A commuter making a contactless payment through New York's subway system

Beyond the credential: Understanding the potential of digital identity

Governments around the world are making once-in-a-generation investments in digital identity. Providing a legal identity for all is part of the UN’s Sustainable Development Goals. The European Union is rolling out Digital Identity Wallets to all 450 million citizens. India’s Aadhaar system has enrolled over a billion people and underpins a growing ecosystem of digital public services. Australia is consolidating its digital identity infrastructure with myID.

The UK is planning to introduce Digital ID as part of a Digital Access to Services Bill and is currently completing a public consultation. This planned investment in digital identity is an opportunity to create next-generation public and private sector services that work better for UK citizens.

Let’s explore some of the considerations that will enable the UK to realize the full potential of its investment in digital identity. While grounded in the specific context of the UK, the insights are relevant to governments everywhere.

Digital ID: A foundation for a new model of UK services

Digital identity enables a new model of government in which citizens share information once, remain in control of their data, and receive simpler, more proactive services. It’s a model that can also reduce fraud and improve government efficiency, decision-making and data quality.

The new model can proactively provide someone managing a long-term condition with all the support they are eligible for, rather than requiring them to interact with 40+ different public sector services. It can enable an entrepreneur to start a small business through a single guided digital journey without needing to understand the structure and processes of national and local government.

A secure digital identity in your pocket is a crucial foundation for this model, but it’s not sufficient on its own. An ambitious digital transformation of the whole government, of the kind envisioned by the Blueprint for a Modern Digital Government, is required to unlock its full potential. Of particular importance is a renewed focus on customer-centered whole-of-sector service design and a common, trusted, cross-government data sharing model.

Building identity people want to carry

The UK’s consultation on digital identity sets out a strong starting point, requiring the scheme to be useful, inclusive and trusted.

GOV.UK One Login is already being rolled out as the preferred way for people to sign in to government digital services. The consultation is poised to complement One Login with a government-issued digital identity credential, including a photo, securely stored on people’s smartphones. In other words, it’s a high-confidence biometric digital identity that many people will routinely carry in their pocket.

To maximize the scheme’s usefulness early delivery should focus on how valuable this is: it enables simple, time-bound, high-confidence evidence that the legitimate person is present during a transaction across digital and in-person channels. For example, when creating a lasting power of attorney or attending a JobCentre benefits interview.

Delegated authority is also crucial for maximizing usefulness. Experience from earlier digital identity initiatives shows that delegated authority is critical to adoption but difficult to retrofit.

Delegation is required whenever someone needs to act on behalf of another person or organization, such as parents acting for children, individuals acting under power of attorney or directors acting for a company. Its importance will increase as citizens and businesses rely more on authorized apps and AI‑enabled agents to act on their behalf. Estonia has recognized this and recently announced plans to grant digital identities to AI agents.

Using open, interoperable, global standards will also increase adoption. The W3C verifiable credentials data model is a standard for tamper-proof, privacy-preserving digital credentials and is used by EU Digital Identity Wallets. During the COVID-19 pandemic, New York State used this standard to implement its Excelsior digital health credential, delivered in partnership with IBM. The pass was available to all 20 million state residents, becoming one of the earliest large-scale public verifiable credential deployments.

The value of a digital identity does not lie in the credential itself, but in the services it unlocks. That requires a fundamental rethink of how government designs and delivers those services.

Designing around life events

Life events such as moving home or managing a long-term health condition, require citizens to independently navigate multiple government organizations. Moving home can require contacting up to 10 organizations, managing a long-term condition can require interacting with more than 40 services.

Next-generation public services should be designed to deliver whole-sector transformation, rather than simply optimizing individual departmental or directorate processes. They should ideally be designed around life events, not institutional boundaries, and be proactive.

The NHS app provides a glimpse of what is possible when service design spans organizational boundaries. It has over 60 million monthly logins and nearly 40 million registered users. In 2024 NHS England, working with IBM Consulting®, introduced a barcode‑based digital prescriptions service to the app.

It joined up primary care organizations, enabling patients to collect medication from any pharmacy. Nearly 70 million repeat prescriptions are ordered through the app each year, instead of through the historic paper-based process, providing a more efficient, flexible service that benefits both citizens and the health system.

