The Credential Is the New Passport. 1

A quiet revolution is rewriting the rules of digital trust, and this time, proving something once could make it reusable.

Digital identity has a longer history than most people assume. The idea of proving who you are online is almost as old as the commercial internet itself, and the attempts have been many. Login federation like the “Sign in with Google” or “Sign in with Apple”, national eIDs, mobile authentication, bank-based verification… Each wave promised to solve the problem. Each fell short in the same fundamental way: trust remained trapped inside individual organisations.

This time, something more fundamental is changing in Europe. Verification is no longer where the story ends. The proof itself can now travel, from one institution to another, across services and borders, without being rebuilt from scratch each time.

The age of digital credentials has begun, and with it, a redesign of the infrastructure that underpins everything from opening a bank account to accessing public services.

Banks Have Been Rebuilding Trust From Scratch With Digital Credentials.

Every regulated organisation follows the same pattern. When a customer arrives, the bank verifies their identity, collects supporting information and stores evidence of those checks. Then the same customer opens an account elsewhere and the process starts all over again.

For decades, this duplication has simply been accepted as the cost of trust. Every institution creates its own verified version of the customer because the result of one verification rarely travels beyond the organisation that performed it.

Digital credentials challenge that assumption. Instead of producing a verification that remains locked inside a bank or government agency, the process creates a cryptographically verifiable credential that belongs to the individual and can be presented elsewhere. The proof becomes portable.

Identity Is Only the Beginning.

Identity is only part of what banks need to establish. Regulated onboarding increasingly depends on verifying specific attributes: a residential address, a tax identification number and a personal administrative number, all in addition to identity attributes like name or birth date.

Europe’s new digital identity framework is built around exactly this idea. Person Identification Data (PID) establishes identity, while Electronic Attestations of Attributes (EAA) and Qualified Electronic Attestations of Attributes (QEAA) provide trusted proof of specific facts, like the address, income or professional title.

The terminology may be technical, but the concept is simple: instead of requesting the original document every time, the information is verified once and turned into a trusted credential, so the next organisation – or the next interaction – doesn’t have to start from zero.

For banks, that becomes particularly relevant with AMLR. The regulation doesn’t stop at identity verification: it also requires specific customer attributes to be verified. Yet those attributes aren’t consistently available through national identity schemes across Europe.

The challenge is no longer proving identity. It’s proving everything around it.

A New Layer of Banking Infrastructure.

Digital credentials predate the EUDI Wallet. In 2019, the World Wide Web Consortium (W3C) published its first Verifiable Credentials standard: a way to make digital claims cryptographically verifiable and portable between organisations.

Europe is now taking that idea mainstream. Under eIDAS 2.0, every EU Member State must provide at least one European Digital Identity Wallet, designed to hold and present identity data and credentials across borders and services.

For banks, the wallet is the visible part. However, the bigger change sits underneath: an ecosystem in which verified information can move between institutions instead of being collected from scratch each time.

Although this idea has been around for many years, it is only now that Europe is turning it into infrastructure.

The Economics of Trust Are Changing.

Once trust becomes portable, something else changes: how much information needs to travel with it.

Take proof of address. Today, that often means sending the document itself. With a credential, the document can stay where it is; what travels is the verified fact.

Selective disclosure pushes the idea further. Someone can prove they are over 18 without revealing their date of birth, or confirm an attribute without handing over everything used to establish it.

For banks, fewer repeated checks and fewer documents to collect, process and store could mean lower operational costs. Less personal data changing hands also makes data minimisation part of the architecture rather than an afterthought.

The security model shifts, too. Much of digital verification still comes down to one question: does this document look genuine? Credentials replace that visual judgement with a cryptographic one – who issued it, and has it been altered?

The result is a subtle inversion of the current system: move the proof, not the paperwork.

The Credential Is the New Passport.

The passport transformed travel because one country’s assertion about a person’s identity became understandable somewhere else.

Digital credentials bring that principle to the internet and extend it beyond identity to verified attributes.

For banks, regulation may be the immediate driver, and eIDAS 2.0 and AMLR will be no exception. Banks will have to adapt systems, integrate new ways of proving identity and attributes, and navigate an ecosystem that is still taking shape.

The difference is that this time, some of that complexity comes with an unusual promise: making trust portable. Instead of every institution (and every market) building its own way of establishing the same facts, credentials could give those facts a common way to travel.

For decades, banks have built individual systems designed to answer the same question over and over again: Can we trust what this customer is telling us?

And for just as long, they’ve been collecting documents to answer it.

It turns out what they really needed were facts.

Get ahead of AMLR and financial crime with one platform built for both.

Continue reading 

Author

The Credential Is the New Passport. 2

Nikita Rybová
Customer & Product Marketing Manager at IDnow
Connect with Nikita on LinkedIn