The main failure is evidentiary, not just operational. Without a certified process, landlords and agents may struggle to prove that the check met UKDIATF expectations, which weakens the statutory excuse and leaves the organisation exposed when a decision is challenged.
Why a certified digital identity process changes the legal outcome
Right to Rent is not just about whether a document was seen. The certified process matters because it creates a defensible trail showing that identity was checked against an approved trust framework, with the right evidence captured at the right point in the workflow. That is what turns a routine screening step into something an organisation can rely on later if its decision is challenged.
In practice, the process quality becomes part of the compliance argument. A landlord or letting agent can only lean on the statutory excuse if the check was carried out in a way that can be demonstrated, repeated, and audited. A non-certified route may still surface the same person, but it does not reliably prove the same assurance level or evidential standard.
When the question is framed through digital identity rather than tenancy administration, the issue is assurance, provenance, and record quality. Certified identity checking is designed to reduce dispute over whether the asserted identity, the verification steps, and the resulting decision are trustworthy enough for legal reliance.
What fails when the check cannot be evidenced
The first failure is that the organisation may be unable to show that the check met the expected standard of assurance. That matters because the defence depends on more than an internal belief that “we checked someone.” It depends on being able to prove the process, the timing, the outcome, and the basis for the decision.
The second failure is operational consistency. Without a certified process, different staff or agents may apply different thresholds, keep incomplete records, or rely on screenshots and informal notes that do not stand up well when reviewed after the fact. The result is a weaker audit trail and a higher chance that the organisation cannot reconstruct what happened.
The third failure is governance drift. Once checks are done through ad hoc methods, it becomes harder to standardise evidence retention, exception handling, and oversight across branches, contractors, or software tools. That is why identity proofing guidance and digital trust frameworks are often discussed together with Digital Identity, eID and Identity Wallets Guide, which explains how certified digital identity flows are meant to support reusable, verifiable evidence.
What practitioners should verify before relying on the result
What matters most is not whether the process felt robust, but whether it can be demonstrated. The check should produce evidence that ties the person, the verification method, and the time of the decision together in a way that is reviewable later. If that chain is broken, the organisation should assume the statutory excuse is vulnerable.
Practitioners should also verify whether the process used approved identity assurance methods rather than a generic onboarding or screening tool. For this kind of control, the evidence standard is the control. A system that cannot show the verification steps, the trust source, and the record of completion is a weak basis for legal reliance.
This is why identity assurance and verification methods are treated as a distinct discipline, not just a user-experience problem. The relevant control objective is captured well in the Identity Proofing and KYC Guide, which focuses on assurance levels, document checks, and the integrity of the verification path.
Risk and Threat Considerations
When a Right to Rent check is not done through a certified digital identity process, the organisation is exposed to challenge rather than just delay. The practical risk is that an otherwise plausible check may not satisfy the evidential standard needed to defend the decision, especially if the record is incomplete, inconsistent, or hard to reproduce.
Failure mechanism: The organisation relies on a verification workflow that cannot demonstrate approved assurance, retention, and traceability, so the check may fail when tested after the fact.
Impact: The statutory excuse becomes weaker, the organisation has less protection in a dispute, and it may face avoidable compliance and remediation effort.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | IAL — Identity Assurance Level | Digital identity assurance underpins whether the Right to Rent check is evidentially trustworthy. |
| Recommendation — Use the appropriate assurance level to confirm the identity proofing strength behind the check. | ||
| ISO/IEC 27001:2022 | A.5.16 — Identity management | The check depends on governed identity processes and recorded evidence for later challenge. |
| A.5.33 — Protection of records | The statutory excuse depends on keeping records that can prove the check was performed correctly. | |
| Recommendation — Define and operate a controlled identity verification process with retained evidence. Retain verification records so the check can be evidenced during dispute or audit. | ||
| NIST CSF 2.0 | PR.AA-05 — Identity management, authentication, and access control | The process must prove who was verified and how the decision was authenticated. |
| GV.OV-01 — Oversight of cybersecurity and privacy risk management | Certified identity checks require oversight because governance failures weaken legal defensibility. | |
| Recommendation — Ensure identity verification records support a defensible access decision. Monitor whether identity-check processes meet required assurance and evidence standards. | ||
Practitioner Guidance
What to verify: Confirm that the check record shows the approved process, the timestamp, the identity evidence used, and the final decision in a form that can survive later review. If any of those elements is missing, treat the result as evidentially fragile even if the operational check looked correct.
Common mistake: Treating a successful lookup or uploaded document as equivalent to a certified identity check. For this use case, the supporting evidence and process lineage matter as much as the result.
Decision rule: If the organisation cannot prove how the check met the required trust standard, prioritise re-checking through the certified route rather than assuming the earlier screening is sufficient.
Practitioner takeaway: The key judgement is whether the check is defensible, not merely completed; if the process cannot be evidenced cleanly, the statutory excuse is at risk even when the underlying identity looked valid.
Related resources from NHI Mgmt Group
- How should landlords and letting agents implement digital right to rent checks securely?
- What breaks when digital ID checks still rely on collecting full identity data instead of just the age result?
- What breaks when WebAPI access reviews are done manually instead of through an automated process?
- What breaks when identity verification is done after background checks instead of before them?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 10, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org