Interviews
Alexandre Kech: Strengthening Organizational Trust with Verifiable Legal Entity Identifiers

Riley Hughes
·
·
3 min read

In this episode of The Future of Identity Podcast, I’m joined by Alexandre Kech, CEO of the Global Legal Entity Identifier Foundation (GLEIF). Alex leads the organization responsible for the global Legal Entity Identifier (LEI) system and its next evolution: the Verifiable Legal Entity Identifier (vLEI), a cryptographically verifiable framework that enables organizations, employees, systems, and eventually AI agents to prove who they are and who they represent.
Our conversation explores how organizational identity is becoming a foundational layer for digital trust. We discuss why the vLEI was created, how strong governance enables trust at global scale, and what it will take to build interoperable identity infrastructure that can support businesses, financial institutions, and AI-powered ecosystems.
In this episode we explore:
Why the vLEI extends the traditional LEI by enabling organizations and their representatives to prove identity and delegated authority across digital interactions.
How governance, cryptographic trust chains, and qualified issuers create a globally trusted framework for organizational identity.
Real-world applications for the vLEI across financial services, telecommunications, healthcare, trade, digital assets, and cross-border business transactions.
How digital identities, reusable credentials, and organizational identity can work together to strengthen verification while reducing friction.
Why AI agents, delegated authority, and interoperable trust frameworks will drive the next generation of enterprise identity.
This episode is essential listening for anyone working in business identity, digital trust, financial services, or decentralized identity. Alex provides a thoughtful look at how globally governed trust frameworks can help organizations operate more securely in an increasingly digital and AI-driven world.
Thanks for listening, and if you found this conversation valuable, share it with someone who is helping build the future of digital identity.
Learn more about GLEIF and the vLEI ecosystem.
Reach out to Riley (@rileyphughes) and Trinsic (@trinsic_id) on Twitter. We’d love to hear from you.
Listen to the full episode on Apple Podcasts or Spotify, or find all ways to listen at trinsic.id/podcast.
Full Transcript
Transcript lightly edited for clarity.
Riley Hughes: Welcome to the Future of Identity podcast, a show that highlights the world’s most innovative digital ID ecosystems and the people behind them. I’m Riley Hughes, co-founder of Trinsic, and we help businesses accept dozens of digital IDs through one integration. Today, I’m thrilled to be joined by Alex Kech, CEO of the Global Legal Entity Identifier Foundation, which is also known as GLEIF. GLEIF is doing something very ambitious. They are adding a layer of verifiability and trust to the existing large-scale LEI ecosystem that they govern. And as it becomes easier than ever to fabricate a business entirely or impersonate employees, this organizational identity layer is super important for the future of digital trust. I think this is a very information-dense episode. Some episodes we stay high level. This one, we got really into the weeds on the vLEI, on how trust is established in that ecosystem, and we walked through how it applies in several different use cases. Alex also shared the current state of adoption and where he sees it going from here.
Riley Hughes: So if you work in the KYB world or are interested in how trust ecosystems can be built with strong governance, I think this episode is for you. Hope you enjoy it, and now to my conversation with Alex. Alex, welcome to the show.
Alexandre Kech: Well, thank you for having me on the show.
Riley Hughes: Yeah, excited to do this. We recently announced a partnership or involvement in the GLEIF ecosystem, and so I’m excited to talk about that a little bit. But I think it’d be good maybe to start for our listeners who maybe are more familiar with the consumer identity side of things, to just set the stage and the landscape a little bit. So would you mind just giving a little bit of background about GLEIF and the vLEI and the ecosystem that exists today, as well as where this is going and the work that you’re doing to usher in the next chapter of trust with the vLEI?
Alexandre Kech: Sure. So the Global LEI Foundation was created about 12 years ago now, at the back of the 2008 financial crisis, to solve a problem of transparency and understanding who is who and who owns who in the world of legal entities and businesses. So GLEIF was established to maintain a global LEI system that aims at identifying legal entities across the world in a standardized way and verifiable way through today an analog database that can be checked, and you ensure that, okay, that entity has an LEI. That LEI has been issued because the entity has been verified. I can trust that entity exists, and I can also see that that entity owns two or three other entities that are associated to it. So that was the core use case for the global LEI system initially, and it was for traditional finance and banking, regulatory reporting, transparency, and risk management.
