Interviews

Adrian Field – OneID’s Approach to Driving BankID Adoption in the UK

Zack Jones

·

·

7 min read

The Future of Identity episode 025: Adrian Field - OneID’s Approach to Driving BankID Adoption in the UK

In this episode we talk with Adrian Field, the Director of Market Development at OneID, which is a bank-based identity verification product focused on the UK market.

We cover a range of topics, including:

  • How OneID apply a revenue-share model to incentivize banks to participate in their ecosystem

  • The main use cases they’re focusing on in their go-to-market and the drivers that qualify a good use case

  • How Adrian sees the user experience evolving with emerging standards like verifiable credentials

Adrian has a very good grasp on the digital ID ecosystem and is generous sharing his insights after four years working in this space.

You can learn more about OneID on their website: https://oneid.uk/.

Listen to the full episode on Apple podcasts, Spotify or find all ways to listen at trinsic.id/podcast.

Reach out to Riley (@rileyphughes) and Trinsic (@trinsic_id) on Twitter. We’d love to hear from you.

Listen to the full episode on Apple podcasts, Spotify or find all ways to listen at trinsic.id/podcast.

Video timestamps from Adrian Field’s interview

You can watch the full video interview on our YouTube channel, or skip to the timestamps below to find the sections that are most interesting to you.

2:32 – The origin story of OneID

3:26 – How OneID works involves banks in their ecosystem

5:45 – Introduction to OneID’s consent console for reviewing where you’re shared data

8:47 – The user journey of how a consumer would verify themselves

10:09 – OneID’s revenue sharing model

11:59 – The key use cases that OneID is targeting

15:43 – How legislation is changing to enable more digitally-native ID verification

19:09 – Biggest challenges in selling a solution to relying parties

22:41 – How standards like OIDC, verifiable credentials and eIDAS impact user experience

25:37 – Why Adrian sees new standards layering on top of existing systems rather than displacing old modalities

29:27 – How OneID sees the world evolving into a more wallet-based paradigm

33:17 – The speed of verifying through OneID vs. a document scanning flow

36:04 – How fast verifications enable more security and lower fraud

39:26 – How OneID manages different levels of assurance

44:32 – Adrian’s vision for the future of identity

How to get in touch

Most people listen to the Future of Identity on Apple or Spotify. You can find all ways to listen at trinsic.id/podcast.

directly into the form below.

As always, you can reach out to our host, Riley Hughes, on X (@rileyphughes) or LinkedIn. We love hearing from listeners! See you again in two weeks.

Related from Trinsic: see how Trinsic verifies identity in Sweden, and the UK, or explore digital identity verification by country.

Full Transcript

Transcript lightly edited for clarity.

Riley Hughes: Welcome to The Future of Identity, a show that surfaces hard-earned insights needed to succeed in the fast-evolving world of digital identity. On The Future of Identity podcast, we skip the conceptual and theoretical conversations and dive into the tactical lessons learned from people in the trenches taking a product to market. I’m Riley Hughes, co-founder of Trinsic, and we are a reusable identity infrastructure company powering dozens of amazing identity products. In this episode, I talk with Adrian Field, the Director of Market Development at OneID, which is a bank-based identity verification product focused on the UK market. We cover a range of topics, including how they apply a revenue share model to incentivize banks to participate in their ecosystem. We also talk about the main use cases they’re focusing on in their go-to-market and the drivers that qualify those as good potential use cases. And we also talk about how Adrian sees the user experience evolving with emerging standards like verifiable credentials.

Riley Hughes: Adrian has a very good grasp on the ecosystem and is liberal sharing his insights after four years working in this space. I hope you find the conversation useful, and if you do, please reach out to me. I love to hear from people who get value from these podcasts. And now, onto the episode. Welcome, Adrian.

Adrian Field: Hi, thanks, Riley. Thanks for inviting me.

Riley Hughes: Yeah, I’m excited to have you on. We’ve had a few other guests recently on talking about BankID-type products or financial services-focused IDs, and I think it’s a fascinating topic simply because the market for identity in financial services is so massive. So I want to kick things off by throwing an idea out at you and letting you correct me if you think I’m wrong. I see OneID as a BankID solution in the UK, but when I talk to people about BankIDs… I usually talk about two kinds of bank IDs. One is the style of bank ID that exists in the Nordics, Sweden, etc., which feels like a wallet app on your device. And the other kind of bank ID is more like Plaid in the USA or other services in Europe and beyond, where as a user you see a list of options to pick from, and you can select your bank, log in, approve the interaction, etc. So do you feel like this characterization of the two types of bank IDs is the right characterization? And if so, where does OneID fall?

Adrian Field: Yeah, I do think that is the case. OneID was founded to essentially bring kind of Nordics bank ID model to the UK and use the open banking platform. So we are like the Plaid open banking flow of I consent to share my data, I pick my bank from the bank picker, log in securely with the bank, and then that’s a three-step process and I’m done and the data is shared securely. But it’s a bank-based scheme. Because the UK doesn’t really have a national identity, we don’t really have a government ID for private sector use cases, the bank ID model works really well.

