Interviews
Sarah Clark: Mastercard’s ID Network

Zack Jones
·
·
3 min read

In this episode, we sit down with Sarah Clark, SVP of Digital Identity at Mastercard, to discuss Mastercard’s ID network.
As one of the world’s largest payments networks, Mastercard has been on the leading edge of reusable identity. Sarah takes us into Mastercard’s corporate strategy related to identity, plus some of the specific go-to-market strategies the company has employed in Australia and Brazil where its network is live.
The conversation continues as Sarah explains why now is the time for reusable identity to take off. We discuss the challenges relying parties and traditional identity verification companies face with the advent of reusable identity as well as how tech giants like Apple and Google will play a role.
And as always, we end the conversation by delving into why Sarah believes that digital identity is the best place to be if you want to work in the cutting edge of technology.
To contact Sarah, you can reach out to her on LinkedIn at https://www.linkedin.com/in/sarahmclark/. She is also available at sarah.clark@mastercard.com.
Reach out to Riley (@rileyphughes) and Trinsic (@trinsic_id) on Twitter. We’d love to hear from you.
Full Transcript
Transcript lightly edited for clarity.
Riley Hughes: Welcome to the Future of Identity podcast, where we talk to the people building the ID tech products of tomorrow. I’m Riley Hughes, co-founder and CEO of Trinsic, and we build infrastructure for launching awesome identity products. In this episode, I sit down with Sarah Clark, SVP of Digital Identity at Mastercard, to discuss Mastercard’s ID network. As one of the world’s leading payments networks, Mastercard has also been on the leading edge of reusable identity for years. Sarah takes us into Mastercard’s corporate strategy related to identity, plus some of the specific go-to-market strategies that they’ve employed launching their ID network in Australia and Brazil. Our conversation continues as Sarah delves into why now is the time for reusable ID to take off. We discuss the challenges relying parties and traditional identity verification companies face with the advent of reusable ID, as well as how tech giants like Apple and Google will play a role.
Riley Hughes: As always, we end the conversation by delving into what Sarah believes is the future of identity and why digital identity is the best place to be if you want to work at the cutting edge of technology. Now, I hope you enjoy the conversation that I have with Sarah. Sarah, welcome.
Sarah Clark: Thank you, Riley. I’m very excited to be here, and I just want to say I’ve listened to all of your podcasts thus far, so it’s a joy to join you.
Riley Hughes: Awesome. Well, hopefully it’s been useful, and hopefully we’ll find some things here in our conversation today that are useful to others as well. So, Sarah, I wonder if we could start off just by talking about what identity has to do with payments. You obviously work at a payments network, or a company that’s most known for its payments network. Could you maybe give an intro to kind of the concept and how identity and payments relate and what Mastercard is doing with the ID service?
Sarah Clark: Certainly. So yes, identity and payments relate very closely. The two will merge. Payments need to be safer. Identity is the key to trust and safer transactions, including payments. But just backing up a bit, Mastercard has been active in identity in the form that I’ve been driving for quite some time. I joined almost exactly three years ago, and my role has been to lead the global digital identity business and product offering at Mastercard. And what that means in simple terms is that we have built and released something called the ID Network. So I can get into more about what exactly that means, but it’s all about enabling reusable identities to be shared easily with trust globally. And how that rolls up into a strategy for Mastercard is we are part of a Build New Networks theme that Mastercard has been embarking on. So when it comes to identity, a lot of the core expertise that goes into running a payment network at global scale across 300 countries applies to the field of identity. How can identities be shared so that there’s governance, operating rules?
Sarah Clark: How can it be created, or how can the ecosystem be created so that it can scale, so that it can support customer choice, so that it can support conceptually different issuing authorities? Those are many of the themes that my business has taken on. And you can see there’s a great parallel to how the payment network needs to operate. So about five years ago, Mastercard began doing a lot of thinking on this topic. And, you know, I’m quite proud to say that even before my time and during my time, we have been on the leading edge of the paradigm shift that we can all see is happening today with respect to identity: individual ownership, reusable IDs. How do you really crack the nut and solve the big problems that exist with fragmentation, fraud, user experience, and do that in a way that, again, supports individual ownership, individual choice, while making it a sustainable, scalable solution?
