Quick answer
The Digital Identity Services Trust Framework Act 2023 set up a legal framework for trusted digital identity services in New Zealand, overseen by a Trust Framework Authority. Providers can be accredited after assessment of their capability, identification management, privacy and security, and may display an accreditation mark. Accreditation lasts three years. It is voluntary, so not every ID check used by lenders is accredited, but it gives borrowers a useful benchmark.
Key points
- Established by the Digital Identity Services Trust Framework Act 2023
- Accreditation assesses capability, identification management, privacy and security
- Accredited services can display an accreditation mark
- Accreditation lasts three years from the grant date
- The framework is voluntary; ask lenders who runs their ID check
Every online business loan includes a moment where you prove you are you: a photo of your licence, a selfie, perhaps a turn of the head for the camera. Behind that moment sits a provider you have probably never heard of, holding images of your face and your ID. New Zealand now has a legal framework designed to make such services trustworthy. Here is what it is, what it is not, and what it means for borrowers.
What is the Digital Identity Services Trust Framework?
The Digital Identity Services Trust Framework Act 2023 created a legal framework to make sure secure and trusted digital identity services operate in New Zealand. It set up a Trust Framework Authority to regulate accredited providers, supported by regulations and detailed rules — the Digital Identity Services Trust Framework Rules 2024.
The idea is straightforward: if digital identity services meet a common, legally backed standard, people and businesses can rely on them with more confidence, and identity can be verified once and reused safely rather than re-checked from scratch everywhere.
How does accreditation work?
Providers apply for accreditation of specific services. According to the Public Service Commission’s guidance, the assessment covers four areas:
| Area | What is assessed |
|---|---|
| Provider capability | Operational requirements to deliver the service reliably |
| Identification management | Independent evaluation against New Zealand identification standards |
| Privacy | Compliance with the Privacy Act 2020 |
| Security | Risk management and security controls |
The process involves detailed documentation and may include service demonstrations and questions from assessors. Accredited providers can deliver the accredited services under the framework and can display an accreditation mark for each accredited service. Accreditation lasts three years from the date it is granted.
From 28 September 2026, applications for accreditation must comply with the current consolidated version of the Rules 2024 — a sign the framework is maturing.
Is the framework compulsory for lenders?
No. It is a voluntary framework. Lenders and brokers choose their own identity verification providers. Some may use accredited services; others use providers that are well established but not (yet) accredited under the New Zealand framework, or that operate under other standards. Both can be legitimate. Accreditation is a useful signal, not the only one.
How does this relate to the ID check in your loan?
When you apply online, the digital ID verification step typically involves:
- photographing your driver licence or passport;
- a live selfie with a liveness test;
- automated matching and, sometimes, checks against official or commercial data.
The Trust Framework sets expectations for how a provider manages exactly that kind of process: how it confirms identity, how it protects your data and how it keeps systems secure. If your lender’s provider is accredited, an independent assessment has looked at those things.
If you are about to start, the enquiry needs no ID at all — the ID step comes later, once you choose to proceed.
What does the accreditation mark tell you — and what does it not?
It tells you that the specific service was assessed and accredited under New Zealand’s legal framework, covering capability, identification management, privacy and security.
It does not tell you that the lender using the service is legitimate, that the loan is a good deal, or that everything else the provider does is accredited. It is about the identity service.
It can be faked. Scammers copy logos. If a “verify your identity” link arrives unexpectedly, the presence of a mark on the page proves nothing. The real test is whether the link came from your specialist, through a channel you trust. See checking a lender is real.
What questions should you ask a lender about ID checks?
Reasonable questions that any well-run lender or broker should answer:
- Which company runs your identity verification?
- Is the service accredited under the Digital Identity Services Trust Framework?
- Where are my images and data stored, and for how long?
- Is my data used for anything other than verifying my identity for this application and related legal obligations?
- How can I request access to what is held about me?