Riley Hughes: If I could dig in a little bit to how you set up the supply side of your ecosystem, it sounds like you’ve had to get the banks involved, or am I wrong there? Is it the case that simply the access to the open banking APIs, which all the banks in the UK support, is enough to deliver on the premise of bank ID to the relying parties?

Adrian Field: My background is payments, so I think of it as payment instruments on the issuing side and then acceptance in terms of where can I use that instrument. So it’s a two-sided market problem. Open banking has its origins in some EU legislation called the Second Payment Services Directive, or PSD2, and that was all about two use cases. It’s triggering a payment and sharing my banking transaction data. It doesn’t cover identity. The EU have something else called eIDAS, which covers identity, and that essentially means open banking in the UK. The mandated free APIs that the banks were required to build by the Competition and Markets Authority, our competition regulator, they don’t include identity data. So to build our product, we are regulated by the Financial Conduct Authority and Open Banking to connect securely to the banks and to use the security certificates. But the API endpoints we actually call are commercial APIs. So we incentivise the banks through a revenue share model to build the APIs and surface the customer data.

Adrian Field: We can then enable the customer to share that data onwards to the third party. So you need a partnership model with a contract, which you don’t have under open banking. So we’ve built it on top of open banking, which basically gives us access to 90% of UK individuals, around 50 million people. So that’s the issuing side of the market, and 90% of the people in the UK already use online banking. So they already have things like the bank app on their phone or desktop login, so to get through the process they just need to click a button. So there’s no new app or account that they have to download or install or set up. So it makes it much easier for the consumer side to get through the process.

Riley Hughes: So just for clarity, OneID is connecting the dots between many relying parties which want to verify identity of a person from a set of many different financial institutions, right? And so there’s this many-to-many problem, and you’re the kind of router that gets the user where they need to go. Do you create a wallet and store anything about the user yourselves, or are you simply the bridge to get the users from the relying party property, like the app that they’re trying to use from the relying party into the right bank account, or do you do anything else in that process as well?

Adrian Field: So we have what we call a consent console. It’s a cloud service where I can keep track of where I’ve shared my data. So it’s a bit like in a payments app, you keep track of your transactions and where your money’s gone. You can keep track of where you shared your data, which gives you more visibility and control as a customer as to what accounts do I have, who have I shared what data with. And in the future, you’ll be able to do things like revoke consent and ask that party to delete the data, more kind of ability to exercise your rights under GDPR. So we do provide that. We’re looking at wallet services and what our role is. in that space. If the user journey makes sense to have additional functions and components within that, and if the user does want to store their data in a wallet, then we can provide those kind of services as well. So all of the UK banks already have relationships with all of the UK individuals. Ninety-eight percent of people have a bank account. Any UK company also has a bank account.

Adrian Field: So the banks are already an intermediary and a connector between the supply and the demand side of the process. We’re a data broker where perhaps the individual and the corporate may have different banking institutions, then needs the mechanism to data share between them and across banks, and we can enable that to happen.

Riley Hughes: So digging in a little bit to how you’ve got the banks involved, does your model break if one or two of the big banks decides not to play ball with you or that they don’t want to revenue share and take part in the network, or do you have some mechanism for accounting for that? Or have you already solved this problem? Is it already the case that every big bank has a commercial relationship with you in the UK?

Adrian Field: So we’ve already solved the problem, and we don’t have all of the banks partnering yet. We’ve got NatWest and others, but through open banking, we can get the strong customer authentication to know it’s the right person. We can augment that data with credit reference agency data, with fraud data, with other sources of data. It’s the same data you can get from the banks, but you can source it elsewhere. So that gives us the whole of market solution. So that’s the 90% of people that do online banking. We can reach all of those people. So we don’t need the banks to partner with us. There are benefits if they do. But you need a whole of market solution in order to go to the acceptance side and say, we can get all your customers through this process. If you don’t have the whole of market solution, no retailer in the UK is going to put a Lloyds Bank button on their website because, you know, Lloyds is the biggest bank in the UK, has 25% of the market. But if you’re a large retailer, that button can only be used by 25% of your customers.

Adrian Field: You do need that large percentage to get through the process.

Riley Hughes: So you mentioned that involving the banks gives benefits beyond what is there simply from Open Banking plus other data sources. So what are those other benefits? How does the user experience change, or the experience for either the bank, the relying party, or the individual change if it’s a proper or true end-to-end solution where the bank is fully participating?

Adrian Field: So it’s 100% digital. I just click a button, authenticate, and get through the process. The user journey is the same whether or not the bank is providing the data. So that’s the beauty of APIs. You construct the user experience. You’re just pulling data from different sources, which isn’t visible to the end consumer, and it’s also not visible to the relying party. They get a standard data set, and again, that’s the whole of market solution. You get a standard data set regardless of our sources of data, and the consumer has the same experience. You abstract away the complexity from both of those parties.

