I am going to talk about the value of legal person wallets, but mainly about organisation data. Coming from a banking background, I have a lot of experience with organisational data and how to work with that. And if you combine it with all the wallet stuff, I felt the need to sort of make an easy sort of vision on, okay, what do we do here? What's actually the summary of all this? Because there's so many details everywhere. The clicker. Next.
So, there should be a lot of value in business value, as you see lots of money and gold to be dug there. But how to do that and what's meant?
So, you're a medium-sized business and you're not aware of any of the EIDAS regulation. You have no idea what a wallet is and you're just having a lot of struggles with your organisation data and business-to-business relations and all that.
So, what would you need to know? Of course, actually, you should know a little bit about EIDAS II regulation, about what a natural person identity wallet would be. Then maybe what a legal person identity is at all. And then legal person identity wallets, which are two different things, of course. And then what do they need to know?
Well, for companies, they only want to know the value, of course, and what's in it for me. Now, if we look at the EU regulation, what does that say about a digital identity wallet? It should be for natural and legal persons, that's literally written there.
And, well, identification means enabling the authentication and the sharing of data, blah, blah, blah. Then in the other article, it says, and then it's getting, there we get the complexity, which is actually, you would want to draw a schema about that. The person identification data, uniquely representing the natural person, legal person, or the natural person, representing the natural person and legal person.
So that's, wow, I'm already lost there. So, and it should be associated with that digital identity wallet.
So, yeah, it's a lot of persons and representation of representations and persons. And if you then add the whole delegation and authorization set to it, I'm already lost.
Well, and what is a legal person? Well, that's also not so clear. There are a lot of EU directives, and this is one of the descriptions I found. And in member states, that could be different. That a legal person means an entity having a legal personality under the applicable law.
Okay, there you go, applicable law, except for state or public bodies in the exercise of state authority and public international organizations, blah, blah, blah. So it means my governance would not be a legal person.
Well, I think we may have a gap there, isn't it? So, yeah, here we are.
Well, okay, let's start simple with a natural person wallet. Everyone knows what a natural person wallet is, at least everyone in this room. The business people don't know. I call it a secure personal one-person platform where I can have a single dashboard for all the data routing that I do with all these relying parties, attributes to be shown from authentic sources for individual users, use cases depending on whatever I want to connect, and of course, depending on the identity and enrollment strengths, how strong is the identity tied to that wallet.
If there's not a lot of strength in that identity, yeah, I have different use cases than if there's a government identity. And also, that is depending on how strong the identity onboarding process would be. And the trust levels, of course, of all the issuers.
Now, there's a lot of things about there. And of course, I'm using this, and in the market, you see a lot of confusion because distributed identity, decentralized identity, self-sovereign identity, it's in mixed use. But many people, as I said before, they think, well, that's the app, and that's where you have your authentications. And we don't know what's under the hood. And that's a complete different paradigm switch from federated identity, siloed identity, user-based identity, user-managed identity. So you have, actually, it's a big federation of federations of ecosystems.
But not just platforms federating identity for you, but you are your own identity federation platform. So you can imagine the whole mesh of complexity. And now we're adding this legal person wallet.
Now, natural person identity. Some examples, if you have your IKEA ID, it's issued by IKEA, it's relied upon by IKEA, and it's accepted there. And most of the time, it's self-enrolled. So it has not that much value or weight. For generic purposes. The DID identifiers, we also all know, has a bit larger thing, because it's wider, more generic, accepted. And if we have a national identity issued by our government, well, then you really have got a thing. It could be even your mobile driving license could be in there. So it means the enrollment is more strong.
It can read your NFC chip from your passport. The real data from the real source.
And, well, it's a qualified service provider certified by the EU, and it's in a really well done certified EU wallet. So, well, there's more business value. And of course, then we have the bank idea. If they use EU certified wallet, and they issue your identity, not just with government identity, as they have to do, they have to do the whole KYC before they're allowed to do any business at all with you as a person. And for a legal entity, it's even worse. So they have a lot of identity verification. We call it personal political exposure, for instance.
Are you married to someone who is in the Oval Office? It means you have different requirements and they can't do business with you.
Of course, don't you have a synthetic identity? Is your passport really your passport? A lot of things that are not done by the government, they just issue and make you rely on it. But the bank has to do a lot more things than just that.
And also, they could tie it to your bank app. That could be a wallet in itself.
And well, they have a lot more things and also your registered device, which in the government is a bit more not so connected. So in my opinion, the bank is the strongest bank, strongest identity you can have because it includes all the others. And I know I've been head of IAM in the banks, and I know you get a whole ton of auditors three times per year, the European Central Bank, the local auditor, the internal auditor, the external auditor, and they really go through all your systems and want to see how you did and by hindsight. So that's a really weight of them.