Riley Hughes: Yeah, well, certainly, you know, most of the time that I’ve been in the identity space—I don’t know, what year is it now? Time is weird—but six years or something like that, Mastercard has been involved in all of the industry bodies and a lot of the community meetings that we’ve been a part of, and so certainly has been at the forefront there. We recently attended a conference where I heard you speak. It was the LIMinal conference, and you mentioned that the ID network is live in two markets. I wonder if you could speak to that. What is live? What is it really? And, you know, if you could speak to how that looks on a global landscape, I think that’d be a good place to start.
Sarah Clark: Yeah, absolutely. So let me start with what ID network is. It’s a kind of open ID network that supports reusable IDs. And as somebody who’s very familiar with the SSI space, of course you’ll know what the roles are that I’m referring to. So in its simplest form, it supports three core roles: the individual who has a right to own their own digital ID and who should have transparency and consent to sharing their digital ID or any of the attributes or credentials contained within it. There’s the identity provider, which is analogous to an identity wallet. Those are entities who can bolt on to the ID network that act as issuers of IDs. And the third role is the verifier or the relying party who has a need to check that I am Sarah Clark and/or that I hold certain attributes that unlock digital experiences for me. We have set up a network that supports those three roles and that also accomplishes transforming the trust triangle into the trust diamond, to use some SSI lingo for you. So overlaying that, we have governance, we have operating rules, like how can this be standardized.
Sarah Clark: so that should something go wrong, there’s a construct that can be relied upon to rectify that. Conceptually, that’s what we’ve released into market. We are commercially live in two markets, Australia and Brazil. Happy to talk more about kind of the why and the differences between those markets. But kind of in short, Australia is really on the leading edge with a lot of legislation, regulation, the trusted digital identity framework, otherwise known as TDF. So a lot going on in Australia by government moving that market forward, and it’s a bit of a template for other parts of the world. Brazil is a market with tremendous digital growth, a lot of fraud, a lot of newer innovative companies battling with new digital offerings that certainly are thinking that through with trust and identity being at the core of what they’re doing. So we’re live in those two markets. We’ve done pilot activities and prepared for launch in two other markets, the UK and the US, and we’re active across a number of use cases.
Sarah Clark: And I guess one point that I really want to make is when you look at identity and what’s happening in the industry with sort of a shift from one-and-done, fragmented solutions that work well but aren’t really, really solving the problem, how do we solve this so that we are addressing fraud, so that we’re addressing data privacy and other really core concepts that are important to the future that all of us as individuals seek, or I hope we all seek. And to do that, it’s not just going to be one player that can solve the whole problem. It’s going to require industry, multiple players to come together to create an ecosystem. So really our role with ID Network and what I personally believe is the way of the future is to embrace a paradigm where we’re supporting the development of this new ecosystem by allowing multiple players, multiple roles to come together to solve for how reusable IDs can be scaled globally.
Riley Hughes: Awesome. Yeah, I want to talk more about some of those roles and how that ecosystem comes together. But first, you touched on the fact that in these geographies that you’re live in, you’re live with a few different kinds of use cases. I often get asked when I talk to people about reusable identity or decentralized identity, what is the killer use case? And as an infrastructure provider, as Trinsic, we have a unique vantage point to see lots of different applications, lots of different people trying lots of different use cases. And when we’ve plotted all those use cases on a graph or something, unfortunately, we don’t have a satisfying answer. It seems like there’s lots of different use cases. There’s not just sort of one use case that correlates most with success that we’ve found. But I’m curious where you’re seeing success or which use cases you’ve been most excited about as you’ve gone live in these markets.
Sarah Clark: Yeah, so you’re exactly right. I mean, if you look at identity, identity is the basis for trust. Trust is the basis for every single digital experience kind of out there. So one of the biggest problems I think that anybody operating in this space has, and it’s a good problem to have, is it’s applicable to literally every use case if you start to really look at it. And that’s really exciting, but that’s not how we can build an ecosystem deliberately and kind of piece by piece. One of the biggest jobs of those of us steering these types of businesses is focus. The other big problem that we have is the cold start problem. I think it’s just logical that reusing a digital ID is the way things are going to go in the future, but how do you get traction when you’re starting basically from zero? So the use cases that we’re active in, there are quite a wide variety of them, and I guess there’s sort of like two philosophies to how to build this type of ecosystem. And we’ve really begun embarking on strategies that embrace both philosophies. So the first is frequency of use is the gold standard.
