Learn

What Is the UK Digital Verification Services Trust Framework?

UK employers, recruitment platforms, landlords, property platforms, banks, identity providers, and other organizations increasingly use digital verification to onboard customers, verify workers and tenants, and establish trusted access to services. When one organization relies on the service of another, it needs confidence in how that identity or attribute was created or verified.

The UK Digital Verification Services Trust Framework provides common rules and independent assurance that help organizations evaluate and rely on digital verification services. Grounded in Part 2 of the Data (Use and Access) Act 2025, it defines provider roles, establishes a certification model, is supported by Good Practice Guide (GPG) 44 and GPG 45, and supports a public register of digital verification services.

Version 1.0 of the UK Digital Verification Services Trust Framework came into force on September 2, 2026. A transition period is now underway for services certified against the earlier 0.4 gamma framework, meaning valid 0.4 certifications may continue during the applicable transition period while providers move to version 1.0.

Digital identity checks often involve several organizations, technologies, and sources of information. Without a common framework, a business relying on a digital identity service may have limited visibility into how an identity or attribute was created, checked, protected, or shared.

The UK trust framework creates common requirements and independent assurance for digital verification services. For employers and recruitment platforms, that can support more consistent digital onboarding and Right to Work workflows. Landlords and property platforms can use certified services in supported Right to Rent workflows. Banks and other organizations can use the framework to evaluate digital verification providers, while identity providers use it to understand the requirements their services must meet.

DIATF vs. DVSTF

DIATF stands for the UK Digital Identity and Attributes Trust Framework, the title used for versions of the framework before 1.0. The final 1.0 publication uses the title UK Digital Verification Services Trust Framework (DVSTF). The names refer to the same evolving framework rather than separate programs.

The trust framework defines several service provider roles. Services can be certified for one or more roles, provided those roles align with the service's functions and comply with the framework's rules on role combinations.

  • Identity Service Provider: Checks a user's identity using GPG 45 and other applicable requirements.
  • Attribute Service Provider: Collects, creates, checks, binds, or shares verified information about a user.
  • Holder Service Provider: Allows users to collect, store, manage, and share identity or attribute information, including through a digital wallet or similar service.
  • Orchestration Service Provider: Coordinates interactions among digital verification services and relying parties, routing requests and exchanging verified information.
  • Component Service Provider: Provides specific parts of the identity-checking or authentication process used by another digital verification service.
  • Relying Party: Uses digital identities or attributes provided by a DVS. Relying parties do not need trust framework certification simply to use a certified service, but relevant framework requirements are passed through contractual terms with certified providers.

To become certified under the UK trust framework, a specific digital verification service is assessed against the applicable framework version and, where relevant, supplementary codes. Certification applies to the service and its certified role or roles; it does not automatically certify the provider as a whole.

For buyers, that distinction helps clarify what has actually been assessed. Certification can support confidence in a provider's identity-verification processes, but it does not replace the legal, regulatory, or internal requirements that apply to the relying organization's use case.

The Department for Science, Innovation and Technology (DSIT) owns the certification scheme, while the Office for Digital Identities and Attributes (OfDIA) manages the framework and scheme day to day. UK Accreditation Service (UKAS) accredits conformity assessment bodies (CABs), which independently assess services. The DVS Register gives organizations a public way to identify services that meet the applicable registration requirements.

What Is OfDIA?

The Office for Digital Identities and Attributes (OfDIA) is an office within the Department for Science, Innovation and Technology (DSIT) that manages the DVS trust framework and certification scheme day to day. For buyers, one of its most visible functions is supporting the wider regime around certified and registered digital verification services.

What Is UK CertifID?

UK CertifID is the government trust mark for eligible digital verification services certified against version 1.0 and listed on the statutory DVS Register. OfDIA authorized its first use in September 2026. Use of the mark is optional, and an eligible service must receive OfDIA authorization before displaying it. When shown, the mark is accompanied by a unique six-digit identifier that users can check against the DVS Register.

What Are GPG 44 and GPG 45?

GPG 45 focuses on identity proofing and verification: in plain English, how a service establishes confidence that a person is who they claim to be. GPG 44 focuses on authentication: how a service protects access and determines how strongly a user should authenticate.

These guides provide technical foundations for trust framework certification. Most buyers do not need to master the underlying methodologies, but they should understand that a certified service's identity and authentication processes are assessed against the applicable requirements.

How does the UK Trust Framework relate to KYC and AML?

The UK trust framework establishes rules and independent certification for digital verification services. February 2026 government guidance explains how certified services listed on the DVS register can support identity-verification checks under the Money Laundering Regulations. Organizations remain responsible for their wider customer due diligence and AML obligations.

The process can be understood in three steps:

  1. Define the service and scope: The provider identifies the service, certifiable role or roles, and any supplementary code that applies to a specific use case.
  2. Complete an independent assessment: An appropriately accredited CAB evaluates the service against the relevant trust framework, GPG, and supplementary-code requirements.
  3. Certify and register the service: A CAB can issue a certificate when the requirements are met. Certification and registration are separate, and a certified service can apply to be listed on the statutory DVS Register when the applicable registration requirements are satisfied.

The framework's value becomes clearer when applied to real digital onboarding and identity-checking workflows. Supplementary codes add requirements for specific use cases, including Right to Work, Right to Rent, and DBS identity checks.

UK Trust Framework
↓
Certified Digital Identity Providers
↓
Right to Work | Right to Rent | DBS

 

Right to Work

A Right to Work check is the process an employer uses to confirm that a prospective employee has permission to work in the UK. Where an eligible digital route applies, a certified identity provider can support the identity-verification portion of that workflow.

