Skip to main content
Knowledge HubScenario LabAboutTry the tool
Knowledge HubAML ProgrammeDigital Identity Is Not the Whole of CDD
Intelligence Brief

Digital Identity Is Not
the Whole of CDD

A certified result can establish one identity proposition. It does not decide who owns a company, why the relationship exists, whether the customer is low risk or whether the evidence remains current.

Written by Pratik Zanke

United KingdomCDD and onboardingEvidence checked 6 October 2026
Subject
Digital identity evidence in CDD
Evidence checked
6 October 2026
Current assessment
Established for a bounded identity proposition
Next material trigger
Guidance, register, certificate or legislation change

Intelligence status

A certified and registered digital verification service may support the identity-verification proposition described in the February 2026 government guidance. The regulated firm retains the wider CDD duties and remains responsible for the conclusion.[1][2]

Status of this brief: The statutory and government-source boundary is established. The Proof Boundary Record and five control patterns are FinCrimeRadar assessments. Statements about unregistered services, additional attributes, directors and the significance of approved guidance remain qualified.

How to read this brief

This brief separates what the source says, how FinCrimeRadar applies it and what the firm should record or resolve. It uses three evidence states.

Established

Primary legislation, approved government guidance, the statutory register and the certification framework.

Unresolved

A point that remains change-sensitive or needs qualification and independent review.

FinCrimeRadar assessment

The operational model and control response developed from the source boundary.

A pass is not a customer verdict. It is a bounded evidence result.

Executive assessment

The United Kingdom's digital verification regime gives regulated firms a clearer route for using certified services in identity verification. The February guidance says a certified service on the statutory register can be treated as a reliable and independent source with anti-impersonation assurance. For an individual customer, it may support the identity-verification limb of Regulation 28. The guidance also permits use for company directors.[1]

That benefit is valuable and narrow. Regulation 28 separately addresses identification, verification, purpose and intended nature. It contains further duties for corporate customers, beneficial owners, persons acting for customers, risk-sensitive measures and ongoing monitoring.[2]

FinCrimeRadar assessment

A useful result creates risk when it is allowed to prove too much. The control response is to record its evidential boundary before making the wider CDD decision.

Intelligence timeline

  1. Approved MLR guidance

    HM Treasury and DSIT published approved guidance for MLR compliance. It set the central boundary: certified and registered services can support identity verification, while wider CDD remains with the firm. Regulation 76 gives approved guidance relevance, but not a safe harbour.[1][4]

  2. Trust framework 1.0 finalised

    The framework defines roles, rules and identity outcomes for natural persons and attributes.[7]

  3. Identity and attributes clarified

    OfDIA distinguished confidence selection and identity outcomes from additional attributes and screening.[8]

  4. Certification against 1.0 goes live

    The certification scheme table records scheme 1.0.1 as live from 2 September 2026. It also records Gamma scheme 0.4.4 as live from 1 July 2025 with an expiry date of 1 December 2028.[7]

What changed, and what did not

Established

A clearer identity-evidence route

Within the stated scope, a certified and registered service can provide reliable and independent identity evidence for an individual.[1][2]

Established

The structure of CDD remains

The firm still has to address purpose, risk, corporate facts, authority, ownership, beneficial ownership, enhanced measures and monitoring where they apply.[1][2]

Established

The exact service matters

Registration is tied to named services and their roles, certificates and scope, not only to a provider brand.[5][6]

FinCrimeRadar assessment

One response can contain several propositions

Identity, attributes, screening and wider risk conclusions need separate evidence states even when one vendor response carries them.

The proof boundary

An identity outcome answers a question about a natural person's identity at a stated confidence. An address attribute answers a different question. PEP and sanctions screening concern different propositions. Corporate identity, authority, ownership and control concern different subjects and evidence again.[2][8]

The boundary matters because certification attaches to specified services and roles. A firm using a certified identity component must not represent its whole onboarding process as certified.[7]

The six-field Proof Boundary Record

The Proof Boundary Record is a FinCrimeRadar control model. It does not replace legislation or the firm's risk assessment.

1. Subject

The natural person actually checked: individual customer, director, representative or beneficial owner.

2. Proposition

The conclusion supported by the result, usually identity at a stated confidence, not low risk or complete CDD.

3. Service scope

The named registered service, certified role, framework version, certificate status and relevant profile or code at the time of the check.[5][6][7]

4. Assurance

The returned confidence or profile and why the firm treated it as commensurate with the assessed risk.[2][8]

5. Residual duties

Every separate duty still open, including purpose, authority, corporate identity, ownership, beneficial ownership, EDD, monitoring and records where applicable.[1][2][3]

6. Change trigger

The customer, service, certificate, risk or behavioural event that makes the recorded boundary stale or incomplete.

