Join our Newsletter — 33% off our NHI Course
Governance, Ownership & Risk

GPG 45

← Back to Glossary
By NHI Mgmt Group Updated September 27, 2026 Domain: Governance, Ownership & Risk

GPG 45 is the UK government guidance for checking and verifying a person’s identity. It is outcomes focused rather than process focused, so organisations can use different methods as long as they reach the required assurance level. The guide supports consistent identity checking for customers, employees, and people acting on behalf of a business.

What GPG 45 is designed to do

GPG 45 is a UK government identity guidance framework that sets an assurance outcome, not a fixed procedure. That means organisations can use different methods, as long as the combined checks reasonably support the level of identity confidence the use case requires.

Its value is consistency: a customer onboarding flow, an employee check, and a representative acting for a business can all be assessed against the same assurance logic, even if the evidence collected is different.

Outcomes-focused identity checking

The key idea in GPG 45 is that identity verification should be judged by the strength of the outcome rather than by whether a prescribed sequence was followed. In practice, that lets organisations mix documents, electronic evidence, liveness checks, database checks, or other signals, provided the process still reaches the expected assurance level.

This flexibility matters because identity proofing methods vary by population and risk. A method that is suitable for a low-friction customer journey may be inadequate for higher-risk employee access, while a strong manual process may be too slow for modern onboarding volumes.

Where GPG 45 fits in identity governance

GPG 45 sits at the boundary between policy and implementation. It helps organisations translate a general requirement, “verify this person’s identity”, into a defensible control objective that can be applied across channels and service models.

That makes it useful for teams that need to align operational checks with assurance requirements without locking themselves into one vendor method. It also helps reduce inconsistency when different business units, partners, or third parties verify people on behalf of the organisation.

Common uses and practical implications

GPG 45 is often relevant anywhere identity evidence has to be trusted before access, enrolment, or transaction completion is allowed. The practical question is not simply whether identity was checked, but whether the check produced enough confidence for the decision being made.

Because the guidance is outcomes focused, organisations need to define how they will demonstrate that their chosen method actually meets the required assurance level. That typically means aligning the verification process to the sensitivity of the interaction, the likely fraud pressure, and the consequences of a false acceptance or false rejection.

Risk and Threat Considerations

Weak identity checking can let impostors pass as legitimate users, which creates fraud exposure, account takeover risk, and downstream trust failures. The main danger is not just a single bad onboarding decision, but the compounding effect when an inadequate check is reused across many channels or delegated to inconsistent third parties.

Failure mechanism: An organisation treats identity verification as a box-ticking exercise, so low-quality evidence, weak document handling, or uncalibrated automated checks produce false confidence.

Impact: Invalid identities can be enrolled, people can gain access or act on behalf of others, and the organisation may face financial loss, compliance issues, and remediation overhead.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63Digital Identity GuidelinesDefines assurance levels and identity proofing outcomes for digital identity.
Recommendation — Map verification methods to the required assurance level and document how evidence supports that outcome.
NIST SP 800-53 Rev 5IA-12 — Identity ProofingCovers proving a person's identity before establishing access or trust.
Recommendation — Apply identity proofing controls that match the decision risk and retained evidence requirements.
ISO/IEC 27001:2022A.5.16 — Identity managementAddresses management of identities and their assignment across organisational processes.
A.5.17 — Authentication informationSupports safeguarding identity evidence and authentication material used in checking.
Recommendation — Define accountable identity-checking ownership and maintain consistent identity assurance rules. Protect identity evidence and supporting authentication material throughout the verification process.

Practitioner Guidance

Why practitioners should care: The most common mistake is assuming that a standard process is automatically “good enough” because it is familiar or widely used. GPG 45 asks teams to justify assurance outcomes, so the real task is to prove that the method matches the decision being supported.

Governance implication: Ownership should sit with the business process that consumes the identity decision, not only with the team performing the check. That keeps the assurance target, evidence standard, and exception handling aligned to the actual risk.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org