Now we have the organisation data. I've been struggling with that as well because if I had to build all the identities of the whole bank, employee identities, and I wanted to make sure that I also knew in what department they would work so I could do my role-based access control. So in this department, you can do this and the other department, you can do that. So you have natural person identity of your employees and you want to tie it to their work location, their organisation part.
Well, then you have a big challenge. And that was back in the year 2003, I was doing this for ING.
And okay, let's draw the organisation tree. Okay, we have all codes. They're connected to the cost centre code, financial hierarchies, but they add something. So it's a different format, but it's an extension on the cost centre codes. Then we have the legal structure, which is obviously for tax purposes, completely different from the hierarchic lines because we don't want to pay extra tax when some services, internal services, go cross-border and back.
So we do an office in Switzerland, which is a legal entity because we have less tax, but actually their performance in the hierarchic lines and the reporting lines, no, they're different. And then we bought ING bearings for one euro or one guilder, I don't remember, the Nick Leeson scam. So we got 15 extra countries and a completely different legal entity and they had their own org structure. And mergers and acquisitions make it even worse.
And in the internal organisation structure of one corporate, you would have many independent legal entities and there was a whole data dictionary on all these, it's called Cosmos, they had internally, that held all the names and legal entity structures and they were never, ever, ever compatible with each other. That was really a problem. And of course, then you can do it according to hierarchic geography, geography location. You can have a matrix of organisations and in many corporates, you have all of that at the same time or you have none of them and you don't know who's owning it.
And in certain cases, it's even worse because today we have all these supply chains. They could be suppliers or they could be daughters, tied agents. You really need to be a lawyer to understand an org structure of a corporate with multiple seats in many countries. And you never know who owns all that data. That's really scattered data and no one wants to be accountable for that. So what to do? Can you trust it? Is it up to date? Where to find the owner? Where to find the whole database? It's a lot worse than personal entities.
And then we have the AML for legal entities and it's going to be refreshed. As you said, we had the legal entity wallet structure and that has a lot of things about the KYC for legal entities, not persons.
Now, I've been looking and trying to find what type of legal global identity providers do we have, which are external to the companies, but for instance, could be your VAT, tax registration number, the decentralized identifiers, of course, the SWIFT codes for the financial industry, then, well, AMSI, the VLI and LI, I'm really a fan of those. It's the GLIFE organization. I always try to promote them because they have, well, there's another slide about that. Then there is the Dun & Bradstreet number and it's not really obsolete, but it's what if two come, they do that as a company.
They keep track of companies and their financial stance. You know, if you don't trust someone, you can ask for their number. You can ask even for the financial status through Dun & Bradstreet. But of course, if there are mergers and acquisitions, this whole number is not valid anymore because now we are one company and used to be two. If I want to go back into historic data, that's even more difficult.
Of course, the international standard naming identifier. Well, if I'm a business and I want to know more about the whole legal wallet things, there's a lot of complexity in the data only. So the data formats are not the same. The assurance levels are not the same. Historic data could be a problem. You want to know that the issuing process for issuing these numbers is also not tampered with. You want global coverage because you want to do business globally, cross-border. And of course, there's so many types of legal entities with different authorities.
So anyway, the same diversity as the personal wallet data and identities, but a bit more complex because companies are more complex. Now, so what would we want from a legal entity, person, legal person, or legal entity ID? Legal person identity, legal entity identity, or organization identity? We would want it to be unique globally and persistent so we could always find it somewhere. We would want it to be legally globally recognized and it should be from trusted issuers. It should be verifiable, standardized in format so it's easy to share.
And the semantics and taxonomies should also be clear. And that, I think the taxonomy is the most difficult part, like the org structures. And it should be up to date, of course. And all these organization, internal, external, and supply chain, whatever relations and liabilities when you get to the legal part, of course, that's why you want to know this. You want to know who's liable and who is, if you're dealing with them, not just who they are, but also what their liability is. So the relations are also important.
I used to be working about the anti-money laundering regulation sort of data, the KYC for legal entities. And if you really make it very simple, a legal entity KYC process needs you to have all the beneficial owners' identity validated and that they are really working for that company. And the same for the representatives. They shouldn't be the ultimate beneficial owners, but they could be only a representation. Their identity verification, like the one you do if they were a customer, like the background checks, the whole thing, all these people. And they should be tied to that legal entity.
