TL;DR: Government digital ID policy and liveness assurance are maturing as Yoti reports 62% revenue growth to £29.0 million in 2025, more than 1 billion age checks over seven years, and a Digital ID wallet download surge to 5.55 million globally, according to Yoti. The governance issue is no longer just adoption, but whether identity proofing, age assurance, and verified credentials can be trusted at scale.
At a glance
What this is: This is a Yoti commentary on record revenue, digital ID wallet growth, and advances in liveness and facial age estimation, with the strongest finding being that identity assurance is moving from pilot use into broader policy and operational adoption.
Why it matters: It matters because IAM, verification, and fraud teams need to understand how proofing, wallet adoption, and presentation-attack resistance change the control environment for human identity programmes.
By the numbers:
- Revenues grew 62% in 2025 to £29.0 million, up from £17.9 million in 2024.
- Global downloads increased from 1.62 million in 2024 to 5.55 million in 2025.
- Yoti says the average distance between the eye pupils is around 120 pixels when it captures selfies for facial age estimation.
👉 Read Yoti's analysis of digital ID growth, liveness, and age assurance
Context
Digital identity assurance now sits at the intersection of identity verification, age assurance, and wallet-based credential presentation. As more government and private-sector ID systems compete for adoption, the operational question for IAM teams is not whether identity will move into wallets, but which assurance models will hold up when scaled across consumers, regulated checks, and high-friction use cases.
This article is primarily about the commercial and policy momentum behind digital ID, plus the technical maturity of liveness checks and facial age estimation. For practitioners, the governance issue is how to decide which proofing signals are strong enough to support trust decisions, and where a wallet, a selfie-based liveness check, or a facial age check should sit in the identity lifecycle.
The UK digital identity debate makes the issue even more concrete because policy direction can materially change adoption patterns. That makes this a human identity governance story first, with downstream effects on verification programmes, fraud controls, and the role of certified credentials.
Key questions
Q: How should organisations set trust thresholds for digital ID and age assurance?
A: Start by mapping each use case to a risk tier, then define the minimum evidence needed for that tier. Low-risk journeys may tolerate wallet presentation or model-based age checks, while regulated or high-value flows may need stronger proofing, re-authentication, or document-backed assurance. The key is to make the threshold explicit, testable, and owned by the identity programme.
Q: When should facial age estimation be used instead of document verification?
A: Use facial age estimation when the business problem is fast eligibility screening and the risk appetite supports probabilistic decision-making. Use document verification when the legal, regulatory, or fraud risk requires stronger evidence of identity or age. Many programmes will need both, with the model handling low-friction gating and document checks reserved for higher-risk or exception paths.
Q: What do healthcare teams get wrong about digital identity wallets?
A: They often treat wallets as a front-end convenience layer instead of a new trust model. The real work is in issuance quality, revocation handling, verifier policy, and minimum necessary disclosure. Without those controls, a wallet just moves the same governance problems into a different form.
Q: How do IAM and fraud teams work better together on identity proofing?
A: They need shared policy for evidence quality, risk scoring and escalation. IAM controls decide what access is granted, while fraud controls surface suspicious patterns before or after issuance. When those teams operate separately, weak proofing can look compliant even while fraud risk is increasing.
Technical breakdown
Why liveness checks matter for identity proofing
Liveness checks are designed to distinguish a real person from a spoofing attempt such as a photo, mask, replay, or synthetic presentation. In practical identity systems, they sit inside proofing and step-up verification flows, where the goal is to reduce account takeover and fake enrolment risk without making every interaction friction-heavy. The technical point is that liveness is not identity by itself. It is a control that raises confidence in the subject behind the camera. When the model is weak, attackers can still pass verification with presentation attacks or bot-assisted capture. Strong liveness improves trust, but only within the wider assurance stack.
Practical implication: treat liveness as one signal in the proofing chain, not as proof of identity on its own.
Facial age estimation as an assurance control
Facial age estimation is a probabilistic model that estimates age from a face image, usually to determine whether a person falls above or below a policy threshold. The model does not verify legal identity, and it does not replace document-based checks where regulation or risk demands stronger evidence. Its value is operational: it can support age-gated access at scale when the business need is to make a fast, low-friction eligibility decision. Accuracy depends on image quality, face size in frame, demographic variation, and calibration against the use case. That is why vendor performance claims must be evaluated against independent testing and your own acceptance criteria.
Practical implication: validate age estimation against your policy threshold, error tolerance, and demographic risk before relying on it.
Digital ID wallets change the trust boundary
Digital ID wallets move identity evidence from a central login event into a user-controlled credential container. That changes the trust boundary because the organisation is no longer only authenticating a person, it is also deciding whether to accept a credential presentation, a wallet issuer, and a verification flow that may span multiple parties. In governance terms, this introduces questions about credential provenance, assurance inheritance, revocation, and re-authentication. Wallet adoption is therefore not just a product story. It is a shift in how identity assurance is packaged, delegated, and consumed across human identity journeys.
Practical implication: map wallet-based flows to your assurance policy so issuer trust, re-authentication, and revocation are explicit.
NHI Mgmt Group analysis
Digital ID adoption is becoming a human identity governance issue, not just a UX issue. Once wallet-based credentials and government-backed identity apps reach mainstream use, IAM teams have to govern multiple assurance sources rather than a single login path. That changes verification policy, recovery design, and trust decisions across onboarding and step-up journeys. The practitioner conclusion is that digital ID strategy now belongs inside identity governance, not outside it.
