A digital identity is a usable representation of a person and relevant information about them in a digital service. It is built from identity attributes and evidence, then used to support decisions such as opening an account, recovering access, receiving sensitive information, or authorising a higher-risk action.
A digital identity is not the same as a username, password, social-media profile, or browsing history. Those things may be associated with a person, but they do not automatically establish who that person is. This guide explains how digital identity is established, verified, authenticated, and used in customer journeys.
A digital identity is a digital representation of a person that allows an organisation or service to make decisions about them with an appropriate level of confidence. It draws on relevant identity information, such as name, date of birth, address, or age, and on evidence used to support that information.
“Digital identity becomes useful when it gives an organisation enough confidence for a specific decision without collecting more information than the decision needs.”
Paul Holland, Founder and CEO, Beyond Encryption (Mailock)
The UK Digital Verification Services Trust Framework describes identity information as attributes about a person and uses confidence levels to express how strongly an identity has been proven. The amount of information and confidence needed depends on the service. A provider checking that someone is over 18 does not necessarily need the same attributes as a pension administrator acting on a transfer instruction.
A digital footprint is different. Online activity, device data, and account history may provide useful context or risk signals. They are not interchangeable with a verified digital identity, and they should not be treated as one without a defined evidence process.
Identity Attributes, Evidence, and Credentials
Several components work together in a digital identity process:
Identity attributes are pieces of information about a person, such as their name, date of birth, address, or a professional status.
Identity evidence supports those attributes. It might include an official document, a trusted data source, or another approved record.
Biometric evidence can help bind a person to a document or record, for example by comparing a live facial image with a document portrait. The precise process and risks depend on the service.
Credentials and authenticators help the person return to a service later. These can include an account, passkey, security device, password, or one-time code.
Risk signals provide additional context, such as a changed device or unusual behaviour. They can inform a decision but do not replace identity evidence by themselves.
Good design separates these components.
Passwords and passkeys are authenticators, not identities. An address is an attribute, not proof on its own.
A document is evidence, but its value depends on whether it is genuine, current, connected to the person presenting it, and appropriate for the decision.
Digital Identity Terms at a Glance
These activities often appear in one journey, but they serve different purposes.
Term
What it means
Example
Identity proofing
Collecting and assessing evidence to build confidence in a claimed identity
Checking identity evidence during account opening
Identity verification
Testing whether identity information and evidence support the person’s claim
Validating a document and connecting it to the applicant
Authentication
Checking that someone returning to a service controls an approved authenticator
Using a passkey or another account sign-in method
Recipient authentication
Applying an access check before protected content opens
Email, Q&A, or SMS verification in a secure email journey
Authorisation
Deciding what an authenticated person is allowed to access or do
Allowing a customer to view a document but requiring more evidence before changing payment details
Identity and address checking
Checking identity information and whether a person is connected to an address
Comparing supplied details with suitable evidence or data sources
A customer can be strongly identity-verified at onboarding and still need authentication later. A successful sign-in does not decide whether they are authorised to perform every possible action.
How a Digital Identity Is Established
A typical identity process starts with a claim: a person provides information about who they are. The service then gathers suitable evidence, checks whether the evidence is valid and genuine, and determines whether it belongs to the person presenting it.
Check that the claimed identity has existed over time.
Check whether the identity is at high risk of fraud.
Check that the identity belongs to the person presenting it.
Not every service performs each activity in the same way or to the same strength. The organisation should select an evidence process that fits the risk, legal context, user population, and consequences of a wrong decision.
Once sufficient confidence is established, the service may create an account, credential, or record that can be used in later interactions. That later route must be protected because a strongly proven identity can still be undermined by weak account recovery or compromised authenticators.
How Identity Is Used Later
After onboarding, organisations rarely repeat the entire identity-proofing process for every routine interaction. They normally authenticate the customer using an approved route and step up the evidence when the situation demands it.
A later journey might include:
authenticating access to an account or protected message;
checking that contact data is still current;
using additional evidence for account recovery;
rechecking identity after a long period of inactivity;
reviewing risk signals when behaviour or devices change; and
authorising a particular instruction only after its evidence threshold is met.
This is why “verified once” is not a permanent guarantee. People change address, replace phones, share inboxes, lose authenticators, and return to dormant relationships. Trust needs to be maintained in a way that remains proportionate to the service.
Why Identity Assurance Varies by Task
Identity assurance expresses how confident an organisation can be in the identity claim and the evidence behind it. The appropriate level depends on what can happen if the decision is wrong.
A customer reading a routine update presents a different risk from a person opening a new account, recovering dormant pension records, changing payment instructions, or requesting a high-value transfer. The same person may therefore move through different evidence thresholds during one relationship.
