Linking the record is the part a digital identity cannot skip

Technology and AI

Linking the record is the part a digital identity cannot skip

By Staff Writer  |  3 September 2026

A row of mobile archive shelving units closed together in a corridor, numbered document boxes visible on one open bay

The national digital identity scheme was abandoned in July. The spending watchdog has published its lessons anyway, and the one that will outlast the policy is that proving who somebody is was never the hard part. Matching them to the right record in each service is.

Managing digital identity was published by the National Audit Office on 2 September. It is a lessons learned report rather than an examination of any programme, and it says so in terms: it does not examine or evaluate the performance of any specific programme or organisation. It draws on the office's own earlier work on digital transformation, data and identity, and on evidence from audit bodies in other countries.

The timing is what makes it worth reading. In July 2026 the government announced that it would not proceed with its proposals for digital identity. The office has published the work anyway, on the view that the questions it addresses did not go away with the policy.

The identifier problem

The finding with the longest reach has nothing to do with wallets, credentials or standards. Different public services use different identifiers for the same person: a National Insurance number in one place, a Unique Taxpayer Reference in another, an NHS number in a third. Establishing a trusted identity so that somebody can prove who they are is one problem. Attaching that identity to the correct record inside each service is a second one, and connecting records about the same person across different systems and organisations is a third, made harder by differences in systems, in standards and in data quality.

A person can appear differently in different systems. Until that is addressed it puts a practical ceiling on what any identity layer sitting above those systems can deliver.

What the office says about sequencing

The report's other finding for anyone running a large integration is about order of work. A digital identity is less likely to deliver its intended benefits where the technology is built before the objectives, the business processes, the data constraints and the integration challenges are clearly understood and addressed. Implementing at scale across fragmented services is described as a complex integration challenge requiring long timescales, and delivery is said to depend on realistic assumptions about timescales and costs, supported by clear decisions on funding, ownership and accountability.

On take up, the office reports that outside countries with a history of mandatory identity systems, success depends on people finding the thing useful and wanting to use it. That is a finding about behaviour rather than about engineering, and it is the one the head of the office chose to put in his own statement.

Despite government's recent announcement that it will not be going ahead with its digital identity plans, questions about how people can conveniently and securely prove who they are or something about themselves in a digital world remain relevant.

Gareth Davies, head of the National Audit Office

Why this reads across to any large programme

Strip out the subject matter and this is a report about integration risk, and the pattern is familiar to anyone who has watched a programme built on the assumption that the data underneath it is cleaner than it is. The identity layer was the visible part, the part with a launch date and a minister attached. The unglamorous part was reconciling records that were never designed to be reconciled, and the office's judgement is that the second would have constrained the first.

Three questions are left for any future attempt. What the objectives and the delivery model actually are, and how the constraints in legacy systems and fragmented data will be dealt with. Which scenarios come first, and how they are to be funded, delivered and integrated. And how far to build new public capability against how far to rely on private provision inside the existing trust framework.

The report is numbered HC 586 of session 2026-27. The programme it was written for no longer exists. The integration problem it describes is still sitting in the same systems it was sitting in before the announcement.