TL;DR: Reusable, privacy-preserving KYC credentials across Ethereum, Arbitrum, Avalanche, Polygon and Base are being introduced through SumSub’s partnership with Chainlink, letting users prove claims on-chain without exposing raw personal data while supporting permissioned access and reusable identity across wallets. The bigger issue is that on-chain identity is becoming a governance layer, not just a verification step.
Editorial analysis by NHI Mgmt Group, based on content published by SumSub: “Sumsub Partners With Chainlink to Power Cross-Chain Identity for On-Chain Compliance”.
Key questions
Q: How should security teams govern reusable identity credentials across blockchains?
A: Security teams should treat reusable identity credentials as governed assets with explicit issuance, binding, revocation, and re-authorisation rules.
Q: Why do privacy-preserving KYC credentials still need strong lifecycle controls?
A: Privacy-preserving KYC reduces what is exposed, but it does not remove the need to control how long a claim remains valid, who can rely on it, or when it must be withdrawn.
Q: What breaks when wallet ownership is not bound to a reusable identity claim?
A: The same credential can be replayed through another wallet, which weakens accountability and can let one verified identity be trusted in the wrong context.
Practitioner guidance
- Define claim acceptance boundaries Specify which chains, wallets, assets, and user populations can accept a reusable KYC credential, and document where a fresh verification step is still required.
- Bind credentials to wallet control Require explicit proof of wallet ownership and record how that binding will be revalidated if the wallet changes or the user adds another wallet.
- Separate verification from authorisation Map each downstream access decision to the exact claim it depends on, then keep compliance proof and entitlement logic under different governance owners.
Bottom line: Reusable KYC credentials shift the governance problem from one-time identity proofing to ongoing control of claim reuse.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Privacy-preserving KYC is becoming an identity governance layer, not a verification feature. The article shows that compliance is no longer just about checking a user once and moving on. When the same verified claim can be reused across wallets and chains, the real question becomes who governs that claim over time. Practitioners should stop treating on-chain KYC as a front-end control and start treating it as a lifecycle-controlled identity asset.
A few things that frame the scale:
- 93% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to Ultimate Guide to NHIs.
- 71% of NHIs are not rotated within recommended time frames, increasing the risk of compromise over time.
A question worth separating out:
Q: What should IAM teams ask before approving cross-chain identity use cases?
A: IAM teams should ask who issues the claim, where the credential is stored, how it is revoked, which protocols trust it, and how revalidation works when access moves to a new wallet or chain. If those answers are unclear, the use case is not ready for production governance.
👉 Read our full editorial: Privacy-preserving KYC credentials across chains raise new IAM questions
Cross-chain KYC is becoming an identity authority layer, not just a verification step. When a verified claim can follow a user across wallets and blockchains, the control surface changes from onboarding to ongoing trust assignment. That means the programme now has to govern assertion reuse, not just proof of identity. Practitioners should treat reusable credentials as a new IAM boundary that needs explicit policy.
A question worth separating out:
Q: How do organisations separate KYC verification from on-chain authorisation?
A: By assigning different owners, controls, and decision rules to each step. KYC verifies who the user is or what they are eligible for. Authorisation decides whether that claim is sufficient for a specific asset, protocol, or workflow. If the two are merged, compliance proof is likely to be overtrusted.
👉 Read our full editorial: Privacy-preserving KYC credentials across chains raise new IAM questions