Settled and unresolved

Established

Settled enough to use

  • A certified and registered service may support the individual identity-verification proposition described in the February guidance.[1]
  • That result does not complete every CDD duty.[1][2]
  • The exact service, role and assurance matter more than provider brand.[5][6][7]
Unresolved

Keep qualified

  • The guidance says an unregistered and uncertified service cannot reliably be deemed suitable under that guidance. This is not presented as a universal statutory ban.[1]
  • A director result does not prove the corporate customer, authority, ownership, control or beneficial ownership.[1][2]
  • Attribute outputs may be inside or outside certified scope.[6][8]
  • Approved guidance has statutory relevance under Regulation 76, but this brief does not describe it as a safe harbour.[4]

Decision Horizon

Now

Map the evidence

  • Inventory services and outputs.
  • Match each to an exact register entry, role, certificate and framework version.
  • Find where a pass closes unrelated propositions.
Next control cycle

Build the boundary into controls

  • Add the six fields to policy, procurement, onboarding and QA.
  • Define assurance by risk, not provider brand.
  • Test files for subject and proposition leakage.
On change

Reassess the record

  • Respond to service, certificate and guidance changes.
  • Revisit assurance when risk changes.
  • Reopen purpose or ownership when facts change.

Operational implementation

Policy owners

Replace “use an approved provider” with conditions for subject, service, role, scope, assurance and date. State which proposition closes.

Procurement and assurance

Evaluate the service used, not only the provider. Preserve register and certificate facts and define change notification.

Onboarding and systems

Keep identity, attributes, screening, corporate facts, authority and risk as separate decision fields.

Reviewers and MLRO teams

Ask whether the proposition matches the evidence, then identify what remains open. Retain valid identity evidence when another proposition is inconsistent.

Records management

Retain enough information to reconstruct the evidence and decision. A vendor pass alone may not explain scope, assurance or residual duties.[3]

The FCA's 2026 CDD review said most reviewed firms had documented identity-verification procedures, but few gave staff enough practical detail. It separately said several firms distinguished standard CDD from EDD and most tailored CDD to customer risk. The FCA presented clear differentiation and risk-tailored CDD as examples of good practice.[9]

What Would Change Our Assessment

  1. HM Treasury or OfDIA changes the February guidance.
  2. A relevant sector body updates approved MLR guidance.
  3. The statutory register, trust framework or certification scheme changes a relevant role or field.
  4. A service leaves the register, its certificate ceases to cover it, or its registered role changes.
  5. Regulation 28, 40 or 76 changes materially.
  6. Independent review finds the treatment of unregistered services, additional attributes, directors or approved guidance too broad.

Worked decisions

Scenario 1

The verified customer with an unexplained relationship

An individual customer returns a valid result from a certified and registered service at an assurance selected for the initial risk. The declared business purpose is incomplete and the first funding pattern conflicts with expected activity.

  • Identity result valid
  • Purpose incomplete
  • Funding pattern inconsistent
  • Relationship risk unresolved
What should the analyst do?

Source, Application and Action reasoning
Source

The government guidance confines the benefit to identity verification. Regulation 28 separately addresses purpose, risk-sensitive measures and monitoring.[1][2]

Application

The funding inconsistency does not by itself displace the identity evidence. It affects whether purpose and risk remain credible.

Action

Preserve the identity result. Resolve the purpose and funding inconsistency, reassess risk and apply EDD if required. Keep wider CDD open.

Counterfactual: If coherent purpose evidence is obtained and subsequent activity matches it, the relationship proposition may close. The original identity result does not acquire a wider scope.

Scenario 2

The verified director of an unresolved company

A director completes a registered digital identity check. The customer is a company, signing authority is unclear, ownership is layered and a beneficial owner has not been independently established.

  • Director identity result valid
  • Corporate customer unresolved
  • Authority unclear
  • Beneficial owner not established
What can the analyst conclude?

Source, Application and Action reasoning
Source

The guidance permits use for company directors. Regulation 28 separately addresses corporate particulars, ownership, control, beneficial owners and authority to act.[1][2]

Application

The result is relevant and bounded. It concerns one natural person, not every fact about the company or that person's relationship to it.

Action

Retain the director result in the correct subject record. Keep corporate identity, authority, ownership, control and beneficial ownership open.

Counterfactual: If the corporate and authority propositions are independently established, those fields may close because of that evidence, not because the director result changed scope.

