Map the evidence
- Inventory services and outputs.
- Match each to an exact register entry, role, certificate and framework version.
- Find where a pass closes unrelated propositions.
A certified result can establish one identity proposition. It does not decide who owns a company, why the relationship exists, whether the customer is low risk or whether the evidence remains current.
A certified and registered digital verification service may support the identity-verification proposition described in the February 2026 government guidance. The regulated firm retains the wider CDD duties and remains responsible for the conclusion.[1][2]
Status of this brief: The statutory and government-source boundary is established. The Proof Boundary Record and five control patterns are FinCrimeRadar assessments. Statements about unregistered services, additional attributes, directors and the significance of approved guidance remain qualified.
This brief separates what the source says, how FinCrimeRadar applies it and what the firm should record or resolve. It uses three evidence states.
Primary legislation, approved government guidance, the statutory register and the certification framework.
A point that remains change-sensitive or needs qualification and independent review.
The operational model and control response developed from the source boundary.
A pass is not a customer verdict. It is a bounded evidence result.
The United Kingdom's digital verification regime gives regulated firms a clearer route for using certified services in identity verification. The February guidance says a certified service on the statutory register can be treated as a reliable and independent source with anti-impersonation assurance. For an individual customer, it may support the identity-verification limb of Regulation 28. The guidance also permits use for company directors.[1]
That benefit is valuable and narrow. Regulation 28 separately addresses identification, verification, purpose and intended nature. It contains further duties for corporate customers, beneficial owners, persons acting for customers, risk-sensitive measures and ongoing monitoring.[2]
A useful result creates risk when it is allowed to prove too much. The control response is to record its evidential boundary before making the wider CDD decision.
HM Treasury and DSIT published approved guidance for MLR compliance. It set the central boundary: certified and registered services can support identity verification, while wider CDD remains with the firm. Regulation 76 gives approved guidance relevance, but not a safe harbour.[1][4]
The framework defines roles, rules and identity outcomes for natural persons and attributes.[7]
OfDIA distinguished confidence selection and identity outcomes from additional attributes and screening.[8]
The certification scheme table records scheme 1.0.1 as live from 2 September 2026. It also records Gamma scheme 0.4.4 as live from 1 July 2025 with an expiry date of 1 December 2028.[7]
Within the stated scope, a certified and registered service can provide reliable and independent identity evidence for an individual.[1][2]
The firm still has to address purpose, risk, corporate facts, authority, ownership, beneficial ownership, enhanced measures and monitoring where they apply.[1][2]
Registration is tied to named services and their roles, certificates and scope, not only to a provider brand.[5][6]
Identity, attributes, screening and wider risk conclusions need separate evidence states even when one vendor response carries them.
An identity outcome answers a question about a natural person's identity at a stated confidence. An address attribute answers a different question. PEP and sanctions screening concern different propositions. Corporate identity, authority, ownership and control concern different subjects and evidence again.[2][8]
The boundary matters because certification attaches to specified services and roles. A firm using a certified identity component must not represent its whole onboarding process as certified.[7]
The Proof Boundary Record is a FinCrimeRadar control model. It does not replace legislation or the firm's risk assessment.
The natural person actually checked: individual customer, director, representative or beneficial owner.
The conclusion supported by the result, usually identity at a stated confidence, not low risk or complete CDD.
The named registered service, certified role, framework version, certificate status and relevant profile or code at the time of the check.[5][6][7]
The returned confidence or profile and why the firm treated it as commensurate with the assessed risk.[2][8]
Every separate duty still open, including purpose, authority, corporate identity, ownership, beneficial ownership, EDD, monitoring and records where applicable.[1][2][3]
The customer, service, certificate, risk or behavioural event that makes the recorded boundary stale or incomplete.
Replace “use an approved provider” with conditions for subject, service, role, scope, assurance and date. State which proposition closes.
Evaluate the service used, not only the provider. Preserve register and certificate facts and define change notification.
Keep identity, attributes, screening, corporate facts, authority and risk as separate decision fields.
Ask whether the proposition matches the evidence, then identify what remains open. Retain valid identity evidence when another proposition is inconsistent.
Retain enough information to reconstruct the evidence and decision. A vendor pass alone may not explain scope, assurance or residual duties.[3]
The FCA's 2026 CDD review said most reviewed firms had documented identity-verification procedures, but few gave staff enough practical detail. It separately said several firms distinguished standard CDD from EDD and most tailored CDD to customer risk. The FCA presented clear differentiation and risk-tailored CDD as examples of good practice.[9]
An individual customer returns a valid result from a certified and registered service at an assurance selected for the initial risk. The declared business purpose is incomplete and the first funding pattern conflicts with expected activity.
The government guidance confines the benefit to identity verification. Regulation 28 separately addresses purpose, risk-sensitive measures and monitoring.[1][2]
The funding inconsistency does not by itself displace the identity evidence. It affects whether purpose and risk remain credible.
Preserve the identity result. Resolve the purpose and funding inconsistency, reassess risk and apply EDD if required. Keep wider CDD open.
Counterfactual: If coherent purpose evidence is obtained and subsequent activity matches it, the relationship proposition may close. The original identity result does not acquire a wider scope.
A director completes a registered digital identity check. The customer is a company, signing authority is unclear, ownership is layered and a beneficial owner has not been independently established.
The guidance permits use for company directors. Regulation 28 separately addresses corporate particulars, ownership, control, beneficial owners and authority to act.[1][2]
The result is relevant and bounded. It concerns one natural person, not every fact about the company or that person's relationship to it.
Retain the director result in the correct subject record. Keep corporate identity, authority, ownership, control and beneficial ownership open.
Counterfactual: If the corporate and authority propositions are independently established, those fields may close because of that evidence, not because the director result changed scope.
The closing grid repeats the five control patterns exactly and provides the source for the summary image.
No. Check the exact named service, certified role, current certificate and relevant scope. Suitability also depends on assurance commensurate with the firm's risk assessment.[5][6][8]
No. It can support an identity proposition. Risk, purpose, activity and enhanced measures need their own evidence and decision.[1][2]
The February guidance says a service that is not certified and on the register cannot reliably be deemed suitable under that guidance. This brief does not turn that into a universal statutory prohibition.[1]
No. It can evidence the director's identity. Corporate identity, authority, ownership, control and beneficial ownership remain separate.[1][2]
Not automatically. They are separate attributes or screening propositions whose status depends on the service role, certified scope and source.[6][8]
Retain the material required by Regulation 40 and enough context to reconstruct why the result was relied on and what remained open.[3]
Primary legislation, government guidance, the live statutory register and an FCA review were checked directly. Third-party commentary is excluded from the legal and control conclusions. The Proof Boundary Record and pattern names are FinCrimeRadar assessments.
Last reviewed: 6 October 2026.