Interviews

Chris Goh – Scaling Mobile IDs in Australia with ISO mDocs

Kelly Javanmardi

·

·

7 min read

The Future of Identity episode 038: Chris Goh – Scaling Mobile IDs in Australia with ISO mDocs

In this episode of The Future of Identity Podcast, I’m joined by Chris Goh, former National Harmonisation Lead for Australia’s mobile driver’s licenses (mDLs) and the architect behind Queensland’s digital driver’s license. Chris played a pivotal role in driving national alignment across states and territories, culminating in the 2024 agreement to adopt ISO mDoc/mDL standards for mobile driver’s licenses and photo IDs across Australia and New Zealand.

Our conversation dives into Australia’s path from early blockchain experiments to a unified, standards-based approach – one that balances innovation, security, and accessibility. Chris shares lessons from real-world deployments, cultural challenges like “flash passes,” and how both Australia and New Zealand are building digital ID ecosystems ready for global interoperability.

In this episode we explore:

  • Why mDoc became the foundation: Offline + online verification, PKI-based trust, and modular architecture enabling scalable, interoperable credentials.

  • From Hyperledger to harmony: Lessons from early decentralized trials and how certification and conformance reduce fragmentation.

  • Balancing innovation and standardization: Why agility and stability must coexist to keep identity ecosystems moving forward.

  • The cultural realities of adoption: How flash passes, retail constraints, and public education shaped Australia’s rollout strategy.

  • The road ahead: How national trust lists, privacy “contracts,” and delegated authority could define the next phase of digital identity in the region.

This episode is essential listening for anyone building or implementing digital credentials, whether you’re a policymaker, issuer, verifier, or technology provider. Chris offers a clear, grounded perspective on what it really takes to move from pilots to national-scale digital identity infrastructure.

Enjoy the episode, and don’t forget to share it with others who are passionate about the future of identity!

Learn more about Valid8 here.

Video timestamps from the Chris Goh interview

You can watch the full video interview on our YouTube channel, or skip to the timestamps below to find the sections that are most interesting to you.  

1:19 – Chris shares his experience with mDLs

2:48 – Chris shares about his work at the Department of Transport in Australia

6:49 – How the mDoc format was chosen for Australia

6:57 – Fragmentation within the identity space similar to blockchain a fews years ago

19:36 – Exploring the various kinds of identities

24:31 – Top down versus bottoms up approach to digital ID

30:09 – Landscape of digital IDs in Australia and New Zealand

37:07 – Should consumers be protected from malicious relying parties

41:53 – Thoughts on how the wallet landscape with play out

46:26 – Overview of Australia and New Zealand and what Chris is working on now at Valid8

How to get in touch

Most people listen to the Future of Identity on Apple or Spotify. You can find all ways to listen at trinsic.id/podcast. 

We write a weekly newsletter to highlight the biggest news and developments from the reusable ID industry. To sign up and join over one thousand readers from the identity industry, you can input your email directly into the form below. 

As always, you can reach out to our host, Riley Hughes, on X (@rileyphughes) or LinkedIn. We love hearing from listeners! See you again in two weeks.

Related from Trinsic: see how Trinsic verifies identity in the United States, and Australia, or explore digital identity verification by country.

Full Transcript

Transcript lightly edited for clarity.

Riley Hughes: Welcome to the Future of Identity podcast, a show that highlights the world’s most innovative digital ID ecosystems and the people behind them. I’m Riley Hughes, co-founder of Trinsic, and we are the first identity acceptance network. Our product is a gateway that helps businesses accept dozens of digital IDs through one seamless integration. And today, I was joined by Chris Goh, founder of Valid8 — that’s like validate, but with the number eight — and his work is to advise governments and organizations around the world on how to adopt, use, and scale mdocs. In our conversation today, we dove deep into the mobile driver’s license ecosystem in Australia and New Zealand, from Chris’s story about him getting the first standards-compliant mDL issued to him in Australia and using it to access a toilet, to his experience leading the harmonization efforts driving mDL adoption across the entire region. I really appreciated Chris’s nuanced point of view on a variety of topics, including privacy, innovation versus interoperability, and inclusion in the mobile driver’s license space.

Riley Hughes: Now, without further ado, my conversation with Chris. Chris, welcome.

Chris Goh: Riley, thank you. It’s great to be here.

Riley Hughes: Yeah, it’s great to have you. I’ve been a follower and admirer of your content on LinkedIn for some time. I think you post a lot of really useful snippets and tidbits on mobile driver’s licenses and digital ID generally. Anybody listening, I would encourage them to go give you a follow. But I had to ask: given all the content on mDLs, do you have an mDL? And if so, where have you used it?

Chris Goh: Yeah, so I have, actually. I was technically the first in Queensland because I developed the Queensland digital driver’s license and I used it. And actually, the first time I used it was at an airport on the day, and for some reason, without a blink, the airport person just said, Okay, and also the accommodation. So we hadn’t actually passed legislation. We must admit it was a flash pass. We won’t do that ever again. But yes, I had it out and I just showed it, and they said, Oh, that’s okay. And for us, and that was very fortunate that Queensland came after South Australia and New South Wales in doing that, so people were used to seeing it in the wild. And when we launched it, everyone was just going, Oh, okay, this is probably a New South Wales one. But I’ve used it lots of places: Australia Post. The most extraordinary one was in a regional town called Toowoomba in Queensland. And in order to get access to the toilet and get a big wooden key with the key, at the end of it, I had to show my driver’s license. So, yeah, to access the toilet, I have used my mDL.

Chris Goh: So that was probably the most interesting use case I’ve had to use my mdoc.

Riley Hughes: Yeah, that is certainly an interesting use case. And of course, leave it to me to ask the question: do you have an mDL when you were the one who developed it in Queensland and you got the first one? So it shows where I could potentially do a little more research, but no, I’m just teasing here. That’s really interesting. I wanted to jump in there because I know that you were at the Department of Transport in Australia, leading out on this initiative and now obviously striking out as an advisor in the digital ID world. I wonder, could you give an overview of what was your work like at the Department of Transport in Australia, and what did you accomplish there? Was it limited to Queensland or was it nationwide? Yeah, just give a lay of the land.

