The Digital Identity Trust Layer: Why Verifiable Credentials Are the Next Balance-Sheet Item for APAC BFSI
Executive Summary
For a decade, digital identity in Asia-Pacific banking and insurance has been treated as a compliance line item - a KYC cost, a fraud tax, a login problem. That framing is now obsolete. In 2025 and 2026, three forces have collided: the roll-out of reusable, cryptographically verifiable credentials (ConnectID in Australia, SGFinDex in Singapore, MyDigital ID in Malaysia, India's DigiLocker-anchored stack, Hong Kong's iAM Smart), an escalating scam and synthetic-identity crisis that has forced regulators to redistribute liability toward institutions, and the maturation of decentralised identity standards (W3C Verifiable Credentials 2.0, ISO/IEC 18013-5 mobile driver licence, OpenID4VC) that finally make cross-institution trust portable.

The result: identity is being repriced from a cost centre to a balance-sheet asset. Institutions that own a high-assurance, reusable identity graph will onboard faster, lose less to fraud, sell more embedded products, and meet incoming operational-resilience and consent obligations with lower marginal cost. Those that do not will inherit a rising compliance run-rate and a growing gap in customer trust.
This article sets out the shift, the numbers, and a 12-month executive agenda for CIOs, CDOs, Heads of Risk and Chief Digital Officers in APAC BFSI.
Introduction
Identity is the single control that sits under every other control. Every fraud rule, every KYC screen, every entitlement, every open-finance consent and every AI decisioning workflow ultimately resolves back to the question: is this really the counterparty they claim to be, and can we prove it later? For most APAC banks and insurers, that question is still answered through a patchwork - a document upload here, a selfie liveness check there, an SMS OTP, a re-key against a legacy customer master. The patchwork works, but it is expensive, brittle, and increasingly out of step with both regulators and customers.
The industry is now moving, faster than most executives realise, toward a shared identity trust layer - infrastructure that lets a credential issued once by a trusted party (a bank, a government, a telco) be presented anywhere, verified cryptographically, and stored under user control. This is not a theoretical future. Australia's ConnectID moved into full commercial operation across the four majors in 2024-2025. Singapore's SGFinDex has extended from wealth aggregation to consented data exchange across banks, CPF, IRAS and insurers. India's Account Aggregator framework crossed 100 million linked accounts. The European eIDAS 2.0 Digital Identity Wallet is entering member-state rollout in 2026, setting a template that APAC regulators are actively studying.
For BFSI leaders, the question is no longer whether to participate. It is what role to play, on what stack, and how quickly to rewire onboarding, fraud, servicing and product distribution around it.
Industry Context: Three Forces Converging

1. The scam and synthetic-identity tax has become unsustainable
Losses to authorised push payment scams and identity-driven fraud have moved from a customer-experience problem to a prudential one. In Australia, Scamwatch recorded A$2.74 billion in reported scam losses in 2023, with investment and remote-access scams dominating (ACCC, 2024). Singapore reported S$651.8 million in scam losses in 2023, a 46.8% year-on-year rise (Singapore Police Force, 2024). Hong Kong's technology-related crime losses exceeded HK$5.5 billion in 2023 (Hong Kong Police Force, 2024).
The regulatory response has been to shift liability. The UK's mandatory APP reimbursement regime (PSR, October 2024) - capped but consequential - has already been referenced by APRA, MAS and HKMA as a benchmark. Singapore's Shared Responsibility Framework went live in December 2024, allocating losses across banks, telcos and consumers based on demonstrable control failures (MAS & IMDA, 2024). Australia's Scams Prevention Framework, legislated in 2025, imposes ecosystem-wide obligations on banks, telcos and digital platforms with penalties of up to A$50 million per breach.
Every one of these regimes rewards institutions that can prove, cryptographically and after the fact, that the counterparty on the other side of a payment or an application was who they said they were. Verifiable credentials are the mechanism that produces that proof.
2. Onboarding economics no longer clear the hurdle rate
The unit economics of digital onboarding have deteriorated. McKinsey's 2024 Global Banking Annual Review estimated that customer acquisition costs in retail banking have risen 20-30% over five years, driven largely by KYC, fraud and abandonment (McKinsey & Company, 2024). Deloitte's 2024 Insurance Outlook flagged that up to 40% of digital insurance applications are abandoned mid-flow, with identity friction the leading cause (Deloitte, 2024). At the same time, expected returns on digitally acquired mass-market customers have compressed as deposit betas rose and net interest margins normalised.