The right assurance level depends on the decision being made, not on a blanket preference for the strongest available check.
Factors to consider include:
the sensitivity of information and the value of the action;
whether this is a new or established relationship;
how identity and contact data were originally established;
the freshness and reliability of available records;
fraud, impersonation, and account-takeover risks;
the evidence the organisation must retain;
customer effort, accessibility, and likely exclusion; and
the cost and ownership of referrals and exceptions.
Higher assurance is useful when the evidence supports a necessary decision. Applying the strongest available process everywhere can create abandonment and manual work without improving the underlying journey.
Digital Identity in Financial Services
Financial-services journeys show why the distinctions matter:
Account opening: the provider may need to establish identity, check an address, complete relevant regulatory checks, and bind the customer to a usable digital route.
Pension administration: routine documents can use an established communication channel, while a transfer or dormant-record recovery may need stronger evidence.
Insurance claims: the customer may need to share sensitive evidence, authenticate during later contact, and authorise a settlement instruction.
Personal-data or payment changes: the firm should consider whether the existing authenticator provides enough confidence for a change with greater consequences.
Sensitive document delivery: the immediate need may be controlled recipient access rather than a new full identity-proofing exercise.
Identity verification is one component of the journey.
Thinking About Digital Identity And Trust?
Discover how AssureScore approaches proportionate identity challenge, trust signals, and risk-aware digital interactions.
Customer due diligence, fraud controls, screening, authentication, and authorisation have their own purposes and should not be collapsed into a single “verified” label.
Digital Identity Risks and Design Trade-offs
A digital identity process can improve access and confidence, but it introduces risks that need active management.
False Acceptance and False Rejection
A process can accept the wrong person or reject the right one. Thresholds, evidence quality, and review routes affect both outcomes. Teams need to understand the consequences rather than treating an automated result as infallible.
Stolen, Synthetic, or Manipulated Evidence
Documents and identity data can be stolen, altered, or combined into synthetic identities. Evidence validation, binding, fraud checks, and appropriate human review can reduce risk, but no single control removes it.
Compromised Authenticators and Weak Recovery
A well-proven identity can still be exposed through a compromised inbox, shared phone, stolen credential, or weak recovery process. Later authentication and recovery need the same design attention as onboarding.
Privacy and Data Minimisation
Collecting more identity data increases the amount that must be protected and governed. Organisations should define what they need, why they need it, who can access it, and when it will be deleted.
Accessibility and Exclusion
Some customers will not have a suitable document, device, camera, address history, or level of digital confidence. Others may need assisted access. Alternative routes should be part of the service design, with equivalent care around privacy and assurance.
Operational Exceptions
Referred, mismatched, or incomplete results need clear ownership.
“The real operating model appears when a check does not pass cleanly. Teams need to know what evidence they can see, what route the customer can use next, and who owns the decision.”
A digital identity check adds little value if every successful case is manually repeated or every exception falls into an unmanaged queue.
Digital Identity and Secure Customer Communication
Identity increasingly intersects with communication because many important customer actions begin in an email. An organisation may establish identity during onboarding, authenticate the person in later interactions, deliver protected information, retain evidence of access, and request stronger evidence before a higher-risk action continues.
Recipient checks provide different evidence. An email code can show access to an address, Q&A can test shared knowledge, and SMS can show access to a mobile number. These checks can be useful without being described as complete proof of identity. Read the practical comparison in Email, Q&A, SMS or Identity Checks once the guide is published.
Mailock currently supports several recipient-verification routes within secure email, subject to interface and configuration. Beyond Encryption is preparing stronger identity-checking capabilities intended to extend the levels of assurance available in these communication journeys. Final availability and implementation remain subject to product confirmation.
FAQs
Is a digital footprint the same as a digital identity?
No. A digital footprint is the data and activity associated with a person’s online behaviour. It can provide context, but a digital identity uses relevant attributes and evidence to support decisions about who a person is.
What is the difference between identity verification and authentication?
Identity verification assesses evidence supporting a claimed identity. Authentication checks that someone returning to a service controls an approved authenticator connected to the established account or record.
Does an email code verify identity?
An email code can verify access to an email address at that time. It does not automatically prove the legal identity of the person entering it.
What is authorisation?
Authorisation is the decision about what an authenticated person is permitted to access or do. A customer may be allowed to read a document but require additional evidence before changing payment details.
Why do identity assurance levels vary?
The consequences of a wrong decision vary. Organisations should match evidence to the sensitivity, action risk, relationship, contact-data quality, user needs, and regulatory or contractual context.
Sabrina McClune writes about cybersecurity, data protection, digital identity, and digital transformation for Mailock by Beyond Encryption, helping regulated sectors understand complex technology and compliance topics with greater clarity.