Sarah Clark: If you think about the individual and this shift in thinking that they need to go through to say, Aha, I have this digital identity and I can use it and reuse it. If there’s no concept of reuse, then that’s not going to provide a lot of value or really the knowledge needed to get a habit formed by that individual. So high-frequency use cases really are key to gaining traction. And where do you find those? So I know that age verification is something that’s been talked about quite a lot. I think there’s a lot of interesting stuff going on by legislators and regulators globally. Typically, that’s pretty high frequency because whether it’s content online or restricted purchases, alcohol, that type of thing, typically those are things that a single individual would do frequently. So that is certainly a really interesting use case. It’s something that we have begun moving forward with in Australia, where the regulations are changing, and of course we see that globally. Other forms of use cases that offer frequency that maybe are a little bit less obvious include university life.
Sarah Clark: One of our core use cases and strategies in Brazil is we have the next generation of digitally active, financially active young adults coming up through university. We have universities that need to have an online and offline contiguous knowledge of your digital identity. Everything from logging into student portals to checking in for exams. I think you’d be shocked at how much fraud there is with respect to even things like if you’re a medical student sitting in on a key exam. which is critical for you to get your medical degree, which should be critical for all of us to know that our doctor has that degree. There is fraud in that type of thing. So university life, a variety of use cases within that, and then you can kind of expand that circle out to other use cases for that demographic. Another example is simply within the same relying party, not just looking at identity verification or digital identity as a tool for onboarding, but rather to look at it as a tool across multiple use cases within that same relying party.
Sarah Clark: So, for example, a digital financial services company or a crypto company. One of the biggest fraud vectors is with respect to mule accounts. So if you onboard somebody using a great digital identity verification process, but that isn’t contiguous with ongoing authentication, whether it be for step-up or just for continued login, you are leaving a gap open for a mule account to kind of come in and disrupt that individual and your product with fraud. So more and more, we’re seeing single entities that are saying, Aha, this is a great technology. I get a full stack of identity technology. It’s reusable. It’s easier. Biometrics, and it can plug these holes where I was maybe using fragmented and non-contiguous approaches. So multiple use cases within a single relying party, high-frequency use cases for the individual, certainly a big part of our strategy and things that we have gone live with. On the flip side, you also have high assurance use cases where the diligence that’s required to onboard to a reusable ID, by definition, should be very, very high.
Sarah Clark: We don’t want an ecosystem where we’re enabling a future of reuse if those IDs aren’t the strongest possible in the world. A clear use for those are for things that require a high level of assurance. One of the use cases that we’re active with is wireless. In Australia, we have the second largest wireless provider that is using our reusable ID to onboard into new wireless accounts. That’s helping with fraud that all wireless providers have. This can also unlock the ability for an entity such as a wireless carrier, such as a bank, to become identity providers themselves. So, high assurance use case scale company who also says, Aha, I also want to provide more services to my customers. I want to be at the center of growing digital experiences. I can solve a fraud issue. I can solve a multi-use case issue. And through this, I can also allow my app to become an identity provider itself, getting more engagement, getting more touch points with that customer. So those are some of the strategies that we’ve used across wireless, across banking, crypto, universities, and age assurance.
Riley Hughes: That’s really a great answer. I think there’s several patterns that you articulated there. I think there’s an interesting kind of dichotomy between the high frequency use cases, which is, you know, really interesting for an obvious reason that a consumer gets a habit of using something like this, versus the low frequency use cases, which are often higher assurance, which is actually where, you know, if you’re going to go through a bunch of onboarding or an issuance process that requires really good due diligence, it’s most applicable to those high assurance use cases. But it’s interesting, that dual-pronged approach that you’ve described, as well as the multiple use cases within the relying parties. I think that’s something that’s really underexplored as well, and that’s a really good insight.
Sarah Clark: Yeah, and I guess one other aspect that I would toss in there is online, in-person, cross-channel, multi-channel. An unlocking mechanism to more experiences is being able to cross those different barriers consistently and effectively. And a lot of companies have their own silos of data, not necessarily a continuous way to do that effectively. Even stuff like purchasing something online, curbside pickup, crossing those digital channels or digital and in-person. There’s a lot there. And when we really get this reusable ID thing right, it is going to expand the addressable market for identity in a lot of ways. It’s really exciting.
