Digital identity was going to make the hardest part of taking on a new client somebody else's problem, and in July 2026 the government announced it would not proceed with its proposals. On 2 September the National Audit Office published a lessons learned report on what three decades of attempts have taught it. The document is written for Whitehall, and it carries a plain message for any firm that has to satisfy itself who a client is.

Gareth Davies, who heads the NAO, put the point directly. Despite the decision not to go ahead, he said, questions about how people can conveniently and securely prove who they are, or something about themselves, in a digital world remain relevant. Read from a law firm, that is a statement about you. The scheme is gone. The question it was meant to answer sits on your desk every time a new matter opens.

The question it was meant to answer sits on your desk every time a new matter opens.

What the report says

The NAO treats digital identity as an ecosystem rather than a product, being services, credentials, standards, providers and governance arrangements spread across government and the private sector. Its lessons come to three. Government has to define its objectives and its delivery choices before it deploys anything, and confront the legacy systems and fragmented records sitting underneath. It has to pick the scenarios that matter most and work out how to fund them, deliver them and fit them into services that already exist. And it has to decide whether to build public capability of its own, digital wallets and the infrastructure behind them, or to lean on private provision operating inside a trust framework.

That third choice is the one that reaches your practice. The report notes the country already has the legislation, the standards and the digital identity services to build on, and the trust framework it points to is live, running in version 1.0 since June and owned by the Office for Digital Identities and Attributes. Providers obtain independent certification against it. If the state declines to build the wallet, the market supplies it, and the firms buying electronic identity verification today are buying from that market whether or not they think of it that way.

What it changes in your onboarding

No rule has moved. What has moved is the horizon. A firm that has been waiting for a national scheme to arrive and take the weight off client due diligence should stop waiting. On the NAO's own account, implementing digital identity at scale across fragmented public services is a complex integration problem needing long timescales. Nobody is coming to verify your clients for you inside the life of your current practising certificate.

The attack, meanwhile, has become cheaper. A synthetic face convincing enough to sit through a liveness check no longer needs a specialist behind it, which is why the SRA named deepfake identity fraud in its sectoral risk assessment in August. So the steps worth taking are unglamorous ones. Ask your identity verification supplier, in writing, whether it holds certification against the UK trust framework and against which version, because a supplier that answers with marketing rather than a certificate has told you something. Ask separately how it handles a face held up to a camera and how it handles a video stream fed straight into the software, which are different attacks and are often answered as though they were one.

Then keep one check in the process that does not travel through a screen. A document examined in the room, or a detail confirmed on a call to a number you found for yourself rather than one the client sent you, is slow and awkward and remains the part of the process a forged video cannot reach. Give somebody in the firm the job of asking those questions of your provider this month, and diarise the answer for review when the framework moves to its next version.

The study is published as the National Audit Office's lessons learned report on managing digital identity, which is open to anyone and asks for no sign-in.

If you want your onboarding process read against what your identity provider can genuinely evidence, we do that in a morning: start with a conversation.