Under the Privacy Act 2020, you have the right to request access to personal information held about you, and organisations must store it securely and keep it no longer than necessary. Our Privacy Act basics page covers those rights.
Why does trusted digital identity matter for business lending?
Identity fraud is a real risk in lending. A criminal who can pass an identity check in your name could borrow against your business or your property. Strong identity verification protects you as much as the lender. A common, legally backed standard raises the bar across providers.
It also matters for convenience. As accredited services become more common, the long-term promise is reusable digital identity: verify once with a trusted provider, then share that verified identity, with consent, when you need to. For a director who applies for finance, opens accounts and signs contracts regularly, that could remove a lot of repeated photo-taking.
How does this connect to e-signing?
Identity and signing go hand in hand. Under the Contract and Commercial Law Act 2017, an electronic signature needs to identify the signer and show their approval, reliably. A strong identity check earlier in the process supports the reliability of the signature later. Read e-signing loan documents for the signing side.
What can you do to make your ID check smooth?
- Make sure your driver licence or passport is current.
- Use good, even lighting and a plain background.
- Make sure the name on your ID matches the name on company records, or tell your specialist about differences up front.
- Use the link your specialist sends, on a device you control.
- Tell co-directors and guarantors to expect their own links.
Worked example (illustrative): a Whangārei boatbuilding company has three directors. The broker explains which provider runs the ID check and that it is accredited for the relevant service. Two directors verify on their phones in minutes. The third, whose licence expired last month, renews it before verifying rather than trying an expired card that would fail.
Where is this heading?
The framework is still young. Expect more providers to seek accreditation, more lenders to prefer accredited services, and gradually more reuse of verified identity across services. For borrowers, the practical effect is likely to be fewer repeated checks and clearer standards about how identity data is protected.
Does the framework replace RealMe or other government identity services?
The framework is about setting rules and standards for digital identity services generally, including private providers, rather than replacing any single service. Government and private identity services can sit side by side. For a borrower, the practical question remains the same: who is running this check, are they trustworthy, and how is my data protected? The framework gives you a recognised benchmark when you ask.
What should sole traders and small companies take from all this?
You do not need to understand the legislation in detail. Know that a legal framework now exists, that accredited services carry a mark, and that you are entitled to ask who handles your identity data and where. Use only links you trust, keep your ID current, and treat any unexpected “verify your identity” message as suspicious until confirmed.
How long are ID images usually kept?
That depends on the provider and on the legal obligations of the lender using it. Some identity records must be kept for a set period under laws that require businesses to verify customers; others can be deleted sooner. Ask your lender for the specific retention period. A clear answer is a good sign that the provider has thought about privacy, which is exactly what accreditation assesses.
Begin with a team that is open about its checks
Our enquiry needs no ID and no credit check. Your details are kept with one team, not passed down a chain of lenders, and a real specialist reads them. When it is time for an ID check, we will tell you who runs it and why. Please make sure the names you give us match your ID and company records, so the check passes first time. Start your 60-second enquiry.
Frequently asked questions
What is the Digital Identity Services Trust Framework?
A legal framework, set up by the Digital Identity Services Trust Framework Act 2023, for digital identity services in New Zealand, with rules, accreditation and an authority that oversees accredited providers.
Do lenders have to use an accredited provider?
The framework is voluntary. Lenders choose their identity verification providers, which may or may not be accredited under it.
What does the accreditation mark mean?
That the provider has been assessed and accredited for that specific service under the framework's rules. It relates to the accredited service, not everything the provider does.
How long does accreditation last?
Three years from the date it is granted, subject to the provider maintaining compliance.
Is a selfie check safe?
Reputable providers protect images and data under the Privacy Act 2020. Ask who runs the check, where data is stored and how long it is kept.
What changed in September 2026?
From 28 September 2026, applications for accreditation must comply with the current consolidated version of the Digital Identity Services Trust Framework Rules 2024.