Riley Hughes: I see. Last thing I want to dig in on here is the revenue share. If we zoom out of BankID and generalize the conversation for a moment to the broader reusable ID landscape, there are various attempts at solving this sort of business model problem for verifiable credentials and other reusable ID systems. And some of these are, you know, blockchains that are purpose-built to do revenue share with the original issuers, and others are doing… Revenue shares based on fiat or others are just not offering revenue share, and they’re doing some other mechanism for incentivizing the identity providers to join the ecosystem. So I wonder if you could speak to how did you land on this model, what has worked about it, and maybe what are some of the challenges you faced with it.

Adrian Field: My background’s payments in cards, so it’s quite similar to the kind of card revenue sharing model in terms of the relying party is the one that gets the value from the process in terms of better onboarding, increased sales, lower fraud, better data, all those kind of things. So there’s value that’s created that they pay a small percentage for using the service that you can then share across the supply chain to your sources of data. And banks are fairly traditional businesses. They want to be paid in fiat currency rather than crypto coins, and they don’t want the kind of volatility. So that fits in terms of just normal monthly totting up how many API calls you’ve made, put that through a billing engine, monthly invoices into bank, the typical ERP procurement accounts receivable type processes. If you’ve got some other kind of way of paying some people, they’ve got to make a change to integrate that. Whereas if you’ve worked with traditional systems, it makes it far easier.

Adrian Field: You can send people invoices at the end of the month, they pay you in fiat via established payment mechanisms and established business accounting platforms. It makes the whole process much easier if you just work with what’s already there.

Riley Hughes: I want to transition from the supply side of the ecosystem over to the demand side, or in other words, the businesses that want to verify the identities of their users, right? In identity lingo, we usually use the term relying parties. So a lot of times in the podcast, I’ll try to use regular English, but sometimes I slip into identity speak accidentally. So I’ll probably use relying party quite a bit here. But what are the kinds of businesses that you sell to? What are the types of relying parties that— are demanding the solution that you’re offering and that are fueling your growth.

Adrian Field: Yeah, this is where it gets really interesting as a topic, I think. OneID is about four years old. In the early days, we were very much a product-based company in terms of building the product, getting it certified. We’ve now pivoted that to being very much a customer-led organisation. So what’s the business problem that we’re trying to solve and who for? There’s four use cases we’re now focused on. The earlier one was age verification, where we took the typical selective disclosure of, I don’t want you to give my full date of birth, I just want to say, am I over 18, yes or no. We started with that on platforms like Shopify and WooCommerce and just had a drag-and-drop widget that was easy to integrate. But actually, that’s quite a hard market to sell into because typically in the UK, for age-restricted goods online, vapes, alcohol, knives, a lot of retailers don’t do any checks at the moment, so they’re non-compliant with the regulations. But there’s quite a low risk of them being fined for that non-compliance.

Adrian Field: To introduce a small cost for the service and also a small step that the user has to go through is friction and cost to a process, so it’s quite a hard sell for them at the moment. We see that market evolving. There is new online safety legislation and new data legislation that will make those fines and that risk higher and mandate certain corporates to adopt some of these things. So we see that market being driven by the new legislation, which will get over some of those hurdles. As we’ve grown out from that to a full identity product, all of the KYC data that you need for somebody, we’re now in the kind of sweet spot I see for a bank-based identity product, is selling into other regulated sectors. So other sectors that have to do anti-money laundering, know your customer checks. You can source all of that data and risk score it into a downstream process makes that a very useful source of information and has benefits versus doc scanning and other processes. So that’s the next one, KYC onboarding. We’re also looking at e-signing.

Adrian Field: So we’re partnered with DocuSign, Adobe Sign, a number of other platforms to do an identity check before you do sign a contract online. So typically with an electronic signature solution, you’ll receive an email, you click the email, go and view the PDF, click that and set your signature, and that’s it, job done. But you don’t know who’s received that email. If you’re the sending organisation, that email could have gone to anyone. So typically most corporates today will do a one-time passcode via SMS, which isn’t the most secure mechanism, and manage the ID check part that way. But SMS really, that just checks that you’ve got the device. It doesn’t check who you are. Whereas a certified ID on the front of that solution actually checks it’s the right person. So that reduces things like contract fraud. And then the last use case is employee screening. So in the UK, there are some scheme rules around criminal records checking and right to rent, right to work.

Adrian Field: Do you have the various rights to do things in the UK where there are rules for digital identity, and we’re servicing those use cases as well.

Riley Hughes: Are those the use case focuses because there’s some common thread throughout them? For example, are they growing faster than other use cases for identity verification in places like marketplaces or fintech onboarding or whatever? Or are they more sensitive to friction and therefore more likely to pick up your solution? Or what is the common thread across these relying parties that makes them more— Suitable for your offering.

