On 2nd September the National Audit Office published Managing digital identity, a “lessons learned” report drawing on its previous work on digital transformation, data and identity, and on evidence from audit bodies in a dozen other countries.
The ADVP welcomes it. The report is an independent, evidence-based validation of the position this Association has argued consistently: digital identity is not a single product to be procured, and the UK does not need to start again. It is an ecosystem of services, credentials, standards, providers and governance arrangements spanning both the public and private sectors – and the UK already has one.
Three findings matter most:
None of this is new. In March 2008, Sir James Crosby delivered his independent review to the Treasury, Challenges and opportunities in identity assurance. Read alongside the NAO’s report, the continuity is striking.
Crosby drew a distinction he called fundamental: between “ID management”, which serves the interests of whoever owns the database, and identity assurance, which he described as “a consumer-led concept” – a process that meets a real need for the individual. A system built for its owner and a system built for its user, he argued, have very little in common, and only the second one gets used.
The NAO reaches the same place by a different route. Outside countries with a history of mandatory identity systems, it finds, successful digital identity depends on people finding it useful and wanting to use it. Take-up follows practical benefit in everyday life.
Crosby also identified scale and frequency of use as the critical success factor; warned that a proliferation of schemes of uncertain quality was itself becoming a source of exclusion; argued that data should be minimised and that identity should be verifiable without releasing the underlying data; and said plainly that the market should play a role in delivery. Eighteen years on, those points read as a description of selective disclosure, verifiable credentials, tokenisation and a certified provider market – the things the NAO now identifies as where the international direction of travel is heading.
There is one recommendation of Crosby’s that should sit uncomfortably with all of us. He urged government, as a matter of urgency, to make sure that employers large and small could quickly and confidently satisfy right to work requirements. Eighteen years, several programmes and one cancelled digital ID scheme later, that work is being done – and it is being done overwhelmingly by certified private providers operating within a statutory framework.
The significant difference between 2008 and 2026 is that the trust framework Crosby’s principles implied now exists in law. The Data (Use and Access) Act 2025 placed the DVS trust framework on a statutory footing, with certification, accredited assessment bodies and a public register. The market Crosby said was not delivering has, with the rules in place, delivered.
The ADVP’s role is to make that framework a practical reality and to drive up adoption. On the strength of this report, we would suggest four priorities:
The NAO has set out the lessons clearly and fairly. Our members are ready to work with government, OfDIA and standards bodies to act on them.
The NAO report, HC 586, is available at nao.org.uk. Sir James Crosby’s 2008 review is available via the National Archives.
The Association of Digital Verification Professionals represents the UK’s trusted digital verification industry. We champion privacy, security and consumer choice.
About
The Framework
Why it Matters
Members
News
Press & Media
Consultation
FAQ
Briefing Pack
Press Enquiries
General Contact
© 2026 Association of Digital Verification Professionals. All rights reserved.