The UK's approach to digital identity has changed a lot in a few years. It started as a voluntary pilot. Now it's a statutory framework. If you're building or reviewing identity checks for UK customers, that shift changes what a provider's certification claims are actually worth.
From a voluntary pilot to a statutory framework
You'll often see this called the UK Digital Verification Services (DVS) trust framework. It started life as the Digital Identity and Attributes Trust Framework (DIATF), first published by the Department for Digital, Culture, Media and Sport in 2021. For most of its life, certification against it was optional.
That changed with the Data (Use and Access) Act 2025. Here's the timeline:
- Mid-2025. The Act received Royal Assent.
- 1 December 2025. The Act's DVS provisions came into force, putting the framework on a statutory footing for the first time.
- 6 March 2026. Version 1.0 of the trust framework was published, bringing in a formal UK digital identity trust mark and a statutory register of certified providers.
The Department for Science, Innovation and Technology (DSIT) leads on this.
What the trust framework actually governs
The framework sets rules for organisations that collect, verify, store, or share personal data as part of a digital identity or attribute service. It covers three provider roles, each with its own certification requirements:
- Identity service providers. Verify who someone is.
- Attribute service providers. Verify specific facts about someone, like a qualification or an address.
- Orchestration service providers. Coordinate the overall verification journey.
Certification is done by independent, government-approved bodies. Not by government itself.
You don't legally need certification to operate. But you do need it to appear on the statutory register and use the official trust mark. More sectors are starting to treat that certification as a baseline signal of credibility, including right to work and right to rent checks, and the Disclosure and Barring Service.
Where GPG45 fits in
Good Practice Guide 45, or GPG45, is the technical engine underneath the trust framework. It isn't a separate scheme. It's the government's method for scoring how confident an identity check can be.
Good Practice Guide 45, or GPG45, is the technical engine underneath the trust framework. It isn't a separate scheme. It's the government's method for scoring how confident an identity check can be.
- The strength of the evidence used. Is it a passport, a utility bill, or something weaker?
- How well that evidence is checked against the person claiming it. Was it just glanced at, or properly verified?
GPG45 sets confidence levels: low, medium, high, and very high. It also defines specific verification profiles within those levels, such as M1B, M1C, or H1B, each combining a particular mix of evidence and checks.
A relying party, say a bank or a right to work checking service, can set the minimum GPG45 level it needs. A certified provider then builds its verification journey to hit that bar.
What this means for you if you rely on a third-party check
Don't just take "we're DVS certified" at face value. Two questions matter more:
- Which version of the framework is the certification against? The framework has changed a lot. Version 1.0 is current as of March 2026.
- Which GPG45 level and profile is the provider actually certified to deliver? A provider certified for a low-confidence profile isn't a substitute for one certified at high confidence, if your relationship carries more risk.
How MemberCheck fits
The DVS trust framework and GPG45 handle one thing: how confidently a person's identity has been verified. Once that's done, MemberCheck picks up the next layer for UK-facing onboarding. MemberCheck doesn't carry out GPG45-certified identity verification itself. It's built to sit right alongside it.




