Home » Digital ID for AML: the rules have just changed -and some firms may not have noticed
Digital ID for AML: the rules have just changed - and some firms may not have noticed
Anne Austin
Director
This article follows on from our March 2025 piece on the Companies House identity verification process, which introduced mandatory IDV for company directors and PSCs under the Economic Crime and Corporate Transparency Act. If you haven’t read that yet, it provides useful context. The developments covered here are related but distinct – and together they represent a significant shift in how identity verification works across the legal sector.
New government guidance published in February 2026 has done something long overdue: it has formally confirmed which digital identity checks count for AML compliance – and which ones don’t. If your firm uses digital ID tools for client onboarding, this affects you directly.
For years, law firms have been using digital identity verification tools as part of their client onboarding and AML processes. The technology has been widely available, actively encouraged by the SRA, and increasingly expected by clients who do not want to post their passport or visit an office to prove who they are.
There has, however, been a persistent problem: whether digital ID checks actually satisfied the requirements of the Money Laundering Regulations (MLRs) was never formally confirmed. Firms were using these tools on the reasonable assumption that they were compliant – but without official guidance to back that up, there was always an element of ambiguity.
On 26 February 2026, that ambiguity was resolved. HM Treasury and the Department for Science, Innovation and Technology (DSIT) published joint guidance that, for the first time, formally establishes how digital identity verification interacts with the MLRs – and what firms need to do to ensure their digital ID processes are genuinely compliant.
The SRA followed up in its March 2026 Update (issue 148), pointing all regulated firms toward the guidance and confirming its status as official guidance for AML compliance purposes.
The headline message is both enabling and cautionary: yes, digital ID can satisfy your MLR obligations, but only if the provider you are using meets the right standard. And a significant number of firms may currently be relying on providers that do not.
What the guidance actually says
The guidance centres on the UK Digital Identity and Attributes Trust Framework – a government-run certification scheme for digital verification service (DVS) providers, now placed on a statutory footing by the Data (Use and Access) Act 2025. Providers that meet the framework’s standards are independently certified and listed on the government’s DVS Register.
The February 2026 guidance makes three things clear:
- Certified and registered DVS providers can be used to fulfil Regulation 28 of the MLRs. This is the regulation governing customer identity verification as part of CDD. For the first time, the government has formally confirmed that digital identity checks — from a qualifying provider — satisfy this obligation.
- Only certified providers meet the standard. The guidance is explicit: digital verification services that are not certified against the trust framework and not on the DVS Register “cannot reliably be deemed suitable for identity verification in compliance with the MLRs.” Using an uncertified provider does not satisfy your AML obligations, regardless of how sophisticated the technology appears.
- The firm’s responsibility does not transfer to the provider. Using a certified DVS does not remove your firm’s regulatory accountability. You remain responsible for customer risk assessments, enhanced due diligence where required, ongoing monitoring, and record-keeping. The DVS handles the identity verification component – everything else remains with you.
Why this matters more than it might first appear
The practical implication of this guidance is that there is now a clear line between compliant and non-compliant digital ID – and that line is the DVS Register.
Before February 2026, a firm using any reputable-looking digital identity tool could argue it was taking a reasonable approach to CDD. That argument is now much harder to sustain. The government has defined what “reliable” means in this context, and it means certified. Firms that cannot point to a DVS-registered provider are, in effect, relying on a tool whose compliance with the MLRs has not been independently verified.
This matters particularly in the context of CQS audits and SRA AML inspections, both of which – as we have covered recently – are increasing in frequency. An auditor reviewing a firm’s AML processes will now have a clear benchmark to apply to digital ID: is the provider on the DVS Register? If not, that is a compliance gap.
The SRA’s own AML report for 2024-25 noted that the regulator conducted 935 AML supervisory engagements in that period – a 72% increase on the previous year – and that conveyancing firms remain among the highest-risk categories. Digital onboarding processes are squarely within scope of what those inspections examine.
The connection to the Companies House IDV changes
If you read our article last year on the new Companies House identity verification process, you will remember that from March 2025, company directors and persons with significant control (PSCs) are required to verify their identity either through GOV.UK One Login or via an Authorised Corporate Service Provider (ACSP).
The February 2026 guidance adds an important layer to that picture. It confirms that certified digital identity services can also be used to verify the identity of company directors for MLR purposes – not just for the Companies House requirement. This means that for firms acting as ACSPs, or for those onboarding corporate clients and needing to verify the directors behind them, the same DVS-certified provider could potentially satisfy both obligations simultaneously.