Age assurance is a policy control, not a point feature. The article’s liveness and age-estimation discussion shows that businesses are trying to translate image-based signals into regulated access decisions. That means error tolerance, appeal paths, and evidence thresholds matter as much as model performance. The practitioner conclusion is that age assurance must be governed as part of a formal decision policy.
High-assurance verification still depends on independent validation. Yoti’s references to iBeta and NIST matter because they show the difference between self-asserted capability and independently tested performance. For identity teams, that distinction is critical when controls are used to support fraud prevention, age gating, or verification at scale. The practitioner conclusion is to anchor trust decisions in external validation rather than marketing claims.
Digital ID wallet growth creates a credential lifecycle problem as much as an adoption problem. Wallets are only useful if issuers, verifiers, and relying parties can manage provenance, reuse, revocation, and re-authentication coherently. That makes lifecycle governance central to the model, especially when citizens may carry multiple credentials across government and private-sector ecosystems. The practitioner conclusion is to treat wallet governance as an identity lifecycle discipline, not a distribution channel.
Identity assurance standards are converging, but policy maturity is lagging implementation. The combination of government digital ID discussion, verified credentials, and model benchmarking points to a market that is moving faster than many organisations’ governance design. The practical implication is that teams need clearer rules for when to trust self-asserted, wallet-presented, or model-derived evidence across the identity journey.
From our research:
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
- For lifecycle context, see Ultimate Guide to NHIs , Lifecycle Processes for Managing NHIs.
What this signals
Digital ID teams should expect policy pressure to move faster than organisational control maturity. If identity proofing is being pushed into wallets and age checks, the programme needs explicit decisions on issuer trust, revocation, and fallback paths before adoption scales beyond a pilot population.
Identity evidence debt: the longer organisations rely on loosely governed verification signals, the harder it becomes to explain why one check was accepted and another rejected. That debt shows up in audit, customer support, and fraud disputes, and it grows when teams cannot point to a single policy owner.
For practitioners, the practical signal is whether verification, IAM, and fraud controls are converging on one evidence model. If they are not, the organisation will struggle to turn digital ID growth into durable governance.
For practitioners
- Define assurance tiers for digital ID use cases Separate low-risk, mid-risk, and regulated identity journeys so teams know when wallet presentation, document checks, or stronger verification is required. Tie each tier to a named policy owner and a documented acceptance threshold.
- Validate liveness and age-estimation controls independently Require test evidence that matches your own environment, thresholds, and demographic profile rather than relying on published claims alone. Include failure handling for spoofing attempts, borderline ages, and exceptions that require manual review.
- Map wallet trust to lifecycle governance Document how credentials are issued, re-authenticated, refreshed, and revoked across government and private-sector wallets. If a credential can be reused across journeys, define where assurance is inherited and where it must be re-established.
- Align fraud and IAM teams on evidence thresholds Set common rules for what constitutes sufficient evidence for onboarding, age checks, and account recovery so security, fraud, and product teams are not making conflicting trust decisions.
Key takeaways
- Digital ID wallet growth is now a governance problem as much as an adoption story, because trust has to be defined across issuers, verifiers, and re-authentication flows.
- Independent validation matters because liveness and facial age estimation are only useful when their measured performance matches the organisation’s own risk thresholds and decision policy.
- Identity teams should translate wallet-based proofing into lifecycle and assurance rules before scale makes the operating model harder to change.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the technical controls, while GDPR define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | SP 800-63A | Digital identity proofing and identity verification are central to this article. |
| NIST CSF 2.0 | PR.AC-1 | The article centers on access and trust decisions in identity journeys. |
| NIST Zero Trust (SP 800-207) | Wallet-based identity changes trust boundaries and re-authentication assumptions. | |
| NIST SP 800-53 Rev 5 | IA-2 | Identity proofing and authentication assurance align with identification and authentication controls. |
| GDPR | Art.32 | Age assurance and identity verification can involve personal data processing and security duties. |
Review whether biometric and identity processing meets security, minimisation, and accountability obligations.
Key terms
- Liveness Detection: Liveness detection is the mechanism that checks whether a biometric sample comes from a real, present person rather than a spoof such as a photo, screen, or mask. In identity programmes, it is a core defence against presentation attacks and should be tested under realistic operating conditions.
- Facial Age Estimation: Facial age estimation uses a selfie or live camera image to estimate whether a person is above or below a required age threshold. It is a probabilistic verification method, so its governance depends not only on model accuracy but also on how the image is captured, processed, retained, and disclosed.
- Digital Identity Wallet: A digital identity wallet is software that stores and presents credentials for a person or organisation. It is a portability layer, not an authorization system. The wallet moves verified proof between parties, while the relying party still has to decide whether the proof is sufficient for the requested action.
What's in the full article
Yoti's full post covers the operational detail this post intentionally leaves for the source:
- The full revenue breakdown across 2023, 2024, and 2025, including EBITDA timing and investment allocation.
- The detailed download figures by geography, including UK, France, and the US, plus the adoption context behind each trend.
- The full discussion of UK digital ID policy, UKDIATF, and the potential role of certified private-sector wallets in age assurance and verification.
- The iBeta and NIST benchmarking discussion that supports the liveness and facial age-estimation claims.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org