For example, a recruitment platform can embed a certified digital identity check into candidate onboarding rather than requiring every identity step to be handled manually. The employer then completes the remaining Right to Work requirements that apply to the candidate.

Right to Rent

A Right to Rent check is the process a landlord uses to confirm that a prospective tenant has the required right to rent residential property in England. A certified digital identity service can support identity verification within an applicable digital Right to Rent workflow.

For a property or tenant-onboarding platform, this can make identity verification part of a structured digital journey before the landlord completes the remaining Right to Rent requirements.

DBS Identity Checks

The trust framework also supports certified digital identity services used in DBS identity-checking workflows. This can help recruitment, background-screening, and safeguarding teams establish identity through a consistent digital process before the broader DBS-related workflow continues.

How Do Right to Work and Right to Rent Fit Within the UK Trust Framework?

The trust framework provides the core requirements for certified digital verification services, while supplementary codes add requirements for specific Right to Work and Right to Rent use cases. This gives employers, landlords, and the platforms that support them a defined way to use certified digital identity services within applicable digital checking routes.

Using a certified provider does not transfer responsibility for the overall check. The provider performs identity verification within its certified scope; the employer or landlord remains responsible for meeting the requirements that apply to the final Right to Work or Right to Rent decision.

The current version 1.1 supplementary codes for digital Right to Work and Right to Rent checks came into effect on September 2, 2026, alongside trust framework version 1.0. They align the framework with regulatory changes taking effect on October 1, 2026. From that date, where an employer or landlord uses a digital verification service for an applicable check, the service must be certified and registered against the UK DVS trust framework and the relevant supplementary code for the organization to obtain the applicable statutory excuse.

Services already certified against gamma versions of the framework and supplementary codes may continue under the applicable transition arrangements while moving to the newer requirements. Organizations should therefore check the DVS Register to confirm a service’s current certification, registered status, roles, supplementary codes, and identity profiles.

What Role Does a Certified Identity Provider Play?

A certified identity provider performs identity verification within the scope covered by its certification. That independent assessment can give relying organizations greater confidence in how the service checks identity and can help them build digital onboarding workflows with less reliance on manual identity verification.

Certified services can also support more consistent processes, fraud detection efforts, and operational efficiency across high-volume onboarding. The exact role depends on the provider's certification, the use case, and any applicable supplementary code, so buyers should confirm that the service they select is certified for the role and workflow they need.

Entrust Certification

Entrust IDV, formerly Onfido, is listed on the statutory DVS register with certification against the 0.4 gamma trust framework for the Identity and Component roles. Its registered service includes medium-confidence M1A and high-confidence H2B identity profiles for Right to Work, Right to Rent, and DBS supplementary codes.

Entrust Roles

In its Identity role, Entrust supports the identity-verification (IDV) portion of applicable workflows. In its Component role, Entrust can provide parts of the identity-checking process used within a broader digital verification service. Entrust provides the certified identity-verification component for supported Right to Work and Right to Rent pathways. The employer or landlord remains responsible for completing the overall check and making the final employment or tenancy decision.

Identity Verification vs. Eligibility Determination

Identity verification answers a specific question: Is the person completing the check the person they claim to be? Eligibility determination is a separate question about whether that verified person meets the requirements for a particular outcome.

For Right to Work, Right to Rent, and DBS-related workflows, Entrust supports identity verification within its certified scope. Its verification outcome can inform the wider process, but it does not determine a person's right to work or rent or make a DBS-related suitability decision.

How We Can Help: Entrust's Responsibilities

Entrust combines identity verification, fraud detection, and workflow orchestration to support UK onboarding and identity-checking use cases. Depending on the workflow, Entrust can use document, biometric, and data checks to establish identity at the appropriate confidence level, identify suspicious evidence or behavior, and help organizations configure consistent digital verification processes.

Entrust's certification covers defined identity-verification activities, not the customer's entire compliance process. Organizations should confirm the certification scope, applicable supplementary code, and their own legal or policy obligations when designing a workflow.

Explore KYC for the UK or the Entrust IDV Compliance Suite to learn more about Entrust identity verification for regulated digital services.

Does My Organization Need Trust Framework Certification to Use a Certified Identity Provider?

No. An employer, landlord, bank, or other relying party does not need trust framework certification simply to use digital identities or attributes from a certified service. Certification is relevant to the digital verification service and its certified role or roles.

What Part of a Right to Work, Right to Rent, or DBS Check Can a Certified Identity Provider Support?

Within the scope of its certification, a provider can perform the identity-verification activity required for an applicable workflow. The employer, landlord, or other responsible organization then uses that verified identity within the broader Right to Work, Right to Rent, or DBS process.

Does Trust Framework Certification Replace Right to Work, Right to Rent, DBS, KYC, or Other Legal Requirements?

No. Trust framework certification provides independent assurance that a digital verification service meets the requirements within its certified scope. Organizations using the service remain responsible for the laws, regulatory requirements, contractual obligations, and internal policies that apply to their own use case.

Talk with an Entrust specialist about the UK trust framework, KYC, and identity verification requirements. Contact a Specialist

Talk With a Compliance Specialist

The content shared on this page is for informational and referential reasons only. Please reach out to a business or legal professional for how this data pertains to your business. An Entrust specialist is also available to discuss how our identity security, data security, and issuance solutions can help support your specific business needs.