In other words, the Companies House IDV regime and the AML/CDD digital ID framework are now explicitly connected through the shared infrastructure of the trust framework and DVS Register. Firms that have already invested in compliant digital onboarding for the Companies House changes are well-placed, provided their provider is DVS-certified. Those using separate, uncertified tools for AML purposes may find themselves with a gap they did not know existed.
What the DVS Register and trust framework actually involve
The trust framework sets the technical and governance standards that a digital verification service must meet to be certified. This includes:
- The quantity and quality of identity evidence collected (for example, whether the check uses a passport chip, biometric matching, or relies solely on document images)
- How that evidence is authenticated and cross-referenced against authoritative data sources
- The anti-impersonation measures in place — for example, whether a liveness check is performed to confirm the person presenting the identity is real and present
- The level of identity assurance the service can achieve, from low to very high, as defined in Good Practice Guide 45 (GPG 45)
Certified providers are independently assessed by conformity assessment bodies overseen by the UK Accreditation Service (UKAS), and they can be removed from the register if they fall out of compliance. The framework is technology-agnostic – it sets the outcomes required, not the specific tools used.
Importantly, a provider can be certified for specific use cases – for example, right-to-work checks – or for specific levels of identity assurance. Firms should check not just that their provider is on the register, but that the certification covers the use case they are relying on it for.
A new “CertifID” trust mark is being introduced in 2026 to make this easier to identify. Providers carrying the mark will have been certified against the framework and will be subject to ongoing oversight. This should make it more straightforward for firms and auditors to assess whether a provider meets the standard at a glance.
What firms should do now
The guidance gives regulated firms a clear direction of travel, and the steps to align with it are not complex – but they do need to be taken actively. The following checklist is a sensible starting point:
- Check whether your current digital ID provider is on the DVS Register. The register is publicly available at gov.uk. If your provider is not listed, that is a compliance gap that needs to be addressed before your next audit or inspection.
- Check what the provider’s certification covers. Being on the register is necessary but not sufficient. Confirm that the certification applies to the identity verification use case you are relying on it for, and at an appropriate level of assurance for your client risk profile.
- Update your AML policies and procedures. Your firm’s AML documentation should explicitly reference the use of certified digital identity services and confirm that your provider meets the DVS standard. This is what an auditor will be looking for.
- Train your team. Staff involved in client onboarding need to understand what digital ID checks can and cannot do under the new framework. Using a certified DVS for identity verification is not a substitute for assessing client risk, applying enhanced due diligence where appropriate, or completing source of funds checks. These obligations remain entirely with the firm.
- Review your record-keeping. The guidance reinforces the obligation to retain copies of identity documents and CDD information for at least five years from the end of a business relationship or transaction. This applies regardless of whether verification was carried out digitally or manually.
- If you act as an ACSP, consider the combined opportunity. If your firm is registered as an Authorised Corporate Service Provider under the Companies House regime, a DVS-certified provider could allow you to meet both the Companies House IDV obligation and your AML CDD obligations through a single, consistent onboarding journey. This is worth exploring with your provider and your compliance team.
The bigger picture
The February 2026 guidance is part of a broader, ongoing shift in the regulatory treatment of digital identity. The Data (Use and Access) Act 2025 placed the trust framework on a statutory footing. The DVS Register moved from a manually maintained spreadsheet to a proper GOV.UK service in April 2025. A new version 1.0 of the framework is expected later in 2026, at which point the CertifID trust mark will be introduced. And further draft AML regulations are expected to be laid before Parliament in 2026, which are anticipated to strengthen the CDD framework further.
The direction of travel is clear: digital identity is moving from an optional convenience to an expected part of a well-functioning compliance framework – but on the regulator’s terms, not the technology market’s. Firms that get ahead of this shift, by ensuring their digital ID processes are built on certified foundations, will be in a strong position. Those that don’t may find the gap increasingly hard to explain when an auditor asks.
In summary
The February 2026 guidance and SRA Update 148 together mark an important moment. Digital ID is now formally part of the AML compliance framework for law firms – but only when done right. The three things to take away are:
- Only DVS-certified providers satisfy the MLR standard for digital identity verification. If your provider is not on the register, it does not count.
- Your AML obligations do not transfer to the provider. Risk assessment, enhanced due diligence, ongoing monitoring and record-keeping remain entirely your responsibility.
- This connects directly to the Companies House IDV changes. Certified digital identity tools can satisfy both regimes — but only if implemented correctly.
If you are unsure whether your current digital ID processes are aligned with the new framework, now is the right time to find out – before an auditor does it for you.