Imagine the benefits for both citizens and state if government can automatically provide someone managing a long-term health condition with all eligible support, rather than requiring them to navigate government bureaucracy themselves.

Digital ID Wallet demonstration

Investments in digital identity can help to enable customer-centered, whole-sector, service design, by making it easier to identify an individual and confirm their consent. Another key foundation for improved service design is better data sharing.

Reducing data fragmentation: Creating a digital backbone

The State of Digital Government review highlights data fragmentation as a key issue for public service delivery. Reducing fragmentation through improved data sharing has been a recurring ambition of government for decades, but progress has been slow because it requires coordinated change across policy, culture, data standards and technology. Several recent developments, described further in this section, suggest this ambition is now more achievable than at any previous point.

The Blueprint for Modern Digital Government commits to creating a digital backbone for cross-government data sharing and orchestration, alongside mandating open APIs for new government services. This orchestration will help to reduce the proliferation of complex, expensive, point-to-point integrations.

The digital identity consultation envisions the identity credential being stored in a wallet on people’s smartphones. Well-designed wallets require users to authenticate and explicitly consent before any data is shared. As additional government and private-sector credentials are issued, such a wallet might evolve into a personal verifiable data store, enabling automated, tamper-proof, data sharing by using the wallet. This development places people in control of when and with whom their data is shared.

This model might reduce the need for certain forms of government‑to‑government and government-to-business data sharing, replacing them with citizen-mediated, consent-based exchange of verified attributes.

Government organizations are already experimenting with personal data stores. IBM Consulting worked with a large central government department to develop a proof of concept showing how the Solid open standard can give citizens control over their data while still enabling secure and efficient data reuse by public services.

To see the benefits of automated data sharing, common definitions for core data entities and events that are accepted across departments will need to be established. These definitions might include a person’s identity, employment status and key events such as change of address or ability to work.

Establishing these definitions will require a pragmatic, iterative approach to avoid “analysis paralysis” but without a shared core vocabulary, investments in a digital backbone will struggle to deliver scalable outcomes.

Turning ambition into impact

Many of the ideas in this paper are not new. Life events featured in the Cabinet Office’s Modernising Government white paper in 1999. Cross-government data sharing has been a recurring ambition for decades. ID cards were being developed in the 2000s before being scrapped by a change of government. Developments in technology, renewed political will and changing public expectations, make this vision more achievable than at any point in the past.

A delivery approach that matches the challenge is required. Delivery should be federated, not centralized in a single program. Championing open source practices like coding in the open is an effective way of driving decentralized collaboration. The government and the private sector should work in partnership to collectively strengthen the UK’s digital ID ecosystem. Services should be built and iterated incrementally, with early use cases chosen to demonstrate value quickly and build public trust.

What is required now is a sustained focus on delivery, cross-sector collaboration and strong ministerial sponsorship that has historically made the difference between ambition and impact.

Learn more about how IBM Consulting helps governments deliver public services with efficiency, speed and impact

Cristina Agramunt, User Experience and Visual Designer; Kris Coverdale, Executive IT Architect; and Paul Macpherson, Senior Partner, also contributed to this report.

Authors

Stewart Jeacocke

Partner, Government Center of Excellence,

IBM Consulting

Hass Niazi

Distinguished Engineer, CTO for UK Civil Government

IBM Consulting

3d sphere and cube shapes surrounded by locks
Related solutions
IBM HashiCorp Vault

Manage access to secrets and stop credentials from falling into the wrong hands with identity-based security for humans, machines, and the AI agents now operating across your infrastructure. 

Explore Vault
Identity and access management (IAM) solutions
Secure and unify identities across hybrid environments, reducing risk while simplifying access.
Explore IAM solutions
Identity and access management (IAM) services

Protect and manage user access with automated identity controls and risk-based governance across hybrid-cloud environments.

    Explore IAM services
    Take the next step

    Enhance identity and access management (IAM) with IBM Verify for seamless hybrid access and strengthen identity protection by uncovering hidden identity-based risks with AI.

    1. Discover IBM Verify 
    2. Explore identity and access management solutions