Home
/
Blog
/
What Is the UK's Digital Verification Services Trust Framework and How Does GPG45 Fit In?

What Is the UK's Digital Verification Services Trust Framework and How Does GPG45 Fit In?

#UKDVSTrustFramework #DIATF #GPG45 #DigitalIdentity #UKIdentityVerification

date icon
August 21, 2026
3 Minutes

Introduction

The UK's approach to digital identity has changed a lot in a few years. It started as a voluntary pilot. Now it's a statutory framework. If you're building or reviewing identity checks for UK customers, that shift changes what a provider's certification claims are actually worth.

From a voluntary pilot to a statutory framework

You'll often see this called the UK Digital Verification Services (DVS) trust framework. It started life as the Digital Identity and Attributes Trust Framework (DIATF), first published by the Department for Digital, Culture, Media and Sport in 2021. For most of its life, certification against it was optional.

That changed with the Data (Use and Access) Act 2025. Here's the timeline:

  • Mid-2025. The Act received Royal Assent.
  • 1 December 2025. The Act's DVS provisions came into force, putting the framework on a statutory footing for the first time.
  • 6 March 2026. Version 1.0 of the trust framework was published, bringing in a formal UK digital identity trust mark and a statutory register of certified providers.

The Department for Science, Innovation and Technology (DSIT) leads on this.

What the trust framework actually governs

The framework sets rules for organisations that collect, verify, store, or share personal data as part of a digital identity or attribute service. It covers three provider roles, each with its own certification requirements:

  • Identity service providers. Verify who someone is.
  • Attribute service providers. Verify specific facts about someone, like a qualification or an address.
  • Orchestration service providers. Coordinate the overall verification journey.

Certification is done by independent, government-approved bodies. Not by government itself.

You don't legally need certification to operate. But you do need it to appear on the statutory register and use the official trust mark. More sectors are starting to treat that certification as a baseline signal of credibility, including right to work and right to rent checks, and the Disclosure and Barring Service.

Where GPG45 fits in

Good Practice Guide 45, or GPG45, is the technical engine underneath the trust framework. It isn't a separate scheme. It's the government's method for scoring how confident an identity check can be.

Good Practice Guide 45, or GPG45, is the technical engine underneath the trust framework. It isn't a separate scheme. It's the government's method for scoring how confident an identity check can be.

  • The strength of the evidence used. Is it a passport, a utility bill, or something weaker?
  • How well that evidence is checked against the person claiming it. Was it just glanced at, or properly verified?

GPG45 sets confidence levels: low, medium, high, and very high. It also defines specific verification profiles within those levels, such as M1B, M1C, or H1B, each combining a particular mix of evidence and checks.

A relying party, say a bank or a right to work checking service, can set the minimum GPG45 level it needs. A certified provider then builds its verification journey to hit that bar.

What this means for you if you rely on a third-party check

Don't just take "we're DVS certified" at face value. Two questions matter more:

  • Which version of the framework is the certification against? The framework has changed a lot. Version 1.0 is current as of March 2026.
  • Which GPG45 level and profile is the provider actually certified to deliver? A provider certified for a low-confidence profile isn't a substitute for one certified at high confidence, if your relationship carries more risk.

How MemberCheck fits

The DVS trust framework and GPG45 handle one thing: how confidently a person's identity has been verified. Once that's done, MemberCheck picks up the next layer for UK-facing onboarding. MemberCheck doesn't carry out GPG45-certified identity verification itself. It's built to sit right alongside it.

FAQs

Is DVS certification legally required in the UK?

No. It's not mandatory to operate. But you need it to appear on the statutory register and use the trust mark. More sectors expect it as standard.

What does a GPG45 confidence level actually tell you?

It tells you how much trust a verification process deserves. That's based on the evidence used and how thoroughly it was checked. It's not simply a record that a document was looked at.

Does a high GPG45 level mean fraud is impossible?

No. It lowers the risk of a process being fooled by fake or stolen documents. It doesn't remove that risk completely. Match the confidence level to the actual risk of the relationship, don't assume higher is always necessary.

Related articles

crpto coin bitcoin,ethereum, tether, binance, xrp, solana

What is KYC

November 30, 2022
4 Minutes
#AML #KYC #KYB

To combat this complex and persistent problem plaguing societies, economies, and organisations around the world, AML laws have been designed to make it harder for criminals to move and hide their illicit money...

Learn More
why you should image

Why you should invest in an Identity Verification (IDV) solution for your business?

February 4, 2022
3 Minutes
#IDV #MFIs #AML

Are you losing good customers to a cumbersome onboarding process? Do you want to stay ahead of potential data breaches and risks of farming out the customer verification process to third-party vendors?...

Learn More