Join our Newsletter — 33% off our NHI Course

Digital Identity Workflow

A digital identity workflow is the sequence of steps used to verify, approve, or authenticate someone in an online service. In charity settings, it often includes consent collection, identity proofing, referee checks, or login controls, depending on the risk and the type of participant involved.

What a digital identity workflow actually does

A digital identity workflow is not just a login screen. It is the ordered path a person moves through so a service can decide whether to accept, trust, or continue authenticating them based on the service’s own risk and assurance needs.

That workflow may be lightweight for low-risk access and much stricter for higher-risk use cases. In practice, it can combine enrollment, proofing, consent, approval, step-up verification, and ongoing access checks into one control sequence rather than treating identity as a single event.

Where digital identity workflows are used

These workflows appear anywhere a service needs to balance convenience with trust. Public sector portals, financial onboarding, healthcare access, charity platforms, and internal enterprise applications all use different versions of the same pattern, depending on who the participant is and what they are allowed to do.

For example, one workflow may accept an email link and password, while another requires document checks, referee validation, or a stronger identity standard before access is granted. That difference is the point: the workflow should fit the trust requirement, not force every user through the same process.

When workflows support reusable identity credentials or wallet-based identity, they also become part of broader digital identity infrastructure. The European framework for digital identity wallets is a useful reference point for how identity verification and cross-border trust can be structured at scale, including through eIDAS 2.0, the EU Digital Identity Framework.

The security controls inside the workflow

A digital identity workflow is defined by its control points. Identity proofing establishes whether the claimed person is real enough for the service’s risk level. Authentication proves they are the same person on return visits. Approval steps, consent capture, and referee checks add governance where the service needs human review or policy validation.

Those controls are often separate for a reason. A service may trust a proofed identity for account creation, but still require a stronger authenticator for sensitive actions. Likewise, a workflow can combine proofing and login without making them the same control, because one answers “who is this?” and the other answers “should access continue?”

This distinction matters because weaker identity steps can be acceptable in low-risk contexts but dangerous when reused for higher-risk access. Identity proofing and remote verification methods need to be chosen deliberately, especially when the workflow is being used to establish trust for future transactions. Identity Proofing and KYC Guide is a natural companion for understanding those assurance choices.

Why workflow design affects trust and assurance

The quality of a digital identity workflow shapes the confidence a service can place in the resulting identity record. A workflow that is too loose can admit fraud, synthetic identities, or impersonation. A workflow that is too strict can block legitimate users, increase abandonment, and create operational friction.

Good workflow design therefore starts with the decision the service is trying to make. Is it only trying to authenticate an existing user, or is it onboarding a new person whose identity must be established, approved, and possibly rechecked over time? The answer determines the level of evidence, the number of checkpoints, and the amount of review needed.

For organizations that manage these journeys at scale, the workflow should also connect to identity governance and lifecycle control so approvals, exceptions, and access changes remain visible over time. Identity Security Programme Guide helps place the workflow inside a broader operating model rather than treating it as a one-off onboarding task.

Risk and Threat Considerations

Digital identity workflows are attractive targets because they sit at the point where trust is granted. If proofing is weak, attackers can create fraudulent accounts, hijack enrollment, or slip synthetic identities into the system. If authentication is weak, an attacker may reuse stolen credentials or bypass step-up checks to reach protected services.

Failure mechanism: The workflow fails when its assurance step does not match the real risk of the action being granted, or when one step is treated as sufficient for every later use of the identity.

Impact: The result can be unauthorized access, fraudulent enrollment, account takeover, compliance failure, and loss of trust in the service’s identity records.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-63 IA-12 — Identity Proofing Digital identity workflows often depend on proofing assurance before authentication.
IA-5 — Authenticator Management The workflow includes login controls and authenticator handling for online access.
Recommendation — Use identity proofing requirements to match the workflow's assurance level to the risk of the service. Manage authenticators so the workflow's authentication step remains strong across enrollment and login.
NIST SP 800-53 Rev 5 IA-2 — Identification and Authentication (Organizational Users) Workflows for online services commonly need explicit user identification and authentication controls.
Recommendation — Apply organizational-user identification and authentication controls to the workflow's access step.
ISO/IEC 27001:2022 A.5.16 — Identity management Digital identity workflows are part of identity governance and controlled access operations.
A.5.17 — Authentication information Workflow steps rely on credentials and other authentication information to prove access.
Recommendation — Define identity management responsibilities for each step in the workflow. Protect authentication information throughout the workflow and during any credential handling.

Practitioner Guidance

Governance implication: Set the workflow to the risk of the service action, not the convenience of the user journey. Low-risk access can justify a lighter path, but higher-risk onboarding or sensitive transactions need stronger proofing, clearer approval logic, and a distinct reauthentication model.

What to watch for: Watch for workflows that overload one control, such as using a simple login to stand in for identity proofing, or relying on one-time approval without tying the result back to lifecycle governance. That is usually where assurance decays fastest.