Riley Hughes: You’ve done a really good job articulating the value proposition for the identity providers and the relying parties, as well as the individuals. But I’m curious where the rubber meets the road and some user goes to a wireless carrier or to a crypto exchange or something and wants to obtain some service, but they need to have their identity verified first, and they don’t already have a reusable ID. That seems to be a spot that’s really important where there’s a lot of friction. And I think what we’ve seen is some approaches which sort of redirect users out to an app store to download an app, etc., versus other ones that try to keep the experience inside of the app but require a document scan and a selfie or something like that. I mean, there’s lots of different kinds of approaches here, and I’m curious what approach you’ve taken or what you’ve seen work, you know, at that moment where the rubber meets the road and a user is getting onboarded into their reusable ID for the first time.
Sarah Clark: That is one of the biggest objections that we come across when it comes to onboarding relying parties. And I guess first I would say that is one of the opportunities that, as ID Network, we see as really important and a role that we play is how do we help bring together individual choice along with meeting the need of a relying party that they’re not going to have a NASCAR sort of screen of different identity providers that somebody could use. So that is, I think, one important thing that we’ve been really focused on. But in the— early days, even that doesn’t solve the fundamental problem that somebody needs to onboard in order to be able to share their reusable ID effectively. So the structure that we’ve been using is we do use and require an app, and we have been looking at different ways to make it so that a relying party can put the option on only if it’s detected that an individual has a qualifying app. So that helps alleviate some of the concern.
Sarah Clark: But it still could be the case that somebody would have the app and still need to onboard either to have a reusable ID or to have sufficient evidence to meet the needs of that relying party. So depending on the business they’re in, the level of assurance they need, they may or may not require sort of an assurance level that even if the person has a reusable ID, they don’t currently meet. That is something that I don’t have a solution for that meets the wants, I guess, of all relying parties. But I will just say that if somebody’s onboarding into your service and they need to do a doc scan, they need to go through a diligent process, doing that in the context of an app where they then share the data is really almost the same as doing it within the relying party site itself. And one of the big benefits that I think deserves more focus and is something that is beginning to receive more focus is the liability of data. So, as you know, a relying party in any industry, my core business might be enabling, let’s say, car sharing or a wireless service.
Sarah Clark: My core product and my core specialty is not the handling of identity data. And given data privacy regulations, given data breaches, I may not even want to be sort of entering that realm for myself and my business. You do not need my driver’s license generally in order to run your relying party business. So there are also benefits to using a service that uses individual ownership, consent, and minimize data sharing that are becoming increasingly important. So I personally believe this sort of tension between doing it on the relying party site and doing it into another app will start to dissipate as more and more proof points about user experience are proven out, and we’re beginning to get those types of quantified results. And as data privacy regulations finds the kind of liability of having personal data continue to rise in terms of importance to avoid by relying parties, and also the importance to individuals as they become more educated on the topic.
Riley Hughes: This has been a really fascinating discussion. There’s lots of stuff I want to get to, but I think one more thread I want to pull and just get your take on is there are several decentralized identity approaches out there that bring an economic incentive element into the picture. When I worked at the Sovrin Foundation in the early days, I worked on the Sovrin token. Sovereign never ended up doing a token, but we were sort of looking at that, and the goal of it would be to essentially allow, you know, some value exchange to happen between the relying party and the attestation provider or identity provider or issuer to both incentivize issuers to get on board, as well as to offer privacy-preserving payment mechanism in a decentralized way. One interesting thing about Mastercard is you’ve got the ID network, you’ve got the payment network. I wonder, have you thought about how these bridge, or maybe if you can’t speak to it in the context of Mastercard, just in general, what is your take when you see some of these approaches in the market?
Riley Hughes: How do you think reusable ID and kind of the economics of reusability will play out?
Sarah Clark: So that is somewhat our business model, where a verifier or a relying party, you know, similar to the kind of one-and-done paradigm that we’re in today, they pay for a verification, and that money flows back to the identity provider. That is the business model that we’re live with and that we’ve adopted. But I think beyond that, incentivizing the identity companies of today to participate in the evolution to the future, to me that is one of the kind of unlocking keys to how the ecosystem is developing and should develop. So what do I mean by that? If a relying party is using an identity verification provider to onboard folks into their ecosystem, and that exists today, there is no reason that that shouldn’t have the ability to then flow into a reusable ID framework and for an economic exchange to happen at that point. So we’ve been experimenting with a lot of these different types of business models, and I think that the sort of gist of it is that this future is coming.