Chris Goh: Yeah. So I started in Transport Main Roads, actually, of all things, in head of discipline for cyber and HR and a whole bunch of other things, architecture as well. So I transitioned very quickly because we had to replace what we call our registration and licensing system and modernize it. So then they said, could you modernize it? It was a significant project. It had more than 135 applications internally using this source of truth, and it accounts for a lot of the department’s revenue, so about 2.4 billion in just revenue for registrations alone. So it was quite huge in that. And what we were trying to do at the time was uncouple that and stagger the iteration of the development of the platform. We were lucky that it was in a modular build, and we were trying to exit in a modular way so that we didn’t put all the eggs in one basket. And the first aspect of that was the customer management component of that: how do we manage the customer, and do we do a traditional CMS, customer management system or what have you? We’re breaking the financial components out.

Chris Goh: And again, we reviewed how do we uncouple it, and then we realized that a lot of the single sign-on capability we had also needed to upgrade, and we realized this was a really good opportunity to have some sort of digital driver’s license. And that’s where that journey really began to do that. And that was coincidental because at the time, Amber… Austroads in EReg held their first global summit in 2018 down in Melbourne. My Director General, a wonderful man called Neil Scales, rang me up and said, You need to be down there. And at that stage, I had no idea what an mDL, MDoc was. And then not long after that, I came back to my team and said, We’re going down MDoc path. So we had actually tried blockchains, hyperledgers. We’d done proof of concepts and we would do that. And I saw that, and then I also went to Nebraska, I think the following year in 2019, and saw a test event, and I saw the end-to-end capabilities, and I just said, Well, okay, that’s pretty straightforward. Let’s go down that path. And so then we went down that journey.

Chris Goh: After that too, I think in 2022, I was asked then to lead that nationally. So worked through and worked with Austroads to be the national harmonisation lead for Australia. And in June in 2024, we got agreement from all states and territories to adopt the mDoc formats for mDLs and photo ID. So for me, that’s been a huge journey to get there. But I have to thank my colleagues across states and territories and New Zealand, by the way, so up there because of their efforts to, I suppose, modernise an approach. And again, not just about mobile driver’s license. We understood, like many other people, that the driver’s license, the humble driver’s license, had become a form of identity in the community, a trusted form. And what we wanted to do was enable that capability well beyond the driver’s license. Just an interesting stat for you before I finish that. When we did the mobile driver’s license trials, we discovered that it was 50 times to one that the driver’s license was used for other things than validating that you were competent to drive, so the primary use of a driver’s license.

Chris Goh: So 50 times it was used for other things before you actually got a check by the police or the licensing authority. So for us, that was a good wake-up call. to understand why we needed to make sure that this was in digital form, because we also understood it enabled a lot of ongoing digital services, and that was the primary means by which we transitioned and encouraged all of Australia, states and territories, and also New Zealand to go that way. And I have to say that, yeah, it’s come a long way, but we’re—

Riley Hughes: Yeah, that’s an awesome overview. Exactly what I was looking for. And there’s a few areas I want to double-click on there. I want to ask about digital identity generally and where mobile driver’s license fits within that, but I’m going to park that for a second. And it was interesting that you had started off, like you say, with blockchains and Hyperledger and different things like this. What was it about the event you attended that convinced you that mDoc was the way to go? I think a lot of folks certainly today are adopting this same format, particularly because others are adopting it, and so it’s a self-perpetuating thing. But I think when a lot of technologists especially look at this from first principles, they get excited about other formats that have all kinds of bells and whistles, or they enable more complete privacy protections around the presentation of a digital ID. So I’m curious, what was it about the mDoc format that caused you to end up going in that direction?

Chris Goh: I think there were three primary reasons that drove that. I think the first one was, so when we did Hyperledger and blockchains, when we worked with one vendor, maybe up to two, we had really good interoperability. You can implement it without a doubt in any of those protocols, right? Web3 too, we were interested in the trials in Europe also around that Web3 type stuff. So within the stack, it worked really, really well, and I think What we discovered, though, is we included other organisations with their variations or variants of hyperledger and that. It became really clear to me that there wasn’t an easy end-to-end management, and between that, you almost have to choose a platform, you have to choose a stack that everybody was in there. And that was what I loved about mDoc and mDL in general was it was elegant. It used standard X.509s, certificates as part of that management, so everything that’s already existing. Like, it wasn’t a huge jump. But three things stood out at me, particularly in Nebraska.

Chris Goh: One was that it was end-to-end in relation to at least presentment when you’re there, and there was the vision of having that online. And I think that was the big challenge for us. I think a lot of people now, maybe it might not have happened, but was trying to solve the online first. What we had to do was also be able to show from an accessibility point of view, and this is where people, Mr. Government requirements, that we have to cover both online and also offline, so in presentment. And this was the first time that I could see this working, and that was the second thing, was that it presented an opportunity to work offline. We have regional and rural remote. We have a large Indigenous population. At the time, we had, and we still do, black spots, and we needed a capability to work offline. And that was, from a channel point of view, we needed to have no channel left unturned, and that was probably the first selling point of mDoc, is that it could work offline. All the others required online all the time. Second was the gymnastics in relation to stack.

Chris Goh: We could see end-to-end, the vision of it was from pre-auth and enrolment all the way up to revocation, and I hadn’t seen that level of capability as part of that process. The other thing that also was really challenging at the time was selective disclosure, and they adopted ICAO 9303, which is also what SDJ has done as well, is adopt the same format, but— What was really good in relation to that privacy preserving for me around that selective disclosure was that for the first time, I could see that we could use it for other identity stuff besides driver’s license. Because in a driver’s license, you pretty much, from a regulatory point of view, you have to hand over everything to police. But we needed a way to do that, and that was very hard actually in those years. It’s better now with hyperledger, because you either got the public side or the private side of the blockchain ledger. Public everyone sees, and the other side nobody sees. And now there are selective disclosure methods, and they’re not consistent, but they are in those technologies.

Chris Goh: But back then, this was really important because at Demerit Point, you don’t want that on the public side, but you want police to access it, right? So that was a really critical thing. So again, to iterate, we saw this offline-online capability. We saw this end-to-end interoperability, particularly around that accessibility, combined in both online and offline. And then third, in relation to selective disclosure, we’d done all the right work to get us there. And again, seeing that in the flesh and seeing people work that out and validate that was really, really impressive when I first went and saw it in Nebraska.