Alexandre Kech: The system over the years has evolved to cover more and more use cases of identification of legal entities or organizational identity requirements, not only in finance and banking, but more and more in trade and other use cases such as supply chain management. And it has recently evolved to include a verifiable cryptographic version of it called the vLEI, verifiable Legal Entity Identifier, that enables a company to prove who they are on any digital… Digital platform, but also for people, system, and in the future, why not AI agents acting on behalf of a legal entity to prove that they’ve received delegation of authority to do so. A CEO can sign on behalf of the company. Today it’s managed in the physical world with an authorized signatory process. Well, the same. How do we transpose that onto digital infrastructures? It’s through verifiable credentials and the vLEI.
Riley Hughes: Yeah, this concept of delegated authority to AI agents is obviously a very hot topic right now, and it’s interesting. I think there’s so many parallels between organization delegating to agent, right, or maybe more precisely, organization delegating to employee who delegates to agent or something like this, right? And just this chain of trust that GLEIF has been thinking about for a decade plus now is extremely relevant. So excited to dive in. A natural follow-up maybe to what you described there, could you maybe provide some background on, like, why is the LEI not good enough, so to speak, right? What were the use cases that the traditional LEI that is widely used today was not quite as suited to solve for. Or maybe I should say the new use cases that would be possible with a cryptographically verifiable version of the LEI and the motivation for the vLEI rollout.
Alexandre Kech: Sure. So the LEI is an analog representation of a company. So it gives you an identifier, so a number is universal and unique. It gives you reference data about that legal entity, address of headquarters, etc. It gives you relationship with other identifiers, but also other companies linked to that entity. But it’s all data. It’s only data in a way. So it’s not useful if I want to prove who I am as a legal entity. There is additional checks that need to be done on top of the LEI by anybody interested to get that proof that you are effectively that entity or you are working for that entity before you can trust that person.
Alexandre Kech: So what vLEI brings is actually the digital trust that is required on digital infrastructures to enable that verifiability before any transaction is done, to verify the signature of a contract, the signature of a transaction, to ensure that you can trust that it’s not a scammer, that it’s not someone impersonating an entity or a person working at that entity, in a way that is scalable and that is cross-platform, cross-implementation as a protocol, a bit like a security protocol on the internet. Here it’s the security protocol on identity, an organizational identity at scale.
Riley Hughes: Just a couple of follow-ups on that. The original LEI being primarily data and information, right, useful rich information about an entity, but lacks the ability to allow a representative to prove that they are that entity or that they do indeed represent that entity. Am I summarizing that correctly?
Alexandre Kech: Absolutely. And that’s what vLEI brings indeed.
Riley Hughes: And so in that world, is the LEI public in the sense that it’s not a secret number? It’s a public number that people can use to learn about a business, or is it a private number or something that can be used similar to maybe a Social Security number or something where it’s supposedly a private number that can be used for KYC for people? At the same time, though, just because I know your Social Security number doesn’t mean that you should trust me because this isn’t a super strong security model or whatever, right? Talk me through that.
Alexandre Kech: It’s a public number. So what the LEI does is creating a proxy, a cross-border international proxy for domestic legal entity identifiers. So every company is incorporated at domestic level. So that’s where you legally exist. You always legally exist within one jurisdiction. France, for example. When you get created in France, you get a SIREN number, it’s called, which is the domestic identifier that represents you like a domestic identity card. That SIREN number is great in France, but it doesn’t work and is not recognized in Japan, for example, and not discoverable from Japan because it’s in French, the data is in French, and reverse is true as well. The Japanese company data is in Japanese. So it’s not easily discoverable, and it’s not easily reconcilable, if you want, easy to reconcile. So what the LEI does is that it creates that public set of records that anybody can have access to for free, by the way.
Alexandre Kech: It’s absolutely accessible for free by API, file download, and lookups on website, to have that standardized set of data that is always represented the same way, whether the company is a Chinese company, a Japanese company, a French company, a U.S. company. And that helps with entity management in your supply chain, for example, or as a bank, if you need to manage your corporate customers, or anybody who needs to have that visibility and that standardized visibility about the entities they’re dealing with.
Riley Hughes: That is really helpful, thank you. Should then people maybe think about the vLEI at a very elementary level as a sort of private key associated with this public identifier, right? It’s like a private, almost like a passkey or a token or something like that, that is associated to this public identifier, but that unlike a passkey contains more rich information. Right, about the user or the scenario or whatever, is that a fair way to think about how the vLEI relates to the LEI?