Reusable credentials break this cost curve. Australian Payments Plus, which operates ConnectID, has reported that a bank-issued identity presented via ConnectID can reduce onboarding time from days to under two minutes and cut abandonment materially versus document-upload flows (Australian Payments Plus, 2024). Similar patterns are visible in India's video-KYC and Singapore's Myinfo-based onboarding, where digital account opening completes in single-digit minutes at a fraction of manual cost.
3. Standards have finally converged
For years, decentralised identity was a standards debate. That debate is closing. W3C ratified Verifiable Credentials Data Model 2.0 in 2025. ISO/IEC 18013-5 (mobile driver licence) is being adopted by transport agencies from New South Wales and Queensland to Japan and Korea. OpenID Foundation's OpenID for Verifiable Credentials (OpenID4VC) suite is now the de facto issuance and presentation protocol referenced by the EU Digital Identity Wallet, and increasingly by APAC regulators. Apple Wallet and Google Wallet both support ISO mDL and, in 2025, extended support for verifiable ID documents in additional jurisdictions.
Standard maturity matters because it collapses integration cost. A bank that builds a verifier once against OpenID4VC can accept credentials from any conforming issuer - a government wallet, another bank, an insurer, a professional body - without bilateral integration. That is the moment identity stops being a project and becomes infrastructure.
Current Challenges
Even with the tailwinds, the migration is non-trivial. Most APAC BFSI institutions face five constraints.
Fragmented identity data. Customer identity data typically sits across a CIF, one or more CRMs, a fraud platform, a KYC vendor, and business-line systems. Federating this into a single verifiable-credential-ready identity graph is a data engineering problem before it is a cryptography problem.
Legacy KYC vendor lock-in. Multi-year contracts with document-and-selfie vendors were signed on the assumption that this would remain the primary onboarding path. Reusable credentials disintermediate part of that spend, and vendor exit costs are real.
Regulatory ambiguity on cross-border acceptance. A credential issued under Australia's Trusted Digital Identity Framework or Singapore's National Digital Identity is not automatically accepted for KYC in Hong Kong or Indonesia. Cross-border banks must design for jurisdictional variance in what counts as an acceptable issuer.
Fraud team scepticism. Fraud and financial-crime leaders have been burned by promised silver bullets. They will - correctly - insist that reusable credentials be layered with device intelligence, behavioural biometrics and transaction monitoring rather than replace them.
Consumer trust and consent UX. A verifiable credential is only useful if customers understand and choose to present it. Poorly designed consent flows will surface a new class of complaints and regulatory attention around dark patterns.
Key Trends Shaping the Next 24 Months
Five trends will define how the trust layer takes shape across APAC BFSI.
Reusable KYC as a network good. ConnectID in Australia, SGFinDex in Singapore, MyDigital ID in Malaysia and iAM Smart in Hong Kong are all moving from single-purpose pilots to multi-use networks. Banks are simultaneously issuers, relying parties, and - critically - network operators. The economics of network participation (per-verification fees, revenue share on issuance) will become a material line item.
Insurance leaning in. Insurers have historically lagged banks on digital identity. That is changing. The combination of longer sales journeys, higher abandonment, and rising claims-fraud losses makes reusable credentials disproportionately valuable to insurance. Expect major APAC insurers to move from observer to issuer between 2026 and 2027, particularly in life and health.
Business identity gets serious. KYB (know-your-business) is the next frontier. Legal Entity Identifiers, verifiable corporate registries and directorship credentials are being knitted together in initiatives such as GLEIF's vLEI and Singapore's Bizfile+ modernisation. For SME lending, trade finance and merchant onboarding, verifiable business identity will collapse cycle times that today run into weeks.
Agentic AI needs identity too. As banks deploy AI agents that act on behalf of customers or of the institution, the identity of the agent - its provenance, its scope, its delegation - becomes a control point. Emerging work on agent credentials and delegated authority credentials will sit on the same trust layer.
Regulatory convergence on wallets. Following eIDAS 2.0, expect APAC regulators to publish national digital wallet frameworks over 2026-2028. Institutions that participate in early consultations will shape the acceptance criteria; those that do not will inherit them.
Strategic Analysis: From Cost Centre to Trust Franchise
The strategic prize is not efficiency. It is franchise value. Banks and insurers that become trusted issuers in a national identity network gain a durable, hard-to-replicate role in every digital transaction their customers make, well beyond their own product boundary. This is analogous to the shift card networks made from payment rails to identity and trust in the 2010s - but this time the network is national, the credentials are portable, and the customer, not the network, holds the wallet.