Adrian Field: Well, the UK government is actually doing a great job in terms of setting up the new identity framework for the UK and fixing legislation to enable it to happen and to enable adoption. There were some changes through COVID times of recruiting, for instance. Instead of checking someone’s ID face to face, which obviously couldn’t happen in COVID, the Home Office changed the rules to say you could wave your passport at a camera and someone could check your ID that way. But that was given a limited time frame. Once that expired, companies didn’t want to go back to face checking because they got used to digital. So there was a lot of pressure on the government to say, we like being digital. Let’s fix the rules so that we can continue being digital, but let’s make it safe. So let’s have these certified providers and a better way of doing this. So that’s now set up the framework and the new rules for doing this. So if you’re doing these checks now from a digital provider, you have to use a certified provider that’s on the UK certified list. So that’s helped set up the market.

Riley Hughes: I see. Is it fair to say that these use cases across these relying parties, there’s some regulatory reason that as a certified provider under the UK trust framework, you’re able to go to those use cases and fill that gap then?

Adrian Field: Yeah, absolutely. And we’ve invested quite a lot in building a product and getting it certified for the different use cases. We’re certified for an AML use case as well, which gives our customer an increased level of trust in terms of if I buy this solution, I know it’s going to de-risk me from being prosecuted for selling stuff online. Give me safe harbour for things like right to rent, right to work checks or DBS, the criminal records checks. There’s some levels of government protection and legal protection that you get. From buying things from a certified provider, that you don’t get the solutions uncertified.

Riley Hughes: Yeah. I know, Adrian, you’ve been at OneID for how long now?

Adrian Field: Four years in a five-year-old startup, so since quite early days.

Riley Hughes: So, having been here for four years, have relying parties adopted the solution faster or slower than you expected, or how has it panned out relative to expectations?

Adrian Field: So I think, as I said, starting out in AV, it was quite a tough sell. Now we’re getting more into the space where the certification and the mandated nature of some of these use cases certainly helps, and it helps the buyers because they know the rules in terms of what they can buy from them. the market. There’s a set list of vendors that they can go to, and they can pick one from that list. It’s not typically you’d go to the internet or you’d go to some, you know, Gartner report or whatever and see who’s playing in that space. So it removes some of the friction from the buying process, I think. As we move up the food chain into larger and larger corporates, of course, the sales cycles get longer. We’re also working with the banks and through the banks because obviously, as I said, they bank all of the corporates. And this kind of solution has benefits on its own, but also can be packaged into lots of other things to enable the banks to sell core business finance, for instance, into their corporates. So there’s a number of different benefits for all the parties.

Adrian Field: So we’re working with the banks to scale out the acceptance side as well.

Riley Hughes: What has been the biggest challenge in terms of relying party adoption? What is the biggest objection and issue that you run into as you take the product to market?

Adrian Field: So I think some of it, for instance, in the KYC market, some of it is quite cultural in terms of people have had the same job for 20 years in compliance and always scanned documents. You know, before digital, they’d always take a photocopy of your passport, stick it under the drawer. Then when the digital, they want a picture of your passport still, even though it’s digital. And if you’re paying a specialist identity provider to do that identity check, but you still want all the information and you still want to check it yourself as well, it kind of negates the point of Well, I’m paying this third party. I’m not protecting the data. It’s not adhering to data minimization under GDPR because I’ve then got loads of scans of passport images all over my machine, which will probably get leaked and then on the dark web. But it is getting over the cultural thing of actually saying a digital identity has some benefits over doc scanning and traditional ways of doing it. But it also has new benefits in terms of you don’t have to store all of that data.

Adrian Field: AT&T, they lost 73 million customer data records, 65 million of which were no longer customers. So, you know, why are you storing all this old data? It’s just a risk to you. It’s probably not a benefit. It’s just a risk, and you’ll get a huge fine because of it. It’s that cultural thing of thinking through this enables me to be a safer business, and I don’t need that passport scan anymore because I’ve paid this certified corporate to do that for me.

Riley Hughes: That’s helpful. So is it the case then that a lot of the use cases you’re targeting are currently using another type of identity verification solution, for example, doc scanning, or are there areas where because your process is lower friction or somehow otherwise superior that you’re able to enter into net new use cases where because of your solution, there are verifications happening where otherwise there would not have been verifications happening? Does that make sense?

Adrian Field: Yes, I think it’s a bit of both. So some it’s us possibly displacing document scanning solutions. We also have a document scanning solution for global use cases or for people that don’t have online banking to be as inclusive as we can. But because of the digital nature of it, it does lend itself to real digital transformation. I can do an ID check at any point in the process that I want to, and it’s very low friction. I can use this as a step-up mechanism or an additional mechanism. So some of our customers actually like the user journey of log into your bank, do your bank ID check, and scan a document. And for certain use cases, that makes sense, and that also gets over some of this cultural hesitation of, I’ve always had an ID document. I don’t, I can’t get my head around a bank ID. Give me both to start with. I’ll run them in parallel. Then I’ll generate some data, which gives me less fraud, one of the proven benefits, and I can actually turn things off over time.