Riley Hughes: It’s interesting that you mentioned the, because back in the 2018, 19, 20 timeframe, Trinsic was a vendor within the hyperledger world, right? And I saw what you’re describing, this fragmentation take place where there were different variants of everything, right? And different DID methods and different signature schemes and different credential types and different variants of all this stuff. And I was excited when Trinsic transitioned into kind of what we’ve become today, to adopt mdocs as a format, because ostensibly it’s one format, all these states are doing it. However, what we’ve learned is that we’ve implemented now the mdoc, right? Then we implement Dash 7, and then Dash 7 has, we now have support wallets based on Annex A and Annex B and Annex C. And now there’s like a shadow Annex D or like a forthcoming potential that like we support a wallet that’s like according to whatever that will be. And we support wallets that are based on mdoc that have completely proprietary transport protocols that don’t conform to any of those.

Riley Hughes: And this is before we start talking about trust lists and key resolution and certificate management and all of this stuff. So I guess, do you see a similar thing happening in this space that happened in the blockchain space a few years ago? And how do you think we as an industry kind of move past this?

Chris Goh: Yeah, you’re right on point on this one. And I think especially when we get something successful, everyone comes on board. Everyone wants to get a newer feature or do something different, and I think that’s natural. I think a good mentor of mine used to say that every competition is like a yacht race. If you’re up in front, the leader, all they have to do is follow the back yacht, but the one that’s actually behind has to do something different to the front. And that’s what we’re seeing now, is that people are trying to find differences in how they can add value in this space, and that’s where fragmentation occurs. And I think that there are three things that I hope happen as part of this. I think the next stage for this is really around certification. There’s a challenge. There’s different regulations that drive also some of this globally. So Europe’s got GDPR and other privacy constraints and are driving certain things. There are other protocols that are wedging themselves in the mdoc because it’s been legislated to do so.

Chris Goh: And I think what we’re trying to do now is try to figure out what is the right roadmap to minimize that fragmentation as people try to innovate. I think you can’t stop innovation, nor should you do that. But I think in the end, industry, when they ship product, and also particularly relying parties, need some stability. They can’t afford this fragmentation. So I think certification is the next part to standardize what is actually concrete, what are the products, so that we minimize the diversification until we’ve tested it. I think that’s my biggest problem. I don’t mind diversity, but what I’m worried about—and there’s a lot of people do devs and so many repos now do agile delivery on some of these iterations—some of that backward or grandfathering is now being left behind, which causes problem in industry, and they need that stability. I don’t want to get to a point where you’re like an aircraft organization where there’s 15 years before the innovation actually hits the product. I think that’s not what we want.

Chris Goh: But we do want some sort of baseline for industry and certification that makes sure that there’s stability in the relying party from a verification and also issuance point of view. I think the mdoc format is generally well done. I think where you’re seeing the innovations on the edges, particularly around managing that selective disclosure, new mdoc profiles, that’s where people are battling at the moment around how do we do that, you know, with hype coming also on board. But I think the key challenge for us is creating some level of certification, particularly industry and those relying parties like banks, insurance companies, and so on, some stability so that when they get a product, they’re pretty much guaranteed it’s working at a practical level.

Riley Hughes: Yeah, it’s tricky because innovation and standardization are at odds, right? Standardization means slow down, everybody agree, let’s all align on the same thing, right? Innovation means, hey, let’s experiment, let’s try a few things, see what works, and one state’s going to do one thing, another state does another thing. And you mentioned flash passes earlier, almost in a derogatory way or something toward yourself, right? Not toward the concept or whatever, right? But almost in a—not derogatory way—but you mentioned it almost in a flippant way, like it’s not ideal. But actually, if you look at the geographies that have deployed flash passes, you know, a handful of years ago, those geographies tend to be the ones leading out in the current adoption of standard compliant mobile driver’s licenses. And so I think I talked to somebody building a software product that looked like verifiable credentials on the outside, and when I asked them, they were like, no, it’s completely proprietary.

Riley Hughes: And I asked them why, because you could be using verifiable credentials, and isn’t that much better for users and much better for all these reasons? And he basically was like— At any point in the future, when the standards battles all get fought and whatever, I can run a database migration and for each credential in the row in this table, issue according to whatever specification. And so it was like, at any point, I can fix forward. And I think organizations that, especially on the issuance side, issuers that innovate, even with things like flash passes that ultimately get overwritten by superior things, or innovate with things like the, you know, 13-7 with Annex A or something, right, which is maybe how most states now are doing it, end up being out ahead anyway in terms of adoption because they can always add support for these other things in the future. So I think these both can go hand in hand. And obviously at Trinsic, our job is to try to make things less messy for companies, relying parties and whatever in the meantime, while things shake out in the market.

Riley Hughes: But yeah, anyway, I don’t know if you have anything to add to that, but that’s, I think I’m just agreeing with what you were saying.

Chris Goh: Look, flash passes was a necessity for a couple of reasons. One was culturally, it’s what we did, right? So if you try to swim against the culture, you’re going to be in big trouble. You may just won’t be adopted, right? So that’s why we weren’t initially hard on it, because one, we didn’t have the relying party capability for them to have a digital verifier, or they don’t want to, or they don’t understand. And that was a huge change management exercise, which probably, in retrospect, more work had to be done there. But again, the relying party and verifiers were still coming out. We built our own app verifier, but we also discovered from there that staff then let, sorry, retailers and that, their staff to use a mobile phone while they’re actually serving customers. So a whole bunch of things that we learned there. So culturally, we have to meet them where people are until we can actually change that paradigm with them, right? And that’s a partnership that just takes time with the industry, with all sorts of relying parties.

Chris Goh: The second aspect of that too, again, take a really valid point around having that hybrid sort of way. I think for us too, we also have, for instance, signed PDFs and people go, well, that’s a That’s really bad. Even though it was digitally signed, the actual PDF was digitally signed. It was to meet existing regulations, part of that. And people go, That was really bad. I mean, that’s security. But again, we have to meet them where we were. And I think, I don’t want to touch on this because it gets me into lots of trouble, but that’s where server retrieval came from. It was actually coming from the physical world. So when we had, when we, again, from accessibility, you have to remember 18013 came from a card industry standard, right? And what we wanted to do was also cards don’t update. Physical cards don’t update. The SIM card doesn’t update. So how do we make sure that we verify that the smart chip on there has the most up-to-date information? The only thing could do was validate back to the issuer through a server retrieval, which everyone on the internet does.

