Adoption, not architecture: what the NAO report tells us

On 2nd September the National Audit Office published Managing digital identity, a “lessons learned” report drawing on its previous work on digital transformation, data and identity, and on evidence from audit bodies in a dozen other countries.

The ADVP welcomes it. The report is an independent, evidence-based validation of the position this Association has argued consistently: digital identity is not a single product to be procured, and the UK does not need to start again. It is an ecosystem of services, credentials, standards, providers and governance arrangements spanning both the public and private sectors – and the UK already has one.

Three findings matter most:

  • The foundations already exist. The NAO recognises that the UK has legislation, standards and live services to build on: a statutory trust framework, an established provider ecosystem, and hundreds of firms already delivering identity, age and eligibility checks at scale. The report notes that 275 firms were involved in digital identity services in 2025-26, delivering right to work, right to rent and disclosure checks among others, with a growing number certified against the Digital Verification Services trust framework and listed on the official register.
  • Adoption and interoperability are the real challenges – not the absence of technology or standards. Proving your identity in the UK remains inconsistent from one service to the next. A digital identity from a certified provider is still not accepted as voter identification at a polling station. Rules on where an approved digital identity can and cannot be used remain patchy. The NAO is clear that without greater consistency and clearer rules, fragmentation persists and the benefits do not materialise.
  • Uncertainty over government’s role carries a cost. The report warns that unclear signals about what government will build for itself and what it will rely on the market to deliver can undermine confidence and investment. That is not an abstract risk. It is the operating environment our members have been investing in through several changes of policy direction.

An eighteen-year-old lesson

None of this is new. In March 2008, Sir James Crosby delivered his independent review to the Treasury, Challenges and opportunities in identity assurance. Read alongside the NAO’s report, the continuity is striking.

Crosby drew a distinction he called fundamental: between “ID management”, which serves the interests of whoever owns the database, and identity assurance, which he described as “a consumer-led concept” – a process that meets a real need for the individual. A system built for its owner and a system built for its user, he argued, have very little in common, and only the second one gets used.

The NAO reaches the same place by a different route. Outside countries with a history of mandatory identity systems, it finds, successful digital identity depends on people finding it useful and wanting to use it. Take-up follows practical benefit in everyday life.

Crosby also identified scale and frequency of use as the critical success factor; warned that a proliferation of schemes of uncertain quality was itself becoming a source of exclusion; argued that data should be minimised and that identity should be verifiable without releasing the underlying data; and said plainly that the market should play a role in delivery. Eighteen years on, those points read as a description of selective disclosure, verifiable credentials, tokenisation and a certified provider market – the things the NAO now identifies as where the international direction of travel is heading.

There is one recommendation of Crosby’s that should sit uncomfortably with all of us. He urged government, as a matter of urgency, to make sure that employers large and small could quickly and confidently satisfy right to work requirements. Eighteen years, several programmes and one cancelled digital ID scheme later, that work is being done – and it is being done overwhelmingly by certified private providers operating within a statutory framework.

What has changed, and what should happen next

The significant difference between 2008 and 2026 is that the trust framework Crosby’s principles implied now exists in law. The Data (Use and Access) Act 2025 placed the DVS trust framework on a statutory footing, with certification, accredited assessment bodies and a public register. The market Crosby said was not delivering has, with the rules in place, delivered.

The ADVP’s role is to make that framework a practical reality and to drive up adoption. On the strength of this report, we would suggest four priorities:

  1. Government sets the standards; the certified market delivers. The NAO’s international evidence points consistently towards this model. Clarity on the boundary – what government reserves for itself and what it relies on the market for – is worth more to investment and adoption than any single product decision.

  2. Widen acceptance. Certification should mean something in practice. Where an approved digital identity is good enough for a right to work check, the rules on where else it can be used should be consistent and clearly stated. The regulations laid in June 2026 allowing digital age checks at licensed premises are the right kind of step.

  3. Commit to interoperability. EU member states are required to make a digital identity wallet available by the end of this year. The UK has committed to international standards but has not yet said how far its solutions will interoperate. That question needs an answer.

  4. Engage the certified sector directly. The NAO finds the UK’s current approach is poorly understood and that inconsistent communication has raised concerns among providers and civil society. Sustained, structured engagement with the firms actually performing these checks is the cheapest fix available.

 

The NAO has set out the lessons clearly and fairly. Our members are ready to work with government, OfDIA and standards bodies to act on them.
The NAO report, HC 586, is available at nao.org.uk. Sir James Crosby’s 2008 review is available via the National Archives.

AVDP

The Association of Digital Verification Professionals represents the UK’s trusted digital verification industry. We champion privacy, security and consumer choice.

NAVIGATE

About

The Framework

Why it Matters

Members

News

RESOURCES

Press & Media

Consultation

FAQ

Briefing Pack

CONNECT

Press Enquiries

General Contact

LinkedIn

© 2026 Association of Digital Verification Professionals. All rights reserved.