Alexandre Kech: Absolutely, I like that analogy. You could also have the analogy of a biometric passport. So I mentioned the passport is just a paper version of it, and the biometric part securing it further with a verifiable cryptographic way of making sure that you effectively are that entity that you pretend to be, or you are working for that entity that pretends to be. And all is done through chaining of credentials. So you have entity-level credentials chained—well, actually individual-level credentials chained to the entity credentials, chained to the qualified vLEI issuer who have ensured that that entity exists before issuing the vLEI to them, and then GLEIF as a root of trust, very strong root of trust because overseen by 70 regulators from 50 countries and public-private sector related non-for-profit foundation.
Riley Hughes: Great. Okay, so now that we have this foundation, I want to try to make it concrete for folks. There’s this famous example from a year or so ago where there was a bank in Hong Kong. You may know the scenario I’m referring to, but it’s where this user was asked to get on a Zoom call with five executives, and they joined the Zoom call, and the CEO and the CFO and these other executives are all on the Zoom call live talking, and they asked this user to please wire $15 million to whatever, and it needs to be done right now. And the user does this, and it turns out that all those executives that were on the Zoom call were actually just deepfakes. And you mentioned vLEI helps to prevent impersonation, right, which I think is precisely what AI makes universally accessible, right? Like the modern AI tools make it so that anybody can impersonate your voice, your video, your likeness, your way of writing, you know, all these different things. So maybe to make it concrete, could you walk me through, like, how would the vLEI relate to that scenario in that bank in Hong Kong?
Riley Hughes: If vLEI were widely adopted, or widely adopted within that bank, how would it have played a role in that scenario, and what would it have prevented, and what would it not have prevented necessarily? Does that make sense?
Alexandre Kech: It makes sense, and I will link that scenario to an existing use case for actually vLEI and the underlying protocol that we’re using called the KERI, that receipt infrastructure, in the world of telecommunications in general. So currently there is a project which is live with a few users and in development with other users in the context of the GSMA, which is one of the telco organizations, global organizations, that is looking at leveraging the vLEI and the underlying technology to secure phone calls but also messages, SMSs, from origin to receiving iPhone or whatever device you’re using. And the way it does that is that in every step of the process, there is a verifiable credential, which is an ACDC credential. Authentic chain data container, the type of credentials we’re using with vLEI, that is proving and is ported throughout the communication to prove that the origin of the call is effectively, let’s say, Microsoft, although it’s coming from a call center in the Philippines.
Alexandre Kech: The call center has received delegation of authority to call on behalf of Microsoft, and the logo that appears on your phone of Microsoft is also cryptographically verifiably linked to Microsoft. So that chain of credentials that secures completely a communication applies to any communication, and that’s something that is being tested and implemented as we speak, live and pilots. So in the context of your bank in Hong Kong, the same could very much be implemented by Zoom, for example, or Teams to ensure that when you sign in your Teams or Zoom, you use your vLEI credential as CEO or CFO of the company to authenticate yourself in. the Zoom call. And on the receiving side, you can see, okay, that person that is on the screen has authenticated themselves with their credential. I can click on the verification tab. It guarantees me that it’s a legit verifiable credential. Therefore, I can trust that person. So the securing of from origin to receiving side of calls, SMSs, video calls is made possible by the vLEI and similar verifiable credential approaches.
Riley Hughes: That’s helpful, I think. And the use case with GSMA is really interesting. When we talk about this, it just feels so obvious, right? It’s just like, why doesn’t this already exist? And I know that a big part of that is the ecosystem and everything. I want to get to that, the ecosystem part. But before we do, I just want to double-click on the presentation of a vLEI, or, like, as a user who holds a vLEI, maybe I’ve been delegated some authority by my organization, and so now I hold this vLEI that attests to that fact. What is to stop somebody else from recovering my phone, recovering my operating system, or me to transfer this credential to somebody else, or I forgot my phone at the bar and now somebody else has my device and tries to present my credential for me, or these kinds of scenarios where if we zoom in on how do you actually know? Sure, they have the credential, that’s one thing, but how do you know the person presenting it is the right user? A lot of digital IDs will try to solve this with some kind of biometric layer, and that has its own questions.
