TGS


How digital verification services can help businesses meet their obligations under the Money Laundering Regulations 

In early 2026 we (DCMS, formerly DSIT) worked with HM Treasury to publish guidance under the Money Laundering Regulations (MLRs). The guidance sets out how certified and registered digital verification services (DVS) that operate in compliance with the UK DVS trust framework (“trust framework”) can be treated as reliable and independent sources of identity verification for MLR-regulated businesses when they need to check customer identities to meet their legal duties , as part of their customer due diligence processes. 

We’ve been asked a range of questions about how this new guidance applies to different kinds of DVS. To respond to those questions, this blog post explains:

what regulated businesses and DVS providers need to know about using a certified and registered DVS to meet their MLR obligations how a certified and registered DVS can also support other business needs how identity checks and “attribute” checks (such as sanctions screening) are different, and how both can be useful for businesses regulated by the MLRs Identity checks must align to GPG 45 “level of confidence”

Certified and registered DVS must provide an identity check that meets a “level of confidence” as set out in Good Practice Guide 45 (GPG 45). This might be low, medium, high or very high and it indicates how sure the DVS is that the customer is who they say they are. Certified and registered DVS must express identity verification outcomes using GPG 45 levels of confidence because this is required by the trust framework.

Regulated businesses must do a risk assessment when dealing with each of their customers and select the level of assurance that is commensurate with the risks identified. This ensures businesses that are subject to the MLRs decide what level of confidence is right for each customer.

This may affect many existing services that MLR-regulated businesses currently use. It’s important for DVS providers that want to be compliant with the guidance to understand how to avoid producing identity checks that fall short of a GPG 45 level of confidence.

DVS providers seeking certification must ensure their identity verification processes meet the requirements of GPG 45 and the trust framework. Identity outcomes and other attribute data must be handled separately. Separating identity verification from other checks can help providers clearly demonstrate the level of confidence achieved by their identity process, while continuing to offer additional information that supports other business needs.

DVS can provide additional data alongside a level of confidence

Alongside the GPG 45 identity check, a DVS check may return extra data. This could include things like address information or whether the individual is a Politically Exposed Person (PEP) or a sanctions target. We call these pieces of information “attributes”, and they may be useful to meet other business needs.

Where a DVS provides both identity and attribute information, it must clearly distinguish the GPG 45 identity check outcome from the attributes. The MLRs guidance relates specifically to the use of certified and registered DVS for identity verification. As a result, only the identity verification outcome needs to meet GPG 45 requirements. Attributes are not part of the identity check itself and are not covered by the MLRs guidance.

DVS that share attributes must be certified as attribute service providers (ASPs), which means they have been assessed against the attributes guidance. This includes binding attributes to an identity before they are shared.

If a certified ASP does not create, store or share attributes in line with the attributes guidance, it is not compliant with the trust framework requirements.

If a DVS is certified as an identity service provider (IDSP) but not an ASP, the attributes it creates and shares as part of a GPG 45-compliant identity check fall within its certified IDSP service. However, any other attributes it creates or shares fall outside the scope of its IDSP certification and are not covered by the attributes guidance.

DVS must ensure it clearly communicates to relying parties about which attributes form part of its certified service and which do not. Failure to provide this transparency may result in the loss of certification and registration.

Only certified and registered DVS can be relied upon under the MLRs guidance for identity verification

Specifically, for customers who are individuals, entities can fulfil their obligations under Regulation 28 of the Money Laundering Regulations by verifying a customer’s identity using certified and registered DVS.

There is no obligation to source attributes from certified and registered DVS but it is strongly recommended.

Being listed on the DVS register is the clearest signal that a DVS provider delivers services that are reliable and independently assured against the trust framework, including any attribute services they are certified for. Over time, we expect the quality gap between certified and non-certified providers to matter more for relying parties such as MLR-regulated businesses.

What we’ll do next

We will continue to work with HM Treasury, sector guidance bodies and industry to keep the guidance clear and practical. As implementation progresses, we will use the OfDIA blog to share further guidance and respond to common questions.

https://enablingdigitalidentity.blog.gov.uk/2026/08/20/how-digital-verification-services-can-help-businesses-meet-their-obligations-under-the-money-laundering-regulations/

seen at 16:30, 20 August in Enabling digital identity.