to use. Right: Its rules are deliberately outcome-based and direct providers to open technical standards where possible rather than mandating particular technologies, which preserves innovation but means two certified services may be entirely incompatible with each other.
Wrong: The Data (Use and Access) Act 2025 turned the trust framework on. Right: The framework had been running non-statutorily since February 2021; the Act gave it a legal basis in sections 28 to 32, most of Part 2 was commenced on 1 December 2025, and the sections that would let public authorities disclose information to certified providers, sections 45 to 48, were deliberately held back pending a code of practice and were still not in force in August 2026.
52.99 Chapter summary in 20 lines#
- The Identity Cards Act 2006 received Royal Assent on 30 March 2006 and created a National Identity Register with a registration number for each person, of which the card itself was only a token.
- Published cost estimates never converged, with the government citing figures of the order of 5.9 billion pounds over ten years and the 2005 LSE Identity Project report estimating between 10.6 billion and 19.2 billion pounds.
- About 15,000 cards had been issued at thirty pounds each when the scheme was abandoned in 2010, and no refunds were paid.
- The Identity Documents Act 2010 received Royal Assent on 21 December 2010, cancelled all cards one month later and required destruction of the entire register within two months.
- The criminal offences for false identity documents and the passport verification power survived the repeal, so Britain abolished the card and the register rather than identity law itself.
- GOV.UK Verify was designed so that identity providers would not learn which service you used and departments would not learn which provider you chose, at the cost of making record matching each department’s own problem.
- The National Audit Office reported on 5 March 2019 as HC 1926 that Verify had 3.6 million users against a target of 25 million, and 19 connected services against an expectation of 46.
- Verify’s sign-up success rate was 48 per cent against a 90 per cent projection, and only 38 per cent of Universal Credit claimants who attempted it could verify online.
- Verify and its predecessor cost at least 154 million pounds to September 2018, its benefit estimate fell from 873 million pounds to 217 million, and it was formally closed in 2023.
- GOV.UK One Login is an OpenID Connect provider using RFC 8485 vectors of trust, with Cl and Cl.Cm for authentication and P0, P1 and P2 for identity confidence.
- One Login provides a medium level of confidence as defined by Good Practice Guide 45, and states that low and high levels are planned.
- Figures attributed to the Government Digital Service in mid-January 2026 put One Login at 13 million registered users across 120 public services, with Companies House migrating on 13 October 2025 and HMRC entering public beta on 9 February 2026.
- Good Practice Guide 45 scores evidence strength, validity, activity history, counter-fraud and verification, and maps named profiles such as M1A and M1B onto four levels of confidence.
- The trust framework runs from an alpha published on 11 February 2021 to version 1.0 published on 9 June 2026, renamed the UK digital verification services trust framework and expected to come into force on 1 September 2026.
- Certification is performed by conformity assessment bodies accredited to ISO 17065 by the United Kingdom Accreditation Service and approved by OfDIA, normally for three years, against one of five roles.
- The public register held 63 certified services as at 12 August 2026, and providers certified against 1.0 may display the new UK CertifID trust mark.
- Part 2 of the Data (Use and Access) Act 2025, which received Royal Assent on 19 June 2025, gives the framework, the register and the trust mark statutory footing, with most of Part 2 commenced on 1 December 2025 and sections 45 to 48 held back.
- Digital right to work checks have been available since 6 April 2022 for British and Irish citizens with valid passports only, protecting the employer with a statutory excuse against a civil penalty of up to 60,000 pounds per illegal worker, and from 1 October 2026 the duty extends to gig workers and individual subcontractors.
- The Prime Minister announced a mandatory digital ID on 26 September 2025, a petition against it drew 2,984,191 signatures, the mandatory element was dropped on 15 January 2026, a consultation ran to 5 May 2026, and a Digital Access to Services Bill was announced on 13 May 2026.
- Britain differs from India and Europe on three axes: identity is issued by certified private services rather than the state, the law compels the check rather than the credential, and the data rests with providers and relying parties who pay for it rather than in a central repository or the holder’s wallet.