Sarah Clark: So if you’re participating in identity, the time is now to be looking at your strategy and how to become part of a reusable ecosystem, and whether that be enabling reusable ID as an option next to sort of one-and-done identity verification, or whether that be that identity verifications that meet the standards required to offer that individual an upgrade to a reusable ID. There are a lot of sort of sub-business models that we’re experimenting with, that I see others in the industry experimenting with, and for me that’s just part of how do we evolve what we have today to create a bigger addressable market for all parties while also coming together to To create the future.
Riley Hughes: Yeah, I love that. You mentioned the time is now. Why is the time now? What is different now that wasn’t present five years ago, where reusable identity is now possible where it wasn’t before? Or maybe similarly, you know, if we fast forward five years and look backwards, what is it that we will say about 2023 that was the reason why this was the timing that will sort of change the industry?
Sarah Clark: Well, I think there’s a perfect storm of tailwinds that, you know, have been forming for some time that are just coming together really rapidly now. So I don’t know that it wasn’t possible necessarily in the past, but the past focus for many of us that have been in the identity industry have been creating essentially point solutions. And I know there’s integrated identity platforms and kind of a coalescing of multiple point solutions into one, of course, but essentially developing technologies just to keep digital moving forward. So there’s been like a lot of great work with a lot of great solutions, biometrics, some of the doc scanning stuff, many of the signals, et cetera. But why the time is now for this transformation to, in earnest, be taking place? I see a number of factors. So one is government investment in digital IDs, digital driver’s licenses, mobile driver’s licenses. There’s been a lot of work put in, certainly over the decade that I’ve been involved in the industry. Mobile driver’s licenses in the U.S. have been sort of percolating for a number of years.
Sarah Clark: They are becoming real. And that is something that’s happening globally. Governments have the same issue that everybody else has, which is how do you enable digital services securely for your citizens? So we’re starting to see those finally come online. In some cases at scale. And that is the sort of base form of a reusable ID. People are beginning to understand it. And what we see through the work that we’ve done and through the work I’ve done is governments want their citizens to be able to scale their use of these government credentials. But for the most part, governments don’t want to try to own the whole thing. Maybe SingPass in Singapore is a bit of an exception, but generally they want to focus on government services and find other routes to enable their citizens to use these for other things. So that sort of base form of digital ID coming online to me is a huge driver and a huge opportunity for those that are working in the space to enable that and embrace that. Another is simply identity fraud.
Sarah Clark: The times when fraud was a write-off just to be kind of absorbed and sort of brushed to the side really are over. Fraudsters are innovators, and it’s important to keep up. And again, fragmentation, point solutions, they don’t lend themselves to solving for identity fraud. AI, of course, is another just whole set of challenges in that equation. How can I tell that you, Riley, are a carbon-based life form? I need a strong way for you to be able to unlock your identity wallet, the key exchange, etc. So these types of technologies are becoming very, very important to fight the tidal wave of identity fraud that just keeps coming. And I think we know so much more today than we did 10 years ago about data breaches, just this cycle that we’re in where data creates fraud. We need a way out. And if you really look at sort of a well-formed digital ID ecosystem, it is logically the only way out of this fraud situation that we’re in. Another, I think, is just the need to expand digital user experiences. And there’s only so much that can be done with the current framework that’s in place.
Sarah Clark: So again, reusable ID, the ability to cross channels is part of that. And the last thing I’ll point to, again, is data privacy. All related, of course, to data breaches, identity fraud, etc. But regulations, legislation globally, that’s really looking at data privacy and sort of the recognition that trust powers digital, identity powers trust. Businesses, again, want to focus on their core products. They need trust, they need identity, but how do you kind of tap into that in a way that protects your business in regards to data privacy, satisfying the regulations and legislation that’s happening globally? All of these things are coming together. And then on top of that, of course, and something that you very well know, the ratification by the W3C of DIDs, of verifiable credentials. A lot of extremely smart people have been working on this for a long time. Time. So we have technology that’s pretty thought through, although still nascent, but coming into market.
Sarah Clark: And we have government legislation, regulation when it comes to data privacy, the emergence of digital IDs by governments globally. When you swirl that all in with a need for better user experiences and rising identity fraud, you know, boom, the industry needs to bring in kind of the next wave of solution to satisfy all of that.