Three archetypes are emerging.

The Trust Franchise. A bank positions itself as a primary issuer of high-assurance identity credentials, monetising via per-verification fees and using the identity graph as a distribution channel for its own and partner products. Requires early investment, regulatory relationships, and a credible fraud-and-privacy story.
The Relying-Party Optimiser. A bank or insurer accepts credentials from national wallets and other trusted issuers, focusing on onboarding conversion, fraud reduction and servicing cost. Lower capex, faster payback, but no franchise upside.
The Ecosystem Orchestrator. A large institution or consortium operates network infrastructure (schema governance, revocation registries, dispute resolution) on behalf of others. Fewer than a dozen APAC institutions will realistically play this role.
Choosing an archetype is a board-level question. It shapes capex allocation, vendor selection, regulatory engagement and - crucially - the target operating model for onboarding, fraud and customer servicing.
Real-World Examples
Australia - ConnectID and the majors. ConnectID, operated by Australian Payments Plus, went live commercially with CBA, NAB, ANZ and Westpac between 2023 and 2025. Merchants and government relying parties can request identity attributes verified against a bank's KYC record; the customer approves in-app; no document upload is required. Reported onboarding lifts and reduced fraud rates have driven expansion into age verification and beyond (Australian Payments Plus, 2024).
Singapore - SGFinDex and Myinfo. SGFinDex, operated by MAS and the Smart Nation and Digital Government Group, allows consented aggregation of financial data across banks, CPF, HDB, IRAS and, since 2023, insurers. Combined with Myinfo-powered onboarding, the effect is a national trust layer that already carries meaningful volumes of consented data exchange (MAS, 2024).
India - Account Aggregator and DigiLocker. India's AA framework, regulated by the RBI, crossed 100 million linked accounts in 2024 and is now processing hundreds of millions of consented data pulls annually (Sahamati, 2024). DigiLocker holds government-issued documents as verifiable artefacts consumable by regulated entities. Together, they underpin some of the world's lowest-cost digital onboarding.
Hong Kong - iAM Smart and the Faster Payment System link. iAM Smart has expanded from public services into financial services relying-party use cases, and the HKMA's Fintech 2025 agenda continues to push shared identity infrastructure as a competitiveness lever (HKMA, 2024).
Europe - eIDAS 2.0 as a template. The EU Digital Identity Wallet, mandated for member-state rollout from 2026, will require large online platforms and regulated sectors including banking and insurance to accept the wallet. It sets the reference architecture APAC regulators are studying (European Commission, 2024).
Actionable Recommendations: A 12-Month Executive Agenda
The following agenda is calibrated for a large APAC bank or insurer over the next 12 months.

Within 90 days, commission a board-level positioning decision on archetype (Trust Franchise, Relying-Party Optimiser, Ecosystem Orchestrator) and mandate a single accountable executive - typically the CDO or Chief Customer Officer - to own it. Complete an identity data audit: where customer identity attributes live, quality, freshness, and cryptographic readiness. Baseline the current cost per verified onboarding across retail, wealth, SME and insurance channels; most institutions will find they have never measured this end-to-end.
By month six, stand up a verifier capability that accepts OpenID4VC-formatted credentials from at least one national wallet in each priority market. Prioritise the two or three highest-abandonment journeys - typically retail account opening, credit card application, and insurance quote - for reusable-credential integration. Rework fraud rules to consume credential provenance as a signal, not as a replacement for existing controls. Begin a structured conversation with legacy KYC vendors on contract migration paths.
By month twelve, if the archetype is Trust Franchise, issue the institution's first customer-held verifiable credential (typically an identity attestation) into a supported wallet, with a defined go-to-market for relying-party partners. Extend to KYB using LEI-anchored credentials for SME and corporate onboarding. Publish, internally, a target operating model for identity that consolidates ownership across onboarding, fraud, servicing and product - the current fragmentation is the single biggest execution risk.
Across all three horizons, engage regulators proactively. The institutions that shape acceptance criteria, revocation standards and cross-border interoperability rules will operate on more favourable economics than those that inherit them.
sourceCode Perspective
At sourceCode, we have worked with banks and insurers across APAC on the engineering that sits under this shift - customer data platforms, fraud-and-identity decisioning, onboarding orchestration, and the API and event layers that make reusable credentials usable in production rather than in a proof of concept. Three patterns recur in the work we see succeed.
