No ID card. You can still prove who you are in seconds.
Someone opening an account or starting a new job still has to show who they are. So does anyone confirming they are old enough to buy a restricted product. The government has stepped back from a single national identity credential held on a central database. The way you prove identity in the UK without a national ID card has not changed, because that capability never lived in the database. It sits in a certified market of providers a person reaches from the phone in their pocket, usually in a few seconds.
For the individual, the experience is a tap. There is no long form to fill in and no wait for a manual review. The check clears and the account opens.
For the business asking, the same moment decides whether a good customer finishes signing up or gives up at the point of proof. Verification is where regulated onboarding tends to lose people, so how a person proves who they are is a commercial question as much as a compliance one.
On 15 January 2026 the government confirmed that a government-issued digital ID would no longer be mandatory to hold. What that removed was a single design: one state credential sitting on a central database. The duty to check identity and age for regulated activity stayed exactly where it was.
Public concern had centred on that design. The petition against digital ID cards reached nearly three million signatures. The objection was to a universal identifier and a state-held record, and the act of proving who you are was never its target. The certified market is built the other way around, with no central register that a person has to join.
Businesses carry the duty to check every day. A lender confirming a borrower. An operator confirming a customer is over eighteen. Neither obligation depended on the national scheme, and neither ended with it.
As at the Office for Digital Identities and Attributes 2026 Annual Report, the public register listed 46 registered providers offering 64 certified services across identity, attribute, orchestration, holder and component roles. Each is certified under the government’s Digital Verification Services Trust Framework and listed on the public GOV.UK register.
The register sits on a statutory footing under Part 2 of the Data (Use and Access) Act 2025. The Office for Digital Identities and Attributes, inside the Department for Science, Innovation and Technology, maintains the framework and the register. The framework moved to version 1.0, published on 9 June 2026 and coming into force on 1 September 2026, once conformity assessment bodies are accredited by the UK Accreditation Service.
The practical effect for a business is that certification is checkable. You can look up a provider on a government register before you trust it with a customer check, rather than take a vendor’s word for its standing.
The register covers more than one kind of check because businesses need more than one answer. One business needs to know who a customer is to a defined standard before opening an account. Another only needs to confirm a single attribute, such as being over a given age. Other services sit behind the scenes, connecting a business to whichever data source can answer the question in the moment.
That spread is why the register lists roles across identity, attribute, orchestration, holder and component services. A business picks the service that matches the question it has to answer, rather than buying one heavy check for every situation. The person being verified only ever shares what that particular check requires.
A firm that only needs to confirm a customer is over eighteen can pick an attribute service that returns a yes or no on age, and nothing more. A firm opening a regulated account picks a fuller identity check instead. The same public register serves both, and the person on the other side shares only what each check calls for. That is the practical shape of proving identity without a national ID card, many kinds of check with one place to find a certified provider for each.
The reason this works without a central database is in how the checking happens. A person is asked only to confirm one fact, and a source that already holds the relevant information confirms it directly.
Proving you are over eighteen is the simplest case. A source that already holds your date of birth can confirm you are above the age threshold without passing the date itself on. The business asking receives a clear yes. Your date of birth stays where it sits, and so does the rest of your record. The check creates no new central register, and no single identifier that follows you between services. You decide which fact to share, and who receives it.
Behind that single tap, a provider can draw on more than one source and fall back to another if the first cannot answer, so the person is not dropped at the first obstacle. What they see is one screen and a result, usually in a few seconds. There is no long form, and no wait for someone to review it by hand.
For the person on the other side of a counter or a sign-up screen, that is the difference between a few seconds and a stalled application. The check happens in the flow of signing up, and the application goes through.
OneID is one of the certified providers on that register. In the past year, 13 million people used OneID to prove something about themselves. Certified under the government’s Digital Verification Services Trust Framework and listed on the public GOV.UK register, it is one example of the certified route working at scale, alongside the other providers on the register.
The point holds whichever certified provider a business picks. The capability to prove identity is spread across a live, regulated market, and a company chooses the provider that fits the check it needs to run.
On 26 February 2026, HM Treasury and DSIT published guidance confirming that certified, registered digital identity services can satisfy the identity-verification requirement in Regulation 28 of the Money Laundering Regulations. The regulated firm remains responsible for its risk assessment, customer due diligence and overall AML compliance. The certified provider handles the identity step to a defined standard, and the firm keeps the judgement that surrounds it. In practice a compliance team can point to a named, certified service on a government register as the basis for the check, and keep its audit trail intact.
That position is in force now. A firm in scope can route the identity check through a certified provider and rely on it for that step, while owning the rest of its compliance. The obligation is unchanged. It is now met through a provider whose standing is published on a government register.
The wider numbers put the scale of it beyond a pilot. The 2026 Digital Identity Sectoral Analysis, as reported in the OfDIA 2026 Annual Report, estimated the UK digital identity sector at 275 firms, about £2,027 million in annual revenue and an estimated 9,624 full-time equivalents.
A market that size does not depend on any one credential or any one scheme. It is a working supply of verification that regulated businesses already buy, and it kept running while the national scheme was debated and pared back.
For a company that needs to verify identity or age, the steps are short.
The option to prove identity in the UK without a national ID card is available today. It sits on the public GOV.UK register, on a statutory footing under the Data (Use and Access) Act 2025, and works for millions of people from their phones. The task now is choosing the right certified provider and giving the person on the other side of the check a few seconds instead of a form.
The database is gone. The need to prove who you are is not.
For the person opening a betting account or applying for a loan this week, nothing about the sign-up scr...
KYC, explained: how to verify who your customers are without losing the good ones