Riley Hughes: But I’m curious, especially in an ecosystem of many third-party wallets that may exist or something, right? How do you, as a governance layer, standardize on something there to ensure trust in the presentation of
Alexandre Kech: So good question. It really depends on the implementation. Our governance framework is securing, I would say, the delegation of authority from GLEIF to qualified vLEI issuers to vLEIs to official organizational roles. We stop there. So because we can’t do everything that is engagement context roles, as we call them. So a company wanted to issue credentials to all their staff to access a building or to sign in a system, they are responsible of ensuring that the wallets they’re using would be robust enough, or to ensure that only their employees have access to it. They can use two-factor authentication, biometrics, whatever they want, but we can’t cover everything. But what we do cover is if something goes wrong, there is what we call a pre-rotation of key mechanism in the KERI key event receipt infrastructure framework that enables to recover access to that credential, so without having to revoke it and reissue it.
Alexandre Kech: So a vLEI, for example, of an entity that would be corrupted can be recovered through a pre-rotation of key, meaning that every time there is a key creation, there is a backup key, if you want, to simplify, that is created that nobody sees, that the system will allow to take over again if something has been happening to the wallet or to the person managing the key, or in the future when there is a quantum event and that we need to suddenly rotate all the keys to a higher level of public-private key encryption. And that’s also why the system is very robust and institution and enterprise ready, because it is actually post-quantum ready already in the design of the protocol that we’re using.
Riley Hughes: Yeah, okay, so that makes sense. I think the pre-rotation or backup key concept makes a lot of sense there. I guess in a scenario where I issue vLEI to my employee who uses it to authenticate back into my system, right? And it’s a closed loop within my organization. The governance is implicit, or it’s contained within this closed ecosystem, and so that makes sense why that would be out of scope. But if I want to know a vendor sends me an invoice, and that invoice is authentic, or that my employee can share their vLEI with our customers or something for a similar use case, and the use case is like cross-organization or even cross-border, how could the third party ensure trust in the presentation of the vLEI without a common biometric or other kind of presentation layer authentication standard or something, right? Does that make sense what I’m saying? And of course, this is super complicated and maybe too in the weeds, but I’m curious now how you think about this.
Alexandre Kech: It’s a very good question. So there are different contexts. In some contexts, you don’t need to prove that you are Riley and you’re acting on behalf of the company. Sometimes you just need to know that person, system, AI agent in the future that wants to do something with me on a digital platform has received delegation of authority, and the credential that is linked to the legal entity that is linked to the GLEIF ecosystem should be sufficient in that case. And of course, you need to trust that approach and that model, otherwise no trust system works, right? Ultimately, if you want to absolutely link a verifiable credential, delegation of authority verifiable credential to a person, what I see the future is going towards is digital identities that will be issued by governments more and more. Maybe not in the U.S., but in Europe, for example, we will likely have a digital identity in the future.
Alexandre Kech: We already have in Belgium, where I’m from, but could be also cryptographically linked to that verifiable credential, or that verifiable credential hosted into the wallet where my digital identity is, in a way to make the link. Between an individual and the credential. It doesn’t solve the problem of I lost my wallet or I lost my phone. That will always exist, obviously. But if you associate that with biometrics and other ways of authentication into the wallet, you’re kind of reducing significantly the risks of fraud, and you really limit the attack surface, really, for hackers.
Riley Hughes: Yeah, and some of these questions I’m asking, even as I’m asking them, I’m thinking to myself, if we just compare for a moment against the status quo of how the world works today, then this question is like—
Alexandre Kech: It’s way better.
Riley Hughes: Yeah, yeah. It’s like it’s already way better.
Alexandre Kech: It’s already so much better.
Riley Hughes: It’s already so much better that why are we talking at this level? But I think it is interesting because it seems like the crux of something like this is the ecosystem, right? And of course, with any digital credentialing system, you need both the issuers to be involved and the entities who will hold the subjects of the identity data or whatever to hold them. You need the verifiers to be involved, and if the verifiers— if there’s ambiguity, and if they don’t know what they can trust, or they don’t know how the authentication is done, or they don’t know how the identity proofing is done at the issuance, they can’t know these things about the ecosystem, then trust is undermined and it’s challenging on the relying party side. And so, piggybacking on that, I know a very important role of GLEIF is related to governance, right? GLEIF is not the issuer of these LEIs, for example, right? So maybe speak to that governance layer and GLEIF’s role in creating that ecosystem and what you envision that ecosystem looking like over the next five years.