The first is treating identity as a product, not a project. A durable identity capability needs a product owner, a roadmap, service-level objectives and a P&L view. Programmes structured as one-off integrations decay within 18 months.
The second is investing in the verification decisioning layer before the credential itself. The value of a reusable credential is realised only when a bank's fraud, KYC and onboarding systems can consume it in real time and combine it with device, behavioural and transactional signals. This is a data engineering and MLOps problem as much as it is a cryptography problem.
The third is designing consent as a first-class customer experience. The institutions that will win customer trust are those that make credential presentation feel like a benefit - faster, safer, in the customer's control - not a compliance step. That requires design, research and copywriting discipline that most identity programmes underinvest in.
sourceCode's engineering, data and platform teams partner with BFSI clients to make these choices concrete: architecture reviews, verifier and issuer implementations, fraud rule redesign, and the operating-model work that lets identity move from cost centre to franchise asset.
Conclusion
The shift underway is not a technology upgrade. It is a repricing of one of the most fundamental inputs to banking and insurance - the ability to know, and to prove, who you are dealing with. The infrastructure exists. The standards have converged. The regulators are moving. The scam and onboarding economics no longer permit inaction.
Institutions that act in the next 12 months will define the trust layer their competitors have to live inside. Those that wait will find that identity, once a cost, has quietly become someone else's franchise.
If your leadership team is weighing where to play in the emerging APAC digital identity trust layer - as issuer, relying party, or orchestrator - sourceCode's BFSI engineering and platform advisory team can help pressure-test the strategy and design the underlying architecture. Talk with sourceCode about building a reusable identity capability that pays back inside 18 months.
Frequently Asked Questions
What are verifiable credentials in banking? Verifiable credentials are cryptographically signed digital attestations - for example, "this person is a verified customer of Bank X" or "this person is over 18" - that a customer holds in a digital wallet and can present to any relying party. The verifier can cryptographically confirm the credential is genuine, unaltered and unrevoked without contacting the issuer.
How is ConnectID different from a traditional KYC check? ConnectID lets a customer authorise their bank to share verified identity attributes with a third party in seconds, in-app, without document uploads. Traditional KYC typically requires the customer to re-supply documents, and the relying party to re-run verification against them.
Does SGFinDex replace KYC? No. SGFinDex enables consented data aggregation across financial institutions and government agencies in Singapore. It is a complementary trust rail that reduces friction in wealth aggregation, financial planning and, increasingly, product onboarding - while KYC obligations under MAS notices continue to apply.
Are reusable identity credentials safe from deepfakes and synthetic identity fraud? Reusable credentials materially raise the bar because the underlying attestation is cryptographically signed by a trusted issuer, not derived from a document photograph. They do not eliminate fraud risk and should be combined with device intelligence, behavioural biometrics and transaction monitoring.
How should a bank decide between being an issuer and a relying party? The decision is strategic, not technical. Issuers gain a franchise role in the identity network and can monetise verifications, but need scale, regulatory standing and a credible privacy story. Relying parties capture faster payback on onboarding conversion and fraud reduction. Most large APAC banks will end up playing both roles across different customer segments.
References
ACCC (2024) Targeting Scams: Report of the ACCC on Scams Activity 2023. Australian Competition and Consumer Commission, Canberra.
Australian Payments Plus (2024) ConnectID Annual Update 2024. Sydney.
Deloitte (2024) 2024 Global Insurance Outlook. Deloitte Insights.
European Commission (2024) European Digital Identity Regulation (eIDAS 2.0): Implementation Roadmap. Brussels.
Hong Kong Monetary Authority (2024) Fintech 2025 Strategy: Progress Update. Hong Kong.
Hong Kong Police Force (2024) Crime Situation in Hong Kong 2023. Hong Kong.
McKinsey & Company (2024) Global Banking Annual Review 2024: Attaining Escape Velocity. New York.
Monetary Authority of Singapore (2024) Financial Sector Technology and Innovation Scheme: SGFinDex Update. Singapore.
Monetary Authority of Singapore and Infocomm Media Development Authority (2024) Shared Responsibility Framework for Phishing Scams. Singapore.
Sahamati (2024) Account Aggregator Ecosystem Update. New Delhi.
Singapore Police Force (2024) Annual Scams and Cybercrime Brief 2023. Singapore.