Digital identity

The set of verified attributes that make it possible to prove who a person is without them being present. What makes it up, why it ends up scattered across systems, and how it differs from an identity document.

In short

A digital identity is the set of verified attributes that make it possible to prove who a person is when they aren't physically present. It's made up of the data someone declares, the data a system checked against a source, and the evidence of that check.

More than a file or a credential, it's the outcome of a process: someone claims to be a person, a system checks the claim, and keeps the proof that it checked it.

That distinction defines who's accountable. A state issues a document. An organization that verifies builds and maintains a digital identity.

Why digital identity fragments

The same person opens an account, signs up for a product, updates their data and recovers access. In most organizations, each of those moments happens in a different system.

Onboarding reads the document. The access module stores a second factor. The fraud team runs its own rules on its own record. The support channel asks again what was already verified, because it can't see it.

The person is one. The evidence that they are who they claim to be ends up scattered.

Fragmentation has three concrete costs:

  • Friction — the user has to prove their identity again at every touchpoint, even if they already proved it.
  • Blind spots — a suspicious pattern that spans two systems doesn't show up complete in either one.
  • Repeated cost — the same verification gets paid for more than once on the same person.

Where a verified digital identity is required

The concept isn't academic: there are regulations that require it and sectors that already operate with it.

  • Anti-money-laundering — the region's regimes require knowing the customer before onboarding them and keeping the evidence. It's the regulatory origin of most verification processes that exist today.
  • Financial services — account opening, product sign-up and access recovery, where a verified identity is the condition for operating.
  • Betting and gaming — age and identity verification as a licensing requirement.
  • Government — access to procedures and benefits under one's own name.
  • Background screening — identity accreditation in hiring processes.

Each country resolves the requirement with its own law. In Colombia it's the SARLAFT; in Mexico, the anti-money-laundering law.

Digital identity is not the digital identity document

Search results for the term mix the two concepts, and the confusion carries over into project conversations.

A digital identity document is the electronic version of a credential a state issues: the ID card on the phone, the license in an official app. It has an issuer, a defined format, and it's used to prove something. It's a piece of evidence.

A digital identity is the set of verified attributes an organization maintains about a person. It can use that document as an input. It isn't limited to it.

Much of what's published about digital identity talks about the first concept: procedures, official apps, citizen credentials. It's a legitimate and different topic. When an organization talks about digital identity within its onboarding, it means the second.

Digital identity is not authentication

Verifying an identity and authenticating a person are different operations, and they happen at different moments.

  • Identity verification — establishes for the first time that someone is who they claim to be. It happens at sign-up and when something substantial changes.
  • Authentication — checks that whoever returns is the same person who was verified. It happens at every access.

An organization can have strong authentication on an identity it never verified well. The second factor protects an account. It says nothing about who opened it.

Order matters: authentication inherits the quality of the initial verification.

Frequently asked questions

It's the set of verified attributes that make it possible to prove who a person is when they aren't physically present. It's made up of the data someone declares, the data a system checked against a source, and the evidence of that check. More than a file or a credential, it's the outcome of a process: someone claims to be a person, a system checks the claim, and keeps the proof that it checked it. That's why a state issues a document, and an organization that verifies builds and maintains a digital identity.

A digital identity document is the electronic version of a credential a state issues: the ID card on the phone, the license in an official app. It has an issuer, a defined format and it's used to prove something, so it's a piece of evidence. A digital identity is the set of verified attributes an organization maintains about a person, and it can use that document as an input without being limited to it. The confusion is common because much of what's published about digital identity talks about the first concept.

No, and they happen at different moments. Identity verification establishes for the first time that someone is who they claim to be, at sign-up and when something substantial changes. Authentication checks that whoever returns is the same person who was verified, and it happens at every access. An organization can have strong authentication on an identity it never verified well: the second factor protects an account and says nothing about who opened it.

One identity, one SDK

VU ONE brings identity verification, authentication and fraud protection together on a single identity graph.

The verification you run at signup stays available to authentication and to your fraud rules, with no repeated processes and no duplicated data.

Verify, Authenticate and Protect, consolidated in one place.

Request a demo