Digital identity wallets have quickly become one of the biggest talking points in recent times. Every conference seems to have a session on them. Every regulator is exploring their role. Every technology provider has an opinion on what they could mean for customer onboarding, fraud prevention and compliance.
While this has undoubtedly created plenty of online buzz and media attention, it has also created plenty of confusion.
Spend enough time on LinkedIn and you’ll come across huge claims suggesting digital identity wallets will replace onboarding, make physical documents obsolete and even eliminate fraud altogether. While it makes for eye-catching, often scroll-stopping content, it doesn’t reflect how identity and wallets will really work in practice.
Digital identity wallets have the potential to improve customer experiences, strengthen identity assurance and reduce unnecessary friction. They could help firms make better decisions with trusted, reusable identity data.
But they will be one part of a much bigger identity ecosystem, not a replacement for it.
Here are four of the biggest myths surrounding digital identity wallets and what financial institutions and other regulated firms should be thinking about instead.
Myth 1: Digital identity wallets will work for everyone, everywhere
It’s easy to understand why this assumption has taken hold. Every individual will have a digital identity wallet, every business will accept it, and every country will recognise it. As a result, identity verification becomes almost instant regardless of where someone lives or which organisation they’re dealing with.
Simple! Right?
Not quite. In fact, the reality is considerably more complex.
Identity verification is governed by different legal frameworks, different trust models and different levels of digital maturity across jurisdictions. A wallet issued under one framework may not automatically satisfy another regulator’s requirements.
Even within the same country, organisations often have different risk appetites and different customer due diligence obligations. A retail bank onboarding a local customer has very different requirements from an investment firm onboarding an overseas politically exposed person. The identity evidence that satisfies one process may not be enough for another. There are jurisdictions that are pushing ahead with this hard, like the eIDAS 2.0 regulation driving all European countries to bring in digital identity, but there are parts of the world where this isn’t a priority at all.
Customer adoption also varies significantly. Not everyone owns compatible devices. Some customers will continue to prefer physical documentation. Others may have accessibility needs or limited digital confidence that make wallet adoption slower than expected. This is particularly relevant as governments continue introducing new digital identity frameworks.
Myth 2: Digital identity wallets will replace physical documents
One of the most common misconceptions is that passports, driving licences and other physical identity documents are about to disappear.
But that simply isn’t how digital identity wallets are designed to operate.
Before someone can receive verified digital credentials, those credentials usually need to be linked back to official documentation or another trusted identity source and issuer. Rather than replacing physical documents, digital identity wallets often extend their usefulness.
Instead of repeatedly presenting a passport every time a new account is opened, customers may be able to present verified digital credentials that originate from that same trusted document. The wallet becomes another way of sharing identity information rather than replacing the original evidence entirely.
Maybe there is some distant future where that happens, but for the foreseeable at least, there is so much crossover into so many other areas that mean that physical IDs need to stay.
Under eIDAS 2.0, private entities operating under European regulation need to be accepting the eIDAS 2.0 wallets by the end of 2027. But within that regulation, it’s made clear that for high-risk use cases, you will still need a proof of ownership. And for a lot of digital identity wallets, the only way to do that will be to also capture a physical ID where there’s no biometric available from the wallet itself.
Ultimately, we’re not going to be getting rid of physical IDs any time soon, even in the regions that are pushing ahead hard.
Myth 3: Digital identity wallets will replace customer onboarding
This is probably one of the biggest misunderstandings surrounding digital identity wallets. In regulated environments, identity verification is a critical part of onboarding, but it isn’t onboarding itself.
Opening an account involves considerably more than confirming someone is who they claim to be. Regulated firms still need to meet their Anti-Money Laundering (AML) obligations, including customer due diligence, sanctions screening, politically exposed person checks, adverse media monitoring, risk assessment, and ongoing monitoring.
“Wallets are there to help with AML obligations, but they don’t replace your AML obligations. Those checks aren’t going away.” – Robert O’Farrell, CTO at ID-Pal
What’s more, depending on the organisation and its regulatory obligations, firms may also collect business control structures, financial information, registration documentation, and beneficial ownership information.
A digital identity wallet doesn’t remove those responsibilities. Instead, it has the potential to improve one stage of a much larger process.
If a wallet allows a customer to share trusted identity attributes securely, firms can spend less time collecting basic identity evidence and more time assessing actual financial crime risk.
Myth 4: Digital identity wallets will eliminate fraud
Social media has a habit of turning promising technology into miracle solutions, and digital identity wallets have become one of the latest examples. It’s not unusual to see claims that they will eliminate fraud entirely, as though they’re a silver bullet for financial crime.
Those headlines attract attention because everyone wants a simple answer to an increasingly complicated problem, but fraud and financial crime has never been that straightforward.
Fraud constantly adapts. Criminals target new technologies, exploit weaknesses and shift tactics whenever organisations strengthen one area of their controls.
“Wallets are not a silver bullet for preventing fraud. But they will help you to have a far better balance between friction and assurance.” – Robert O’Farrell, CTO at ID-Pal
But digital identity wallets can make some forms of fraud significantly harder to carry out. Trusted credentials issued by recognised authorities provide confidence that identity information is genuine, cryptographically signed and hasn’t been altered after it was issued.
However, those improvements only address one part of the wider financial crime picture. A digital identity wallet can confirm that a credential came from a trusted issuer, but it cannot guarantee the quality of the checks completed before that credential was issued. If weaknesses existed earlier in the identity verification and vetting process, those issues don’t automatically disappear because the credential is stored digitally.
It’s also worth remembering that a digital identity wallet doesn’t automatically prove you’re dealing with the true owner of an identity. While on-device authentication confirms that someone can access the wallet, it doesn’t confirm they’re the legitimate owner. That’s why, in higher-risk scenarios, organisations may still need extra checks to verify the person behind the credential, not simply the credential itself.
This is why fraud prevention has always relied on multiple layers working together. Identity verification is one part of the process, but it works alongside customer due diligence, monitoring, synthetic ID and injection attack detection, AML screening, and ongoing risk assessments. Each part provides a different piece of the picture, and together, each layer help organisations identify suspicious activity that another control may not detect.
Digital identity wallets may strengthen one important layer of fraud prevention, but they don’t remove the need for everything else. The strongest fraud prevention strategies continue combining trusted identity with ongoing monitoring, comprehensive risk screening and assessment, and proactive investigation when something seems off.
Digital identity wallets are part of the future, not the entire answer
Digital identity wallets represent an important step forward in how trusted identity information may be shared across organisations in the not-too-distant future. As regulatory frameworks continue developing and adoption increases, they’ll likely become a familiar part of financial services onboarding.
But that doesn’t mean physical identity documents will disappear overnight. Nor does it mean your AML obligations go away, or fraud suddenly stops altogether.
For compliance teams in regulated firms, the focus should be on how digital identity wallets fit into existing onboarding and AML processes, not on replacing them. As regulation and digital identity continues to evolve, organisations will need onboarding processes that can accept trusted digital credentials while continuing to apply proportionate risk assessments, customer due diligence and financial crime controls. make this sound simpler.
Technology continues to evolve, but the objective remains the same: Know who your customer is, understand the level of risk they present, make informed decisions using trusted information, and continue monitoring that relationship throughout its lifecycle.