Riley Hughes: Yeah, that makes sense. It’s a lot of factors kind of converging together and creating almost the perfect storm. One thing that you kind of alluded to earlier, but wasn’t on your list necessarily, was the sort of bringing some of the legacy or more traditional identity verification, or, you know, identity infrastructure companies along to the reusable ID paradigm. It feels like almost, you know, a few years ago, it was like all of the big document verification companies and all of the big identity verification companies are all kind of looking at everybody else and just waiting to see if anyone was going to do anything. They’re all staring at each other, not wanting to be the first one to move. And then all of a sudden you see a few dominoes start to fall. You know, you see Onfido acquiring Airside and making a big push for reusable identity. You see Plaid and their both acquisition of- Cognito, which is then followed by their reusable ID offering alongside that across the Plaid network. You know, you see other companies that have entered the space as well.
Riley Hughes: I wonder if you’re in the CEO seat at one of these identity verification companies, you know, how are you thinking about this opportunity? On the one hand, it could be viewed as a bit of a threat or a bit of an opportunity, depending on maybe how you see it. If you’re in that seat, how do you navigate this, do you think?
Sarah Clark: Yeah, I mean, absolutely. It’s both a threat and an opportunity. So the doc verification providers, you know, scan physical documents in order to support a better method of identity proofing online. And given the fact that governments are moving towards digital credentials, that will over time wane and be replaced by digital credentials. We certainly already see that, you know, using Australia as an example again, one of the largest states has 90 percent of their population that are actively using digital driver’s licenses. They come into a location that’s using doc scanning to capture your physical ID, and they say, Well, I only have it on my phone. So that’s beginning to already be the case in lots of the world. You look at Brazil, they have the RG card that’s being replaced by a digital version of that. So for someone whose business is about identity proofing, and identity proofing generally requires certain types of evidence to be presented in order to get the level of assurance needed for a regulated use case, among others, anything that requires high assurance.
Sarah Clark: The addressable market of physical document scanning is declining. Granted, it hasn’t declined that much yet, but it’s coming. That threat needs to be turned into an opportunity, and the opportunity, of course, is to participate in some form in this evolution. So that has been something that we at Mastercard have been looking to partner with different identity companies already in the space. Those providers certainly are folks that we would see as really strong partners, as kind of a personal participant or leader in the space. I certainly think that that is a huge opportunity if done right. But again, it’s will the future be certain sort of closed-loop offerings that end up being equally fragmented as the ecosystem we have today, or will there be a bigger sort of consortium that forms in the market? I believe the latter has to happen, otherwise you end up, again going back to that objection by relying parties, I don’t want a NASCAR page of different logos. So how does industry and the different players come together effectively?
Sarah Clark: I don’t think anybody has the perfect solution for that yet. Clearly, we have Apple, we have Google, we have those with wallets looking to expand an identity in the U.S. We have the banks with pays embarking on a wallet. It’s just a matter of time before that has identity. You know, that’s kind of happening everywhere. How do we tie that together so that there’s consistency and also adoption on the relying party side? That’s a big segment of the problem that we’ve been focused on. And how do you tie that together with governance that works across these different players? I think that the industry still needs to shake out. A lot of this still needs to form. But certainly, it’s just logical that being able to reuse a digital ID is the future. And I think it’s really important that innovators start innovating, testing, learning, participating early. So I’ve been really happy to see the shift. And you’re right. I mean, in the last 12 months, it’s been really interesting to see the repositioning that’s happening in the industry. And I think it’s a great thing.
Sarah Clark: Still a lot to learn, still a lot of ground to cover, but another clear Point of evidence of the market forces coalescing.
Riley Hughes: Yeah, it seems like the market is just, for those kinds of solutions, has just gotten really crowded recently, in the sense that, you know, a few years ago, I go to one of these companies and you see fintech, crypto, compliance use cases everywhere, and now you go to these companies and it’s like online dating sites. They’re trying to, I think, maybe expand by targeting different segments or different use cases, though what ends up happening is that a lot of the companies that have a low bar for fraud or a high bar for compliance are willing to accept greater amount of friction to meet those bars. But then once you start moving into other verticals, you start running up against lower willingness to accept friction. I think that maybe one of the key ways that these identity verification companies can expand into the other verticals is by making their identities reusable so that the friction on the part of the user is so much less that their identities that have been verified now can be used in more places, right?