Chris Goh: But that’s now become a thing because cultural norms have changed, right, and there’s expectations. So I think that’s sometimes—and I think the way you posed that was really well—I think there’s always great punters who like to debate that we shouldn’t have START, but part of the challenge of any issuing authority is to work within the cultural limits and expectations of that, and then transition and work on a change management aspect to transition to what is better. So as you know, from an agile point of view, don’t let perfect get in the way of better. And sometimes we think perfection is the only way to go for START, but we need to live with the reality of how the ecosystem players can work today and readily accept that, because a huge change comes with cost, change comes with shifts in capability, and entity certificates, even in the PKI space. Everyone knows PKI, but getting people to understand how does that work in the distributed way in entity certificates, that’s just hard for so many people who’ve been IAM for so long.

Chris Goh: And it took me a couple of years to go, Ah, I see how this works now. But same concepts, same words, but architecturally different and culturally accepted differently. And it’s, again, Riley, right on point. I think sometimes we need to accept where people are and focus on that and then build good as we go.

Riley Hughes: Yeah, and in the meantime, there are jurisdictions that have been waiting till the perfect thing comes out, and in the meantime, every day millions of people in their jurisdiction upload a high-resolution photograph of their entire passport to a third party for processing and training an AI model, right? It’s like letting perfect get in the way of the good or the better while we work toward the best. I think I am very much an advocate for that approach as well.

Chris Goh: Totally agree there.

Riley Hughes: And then for listeners who are not as in the industry as we are, a flash pass—and Chris, correct me here if I’m oversimplifying or something—but a flash pass is basically where the user has an image of the driver’s license on their phone with some visual indications that it’s not just a screenshot or something like that, and they could show the screen of their phone to the police officer or to the retail— person or whatever, and the police officer or whatever can see that this is a legit image and not just a screenshot or something like that, as opposed to something where you can digitally verify it with another device, like a phone or a reader or something like that, right?

Riley Hughes: And server retrieval is a lot of digital credentials can just be verified independently by a reader in a self-contained way, and they don’t need to go to the DMV whether this credential is still valid or not, because the credential itself contains all the information required for the reader to validate that, provided that the reader has some cryptographic material or whatever that it can use to validate that stuff. And server retrieval is where the reader does go back to the issuing authority to check, and that has privacy implications. Obviously, the question being, do you want your government to know every time you go to the bar or every time prove your age for some reason or whatever the case may be? Is that any other jargon that we’ve used, Chris, that you think we should clarify here while we’re at it?

Chris Goh: No, I think you covered that well. I think you covered it well. The only thing I’d say with server retrieval is that if you are using a single sign-on platform, an SSO platform today with the username and password, you’re doing server retrieval, right? Because you’re going back to the RDP as you’re authenticating, right? So this is, I just want to highlight, this is not something that we haven’t done before, but there is new expectations on how we should do it, and I agree with you. Even though there’s clear, NXE is very clear on how not to do tracing, there’s always the fear that someone will switch on something to track and trace. And I think that’s the challenge that we have, is to figure out from a risk-based approach, how do we mitigate that if we want to use it? But I also know that some of that’s actually quite useful use cases. So I know mDocs in a medical environment are very useful in containing that ecosystem, where if you’re doing meds management, for instance, meds management is life or death, right?

Chris Goh: And you want to get the most up-to-date information, you want the server retrieval where that last piece of thing is because it’s not sitting on the phone. And so sometimes… I think there’s a battle to understand identity and credentials and the value proposition. Identity, I agree, should generally not be known who you are or whatever, and you should have the right to forget. But I think people forget credentials actually come from a government-regulated environment, where the initial reason why a credential was issued was about keeping people safe. That’s really what the driver is. You know, are you safe to drive? Are you safe to work on a worksite? Are you safe to do this, safe to do that, is what a credential is, right? And how it traditionally is done is checking back with the issuing authority who’s got those eligibility requirements to see whether the currency of that is right, and that’s really where that’s come from. And so in certain places too, you need to retrieve the most current data.

Chris Goh: And again, how do we do that in a non-identifying way is really the right question, rather than don’t use a protocol. I think sometimes we fight around the protocol and don’t use case we’re trying to support. And I think those use case-driven approaches need to be rethought, rather than having a debate that every firewall at home is horrible. ET actually wanted to go home, just saying.

Riley Hughes: Yeah. Well, it’s really easy on social media to lose nuance and point to a specific thing, right? We see this all the time, regardless of whether it’s in a professional life or personal life or political life or whatever, right? It’s always the quick sound bites always get the — are easy to glom onto. And I’ve seen this recently with the UK digital ID stuff, right? And it’s just like people saying, Oh, digital ID is this, yada yada yada, and it’s — digital ID could be a lot of things. Digital ID could be really bad, you’re right, but it also could be really good. I think we just lose a lot of nuance when we just talk about it in generalities. And I think what you’re saying makes a lot of sense. Look at the use case. If you can do it without phoning home to the issuer, it seems like a good idea, especially when it’s something sensitive, like potentially government-related. If the government’s the issuer, it’s different than if I choose to have a Google account or something like that. I don’t choose my government, and maybe I do, maybe I can move somewhere.

Riley Hughes: But generally speaking, there’s different expectations around some of these things. But if the use case is useful for it or something like that, and it fits the purpose of what is being done, then yeah, we should bring the best technologies to bear to solve the problem people have. So yeah, fully aligned with you there. I want to go back to that topic that I tabled earlier in the conversation about digital ID generally. When you were a part of the—so there’s a few things that I want to touch on here. When you were at the Department of Transport and Roads in Australia, and you were tackling digital driver’s licenses, right? This came up as, okay, we’ve got to modernize licensing for drivers, and we’re going to make this digital. And we know that people use their driver’s license 50 times more than they use their driver’s license for identification, 50 times more than they use it for proving driving eligibility or something. So you know that you’re doing a digital ID here.

Riley Hughes: Does this need to be like a top-down thing from like the highest levels of government or legislatively driven or something like that? Does it need to be statutory in that way, or was it more of a bottoms-up kind of thing where it’s, we’re doing physical IDs, let’s also do digital IDs, and it was viewed as more of a continuation of the existing mandate? Does that make sense?

Chris Goh: Yeah, absolutely. So we tackled it both top-down and bottom-up, so we’ll just talk about that. So from a legislation, it was actually very simple for us. Some people say we have to rewrite whole legislation, but we had a really smart person who said, You know, all we really need to do is change one paragraph here and one paragraph there. And so he said, Let’s just change it so that every time we say that it points to a… Driver’s license, we said that the driver’s license is also equivalent to a digital one, and that was the one change there. And the only other change that we made was that when we looked at the Police Act was you could confiscate a driver’s license, but did you want to confiscate a phone from a 17-year-old who tried to use a fake ID? Probably not. So again, we changed a paragraph there around confiscation of a device if it’s fraudulent ID.