Riley Hughes: I wanted to transition to talking about user experience. I know that OneID is based on open standards like OIDC. I assume that’s the protocol by which you get, like, the data flows from the bank back to the relying party. But I’m curious how you see emerging standards like verifiable credentials playing a role here. I know you’re quite involved in some of the standards bodies and pretty active in the ecosystem. Curious, where do you see the overlap or convergence of these two standards? And then I want to get into how the user experience might change after that conversion in just a minute.

Adrian Field: Yeah, sure. Open banking in the UK is based on OpenID Connect, or OIDC. I’ve done some work with the OpenID Foundation on the identity assurance extension to that, which enables you to share the KYC process as well. So it’s not just I’m sharing name, address, date of birth. I can say I extracted from this document, or I got it from this bank. And you can build in more of that data provenance around that, which is all new data you can feed into your risk scoring mechanism. And you might choose to score, you know, a bank, a credit institution higher than e-money or higher than other sources of data. So that gives you that added richness. I do think that essentially the three models of identity that I see are the centralized one, such as Aadhaar in India, in Singapore. You’ve got centralized government model. There’s a federated model like ours, where you have a network of things and OpenID providers into that network. And then you’ve got the new world of VCs and DIDs. I think all three of those models are going to coexist in the future.

Adrian Field: I don’t see any of them disappearing, because you’re always going to have governments that are going to run their own ID systems. You’re always going to have federated schemes. I don’t see them completely switching to the VC model anytime soon. And the VC layer, through things like the second version of eIDAS, the EU identity legislation, is enabling a mass market of 450 wallets or individuals who have wallets in that market. and that’s going to be layering the VC model on top of OpenID Connect. So you’ve got the OpenID for issuance and presentation of the credentials, and that’s where the specifications will merge and become interoperable. It doesn’t matter if your government issues you a VC in the W3C standards or a mobile driving licence in the mDL standards or an OpenID Connect source of data in a JSON format. The wallets will be able to read in all those data sources. They’ll just present them to the user in a standard format. The user doesn’t need to know about these things going on in the background. And the verifier, they’ll have a portal and dashboard.

Adrian Field: They don’t need to know what format the credentials are in either. So all of that stuff will just be background and work smoothly.

Riley Hughes: I think there are probably two different kinds of people listening to this podcast. Some who do think that the decentralized model will overtake all of the federated solutions out there, right? And there’s probably another kind of person who is skeptical of the decentralized model even taking off at all or getting much adoption at all beyond the government-mandated solutions. You seem to think they’ll coexist. I wonder if you could just expand your thinking there and spend a little more time on why you think they might coexist as opposed to one ruling out in the end over the other.

Adrian Field: Yes, and I think part of being in payments about 20 years, and every new payment method is additional to existing ones. We still have checks in the UK, but we tried getting rid of them in the past and it failed, because there were things that checks did that digital solutions couldn’t do, multi-signatures or people that are used to using checks. Nothing disappears from the landscape. Identity is going to be similar. Unless you completely replicate the functionality from an old identity system, it’s probably still going to exist. Going forwards, as I said, in the eIDAS, VCs are certainly getting traction through new large mandated projects. So in the early days of self-sovereign, you had this somewhat idealistic principle, I think, in terms of not phoning home. So there was always the comparison of, I pay for my driving license, I can then show my physical document to anyone, and the DVLA, the driving registry in the UK, doesn’t know anything about where I’m using it. So that’s fine.

Adrian Field: Trying to replicate that in the digital world works to some extent if I’ve paid for that VC from the government. So the government’s made some money from it; they’ve funded their IT system. I can then go and use that to hire a car, but, you know, how does the verifier trust that? The user-pays model works in the VC world, but I think in order for it to scale out beyond that, as we’ve said, the issuer’s got to have a kind of verifier-pays model to that, which broadens out the options for the VC world to work. So you can have, of the three parties, issuer, holder, verifier, each three of those needs their own intermediary, their own technology provider. Unless, as Trinsic, you’re issuing your own VCs, then you’re your own tech provider, but not everyone is a kind of VC platform. So, yeah, there’s the issuer pays for the VC, which is the government-funded model, i.e. the taxpayers pay for that IT tech. You’ve got the holder-pays model of similar to a physical passport or a physical driving license.

Adrian Field: The holder will pay for the VC and then be able to use it onwards and not have that phone home. But I think if the verifier-pays model, which does need some kind of, not necessarily phone home back to the issuer, but some kind of intermediary that can do the billing and the transaction and the accounting. And extract some money at the end of the month and then pay the issuer could be without the issuer knowing where that usage has happened. So you can still do all that in a privacy-respecting way and uphold some of the principles, but you can actually create a commercial ecosystem where these kind of things can flourish. And that gives you more options, more innovation, more things you can do than just having the issuer or the holder-pays models.

