
The digital identity market is growing. More services are being certified, more sectors are adopting digital verification services (DVS), and certification against the 1.0 trust framework begins later this year.
At the same time, the fraud picture is a reminder of why security matters. Identity fraud remains the most common fraud type recorded in the UK, with over 240,000 cases filed to the National Fraud Database in 2025. Reports such as Cifas's Fraudscape point to criminals using AI to produce both fake documents and synthetic identities at increasing speed and scale. As the digital identity market continues to grow, it is essential that we make sure the security of the ecosystem evolves accordingly.
The trust framework requires certified DVS providers to meet established security standards, including in areas such as data protection, access control and incident management. Now the final release of the 1.0 version of the trust framework has been published, we are starting to focus on what we want to change in the following version. As part of this work, we are looking to improve our understanding of how identity and attribute data flows between trust framework participants and where risks emerge from those connections. Understanding the system end to end will ensure that the framework's rules are targeted where they matter most.
We have recently commissioned a piece of work to support the mapping of data flows. This post explains what the project involves, and what we will be asking of DVS providers.
What the project is
We have appointed an NCSC-accredited cyber security consultancy to carry out a six-week, system-level analysis of the DVS ecosystem. The chosen provider has experience of similar projects across a range of government programmes overseeing complex, multi-party markets.
A core deliverable for the project is a refreshed and comprehensive mapping of the ecosystem's architecture and data flows. This will provide a detailed overview of how identity and attribute data moves between participants in the framework, from initial verification through to a relying party accepting a check. The map will show the information exchanged at each step, the points where responsibility passes from one organisation to another, and how data is protected as it moves and is stored. Where a role depends on other parties (for example, a DVS provider using a third-party biometric or document-checking service) the map will capture that information, so the picture we receive reflects how services are delivered, rather than how roles are described theoretically.
What the project is not
This is not an audit of individual DVS providers. We will not be assessing anyone's internal systems, and the analysis stays at the level of the ecosystem: roles, connections and data flows. It is also separate from certification.
What we will ask of providers
The supplier will build the initial mapping using the UK DVS trust framework and a suite of OfDIA materials. But a map drawn from documents alone risks describing the ecosystem as it looks on paper, rather than as it works in practice. We believe that providers are best placed to tell us where the two differ.
Over the coming weeks we will invite a number of certified DVS providers to short validation sessions. We want to know from providers whether the information flows look right, whether we have captured dependencies and handover points accurately, and whether anything is missing.
What we will do with the findings
The outputs will feed into our thinking on future iterations of the UK DVS trust framework, into guidance we may develop for providers, and into our ongoing work to understand the threats facing the ecosystem. We also intend to share what we learn, in a forum that is useful to you.
If you have questions about the work, or would like to register interest in taking part in a session to validate our findings, you can contact us at anisa.khanom@dsit.gov.uk.

Leave a comment