Chris Goh: So I think it was those two things that sort of like, we took a very practical approach that we understood that people were, when you’re working in a department, everyone wants to peg you in a box, and rightly so, because you have an act that says you can only work within this realm. And so our own ability to act outside of that, and that was also at a national level, I was always pegged saying, Chris, don’t walk outside, transport issue credentials. You know, even the ID, that was more the containerized. You know, we wanted to do a lot more high-level use cases, but by just government structure and regulation, we were forced within a box, and we had to play within that. And that’s why I feel very liberated now walking outside the government that shows lots of use cases. But we did a strategic one to go, how can we enable that verifiable credentials? What’s the return on investment for those? And how do we keep people safe? How does this improve safety? And also, you know, we put head of security, I did the head of discipline for the Commonwealth Games.

Chris Goh: How do we improve it from a where we traditionally program security checkpoints and everything like that? How do we strengthen that so that we can support that? So that was top-down strategic from that point of view. And what was the legislation and regulatory change that we need to do to be able to switch it and accept it on? And we also worked with industry and peak bodies. We worked with Justice of the Peace that acted as a proxy authority in Australia to sign off on mortgage documents and stuff like that. How can they accept that? So we looked at the major touch points in industry, Hoteliers Association in hotels. You know, we looked at rental cars and all those traditional spaces where the driver’s license was accepted, banking from a KYC and or CTF point of view. How do we switch it on? So again, we tried to do that. But I think one of our biggest challenges, and still is today, is The lack of understanding on the versatility of a credential and the identity versus the identity proper, in relation to what people think of in relation to a single sign-on.

Chris Goh: People think a proper identity is a username and password, and they don’t understand this passwordless technology that’s token-based. And that’s still the challenge today, I think, in some of that stuff. And we have to work bottom-up to educate as well. So at the top down, from an outcome point of view, we could communicate that really well, but we then had bottom-up work with the technologists to go, you know, you don’t need to provide all your attributes when you log in. You don’t need to do all that sort of stuff. The biometric pinning as part of the binding is sufficient for the LOA. And this is part of the challenge also with the existing identity legislation, is that it was built around a centralized I know stuff kind of thing and onboarding, and I won’t pass a token except within an accredited token. So the trust is machine to machine, not entity to entity. And it’s a very hard concept for traditional IAM people, the tradition. And we need to do a bottom-up architectural approach to sort of get there. We sort of got there in some cases.

Chris Goh: The states and territories who understood this understood and was willing to accept that, but I have to say that the challenge is to remain, particularly in Australia around that single sign-on. And like you’ve got your equivalent in login.gov, I think. From a US point of view, the UK is obviously struggling with that at the moment on these technologies. And we’re in that sort of like, I think almost flip point by which people go, Ah. And that’s an education piece that people understand, and these architects and these security people hold the controls on where their things are passed in a department. And it’s getting to them at a bottom-up point of view to say, This is how this now works in a different way, and the trust model is flipped on its head. And they’ll go, The customer’s controlling their data. That’s not right. And we go, No, it’s not our data, and it’s theirs.

Chris Goh: And that’s the hard part at a bottom-up point of view, is convincing those, particularly our zero trust people in the security, working on 27001 with separation of duties and all that, they just go, This is, you know, this is hard. And that’s because some of our legacy controls, built rightly so at the time, around our federated identity, which works, uses the same almost protocols but flipped in relation to who actually allows them to be switched on. And that’s a very hard thing to…

Riley Hughes: To help leadership understand that. So I want to talk about the landscape in Australia and I guess maybe taking a step back, Austroads covers sort of New Zealand. as well, right? It’s sort of Australia, New Zealand, and any other territories, or is that—

Chris Goh: No, that’s it.

Riley Hughes: Yeah, okay, yeah, that’s okay. Yeah, so I want to talk about the landscape down here, and you mentioned some of the jurisdictions get it, and other ones took a little longer or are still taking a little longer to wrap their heads around exactly how this will work. I wonder if you could speak to just the landscape, like where are mobile driver’s licenses deployed right now in Australia and New Zealand, and maybe how you think that will be different in a year from now.

Chris Goh: Yeah. At this point in time, Queensland still remains the only ISO issuer of credentials. Saying that, and there is already pilots happening in both Victoria and also New South Wales that are transitioning their existing credentials. Credit firstly to New South Wales—sorry, South Australia should get the credit because they were the first ones to do it. It’s always New South Wales get the limelight, but South Australia did it. But I think all of them are intending to—I think it’s an investment lifecycle issue. All of us, it’s a very tight fiscal season for all governments across Australia and New Zealand, and it’s about getting an investment because they’ve invested in a roadmap, and now they need to flip it in relation to do that.

Riley Hughes: So is it safe to say that there’s maybe a handful of states, South Australia, New South Wales, Victoria, et cetera, that have invested in a digital driver’s license, right, of using technologies that are different than the mDL, mobile driver’s license technology, which has standardized at ISO, right? Could you break that down for people who maybe are under the impression like, Oh, Australia’s got all these different four or five states issuing digital driver’s licenses. Great. And what is that? Practically mean for somebody who’s looking to accept digital IDs that these are using different technologies.

Chris Goh: Yeah. So again, when they all started and the investment lifecycle started, we had single sign-on platforms, all of us. We had Auth0, Okta, Forge kind of product that was sitting at the back end. And generally apps were designed with an API link to the back end and rendering, I suppose, the data that was coming up. And that’s essentially what everybody did, was render an API with the data coming out of their system of record and having some level of authentication at the front end to make sure it was you. That’s what essentially an account is. And that’s how all those apps started. Queensland has a very similar one for when they first started with the portal. And the mDoc format is all cryptographically, you know, you have to put PKI in place. You need to sign certificates in mDocs and MSOs in a way, and have device-bound type of ephemeral keys also linked to your wallet. It’s not a simple thing because of the cryptographic requirements. And so all of them are flipping into that process.

