The UK's approach to digital identity has changed a lot in a few years. It started as a voluntary pilot. Now it's a statutory framework. If you're building or reviewing identity checks for UK customers, that shift changes what a provider's certification claims are actually worth.
You'll often see this called the UK Digital Verification Services (DVS) trust framework. It started life as the Digital Identity and Attributes Trust Framework (DIATF), first published by the Department for Digital, Culture, Media and Sport in 2021. For most of its life, certification against it was optional.
That changed with the Data (Use and Access) Act 2025. Here's the timeline:
The Department for Science, Innovation and Technology (DSIT) leads on this.
The framework sets rules for organisations that collect, verify, store, or share personal data as part of a digital identity or attribute service. It covers three provider roles, each with its own certification requirements:
Certification is done by independent, government-approved bodies. Not by government itself.
You don't legally need certification to operate. But you do need it to appear on the statutory register and use the official trust mark. More sectors are starting to treat that certification as a baseline signal of credibility, including right to work and right to rent checks, and the Disclosure and Barring Service.
Good Practice Guide 45, or GPG45, is the technical engine underneath the trust framework. It isn't a separate scheme. It's the government's method for scoring how confident an identity check can be.
Good Practice Guide 45, or GPG45, is the technical engine underneath the trust framework. It isn't a separate scheme. It's the government's method for scoring how confident an identity check can be.
GPG45 sets confidence levels: low, medium, high, and very high. It also defines specific verification profiles within those levels, such as M1B, M1C, or H1B, each combining a particular mix of evidence and checks.
A relying party, say a bank or a right to work checking service, can set the minimum GPG45 level it needs. A certified provider then builds its verification journey to hit that bar.
Don't just take "we're DVS certified" at face value. Two questions matter more:
The DVS trust framework and GPG45 handle one thing: how confidently a person's identity has been verified. Once that's done, MemberCheck picks up the next layer for UK-facing onboarding. MemberCheck doesn't carry out GPG45-certified identity verification itself. It's built to sit right alongside it.

No. It's not mandatory to operate. But you need it to appear on the statutory register and use the trust mark. More sectors expect it as standard.
It tells you how much trust a verification process deserves. That's based on the evidence used and how thoroughly it was checked. It's not simply a record that a document was looked at.
No. It lowers the risk of a process being fooled by fake or stolen documents. It doesn't remove that risk completely. Match the confidence level to the actual risk of the relationship, don't assume higher is always necessary.