News

Why Digital ID Programmes Stall: The Identity Resolution Problem

Moca Network
September 1, 2026

Identity resolution is the task of determining that records held in different systems refer to the same person. The United Kingdom's National Audit Office has published a lessons-learned review of the country's digital identity work, following the cancellation of the central national scheme. Its finding is not about the credential, the wallet or the technology used to prove who someone is. It is about what sits underneath: public services use multiple, unreconciled identifiers for the same individual, including National Insurance numbers, NHS numbers and Unique Taxpayer References.

The credential was never the hard part.

Key takeaways

  • The review concludes that digital identity remains important despite the central scheme's cancellation, and that it can be built on existing foundations.
  • The binding constraint is record linkage: matching a verified identity against records held across departments with inconsistent data standards and legacy systems.
  • Multiple parallel identifiers mean there is no single key on which to join a person's records.
  • Without interoperable data standards, future identity initiatives will struggle with adoption and operational efficiency, regardless of how good the front-end credential is.
  • The same failure mode appears in large private organisations, usually under a different name.

Three layers, and the one that gets funded

Any identity system has three layers. Programmes reliably fund the first, underestimate the second, and discover the third too late.

LayerQuestion it answersTypical state
CredentialHow does a person prove who they are?Well funded, visible, politically attractive
VerificationHow does a service check that proof?Reasonably well understood
ResolutionWhich records in our systems belong to this person?Assumed to be solved; usually is not

A wallet that produces a cryptographically flawless proof of identity delivers nothing if the receiving department cannot then determine which of four candidate records is the right one. The user experiences this as "the system doesn't know who I am" and does not care which layer failed.

Why parallel identifiers persist

Fragmented identifiers are not an oversight. They are the accumulated result of each service solving its own problem at the time it had it.

A tax identifier is issued for tax purposes, under tax law, with a tax definition of a person. A health identifier is issued for clinical care, where the definition of a person, the tolerance for duplicates and the consequences of a mismatch are all different. A social insurance number carries employment history. None was designed as a universal key, because none needed to be.

Merging them is not a data-migration exercise. It requires deciding whose definition of a person wins, which creates losers among the systems that must change, and raises legitimate concerns about linking records that were deliberately kept separate.

That last point deserves weight. Some separation is a feature. A health record and a tax record being hard to join is, in certain respects, a privacy protection rather than a defect.

The resolution problem outside government

Any organisation past a certain size has the same structure with different labels: a CRM record, a billing account, a support ticket identity, a loyalty membership, a marketing profile. Each was created by a different team to answer a different question. Deduplication projects are perennially underfunded and perennially reopened.

The symptoms are familiar. A customer who has verified identity once is asked to verify again in a different channel, because the second channel cannot tell it is the same person. Fraud controls under-perform because the signals are split across profiles that never join. Data subject access requests take weeks because nobody can enumerate where a person appears.

What actually reduces the problem

A verified identity assertion as the join key. When a person presents a credential that cryptographically proves they are the same individual who was verified before, that assertion can serve as the linkage signal rather than fuzzy matching on name, date of birth and address. It does not require merging the underlying systems.

Attribute-level verification instead of record merging. Many questions that appear to need a unified record do not. Confirming that a person is over 18, resident in a jurisdiction, or the same unique human who registered previously are attribute checks. They can be answered without joining every system that holds data about them.

Standards before scale. The review's core recommendation is that interoperable data standards precede rollout. Programmes that reverse the order spend their budget on reconciliation.

AIR Identity is designed around the second point. A verification performed once becomes a reusable credential the individual holds, and services confirm the specific attribute they need through a zero-knowledge proof. Uniqueness can be established without a central register linking every record, which addresses the resolution problem without creating the linkage risk that makes it politically difficult. We looked at the wider issue of centralised versus distributed models in centralised vs decentralised identity.

For organisations where the resolution failure is commercially expensive — repeat verification costs in user acquisition, or split audience profiles in publisher monetisation — treating it as an identity problem rather than a data-cleaning problem tends to be the cheaper route.

Frequently asked questions

What is identity resolution?

Identity resolution is the process of determining that records held in different systems refer to the same person. It is distinct from identity verification, which establishes that a person is who they claim to be. A system can verify someone perfectly and still fail to resolve which of its own records belong to them.

Why do governments use multiple identifiers for the same person?

Each identifier was created by a different service, under different legislation, at a different time, with a definition of a person suited to that service's purpose. Tax, health and social insurance identifiers were never designed to be interoperable, because none was intended as a universal key.

Does cancelling a national digital ID scheme end the need for digital identity?

No. The audit finding was that digital identity remains important and can be built on existing foundations. What changes is the delivery model: incremental improvement of standards and record linkage rather than a single central programme.

What is record linkage and why is it difficult?

Record linkage is joining data about the same individual across systems. It is difficult when there is no shared key, when data standards differ between systems, when records contain errors or outdated details, and when legal or privacy constraints restrict which datasets may be joined.

Can verifiable credentials solve the identity resolution problem?

They address a significant part of it. A credential proving that the presenter is the same verified individual as before gives a reliable linkage signal without merging underlying systems. It does not resolve historical duplicate records already in a database, which still requires remediation.

Related reading

More from AIR: AIR Identity, verified user acquisition, or browse the full AIR blog.

Paying repeatedly to verify the same person? See how AIR Identity makes one verification reusable across services, or read the developer documentation.

Stay updated on AIR launches
Product updates, partner launches, and research across digital identity, fintech, and loyalty. Unsubscribe anytime.
By subscribing, you agree to our Privacy Policy and consent to receive updates.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
In this article
Blog

Read more articles

Lorem ipsum dolor sit amet, consectetur adipiscing elit.
View all
News
Central KYC Registry vs Reusable Credentials: Two Models
India's central KYC registry lets firms fetch verified customer data with consent, cutting onboarding 50-70%. One of two architectures for reusable KYC.
News
Retroactive Age Verification: The Existing-Account Problem
Brazil bars new under-15 accounts from 1 September and requires existing ones verified or deactivated by January. The second deadline is the hard one.
News
The Federal Single Sign-On Mandate: What M-26-18 Requires
OMB has finalised a two-year deadline for US civilian agencies to move public-facing websites onto one federal sign-on service. The milestones start at 60 days.