Riley Hughes: And as you’ve alluded to, it just expands the pie and makes it that much bigger. That’s how I am sort of thinking it might go. One thing that you mentioned was just in Australia, the mobile ID, the digitally native government ID. It’s really interesting to me to think about how this might look to have these two solutions in parallel. So on the one hand, 90% penetration of a digital ID, you know, I want to understand what does that experience look like for a user when they have a digitally native ID and they’re sort of going through one of these flows. But then I also imagine 90%, you know, there’s still a large portion of the population then, 10%, could be hundreds of thousands of people who don’t have this and who still need a way to get through and get access to the services they need. And so I wonder if you could speak to how you’ve solved this and, like, how do these two things sit in parallel, side by side, and enable a smooth user experience?
Sarah Clark: Well, I don’t know that I would say that it’s solved. How these things come together, I think, is very much still being thought through and solved with pilots, different sort of approaches happening in different parts of the world. But I think that for the future, are you going to use your state app to hold your identity wallet to broadly use throughout the rest of the digital ecosystem? Probably not when you think about a future where it’s not just about your driver’s license; it’s about other credentials you might have in your wallet, etc. So what I hope to see happen is that governments embrace a role of being a credential provider, which can then be fed into a wallet, which can then be augmented with other things about you. And we’re already seeing that in the U.S. with what Apple has started to do with onboarding state mobile driver’s licenses into their wallet. Now, will different identity wallet providers want to handle kind of the governance aspect of it? How important will that be?
Sarah Clark: I think there’s still a lot of ground to be covered and a lot of questions as the ecosystem shakes out. But you’re bringing up an important topic of inclusion. So we saw that, you know, in the U.S. with the states, with unemployment, certain people weren’t able to get through biometric processes. They were using a vendor that provided part of the service, but couldn’t service everyone. So where does that kind of fall? And there could be two processes, as you say, that can be supported side by side. Maybe you have an old document, and that should still be supported until those roll off being valid by the issuing authority or the state or government where you’re a citizen of. These are all things that a good ecosystem understands and can bring together. So I think inclusion is important, but I don’t think that progress necessarily needs to stop for every single inclusion use case either. Because when you’re looking at fraud and some of the problems that we’re trying to solve, one of the main objectives is also to prevent sort of wide-scale attacks and things such as that.
Sarah Clark: So inclusion is important, but it shouldn’t be the end-all be-all to progress in terms of moving forward with solutions that can be augmented over time to include everyone.
Riley Hughes: I agree. We want to solve problems, and we need to be able to move fast to solve the problems that we need to solve today, even if it means some other things need to come tomorrow. As long as that roadmap exists, I think that that makes a lot of sense. I want to shift into talking briefly about relying parties. We’ve touched on them and some of their objections and some of the challenges with getting them involved. I’ve often felt like if I am in the shoes of a relying party and kind of looking at this market, Apple and Google are going to be high on my list of things to be thinking about because the penetration and the potential power that they have. I know that in the new version of iOS, Apple is enabling in-person verification of things like age from your mobile driver’s license. Google is doing a similar thing with verifiable credentials. Both companies also have pretty high bar for their openness. So you need to sort of go to Apple and get verified and get a developer key in order to verify people, for example.
Riley Hughes: Or with Google, if you want to issue something into the Google Wallet, you need to go to Google and get vetted first, right? And so there’s a sort of what can be perceived as a closedness to those ecosystems. But what could also be perceived as a high bar of, you know, safety as well. I wonder if, again, five years from now, if we’re looking back and we see that a more open ecosystem has emerged, why do you think that that will be? Why do you think it will be that an open ecosystem will win? Or maybe asking another way, how could an open ecosystem win when compared to these players that have so, so much penetration?
Sarah Clark: That’s sort of a million-dollar question. One thing that is important is regulations and the direction that that’s going in. So when I think about open ecosystems winning, it’s really interesting to me the work that the EU is doing on the topic. We really haven’t touched on that at all with the EU identity wallet, eIDAS 2. We know the EU has led data privacy, is leading data privacy with GDPR. So I think what they’re doing is definitely something to watch and could sort of support that or not in the end, depending on how that shakes out. Another thing that I would point out is when you’re thinking about this from a U.S.-centric point of view, Apple is a dominant, dominant player. When you look at this from the point of view of the world as a big place, that’s not necessarily the case quite as much.
Sarah Clark: And also when you’re kind of just looking at the problem set to sort of enable digital IDs from different sources for different use cases, the liability construct that might need to be there in some cases, there’s a lot of ground to cover that two players essentially in the market may or may not be willing to, nor kind of want to cover. So I do think that there are a lot of questions about how this is all going to shake out, and the concept of having your wallet sort of embedded with your mobile OS, you know, clearly this is a huge factor in how the ecosystem shakes out. But I do think there’s a lot of other things sort of at play when it comes to strategy, regulations, and covering the world and doing it in a way that makes sense.