Alexandre Kech: Absolutely. So the main role, actually, of the Global LEI Foundation is the governance framework management. So we are the root of trust, in a way, for the vLEI, technically. But more importantly, we are the entity, again, non-for-profit, public-private sector collaboration, that establishes the rules of the game and the governance framework. How does it work? We accredit— What we called LEI issuers and vLEI issuers, meaning that we accredit them through a very painful process, an on-purpose painful process for them to ensure they do their work properly. We reassess them every year. That’s part of the governance framework as well. And we define the rules of the game in terms of issuance of credentials or issuance of vLEIs, depending on the type of players. What happens in case of how many key multi-signature do they need to have to issue and revoke credentials to LEIs, et cetera, et cetera. And all that to ensure that the system can be trusted, as you explained. So the governance framework is public. It’s accessible by anybody. It can be relied upon by anybody.
Alexandre Kech: It can be kind of replicated also down the value chain, in a way, on how each institution can also govern their own approach to issuance and revocation of credentials, or data management, as a matter of fact, for the LEI. And all this, again, being sourced from an organization that has a private sector and a public sector remit, and a very strong oversight by both public and private sector. So is it perfect? No system is perfect. But it’s a very strong level of assurance that we bring to the ecosystem and through the governance framework and the root of trust that makes the system usable not only within a specific use case, but across use case, across border, which is quite essential in digital infrastructures.
Riley Hughes: Yeah, I liked what we did earlier, where we kind of took it into a use case, right? So maybe to make this part concrete, suppose that I want to obtain a vLEI for Trinsic, right? I will need to go to some vLEI issuer and obtain that. So maybe talk me through what will be my user journey, basically, in that process, and where will the GLEIF governance— be applied through that user journey, right? Including on proofing of me.
Alexandre Kech: So if you want a vLEI, you have to have an LEI to start with. So to get an LEI, you go to an LEI issuer. An LEI issuer is accredited by GLEIF to validate and verify companies. They are accredited because they’ve proven to us that they have access to authoritative source of information that can prove that you are effectively the entity in question before issuance of the LEI. It needs to be maintained every year to ensure that you’re still alive behind the legal entity, that the company has not disappeared, and that your data is always up to date, which makes the data more reliable as a legal entity identifier and set of reference data. Okay, that’s the first step. If you have an LEI already, you can go directly to the vLEI step, which is you go to a vLEI issuer. We have accredited so far eight of them. We will have likely 15 by the end of the year, who are accredited, or qualified in that case, that’s the terminology, to double-check again the issuance of the entity who requests the vLEI. That’s a bit more tricky because there we need to also verify individuals.
Alexandre Kech: Because obviously, a vLEI that is representing an entity will have to be managed by not one person at that entity. It needs to be multi-signature managed. You cannot imagine that the identity of UBS, for example, is managed by a secretary or even a CFO at UBS. It needs to be managed collectively by a set of employees that needs to be verified as being employees of UBS in that case, and are authorized to manage the vLEI of the entity. All the roles I’m explaining are defined in the governance framework of GLEIF. Once the entity receives the LEI, then they have autonomy in how they will manage that credential infrastructure for their own company. So for official organizational role, there is a need for third-party verification of CEOs, CFOs, etc. That will also be done by QVI, a bit like a notary would verify that you are effectively an authorized signatory for the company. For anything else, other types of credentials, so staff credentials, system credentials, AI agents credentials in the future, why not? That is really managed autonomously by the entity.
Alexandre Kech: So they issue revoke credentials, a bit like you would manage access to the building for your employees. And when an employee leaves the company, you deactivate their access to the building. And all that is left, in a way, to the companies to organize themselves and to also have the right software wallets and infrastructure to do that. And that’s where the ecosystem is very important.
Riley Hughes: So I think one of the key elements of this ecosystem, of course, is in order to establish trust in the entire ecosystem, there needs to be trust in the creation of the vLEI and the issuance of the vLEI, right? And I know that one of the important layers of governance, as you just described there, is outlining the requirements for proofing this entity and verifying the individuals who operate within this entity. This is where the partner program and the announcement that Trinsic did with GLEIF comes into play, where one of the unique things about the governance framework is that it explicitly allows for use of accredited or notified eIDs as a valid form of verification for individuals that work within a business. So, in layman’s terms, it just means if I want to get a vLEI and I go to a vLEI issuer, and I can use my digital ID to prove who I am there, and that’s a valid recognized form of authentication there.