Chris Goh: So really briefly, and I’ve got to be careful because I just want to put up, just in case my old bosses are watching, I’m not representing Transport for Main Roads or Austroads today. You know, I’m speaking with the previous experience and with public information that’s already there. So has invested in supporting jurisdictions and getting their PKI infrastructure, like ANZ. Actually, we copied and cheated by stealing ANZ’s stuff, I have to say that. And Mike McCaskill reminds me, No, you borrowed. You know, we’re helping you as a partnership. So it’s always very nice to hear that. But the trust list was that anchor point, that we need a trust anchor for all these PKIs. And then we also work to help them broker their data, so basically use their APIs. So Austroads has been, since 1998, a verifier of driver’s licences, right? So how do we change those APIs into mDocs? And so we’ve got now technology to help jurisdictions to use their existing APIs to encode that into an mDoc and self-signed and self-sovereignly managed.

Chris Goh: And that will help every state and territory over the next 18 months, roughly, to all transition to mDocs. So I’m very optimistic, and I can’t speak too much when these dates are, even though I do know, I’m not allowed to say dates, but there, I’m very optimistic that that will happen. Obviously, on the other side is the relying party side. And how do you get, how do you come out where most stores still don’t have verified, digitally verified, and also know that you can’t do a flash pass, and the other thing is that staff aren’t able to carry a mobile phone with party retailers. And then you’ve got the complexity of Part 7. How do you make sure then, you know, you’re dealing with AI agents and all that sort of stuff now doing injections and spoofing. How do you then also make sure that your customers are safe when they’re doing that selective disclosure? Once it leaves the mdoc, that’s actually when the problem begins, because until it leaves the wallet, it’s pretty safe. But then the customer says, I will disclose all this data in PII. Then how do we then protect it?

Chris Goh: That’s the real problem today, no matter whether you’re blockchain or anything else, it doesn’t matter. Once it leaves that system of record, or that format or that ledger, and it has to be stored for regulatory reason, how do you deal with that? So I think the top three things you need to solve, you need to re-prosecute the privacy legislation and regulation to understand what that is. And I’m certainly pushing a thing called Privacy Commons. It’s very similar to Creative Commons, where in the year 2000s, or around just the turn of that millennia, we had issues with intellectual property, and we created a thing called Creative Commons where you download, meet your video, and you’ve got a record that you’ve downloaded underneath these copyright requirements. You know, CC BY is a common free to use. We need a similar thing, what I call Privacy Commons, for when a person has stored it. Right now you’ve got these very long, no one reads privacy statements, and you still don’t know what the purpose is. You don’t know what the data is retained.

Chris Goh: And luckily for us, our colleagues in another international standard working group developed the 27560 around privacy and consent storing, which is also using GDPR as an anchor. But what we hope to do is to have A simple privacy contract that says this is what they’re taking from you, this is the retention period, and this is the purpose by which it’s done, hopefully to a regulation. And then we put those trusted relying parties in some sort of relying party trust list, and then we can authenticate that. And that’s probably the next big stage in relation to regulation. then an updated standards that protect the endpoint in relation to PII, selective disclosure. Anyone can do selective disclosure now. It’s about how you protect those endpoints. And then adopt controls like PCI does. You know, the credit card industry saving billions every year. You use hashed data for storage and things like that. Why don’t we adopt some of those standards in how we protect data at rest?

Chris Goh: So from a regulations point of view, from updating the standard, then also adopting controls that we have in a normal security context to strengthen that. And that takes a while for industry to understand how do they create that in time to also support verifiers as they come on board. And that’s where we are at the moment, trying to do that last stopgap, so to speak. And I think once that’s done, and done well, I think a lot of people want to adopt it to protect people’s privacy.

Riley Hughes: Yeah, that’s interesting. I think the majority of digital IDs around the world solve this problem by having the authority approve each relying party one by one, right? So you’ve got SingPass in Singapore, right, who GovTech, the government agency that operates that scheme, as a relying party, you need to apply and request access, request the ability to verify, and then you submit a bunch of information about your use case and maybe you do a security questionnaire or something. And then GovTech, the issuer, is the one that approves each relying party. In the United States, we have something similar developing where Apple and Google have pretty heavy-handed, or I should say, thorough approval processes and requirements for relying parties to get access to anything inside the Apple Google wallet if it’s related to identity credentials. And I’m sure this will loosen up and be more streamlined over time. But I guess. To your point, do you think that consumers need to be protected from malicious relying parties in a more active way, similar to how a lot of these schemes operate today?

Riley Hughes: Or do you think that it’s better for jurisdictions to issue the credentials out of the system of record, give them to the user, and then let the user go wild, do whatever they’d like with it, and away you go?

Chris Goh: I think, like we’ve said previously, is that we meet the culture where it is, right? So I think, like in Europe, they’ve got a strong regulatory driver, and they want to do that. I think then develop controls to support what has been pushed. And again, that’s okay. But I think, for me, I think what you need to do is provide users simple ways to make informed decisions. And I often use my mother as an example. You know, for a while, she didn’t know what internet was. She said the internet was explorer, because that’s all she had. She says, I’m on Explorer, whatever, and that’s the kind lady she was. And then I said to her, because she was starting to buy stuff, and I said, Make sure there’s a lock. And she looked at, Oh, okay, it’s got a lock. You know, it’s got that SSL, TLS lock on the certificate, right? And again, what we should be doing is to be able to provide those nudges. And I think that’s one of the problems with standards, that standards stop at the CX perspective. And what we need to do is provide some level of consistency around how we nudge and inform people around.

Chris Goh: They should be able to make decisions to disclose to whoever they want. And there might be legitimate reasons that they’re disclosing it to someone that isn’t auth, and we’re not the judges of that. But what we do want to do is provide them is when they make that decision, here are the risks in a very simple way. And then what we want to do is that if a relying party makes a commitment on something, we sign that from a non-repudiable point of view, so we can use basically common law to hold them to account, right? And that’s in 10135, we have the customer transaction log only available for the customer. Any of the data in there is signed, right, individually. So if you have a relying party, then signing that privacy statement, you have a privacy contract, then how do you make sure that that privacy contract is recognized by law? And that’s that thing. So that provides you at least if Google and Apple doesn’t pass and whatever, and they use something on part seven. And I think that’s the thing is that now we’re talking about part seven and they go anywhere.

Chris Goh: It’s not going to be necessarily in your jurisdiction in the U.S. I don’t want to promote Amazon, but today is Prime Week, and, you know, we’re off there buying, and some of them is in the U.S., right? So they won’t be covered by that, and they want to buy something from the U.S., right? Would make an informed decision. But then if Amazon provides a privacy statement and says, yes, this is the purpose, this is how long I’m going to retain it, whatever, and you have a transaction log, we can make that non-reputable, and if we can recognize through common law that that’s actually a privacy contract, then there’s a level of protection, a minimum level of protection. I’m not saying this will cover everybody, a minimum protection for everybody who tries to do that. And then we can give them a bit of a lock. If they’ve got a privacy contract, we can do some sort of read auth or relying party auth. They get a lock that says to customers, at least you’ve got a privacy contract as part of this.

