Public Sector · 7 October 2026

The national digital ID is gone. The identity problem isn’t

The NAO's lessons-learned report makes a point every public sector architect will recognise: proving who someone is was never the hard part. Finding their record is.

By Chris, Ovett & CxO · 5 min read

In July, one of the new government's first decisions was to cancel the national digital ID scheme announced the previous September. On 2 September, the National Audit Office published a lessons-learned report on managing digital identity. Most of the work had been done before the cancellation, and the NAO repurposed it to inform the wider question of how people access public services digitally.

It's one of the more useful things the NAO has published on digital government in a while, precisely because it's no longer tied to a single programme.

Identity is an ecosystem, not a product

The report's central point is that digital identity isn't one product or technology. It's an ecosystem of services, credentials, standards, providers and governance spanning government and the private sector. Much of it already exists and isn't affected by the cancellation: GOV.UK One Login, the GOV.UK Wallet and its digital credentials, and the trust framework for certified private sector digital verification services. Since 15 September, licensed venues in England and Wales have been able to accept digital proof of age for alcohol sales from certified third-party providers.

The NAO's judgement is that the UK has foundations to build on, but that inconsistency across departments, rooted in legacy data and systems, keeps the benefits from materialising.

The hard part is the record, not the credential

The most important sentence in the report, for my money, is about identifiers. Different public services use different ones: National Insurance number, Unique Taxpayer Reference, NHS number. Establishing that someone is who they say they are is only part of the challenge. Government then has to link that verified identity to the right record inside each service.

Anyone who has worked on public sector data knows this is where programmes go to die. A citizen can prove their identity to a very high standard and still be matched to the wrong record, or to two, or to none, because the records were created at different times, with different spellings, by systems that never expected to be joined up. No credential fixes that. It's a master data problem, and it sits inside every department rather than at the centre.

Ask what question each service actually needs answered

The other lesson worth taking is that many services don't need full identity at all. A pub needs to know someone is over 18, not who they are. A library needs to know someone lives in the area. A benefits service genuinely needs to know who someone is and which record is theirs. Designing every service around the strongest possible identity check adds cost and friction where an attribute check would do.

The NAO also points to international experience: outside countries with a history of mandatory ID, digital identity succeeds when people find it useful and choose to use it. That's an argument for starting with the services people use most and making them better, rather than building infrastructure first and hoping demand follows.

What to do while the policy settles

For public bodies, three steps are worth taking regardless of what the centre decides next. Inventory which identifiers your services rely on and how reliably they link to each other. For each service, write down whether it needs identity, an attribute, or neither. And invest in record matching and data quality, because whatever identity layer eventually arrives will only ever be as good as the records it points to.

For regulated private sector firms, the trust framework route is already live: guidance issued with HM Treasury earlier this year sets out how certified digital verification services can count as reliable, independent sources for money laundering checks. That's a practical option today, not a policy debate.

← Back to Insights

Untangling identity and records in a public service?

A short conversation on what your services really need to know, and where your data stands.

Book an introductory call