Riley Hughes: And of course, as Trinsic, we support a large number of these eIDs, and so vLEI issuers and LEI issuers can work through this gateway to access these, and that’s the nature of the partnership. But the thing I wanted to ask you is just, this is pretty forward-thinking, you know, it’s like very innovative in this, like, very niche way, I guess, right? For a governance framework of an international body that’s regulated by 70 different regulators and everything, to be explicitly Allowing for digital IDs and notified eIDs as a form of authentication or verification for users. So I wonder if you could speak to that. Like, what are the circumstances that led to this, what otherwise maybe might seem like an organization that should be, like, more risk averse and just only focusing on the, like, very tried-and-true and old-school methods of verification or something, right, to be supporting digital IDs, including mobile driver’s licenses and things like that. I wonder if you could speak to that.
Alexandre Kech: Yeah. I mean, our objective is to make the system used and scale. And if we stick to only traditional solutions like a passport showing on the screen or the usual way of doing KYB, which today is at risk anyway through the rise of AI, it’s not going to work. So we need to be able to evolve that governance framework to include what we call recognized digital identity approaches in specific countries or by specific organizations to, I would say, smooth the process of getting a vLEI, being verified as an individual acting for the company. And the solutions that you offer are ideal for that because it’s digital to digital in a way, right? You can automate part of the process that otherwise would not be automated and would create friction. So the more you can link trusted digital identity together, in a way, an individual identity to a verifiable credential of a company or a vLEI for a company, the more robust the system is overall.
Alexandre Kech: And that’s really where we’ve always been looking at enhancing the system, enhancing the approach of verification to ensure that the same way that we advocate for the vLEI to be used everywhere, it would be strange that we would not recognize digital identities who have similar objectives for the verification of the individuals entering the system.
Riley Hughes: Yeah, makes a lot of sense. Earlier in my life, I learned Chinese, and I spent some time doing, like, live translations for events and, like, speakers and things. And I draw this analogy between the physical driver’s license. type of verification to digital services, like you always lose something in translation, right? When you translate from one medium to another, one language to another, no matter how good the technology is, fundamentally, translation from one medium to another, you will lose something. It won’t be the same thing that it started as. But from digital to digital, it is possible to preserve the trust and the cryptographic properties, especially in a system designed in the way that vLEIs are, with technology that explicitly can be chained together and connected in a more explicit way. So I think it makes a lot of sense. I wonder, any thoughts come up there?
Alexandre Kech: We have something in common. I’m a translator by degree, by the way.
Riley Hughes: Oh yeah.
Alexandre Kech: English-Russian to French in my case. But I agree with you. It’s obvious that everything is going digital. Everything. Money is going digital through digital assets, stablecoins, etc. Identity are going digital, both and often at domestic level or regional level with the eID, etc. The digital identity in Europe and Belgium and Switzerland and everywhere in the US. So the more we go digital, the more we need to be able to link and bridge those trust islands together. That’s also a role of the vLEI, very importantly, because there will be frameworks domestically or regionally for business, for organizational identity. Those organizational identity, European or regional or national, will not always speak to one another, right? As soon as you leave the borders into jurisdiction, it doesn’t work anymore. And that’s also a role we believe vLEI can play, is being able to enable a level of interoperability between domestic digital infrastructures in one continent with other domestic digital infrastructures in other continents.
Alexandre Kech: And that’s something that is also very exciting for the future of the vLEI.
Riley Hughes: With all this said, and you mentioned that you want to accelerate adoption or trigger usage of vLEI, I wonder if you could speak to adoption or the state of the ecosystem. You mentioned there are already five vLEI issuers, and there will be many more by the end of the year. That’s really exciting. And the GSMA. Work is really compelling, super duper compelling use case. I wonder, yeah, what else could you speak to with respect to the ecosystem, the adoption that exists so far, maybe relative to the LEI, and then how you see that evolving over the next handful of years?
Alexandre Kech: Yeah. So in terms of qualified vLEI issuer ecosystem, we have eight, not five, eight today, and growing to 15 by the end of the year normally, or 12, 15, depending on the speed of implementation of those qualified vLEI issuers. Is that enough? No, clearly. So we need to grow that ecosystem of sources of vLEIs, in a way, and verification of companies to scale the adoption. We also need to scale in terms of the supporting software and service solution provider in the world of vLEI and KERI and ACDC. Today we do have wallet solutions. There are verifier solutions. There are systems that help issuing and revoke credentials, but they are still very niche or not widely spread in terms of availability for users, if you see what I mean. And that’s part of the partner program we have, is to also bring all those together, actually advocate for and advertise for their systems and their solutions to support that software and service provider ecosystem, including like you to verify individuals that needs to get verified as part of the vLEI issuance process. And finally, use cases.
