TL;DR: Digital IDs moved from pilot projects into everyday use in 2025 as regulation tightened, privacy expectations rose, and orchestration became necessary across multiple identity methods, according to Yoti. The shift shows that trust, interoperability, and selective disclosure now shape identity strategy as much as compliance does.
NHIMG editorial — based on content published by Yoti: 2025 year-end reflection on digital IDs, regulation, trust, and Verified Calls
By the numbers:
- In 2025, Yoti passed 1 billion age checks globally, reflecting how widely trusted age assurance is now relied on across regulated industries.
- March 2025 marked Yoti reaching its first EBITDA-profitable month, driven by continued revenue growth and wider adoption of its products.
Questions worth separating out
Q: How should organisations govern reusable digital identity across multiple services?
A: Treat reusable digital identity as a governed trust decision, not a convenience feature.
Q: Why does selective disclosure matter for IAM and identity verification programmes?
A: Selective disclosure matters because it lets services verify only the claim they need, instead of collecting a full identity record.
Q: How can identity teams decide when orchestration is necessary?
A: Use orchestration when multiple certified identity methods, regional rules, or fallback options must be presented through one consistent policy layer.
Practitioner guidance
- Define minimum-claim verification policies Map each use case to the smallest attribute set needed, such as age over 18 rather than full identity document capture.
- Treat orchestration as a governed control plane Assign explicit ownership for provider routing, fallback logic, assurance thresholds, and audit logging so the orchestration layer does not become an unmanaged trust decision point.
- Extend assurance into live interactions Add identity proofing or liveness checks to high-risk calls, onboarding sessions, and sensitive transactions where impersonation could change a business decision.
What's in the full article
Yoti's full post covers the operational detail this post intentionally leaves for the source:
- The full year-in-review narrative behind the profitability milestone and what drove wider product adoption.
- Examples of how orchestration is being used to support multiple certified identity methods across markets.
- The product and policy context behind Verified Calls and why live-interaction assurance became a focus.
- The company’s own view of how regulation changed buyer expectations for privacy-first identity checks.
👉 Read Yoti's 2025 year-in-review on digital IDs, regulation, and trust →
Digital IDs in 2025: what changed for identity teams?
Explore further
Digital ID adoption is no longer a pilot problem, it is a governance problem. Once reusable identity moves into everyday use, the question changes from whether the technology works to whether organisations can govern reuse, retention, and assurance across contexts. That is a lifecycle issue as much as a verification issue, because the same identity proof may be consumed by multiple services with different risk profiles. Practitioners should treat digital ID adoption as an identity governance programme, not a point-solution rollout.
A few things that frame the scale:
- 43% of security professionals are concerned about AI systems learning and reproducing sensitive information patterns from codebases, according to The State of Secrets in AppSec.
- Only 44% of developers are reported to follow security best practices for secrets management, exposing a significant developer behaviour gap.
A question worth separating out:
Q: Who is accountable when digital identity data is stored or shared incorrectly?
A: Accountability should sit with both the issuer and the provider that handles the data, because each controls a different part of the trust chain. Governance teams should assign ownership for proofing, storage, disclosure, and revocation separately so failures can be traced and corrected.
👉 Read our full editorial: Digital IDs moved into mainstream use in 2025