Riley Hughes: Yeah, it’s going to be really interesting to see how it plays out. Obviously, the web era has led to this open system, right, where consumers can go to any website they want, and the mobile era led out with the app store-based model, where Apple and Google provided that layer of protection and were the, for lack of a better term, gatekeeper of whatever goes into this, the apps that consumers can choose to engage with. And I think it’s probably safe to say that there’s been a lot of fraud online, right, on the web. And I think the consumer protection piece is probably pretty real. On the other hand, there’s a non-trivial tax on innovation and on consumer choice when the options are limited to just what’s there in the app store. And so it’s a really interesting dynamic. I really wonder how this will play out in the space. Do you think on this vein, do you think that, and of course, I’m just asking this not as a former government representative, but just as another fellow in the ecosystem here, how do you think the wallet landscape will play out?

Riley Hughes: Is it going to be that jurisdictions all over the world will just rely on the mobile phone to provide the wallet and basically be at the whim of those mobile wallet operators? For all the relying party adoption and activation and all of that, or do you think it will be? a little more decentralized and, dare I say, fragmented or something with lots of wallets out there? And I guess, how do you think that will play out if we look three years in the future?

Chris Goh: I think that especially for credentials and digital credentials that are regulated, we’re always wanting national interoperability, and if possible, and not always, some level of international interoperability. So I think that sort of drives a lack of schisms, and that’s why you see AMBA, eIDAS slash European Commission slash Austroads driving some level of conformity, and that’s really important. I think from a wallet perspective, I look at it like… Word, MS Word. There will be parties that dominate the main functionality, but there will be always wallets. And this is really where I said some people ask me from a wallet point of view, is it worth investing in building a wallet today? And I said, yes, but just understand you need to specialize. It’s that whole yacht race. You’re going to need to do something different from that front runner. You need to add value, and there is lots of value to add. Lifecycle management of a credential is not easy, and it needs to be done. Most of the top ones just do verification.

Chris Goh: They add other things, and they have obviously links back to widgets, and that provides some sort of, like, allowing their partners to add value, and that’s really useful. But also, we want to manage the merit points. We want to manage a user experience within a lifecycle of a particular thing, and that’s not easy to do. And we haven’t even come to delegated authority. There are other things that are still to build out in this space. Delegated authority, I think, is the next holy grail as part of this. I often think about this whole age 18-plus sort of situation is where is the parent in this? Why can’t a parent delegate their child a token? Why does the government need to delegate them an 18-plus? Why can’t a parent, who’s their guardian, say, You’re okay to use YouTube between this time when I’m supervising you? Why is it a total ban, let alone with AI agents?

Riley Hughes: That’s right, you know, who we may want to do things on our behalf.

Chris Goh: Yeah, that’s right. And that’s really critical, and I think you’re spot on with AI agents. That’s kind of—we want to automate stuff, and we don’t want barriers to automation, right? So how do we do that in a privacy-preserving, supporting that innovation? And I think at the moment, these things—I’ve been in government, I’ve been 30 years in government—and these are pendulums that I always see back and forth. There’ll be all these restrictions because everyone doesn’t know what it is, like the normal firewall manager that says, Let’s shut down all the ports, port 80, port 25, let’s kill all of them. They’ll figure out who yells and we’ll switch it on. That’s what we’re seeing at the moment. I don’t understand. AI is going to kill us. Quantum bots are going to just destroy this. Let’s just shut everything down. I think that’s a normal human reaction. And then there’ll be hopefully a nuanced conversation that comes back and, No, we need to make sure that we provide some capability for humans. To make mature decisions around certain things, and so it’s not absolute.

Chris Goh: But we’re seeing a reaction today, and that’s rightly because we don’t understand it, the speed of it. ChatGPT wasn’t around five years ago.

Riley Hughes: Right. Yeah, or even like three or something, right? I mean, it’s crazy.

Chris Goh: You know, I use ChatGPT more than I use Google now. It’s a different world. I didn’t know. My mother says, I didn’t know I needed a TV, and now I’m saying, I didn’t know I needed Netflix, you know, five years ago. These are once change, and then our desires, and then the technology naturally now innovates faster than we can understand or regulate. And so there’s a natural—what we’re seeing now is a bit of whiplash in some sort of realization. And hopefully, once we’ve had that whiplash, we can have some nuanced conversations, and I hope that happens. I understand what’s happening now and how we react as humans, but what we need to do now is go, well, let’s go back to use cases. Can a parent allow their child access, you know, science journals or something like that in the channel? They should be able to, right? You know, there’s good content and different things, but I understand why we’re reacting where we are, because we’re trying to put a brake on something that we’re seeing clearly there’s an accident about to happen.

Chris Goh: We just don’t understand it, and that we assume that we’re already in the accident, and so we’re doing that. And it’s about having really nuanced, complicated questions and answers that are not thrown in the public space where emotions run riot, where we can have really good policy discussions that go, how do we nuance this to get the best outcome as part of this process?

Riley Hughes: And it never happens. Those sorts of policy discussions don’t happen well on social media. I want to give you an opportunity to break down your work now and how you work with jurisdictions and private sector. But before we do that, I just want to ask: we have a lot of international listeners. We have, if you look at the distribution of the people who listen, there’s quite a lot in Europe, there’s quite a lot in North America, and then there’s people from all over the world that listen to the podcast to try to understand how digital ID ecosystems are evolving in different parts of the world. What would you have International listeners know about Australia, or about the Australia-New Zealand ecosystem and how that’s evolving. And what do you think listeners should take away or understand about that?

Chris Goh: Yeah, so Australia, please come. We’d love to have you. What do people think that we do? We put shrimps on the barbie. So if you come, we’ll put a shrimp on the barbie for you. What I love about Australia is that they’re willing to have a go, and it is a common slang, right? We love to have a go at stuff, and that’s why we were early adopters of tap to go. We are the inventors of Wi‑Fi. I remember working with a company called Radiata, who was a subsidiary in Macquarie Park to CSIRO, and that’s how Wi‑Fi was born. They love innovation, and they love to try new things, and I think that’s a really important part of the culture. We’ve got some extraordinary people who just want to get the right outcomes for customers and try to balance. We try to have a fair balance between a regulatory and government-centred driven approach to more of a, we need to also trust our people and make sure it’s modified. I think that’s that you can have those conversations well and nuanced well in Australia. I go to different parts, and the posturing is much stronger.