Riley Hughes: Thanks for expanding on that. I wonder if we zoom in to the world you’re working in, the bank-based ID world. If we take this example of federated networks versus verifiable credential-based or more decentralized networks, and we take that to the world of banking, I could envision bank ID solutions working indefinitely based on this OIDC process that you’ve talked about. I have also seen banks developing their own wallets, usually in an R&D-type capacity. But there was an announcement, I don’t know, half a year ago or something, where Lloyds is working with Yoti, NatWest has dabbled in this space as well, as well as other banks around the world who have been developing their own wallets. Right. So do you think that the bank ID world that you’re operating in will eventually land on something that is more decentralized, where each bank offers their own identity wallet to their consumers, and OneID evolves into sort of connecting wallets together? Or do you think that these things will coexist? How do you see this playing out?

Adrian Field: We’re partnering with NatWest to use their customer data API. So I do see banks as a source of data. What banks do is manage risk and they minimize risk. That’s what they’re all about. Their compliance functions are huge. Their regulation is huge. Working with banks, we can’t just take a bank… Log in, turn it into a VC, give it to the customer and let the customer do whatever they want with it. Because banks want to protect their brand in terms of things like gambling, adult services, stuff that you can legally do online, but maybe the bank doesn’t want to be associated with. The banks want some kind of control over which sectors they go into and how you scale it out, which I think is fair, and so we do all of that. That’s a kind of limiter in terms of the free-for-all. I’m just going to give you a token, you can do whatever you want with it.

Adrian Field: But having said that, I do think putting VCs into customers’ wallets and having some kind of abstraction layer where you could maybe have a slightly different brand or do something else to enable the customer to use that token for other things, but still monetize it, could potentially happen in the future.

Riley Hughes: In a world where the federated model and the VC-based model sit side by side, do you think the user experience changes in the 1ID flow, for example? Say there’s an e-signature platform that continues to use 1ID, and there’s two users that come through the 1ID flow. One user is connecting into, I don’t know, Barclays or something, which is based on OIDC, and another user is going through to, we’ll say NatWest, which is using a verifiable credential or something. Do you think that the user experience changes at all, or that there’s a concrete benefit to one over the other, or do you think it’s pretty much going to be the same with just different technologies under the hood and that’s about it?

Adrian Field: I think it has to be pretty much the same. The secure way of logging in, whether that’s, you know, we’ve got strong customer authentication now in Europe and the UK, where it’s something I have, something I know, something I am, biometrics, that’s not going to change in terms of multi-factor authentication, regardless of what the data source is or the protocol for how I get to that data source. That is the user experience, and it’s more and more going to biometrics. It’s going from… Mainly device-based biometrics. So I see more and more that becoming cloud-based or centralized biometrics. Look at JPMorgan Chase pay with your face type thing. You can enroll, and they’ve got a huge acquirer network, so they can do the payments at the POS. But people trust Chase, and they trust JPMorgan enough to say, okay, I’m all right storing that biometric with them, so they can get the convenience of walking into a shop and just paying with my face. It’s that kind of thing. And you won’t really know or care how the data is being shared across the network.

Riley Hughes: So we’ve talked about two things and maybe slightly a third, right? We’ve talked about the OIDC-based and the verifiable credential-based digital IDs, which will roughly have the same user experience. There may be some slight differences, but generally speaking, they’re going to deliver roughly equivalent value from a relying party perspective. And then you mentioned that OneID has a doc scanning solution as well for those use cases where it’s either needed or where someone doesn’t have an online banking account or global use cases, et cetera. I wonder if we were to compare the analog doc scanning process to this digital onboarding process, do you have numbers or any kind of concrete kind of illustration that you could give to just what that impact actually amounts to? Is it faster time? Is it less fraud? What is the differential between the digital ID and the doc scanning-based ID?

Adrian Field: There’s a number of different benefits. I mean, the most obvious one is speed, because I’ve already got a bank app on my phone. I can get through our process in about ten seconds. It’s three steps. It’s literally consent to share the data, login securely to my bank app. Whereas if I’ve got to onboard with a doc scanning solution, First of all, I’ve normally got to be at home because that’s where my documents are. I can’t be out and about and just do it on my phone. So there’s a time and a place benefit as well. But I might have to, you know, download a new app, install the app, go and find my passport, scan the passport, scan my face. You know, that takes five to ten minutes. And some people really struggle with that kind of coordination process of lining up the phone with the document, and there’s got to be the right light, it’s got to find the holograms, got to do all those kind of things as well. So it’s a much easier customer experience.

Riley Hughes: If I could jump in for just a second, I hear you on those elements, but just to push back a little bit, it seems to me that my bank is about the hardest thing to log into. It’s like they do not make it easy for me to get into my account. And it seems like a lot of times, you know, they’ll inexplicably log me out of my app, or I’ll go to the web-based flow and it’s like, we don’t recognize this browser. You got to go jump through these other hoops. And it’s like, shoot, I need to go on my laptop and get whatever thing. Or there’s probably people who keep their bank password on a sticky note under their keyboard at home, for example, which would be a time and place issue as well. So you mentioned ten seconds getting through the OneID flow. I’m sure that is the sort of absolutely maximally optimized time. What is the realistic timeline or the average or the median time to get through the flow versus the median time to get through a doc scanning process?