Risk, Signal, Response

The closing grid repeats the five control patterns exactly and provides the source for the summary image.

The Green Tick Halo

One successful check lights up the whole customer file.

Risk
A valid identity outcome is treated as evidence that the relationship is low risk and CDD is complete.
Signal
The case status changes to complete when the vendor returns a pass, although purpose, risk or enhanced measures remain unresolved.
Response
Write the Proof Boundary Record, then make a separate decision on wider CDD completeness.

The Brand-Level Shortcut

The provider's name replaces the service evidence.

Risk
Procurement or operations confirms a familiar provider but not the exact registered service, certified role or certificate that produced the result.
Signal
The file records only the vendor name or a generic statement that the provider is certified.
Response
Record and check the exact service, role, framework version, certificate status and relevant scope at the time of use.

Attribute Spillover

Every field in one response inherits the status of the identity result.

Risk
Address, PEP or sanctions outputs are assumed to be covered by identity-service certification because they appear in the same response.
Signal
The control record cannot map each output to a certified role, stated scope and source.
Response
Separate identity outcomes from attributes and screening, then evidence the status and scope of each output independently.

The Verified Director Mirage

Proof about one person is made to stand in for the company.

Risk
A director's successful identity check is treated as proof of the corporate customer, the director's authority, ownership, control or beneficial ownership.
Signal
One result is copied across several subjects or propositions in the CDD record.
Response
Keep the director's identity result, then verify the corporate customer, authority, ownership, control and beneficial owners as separate propositions.

The Frozen Pass

A dated result is treated as permanently current.

Risk
The firm retains the original pass but does not define what would make its evidential boundary stale.
Signal
The record has no service, certificate, customer, risk or behavioural change trigger.
Response
Add a change trigger and reassess when the recorded service scope, customer facts or risk context changes.

Knowledge check

1. A provider appears on the statutory register. What must the firm check next?
2. A certified identity response includes an address and sanctions result. What follows?
3. A company director passes the identity check. Which conclusion is strongest?
4. Identity is valid but stated purpose conflicts with early activity. What should happen?
5. Which record best supports later review?

Frequently asked questions

Is every service from a registered provider suitable for every AML identity check?

No. Check the exact named service, certified role, current certificate and relevant scope. Suitability also depends on assurance commensurate with the firm's risk assessment.[5][6][8]

Does a successful DVS result mean the customer is low risk?

No. It can support an identity proposition. Risk, purpose, activity and enhanced measures need their own evidence and decision.[1][2]

Can an unregistered electronic verification service never be used?

The February guidance says a service that is not certified and on the register cannot reliably be deemed suitable under that guidance. This brief does not turn that into a universal statutory prohibition.[1]

Does checking a director complete company CDD?

No. It can evidence the director's identity. Corporate identity, authority, ownership, control and beneficial ownership remain separate.[1][2]

Are address, PEP and sanctions outputs part of the certified identity check?

Not automatically. They are separate attributes or screening propositions whose status depends on the service role, certified scope and source.[6][8]

What should the firm retain?

Retain the material required by Regulation 40 and enough context to reconstruct why the result was relied on and what remained open.[3]

Update trigger

Evidence checked
6 October 2026
Current assessment
Established for the bounded identity proposition; wider CDD remains with the regulated firm.
Recheck when
Government or approved sector guidance changes, the statutory register or trust framework changes materially, or Regulations 28, 40 or 76 are amended.
Service evidence
Check registration and certificate scope on the date of use. No provider or service is presented as permanently registered.

Sources and methodology

Primary legislation, government guidance, the live statutory register and an FCA review were checked directly. Third-party commentary is excluded from the legal and control conclusions. The Proof Boundary Record and pattern names are FinCrimeRadar assessments.

  1. HM Treasury and DSIT, Using digital identities with the Money Laundering Regulations, 26 February 2026.
  2. Money Laundering Regulations 2017, Regulation 28, current revised text checked 6 October 2026.
  3. Money Laundering Regulations 2017, Regulation 40, current revised text checked 6 October 2026.
  4. Money Laundering Regulations 2017, Regulation 76, current revised text checked 6 October 2026.
  5. Data (Use and Access) Act 2025, Part 2.
  6. Statutory digital verification services register, checked 6 October 2026.
  7. UK digital verification services trust framework 1.0 and certification scheme, checked 6 October 2026.
  8. OfDIA, How digital verification services can help businesses meet their obligations under the Money Laundering Regulations, 20 August 2026.
  9. FCA, Firms' customer due diligence processes and controls: our findings, 8 April 2026.

Last reviewed: 6 October 2026.