Chapter sources: Identity Cards Act 2006, chapter 15, Royal Assent 30 March 2006, long title and part headings, and the National Identity Register provisions; Identity Documents Act 2010, chapter 40, Royal Assent 21 December 2010, sections 1, 2, 3, 4, 6 and 10 as enacted; the LSE Identity Project report of June 2005 and its estimate of 10.6 billion to 19.2 billion pounds over ten years with a median of about 14.5 billion; Comptroller and Auditor General, Investigation into Verify, HC 1926, Session 2017-19, 5 March 2019, in particular the 2016 business case targets of 25 million users by 2020 and 46 services by March 2018, the 3.6 million users by February 2019, 19 connected services, the 48 per cent verification success rate against a 2015 projection of 90 per cent, benefits revised from 873 million to 217 million pounds, spending of at least 154 million pounds to September 2018 including 58 million to providers, the 21.5 million pound cap of October 2018 and the 38 per cent Universal Credit figure, together with the Infrastructure and Projects Authority review of July 2018; GOV.UK One Login service documentation on checking users’ identities and its technical documentation on choosing the level of authentication and the level of identity confidence, using RFC 8485 Vectors of Trust, both pages last reviewed 11 November 2022; Good Practice Guide 44 on authentication and Good Practice Guide 45, How to prove and verify someone’s identity, including the identity profiles M1A, M1B, M1C and M1D and the groupings for low, medium, high and very high confidence; Government Digital Service blog posts of 12 November 2024 on fifty services, 21 January 2026 on the government’s first digital wallet and 28 April 2026 on the HMRC rollout, with the HMRC public beta go-live of 9 February 2026 and the Companies House migration of 13 October 2025; UK digital identity and attributes trust framework alpha version of 11 February 2021, alpha version 2 of August 2021, beta version of 13 June 2022 updated July 2023, gamma (0.4) of 26 June 2025 and the statutory gamma (0.4) of 1 December 2025; UK digital verification services trust framework version 1.0, pre-released 3 March 2026 and published in final form on 9 June 2026, in particular section 0 on version and certification validity, section 1 on OfDIA and the six principles, sections 2.1.1 to 2.1.11 on changes for 1.0, section 3.2 on levels of confidence and section 4 on roles, conformity assessment bodies and certificate validity; the register of digital identity and attribute services maintained under section 32 of the Data (Use and Access) Act 2025, showing 63 certified services and a last-updated date of 12 August 2026; Data (Use and Access) Act 2025, chapter 18, Royal Assent 19 June 2025, Part 2 sections 27 to 55, and the Commencement No. 4 Regulations 2025 bringing most of Part 2 into force on 1 December 2025 excluding sections 45 to 48; Home Office guidance, Right to work checks: an employer’s guide, version of 26 June 2025 with a draft version of 16 July 2026, together with section 48 of the Border Security, Asylum and Immigration Act 2025 in force from 1 October 2026 and the associated draft code of practice on preventing illegal working of 30 June 2026; the Home Office employer survey of September 2024 reporting 79 per cent manual checks, 37 per cent online service use and 23 per cent use of digital verification providers; the Right to Rent code of practice for landlords and their agents of 13 February 2024 and its revised penalties of 5,000 pounds per lodger and 10,000 pounds per occupier for a first breach; DBS ID checking guidelines for standard and enhanced applications from 22 April 2025 and DBS digital identity verification guidance updated 10 July 2026, requiring a minimum of medium confidence for basic checks and high confidence for standard, enhanced and enhanced with barred lists checks, five years of declared address history, address verification within 90 days and two-year record retention; House of Commons Home Affairs Committee, Mandatory to manageable: the government’s plans for digital ID, Eighth Report of Session 2024-26, HC 986, published 20 May 2026, for the announcement of 26 September 2025, the e-petition total of 2,984,191 signatures, the statement of 15 January 2026, the consultation of 10 March to 5 May 2026, the People’s Panel of 120 members, the Office for Budget Responsibility estimate of 1.8 billion pounds across 2026-27 to 2028-29, the census-based passport figures, the 60,000 pound civil penalty, the five million annual right to work checks by ADVP members, the two billion pound sector estimate, the eVisa account and checking figures, and the polling from More in Common and Ipsos; the King’s Speech of 13 May 2026 and the Number 10 briefing note describing the Digital Access to Services Bill; and trade reporting of 30 January 2026 on GOV.UK One Login’s re-certification against the trust framework at profiles M1A and M1B with a certificate expiring 30 October 2026, and on figures of 13 million registered users and 120 services.