Adrian Field: That’s where I think UK is ahead of the US because we’ve had challenger banks for now five, six, seven years. They’ve forced all the incumbent banks to up their game in terms of user experience. And everyone now has a good digital app. Everyone now has a good strong customer authentication login. Most people use biometrics. Something like 80% have bank apps now on their phones. So that 10 seconds is 80% of the market can get through in 10 seconds. If it’s a desktop login, so we have a complete desktop login, we’ve got a decoupled flow with a QR code we can hand off to a mobile, or the best journey is mobile complete and it’s the most secure. But even on the desktop, that might be a little slower in terms of typing, have to type in stuff if I don’t use upfront biometrics, but it’s still using behavioural biometrics. How quick do I type things to catch fraud, and maybe a little longer depending on what the bank interface you use. It’s still quicker than scanning a document.

Riley Hughes: Got it. Okay. I interrupted. Were there other things you wanted to cover on that last question?

Adrian Field: The quicker speed of getting through the process means that you can insert it in more journeys, as we were saying before. I can get more frequent touchpoints, generate more data, check that it’s the right person, not just once they’re in the front door, but what are they doing when they’re in my IT estate? If something suspicious happens, I can flag and do another quick ID. check. We do think there’ll be lower fraud through this process because you don’t have the problem of fraudulent documents and generative AI doing deepfakes. The attack surface on a doc scanning solution and a selfie solution is far greater, whereas for us, you’ve got to be a regulated organisation to get through to call the API from the bank. You’ve got to have been through a bank KYC process to get provisioned a bank account. That’s not to say it’s impossible for fraudsters to get through that process and that they don’t have bank accounts, but it’s a much higher bar. So we think there’ll be less fraud from doing that.

Riley Hughes: Don’t banks use the document scanning vendors to provision that process then? So why is it a higher bar?

Adrian Field: Yeah, the IDVerse, our doc scanning partner, they’re world leaders in doing generative AI and targeting their own systems to try and get through with all the latest AI stuff. So they recognise this problem and they’re actively preventing it, which does mean that it’s hard for fraudsters to get through that doc scanning process to open a bank account. But you’ve got to get through all of that tech layer protections. You’ve got to have the bank account provisioned at the end of it. You’ve got ongoing KYC that the banks do. You’ve got fraud scanning monitoring that the banks do. You’ve got behavioural biometric technology. The banks, out of any sector, spend more on fraud and risk technology than anyone else. We’re a layer above that with strong customer authentication. We then add in other sources of data, other fraud sources of data as well. So it’s a typical security approach of the more layers of security tech you can build up, the stronger it is. And that’s what I mean by we’re building on everyone else’s protection and adding to it.

Adrian Field: That gives you the higher bar because you’ve got to get through all of those layers rather than just the doc scanning part.

Riley Hughes: This dovetails nicely into one of the questions I wanted to ask you about bank-based ID, which is that I have basically two primary bank accounts here in the U.S. One of those bank accounts required me to do a document scan when onboarding, and the other one didn’t. And that’s normal because they probably have different risk tolerances. Maybe they have different data sources they use. One was okay with whatever they got back from, I’m guessing, the bureaus and whatever else that they were using, and the other one wanted to do this additional doc scan type check. But now if I go to a relying party, and if I go through a flow and pick one of those banks over another, one of those banks did a different set of checks and a different type of onboarding, and likely different behavioral biometrics checks and different ongoing monitoring than the second bank. So as a relying party in the UK, if I have a certain risk threshold or level of assurance that I want to be hitting, how do I know that the bank has really done its utmost to meet those requirements, right?

Riley Hughes: Do you ever run into those types of issues or objections, or is there something structurally about how the banks are regulated or what they do that solves for that?

Adrian Field: There’s basically two approaches to how you manage the levels of assurance. One is the government framework in the UK uses something called a Good Practice Guide number 45 of how to check and verify someone’s identity, and they split that into four levels. It’s a bit like Europe and eIDAS. You have a low, medium, high, and very high levels of assurance, or levels of confidence is what they call it in terms of how much checking did you do. So that’s very much a… Step process. In the banking sector, in the FS sector, it’s very much a more granular risk scoring process. So give me all the sets of data, like you were saying, different banks have different risk appetites. Give me all of the data from the onboarding process. I will then risk score that, go into enhanced due diligence or different processes depending on what my risk appetite is. And what we’ve seen through the kind of certification process and the new government framework is those worlds are starting to align more.

Adrian Field: And actually, most bank accounts, most financial services accounts in the UK are around a medium in terms of the level of confidence. Some may be slightly higher, some may be slightly lower. Banks are really, really inclusive in terms of basic bank accounts and giving financial products to people. You can get in with a low level of confidence for some of these things, which is like you were saying, provided may not be doing all these checks up front. It could be an ongoing KYC, and if you’re doing high value payment, they might do a doc scan later in the process. So you’ve got the scoring against different levels, and you’ve got the very granular, give me all of the data and I’ll risk score all of that. We’re enabling both of those things. So through the OpenID Connect identity assurance, we can give you the KYC data. We can say we’ve got a certification that says this scores a medium or a high. If you do a fraud check, you score a high in that framework, and that’s the certified framework process.