Alexandre Kech: So on the use case side, we see a lot of promising pilots, and at this stage, it’s not yet completely live production, but pilots around healthcare. We don’t manage that. It’s a company called HealthKerry, for example, is using the key event receiving infrastructure and vLEI to support healthcare information sharing, for example. That’s a very strong use case as well. We see a lot of activities around, as I said, GSMA and the telco world in the digital asset space as well. As money and assets are moving on-chain and become digital, the challenge there, and I come from that industry, so I know that challenge is big, is scaling. Today, in that world, banks and infrastructures are building centralized, decentralized ecosystems, meaning they’re recreating the wheel, the silos that existed before. And the reason why it’s so is because there is a lack of trust in being able to deal with entities in an open, decentralized system.
Alexandre Kech: And again, there, vLEI can be a very strong support, being able to verify who am I dealing with on this decentralized infrastructure, what am I dealing with, is that asset, that crypto or that digital asset I’m trading really issued by the issuer or is it a fake token? Because there is also a lot of fake tokens on those decentralized infrastructure. And is that person I’m dealing with compliant to AML/CFT and other regulatory requirements? So digital assets is another item where we see a lot of traction. And finally, in trade. And especially everything that is factoring and invoicing, we see a lot of tests and pilots and implementations around trade documents like the electronic bill of lading and invoicing as well that is using the vLEI or looking at using the vLEI to secure, I would say, all that flow. Are we done? Absolutely not. It’s the beginning of the journey, the very beginning of the journey. We’re expecting to see more live implementation of vLEI in the coming one year and a half, with a scale, a progressive scale starting in the following three, four years afterwards.
Alexandre Kech: And the reason is simple. Any new technology, any new approaches that actually challenging the status quo of currently digital certificates, for example, will take time to grow. Just to give you a perspective, the digital certificates that we all use in our emails and stuff, it took between creation and scale usage, it took 15 years before it was really used at scale. And I think that’s unfortunately or fortunately the type of things that takes time. I’d like to add something important. I think AI agents and agentic AI will likely accelerate the need for such a solution. And we will very soon publish a paper on how organizational identity approaches like the vLEI can support verifiable delegation of authority to AI agents, and also verifiability of scope of AI agents into a future agentic economy.
Riley Hughes: Yeah, that’s interesting. I’m looking forward to reading that paper. Certainly is a very hot topic right now. As you were mentioning some of these use cases and mentioning some of the companies building solutions for specific industries and solving specific problems with the key event receipt infrastructure technology, KERI, that is also powering the vLEI ecosystem. It sounds like there’s good kind of overlap, and a lot of the vLEI stuff is a foundational layer, right, that’s powering some of these other use cases, which is interesting. But I wonder how connected are these things really, right? How closely tied is the vLEI to KERI? For example, if it turns out that in the next three years, W3C verifiable credentials and the ISO mDoc formats and other types of digital cryptographically verifiable credentials take off in adoption and KERI lags behind.
Riley Hughes: Could the vLEI use another standard for purposes of more broad interoperability, or is this really like the key value proposition of the vLEI intrinsically connected to some of the key value propositions of the specific technology that you’ve chosen? And the reason I ask is just I’m in this topic of talking about adoption, right? I’m thinking about a lot of the business identity wallets in the EUDI ecosystem, right, using other standards and whether the adoption gains of interoperability could outweigh the functional gains of a more sophisticated technology. Does that make sense?
Alexandre Kech: It does make sense, absolutely. And that’s why we don’t believe that vLEI will be the solution to everything. We believe it will be broadly, it will be more used for more complex and deep use cases where chaining of credentials is essential and important and needs to be global and scalable. And for the other type of credentials, what we do is that we are advocating for the use of the LEI, for example. So if you look at the EU business wallet, which will be based on W3C credentials and approaches, the LEI is one of the attributes that can be added to a EU business wallet. And we’ve done that because obviously the identity layer is the foundation for any business wallets, right? So we want to be there first as an LEI, and then when… there’s a need for a vLEI adoption or a vLEI adoption for interoperability between the various W3C adoptions, which because they’re not the same, we can play that role. The same for, I don’t know if you’re familiar with the OTL, which is the Open Transaction Layer.