Riley Hughes: Awesome. Well, is there anything, Sarah, that you wanted to touch on or wanted to cover or any other threads you’d want to pull on?
Sarah Clark: I guess just looking back, or sort of stepping up, I should say, and looking at identity as just a field to be in, you know, I think we’ve covered quite a lot and, you know, a lot of questions. have just more questions and not straightforward answers in terms of where this is all evolving. But I think that I love the way that community is coming together. And for me, there isn’t a better place to be right now for folks that sort of want to work on the bleeding edge of tech, given the fact that trust is important for everything and identity is at the heart of trust, and just the convergence of standards, beginnings of adoption, innovation, new technologies, biometrics, like, and these sort of quote-unquote fight against AI. I think it’s just a really exciting place to be. Personally, I am a fan of Web3. I mean, that’s another use case we’ve been active in, by the way. It’s like, where are the early adopters, and how are all these things converging?
Sarah Clark: Personally, I’m a big believer in sort of the convergence of digital identity, Web3, and just sort of shifting the paradigm of the internet and digital in general to embrace decentralization, individual ownership, ownership over creative works, you know, you name it. We’re powering NFT for real estate investing as part of what we’re doing in digital identity. So I just think it’s really exciting times. And sometimes when I have these conversations, I feel like I have more questions for question than answers, but that’s what makes all of this really exciting.
Riley Hughes: Yeah, that was really good. I appreciate that. Startups are a roller coaster, right? And it’s like sort of, you know, sometimes you’re on the high end of the roller coaster, other times you’re at the sort of trough, and, you know, next time I’m in the trough, I’ll go play that back and remind myself what a cool place it is that we are here in digital identity world.
Sarah Clark: Yeah, I mean, it’s one of the few things that impacts literally every human on Earth. So—
Riley Hughes: Absolutely. Very impactful field.
Sarah Clark: Yeah.
Riley Hughes: Yeah, absolutely. Well, this has been a blast. I’ve loved this conversation. I think we could have had a conversation twice as long and still had plenty more to cover. But I always like to close by just asking our guests, what does the future of identity look like? Can you paint a picture of what your vision is for how identity looks in 5, 10, 20 years from now?
Sarah Clark: As I was saying, I personally am a big believer in decentralization and the pairing of identity and Web3 concepts. I’m not sure if that’s feasible in five or ten years, but I think logically that’s where digital needs to go. I like that vision of the future a lot, and I like the experimentation that’s happening between digital identity, NFTs, digital currencies. So I truly believe that will be the future, but I believe more kind of imminently. I know that there’s times, I guess, controversy about the use of biometrics and that type of thing. I think that considering the rise of AI fraud tactics that are becoming much more sophisticated, that where it’s going is your biometric and your pairing to a carbon-based life form paired with sort of public-private key infrastructure that’s been codified into standards. That is where the future is going. So it’s exciting to be part of it.
Riley Hughes: Yeah, I look forward to working more with you and everyone else out there on the vision of the future. Awesome. Well, thanks a lot, Sarah. You are a carbon-based life form that has lots of interesting things to say and that I always enjoy talking to. So I appreciate you taking the time. Do you have anything to plug? Do you have anything going on or, you know, if people want to learn more or get in touch, how should they do that?
Sarah Clark: Well, I’m on LinkedIn. So the best way to get in touch with me is through LinkedIn, sarah.clark@mastercard.com. I don’t have anything in particular to plug, but feel free to reach out.
Riley Hughes: Okay. Well, thanks for listening. You can find us on YouTube, Apple, Spotify, and wherever else you listen to podcasts. Feel free to reach out on Twitter at Trinsic underscore ID or to me directly at Riley P Hughes, and visit Trinsic if you’re interested in building the ID tech products of the future. Subscribe to get new episodes as they drop. And thank you very much, Sarah, for coming.
Sarah Clark: You’re very welcome. Thank you for having me.

Zack Jones
Director of Product Partnerships @ Trinsic
Zack Jones leads the product partnerships at Trinsic that together form the connections that make up the world’s largest identity acceptance network. Zack is a published author, expert on digital IDs, and passionate about entrepreneurship.
Newsletter
Subscribe to weekly insights and updates in the digital ID ecosystem.