Chris Goh: And certainly, but I think Australia will provide you, within the next 18 months, a really good place to try any of the mDL, mDoc products, because it will be there. The trust list will be there. A whole bunch of stuff will be there, and the ecosystem’s there. And I know that there are lots of jurisdictions, without naming them, that just can’t wait for this to support and enable a whole bunch of services. I’m really passionate too, so from a social point of view, so I do homeless ministry, and I know that I need to get rid of addresses, a mandatory requirement, because I need these guys to get services, but they can’t because I need these KYCs. But blasted mandatory requirement, call an address, and they don’t have it, right? And this is the dual role I was talking to you about credentials. We have, on one hand, everyone deserves the right to be forgotten, but on the other hand, the credential also needs—we have a duty also not to forget certain use cases and support them. And how you balance that is really critical with a credential.

Chris Goh: So it’s great you have an identity argument that says you should never be tracked. I think that that’s fine for an identity argument, but for a credential one, that’s more nuanced because you’re doing that to help people and keep them safe. And I think you can have that in Australia. You can have that discussion. And I think that’s why. And New Zealand’s the same way, they’ve got their verifier. This is Kiwi, right? The first thing they bring out is not a wallet; it’s how to accept everybody else, right? I think that’s just beautiful. I love New Zealanders. Everyone else is saying, I want to come out first with my wallet and my issuing… And New Zealand goes, No. We want to be accepting. We want to accept other people, and they build the verifier first. So I just love New Zealanders. So these two countries, I think, I’m biased, obviously. I’m close to my heart. But I think you’ll find a relying party community that’s just itching to do this and itching to get into this space.

Chris Goh: And I know a lot of proof of concepts that are happening, and they would love your experience if you have it here. So please come. Please have that nuanced conversation, and we’d love to see how we can collaborate and partner with you. And that’s just not me. That’s, I think, all states and territories I’ve worked with now. I’ve worked in every state and territory, and the feeling’s pretty much the same. There’s good leadership in all of them driving this forward.

Riley Hughes: Awesome. Would you speak to the work you’re doing now, give you an opportunity to, if there’s listeners who may be interested in working with you, what’s your sweet spot? What are the kind of problems that you love to solve and types of companies and organizations that you like to work with?

Chris Goh: So, for me, I’ve realised that I’m in 30 years of public servant, I’m not going to change that. So I love, as everybody does, that, you know, you have your mission statement, whatever. So I’ve got mine, and I’m really passionate about it. I say I’m community-driven, I’m customer-centered, and I’m outcome-focused, and that’s really what I’m passionate about. So if you’re doing any of that, if you’re working to try and enable outcomes for community, and you want to have a customer-led approach, and you want to deliver something that’s usable and practical, I would love to do that with any organization. So at the moment, I won’t name the government organization. So I’m at the moment co-designing a significant, similar to the Europe, the architectural reference framework for this country, in a co-design with industry, with community, with cultural groups. So we have at the moment this huge mirror board, and I don’t know what I got myself into as part of co-design, but there’s a lot of, and I love that, I love a boiler of people who just want to get outcomes.

Chris Goh: And oddly what you find is, if they have their say, they will coalesce in relation to delivering outcomes, and it’s just about that. So my primary role is really facilitating that with the nuancing on what is practical. So I’m not going to tell you that you can do all this. I can present you lots of use cases to drive the enthusiasm, but I go, here’s the practical stuff I’m doing. That’s what I’m doing at the moment with at least one government around providing that practical roadmap around what are the things we switch on first, what parts of the community and use cases are very practical, and how do we scaffold the architecture and the project delivery and program delivery in a way that drives that, and also governance. How do you include your customer in the governance? I was the first one in Queensland government to introduce Customers in the tender. So the customers actually, 100, I think 15 of them, evaluated, and they were 50% of the assessment of the vendor as part of the procurement, I was told. It can’t happen. We can’t involve the customers in that.

Chris Goh: And I go, no, I need to involve customers because government, you silo. You think you know because you’re a customer, but you don’t, because you don’t live on the streets. You don’t go from one woman’s shelter to another, avoiding someone who’s trying to kill you. You don’t have that in your life. So let’s put them in. Let’s put that voice in so we understand that, right? And that’s what I hope to bring in any of my engagement. Another one is more practical in relation to helping people do test certifications and accreditation, and how do we make consistency? How do we test parties and that sort of stuff? And how do we implement that in a way that we can invite people to see the changes and put their products in, but at the same time provide a means to drive conformance around that end point. So either end of the spectrum, business case, program management, but if you are interested in serving your community, I’m a public servant at heart, as I say, and you want to drive an outcome and you just don’t know how, I’d love to help you.

Chris Goh: That’s really where I’m placed, and that’s a passion of mine.

Riley Hughes: Great. Awesome. Is there anywhere where we didn’t just scratch the surface, man? We could—this is a lot of fun. We could do this for hours. But until next time, appreciate you coming on, and yeah, we’ll look forward to the next time.

Chris Goh: Thank you, Riley. And by the way, guys, you did a great job. Saw your stuff in Phoenix. Love that you implemented use case. Keep on doing the stuff that you do. You’re really doing some really good stuff, and good on you, Riley, for this podcast as well. They’re really informative, and I’m a subscriber, so look forward to hearing more from you.

Riley Hughes: Great. All right. Thanks a lot, Chris.

Chris Goh: Thanks, Riley. Appreciate it. Cheers.

Riley Hughes: Thanks so much for listening. If you enjoyed this content, the best way to signal to us that the content is valuable is to share it with others who will benefit from it. Meanwhile, if your organization is interested in accepting digital IDs, you can find me or Trinsic on LinkedIn or X, or on our website at trinsic.id. And if you haven’t already, visit trinsic.id/podcast to subscribe to the Future of Identity newsletter and listen to any of our prior episodes. Thanks so much for listening.

Kelly Javanmardi

Director of Marketing @ Trinsic

Kelly Javanmardi leads marketing at Trinsic, where she focuses on content, demand generation, and go-to-market. She brings deep B2B and identity-industry experience, including prior marketing leadership at Berbix (acquired by Socure).

Newsletter

Subscribe to weekly insights and updates in the digital ID ecosystem.

sphere background icon