Alexandre Kech: That is an open protocol that has been launched by multiple blockchain actors to be able to share information that needs to be shared, but is today not shared because it’s not standardized. They opted for the LEI as the identifier, and they will embed the LEI into the IDs, WebVH, I think, that they’ve opted for. Of course, I would have preferred that they use the vLEI because I think it’s better, but they want to do it step by step, and that’s also fine as well. So if we manage to have the LEI as an identifier, as an open set of reference data and as a universal identifier, embedding into all those credentials approaches, that brings already a certain level of interoperability. And if we can use the vLEI for the use cases where it’s at its best, I would say that’s what we should be focusing our attention to. And those use cases are when you need to chain multiple artifacts together in a way that it’s verifiable throughout back to the legal entity.
Riley Hughes: Yeah, makes sense. So it’s more about different pieces fitting for different parts of the ecosystem. Really interesting to see how this will play out. I wonder if I were a big credit card network or something and I needed to verify a million merchants, right? When do we get to that scale, right? A company like a credit card network or something could just feel confident in like, oh, of course we’re going to use this technology because it’s that widely adopted among, you know, a million merchants or whatever, right? And maybe the merchants that don’t already have it would need to go through it or something, right? But I wonder how long until we get there. And it seems like what I’m hearing from you is that in the same way that Other digital trust technologies, certificates and whatnot, which have these massive ecosystems and are trying to solve such a foundational problem. These things, of course, take time, and that probably we’ll see that level of scale that I’m referring to here in like three- to five-year time horizon, more so than the six- to 18-month time horizon, right?
Alexandre Kech: Yes, clearly, and even beyond, in my view. And I think what will make the difference is how much trust, how much governance is required, and how much root of trust is required as well. The challenge with all those W3C credential approaches is that you always have a different root of trust. The frameworks are not always the same. There is no auditability, or if there is auditability, it’s in a specific way. It could be on a blockchain, auditability meaning historical auditability of actions. It’s not standardized in a way. It’s a bit bespoke, and one W3C implementation doesn’t necessarily speak to another W3C implementation. So that’s really what we’re trying to solve with the vLEI is having that global governance framework, a global root of trust for our main users today initially, but can also be extended to others, which is the financial industry and the banking industry ultimately. These guys cannot rely on a platform-based or even domestic local authority-based identifying system because they act internationally. They act cross-border.
Alexandre Kech: They need that cross-border trust that we believe we can bring. But again, not to replace the domestic frameworks or other frameworks, but to potentially bring interoperability between those frameworks or to be used on its own for specific use cases for which those domestic or platform systems don’t work well.
Riley Hughes: Well, Alex, this has been a really insightful conversation. I feel like I understand the LEI ecosystem and the vLEI model so much better now. So I really appreciate your time, and I think this has been a fantastic use of time, and I think our listeners will get a big kick out of it as well. Somebody listening wants to work with GLEIF or be a part of the partner program or the ecosystem in some way, where should they go? How can they find you? How can they get in touch with GLEIF? And what is the best place to start?
Alexandre Kech: Well, the website is always the right place to start, so GLEIF.org, where you find all the information about becoming a vLEI issuer and LEI issuer, being part of the partner program, all the information I’ve shared with you today in terms of use cases, as well as all the governance framework documentation. We also have now, and that might be useful, an AI search engine that is really helping asking the questions more in a human way and finding the information more easily than having to scroll through thousands of documents. So they should leverage that as well.
Riley Hughes: Good. Well, that seems to be a great place to wrap it up. And Alex, again, appreciate your time so very much. Thank you so much.
Alexandre Kech: Thanks so much for listening.
Riley Hughes: If you enjoyed this content, the best way to signal to us that the content is valuable is to share it with others who will benefit from it. Meanwhile, if your organization is interested in accepting digital IDs, you can find me or Trinsic on LinkedIn or X or on our website at trinsic.id. And if you haven’t already, visit trinsic.id/podcast to subscribe to the Future of Identity newsletter and listen to any of our prior episodes. Thanks so much for listening.

Riley Hughes
Co-founder & CEO @ Trinsic
Riley is the founding CEO of Trinsic, which he started in 2019 after making an impact on the digital identity industry as the first employee of Sovrin Foundation. He regularly writes and speaks on digital ID, including by hosting Trinsic’s podcast, “The Future of Identity.”
Newsletter
Subscribe to weekly insights and updates in the digital ID ecosystem.