Adrian Field: But we can also give you all the data, and you can make your own choice as to whether you think is a high or not.

Riley Hughes: What happens then if you deliver the relying party the payload and they see that it’s a low and they say, That’s not good enough, or if they see that the data was— Obtained from a doc scan, for example, and they have it in their head that doc scanning solutions are prone to generative AI attacks or something. And they want to know, oh, which doc scanning vendor was it, right? Because maybe, as you say, some are better than others or something, right? Are these questions ever a blocker or a challenge? Or am I overthinking this? Am I using an identity practitioner brain to look at this problem that most retailers or whatever will not think too deeply into?

Adrian Field: A lot of them won’t know or care or even think about these kind of issues, but some might. And then I think there’s a combination of things. So can you source that granularity of data? Because again, it’s a bit of a cultural thing. Banks don’t necessarily tell you what they… their KYC process is, and that’s partly from a security perspective. They don’t necessarily want you to know all the different suppliers they use, what checks and balances that they apply, which is the good thing to be somewhat opaque from a security perspective. The data that you can get from that and you can feed it into will enable relying parties over time to generate data to say, okay, if I’m seeing fraud, where are the patterns in the fraud? Is there some common thread in terms of where that ID data came from? Was it doc scanning? Was it BankID? Was it something else? Who were the suppliers? I don’t really see it as a bad thing for the suppliers.

Adrian Field: If we have an issue from doc scanning or a source of data that leads to a down or upstream source of fraud, we want to know about it, and we’ll feed that back into the fraud ecosystem. And the fact that we’re digital and have more frequent touchpoints helps you generate more data, and you should be able to rectify those issues more quickly by fixing an internal process that we have or a supplier that we have or one of our customers.

Riley Hughes: Makes sense. Adrian, is there anything we didn’t cover you wanted to cover?

Adrian Field: Look forward to where the VC market goes and helping with interoperability between UK and other markets. Where other countries have digital identity schemes, we can connect to them, whether it’s OIDC or through VC models, and enable people to share their home digital identity in the UK market or vice versa for UK customers who are abroad. So we see this as a kind of network evolving, and a bit like cheques never expire in the payments world, I see doc scanning as being around for 10 years or plus until that expires. Some countries will always be doc scanning, but other countries will move into the fully digital realm. And once you’ve scanned your document a few times, you want to store your data somewhere. And in our model, that’s the banks. We see that’s a secure place for storing your data.

Riley Hughes: Adrian, I always close out the podcast by asking each guest, what does the future of identity look like to you? You can paint with your most optimistic brush here. What do you think the future looks like?

Adrian Field: What drives me in digital identity is how do you deliver the benefits that better digital identity online can bring? For the UK, it’s a productivity growth. There was the McKinsey study a few years ago that said we can get 3% GDP uplift. That’s about 60 billion pounds in a kind of slow growth economy. That’s a great benefit. You can have better online safety, reducing fraud, protecting your children online. You can do all of these things and make it easy for customers to get through the process. Have their bank as a trusted party that if something goes wrong, I’ve got somebody I can call that I can trust and they help me fix it. And if it’s fraud, for instance, I won’t lose my life savings. So those are the kind of the benefits that we see happening from this, and I think that benefits everyone. It benefits the economy. That’s where I see it going.

Riley Hughes: And that extra productivity impacts people directly, right? Although it’s abstract in the sense when we’re talking about it here, it does result in real uplift for people and improved lives. So I appreciate that comment. Adrian, do you have anything to plug? Is there anything that you’re working on that you are looking for collaborators on, or if people want to learn more or get in touch with you, where should they find you?

Adrian Field: Yeah, just go to our website or email me, adrian@oneid.uk. Yeah, just follow our progress, and we’re moving fairly rapidly and always rolling out new things. So always, if you’re looking to partner or interested in our services, yeah, just reach out.

Riley Hughes: Brilliant. Thanks a lot, Adrian. Thanks so much for listening. If you enjoyed this content, please share it with others who will benefit from it. I’ve been getting some great feedback on the podcast recently, and since we don’t do a lot of self-promotion or ads or whatever, sharing the word really is the best way to signal to us that the content is valuable and that we should keep doing it. You can find us on YouTube, Apple, Spotify, and wherever else you listen to podcasts. Feel free to reach out to me directly on LinkedIn or X at Riley P Hughes, and visit Trinsic if you’re interested in building the future of identity. You can also visit trinsic.id/podcast to subscribe to new shows and subscribe to the Future of Identity newsletter, where we’ll share the essential reusable identity news we rely on straight to your inbox.

Zack Jones

Director of Product Partnerships @ Trinsic

Zack Jones leads the product partnerships at Trinsic that together form the connections that make up the world’s largest identity acceptance network. Zack is a published author, expert on digital IDs, and passionate about entrepreneurship.

Newsletter

Subscribe to weekly insights and updates in the digital ID ecosystem.

sphere background icon