TL;DR: UK age-assurance demand is driving a sharp rise in digital ID app downloads, while certified orchestration, reusable credentials and NIST-ranked facial age estimation are reshaping identity verification flows, according to Yoti. The governance issue is not just adoption, but how age checks, assurance levels and privacy-preserving identity sharing scale without inflating identity risk.
NHIMG editorial — based on content published by Yoti: Digital ID app downloads rise as UK age assurance scales
Questions worth separating out
Q: How should organisations govern reusable digital identity across multiple services?
A: Treat reusable digital identity as a governed trust decision, not a convenience feature.
Q: Why do age assurance and identity verification need separate governance models?
A: Because they answer different questions.
Q: What should IAM teams evaluate before adopting an orchestration service provider?
A: Teams should evaluate how the orchestration layer normalises trust, what assurance signals it hides, and which credential types it accepts.
Practitioner guidance
- Define assurance tiers for each use case Map age checks, identity proofing and reusable digital ID acceptance to separate assurance tiers.
- Document trust assumptions for orchestration layers Treat orchestration services as part of the identity control plane and document which issuers, wallets and attribute sources are trusted for each decision.
- Separate privacy controls from fraud controls Write retention and minimisation rules for attribute sharing independently from fraud detection and support handling, so operational convenience does not expand data collection.
What's in the full article
Yoti's full blog covers the operational detail this post intentionally leaves for the source:
- Monthly download and adoption trends by geography, including UK and French wallet uptake.
- NIST ranking details for the latest facial age estimation model and the reported mean absolute error figures.
- The orchestration service provider model under the UK Digital Identity and Attributes Trust Framework.
- Examples of identity and age-check use cases such as right to work, right to rent and DBS checks.
👉 Read Yoti's analysis of digital ID downloads, orchestration and age assurance →
Digital ID app downloads and age assurance: what changes for IAM teams?
Explore further
Reusable digital ID is becoming an identity distribution layer, not just a verification tool. Once credentials are held by individuals and presented to many relying parties, governance shifts from single-use proofing to lifecycle oversight across issuers, wallets and verifiers. That creates a broader trust surface than classic point-in-time identity checks. Practitioners should treat reusable identity as a governed ecosystem, not a standalone feature.
A few things that frame the scale:
- 71% of NHIs are not rotated within recommended time frames, increasing the risk of compromise over time, according to Ultimate Guide to NHIs.
- Only 5.7% of organisations have full visibility into their service accounts, which shows how often identity governance fails before a control can even be enforced.
A question worth separating out:
Q: How should organisations support Digital ID without increasing privacy risk?
A: Start by removing unnecessary data collection from the verification flow. Use selective disclosure for claims that can be proven without full identity exposure, and make retention, caching, and downstream sharing explicit governance decisions. If the system cannot prove less while revealing less, it is not solving the trust problem it creates.
👉 Read our full editorial: Digital ID app downloads rise as UK age assurance scales