TL;DR: Physical IDs expose full identity data, are hard to revoke when lost, and can be misused without visibility or accountability, according to Yoti. The governance shift is toward selective disclosure, consent, and device-bound verification, not broader data collection.
NHIMG editorial — based on content published by Yoti: physical ID risks and why digital alternatives are being positioned as a safer option
By the numbers:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, with 46% confirmed and 26% suspected.
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes, and as quickly as 9 minutes in some cases.
Questions worth separating out
Q: What breaks when organisations rely on one-time identity checks?
A: One-time checks break when the identity can keep acting after the original trust decision is no longer valid.
Q: Why do physical IDs create more identity risk than digital credentials?
A: Physical IDs expose multiple personal attributes at once, cannot be selectively revoked, and often leave no trace of who copied or reused them.
Q: What do identity teams get wrong about proofing with documents?
A: Teams often confuse document possession with trustworthy identity proof.
Practitioner guidance
- Minimise document collection at the point of verification Replace full-ID capture with the smallest proof that satisfies the business need, such as age over threshold or residency confirmation.
- Adopt selective disclosure wherever the use case allows Use digital identity flows that reveal only the required attribute, then document the business reason for any exception that still requires full-document review.
- Bind high-assurance credentials to the user device Prefer workflows that couple presentation to a controlled device and a local user verification step, so copied or photographed credentials are not enough to complete the transaction.
What's in the full article
Yoti's full article covers the practical detail this post intentionally leaves for the source:
- How Yoti frames the day-to-day user experience of Digital ID setup and presentation.
- The specific privacy controls Yoti says are built into its mobile Digital ID flow.
- The article's own examples of where physical IDs create friction in age checks, access checks, and online verification.
- The consumer-facing explanation of consent, device binding, and data visibility in Yoti's model.
👉 Read Yoti's analysis of physical ID risks and digital identity alternatives →
Physical ID risk and digital credentials: what should identity teams do?
Explore further
Physical ID risk is an identity governance problem, not just a convenience issue. The core failure is over-disclosure. When a verifier demands the whole document to prove a single attribute, the organisation collects more data than the transaction requires and inherits avoidable privacy and fraud exposure. That pattern belongs squarely in identity governance, because the control objective is proportional verification, not just successful checking. Practitioners should treat this as a boundary-setting problem across human identity programmes.
A question worth separating out:
Q: Who is accountable when a business over-collects identity data during verification?
A: Accountability sits with the organisation that designs and operates the verification flow, not just the individual presenting the ID. If a process captures more data than the transaction requires, stores it without purpose limitation, or fails to control access, that is a governance failure as much as a privacy one.
👉 Read our full editorial: Physical ID risk is pushing identity checks toward digital credentials