And of course, is this really a registered legal entity? So you have both natural person problems to validate them and legal entity problems. And coming from the banking background, I knew at that time, I think when I left my last banking position in the Netherlands, a generic bank like ABN AMRO or maybe ING would spend 100 million per year just for KYC. And natural person KYC, you have to do it if there's a trigger and then you don't trust them. And same for legal entity KYC. There should be a three-year repeat.
Every three year you have to revalidate these people, otherwise you're not compliant. So 100 million per year just for identity verification of your customers.
Imagine, I think that's all that gold which we should mine. And yeah, so only for this use case, KYC, customer due diligence, I think there's a lot of business value. And that's Blockchain Coalition. They've been existing for a long time. They have a company passport, which is sort of a way connecting to the wallet sort of setup.
Well, I'm not going to speak on their behalf, but they were offsetting this up with the tax office, the notaries, the chamber of commerce, all the financial, the large banks that I used to work for. And they're really finding out in a very premature way how to make this work. But once more, the GLEIF, they have a really well-established, I think they exist 10 years, last year. So they're really for the regular, they have a regulatory oversight board, the financial stability board, the G20, they're all endorsing this. So their processes should be secure and safe. It's a 20-digit code.
It's free if you want to. You can, there is APIs. You can download it. You can download all these GLEIFs. You can look your own GLEIF. You can register for a GLEIF and you're in that database. So I think this is a very good global startup. And I'm checking every now and then, and every half year, they have half a million more, but still registered active GLEIFs. Go to their website. It's really good to know. I think they could really be supported and also they could help others.
Now, I did a request together with Hank Marsman. I think, Hank, are you in the room?
But no, not sure. We did a, yeah, there you are. We did a questionnaire among identity, so people who are all identity experts. We did a questionnaire on, what do you think has the, who will have the most benefit of the UD wallet? And this was one of the 10 questions. And their answers were, would that be individual users, the government, or companies and organizations? And now I'm going to ask you, as identity in this room, who thinks individual users would be the most, having the most benefit of UD wallets, personal or legal wallets?
Okay, no one? No fingers? Raise your hand. I only see a few hesitant people. Maybe not even 5%, 3%, is that correct?
Yeah, okay. The identity that we asked, 45% of them thought that individual users would have the most benefit. Then the question is, who thinks governments will have the most benefit? You're all very hesitant. Maybe also not even 3% to 5%. So I'm in a good room. The next one is organizations. Who thinks organizations will have the most?
Yeah, there we are, okay. Well, this audience thought only 3%, and this was done this year in January, February. So it's recent information. Maybe the N is one, or the N was really too small, because we didn't have all of our identity that we could talk to.
And only, so that would look like that. I think in this room we have a different view. And the legal personal identity would have most impact, only 27% thought that.
So, well, the benefits of legal person identities, I think we've seen that in the previous slide. I'm also a bit running out of time. But of course, if you could skip only the KYC process for banks, that's 100 million per bank per year, or more if they are larger banks, then you've already got, don't talk about healthcare and all that stuff. So know your customer, know their business, your representative, business-to-business transparency, and compliance alone, if you can evade all these problems.
And risk reduction and fraud prevention, those are qualitative benefits that are not easy to quantify. So, it also saves you a lot of time for an effort for waiting for PII data, personal identifiable data, less data to store, less data to protect, to update, higher business-to-business transparency.
And, well, I think this is all clear. We've seen that in the previous. But I had one question, or one thing which is bothering me. Would we need a company wallet to get all this? Or would it be a company EAA, an attestation that I, as a person, I'm working for this company, and I'm vetted, what would be more feasible? I think those two things shouldn't exist next to each other, like all the other attributes that you had in your wallet.
And I've worked for an infrastructure company in the Netherlands building railways, managing our railways, and they have 600 partners, and they are on site for two weeks, and then they're gone. The vetting happens at these partners, and the user management is done, well, who does that? So they're onboarding for these employees. It's immense if you would have to do that really, really thoroughly, and they're struggling with that.
But if you would have just an attestation that I'm working for this company, my identity has been verified, I've done my background checks, so I'm not on a blacklist or whatever, I think there would also be a lot of fraud prevention. And in the Netherlands, we have a lot of fraud with people who work in healthcare supporting elderly people, and they're not even certified to do that. So they're coming to see my 90-year-old mom, and they're just sitting there working with their phone.
My mom comes whether they've done the cleaning, and they have not done anything, and they're not even intending to do anything. If you had the registration as a healthcare person in the wallet or whatever, I mean, yeah, I think that could be very easy. So my question is, which paradigm should be better, only the attestation or the company wallet, because that would be a lot of things to go through. You have all the things you have to go through, the rule book of what to do to issue such a wallet, to have your company ID in that wallet, all those procedures to validate all the people.
This is really, I think there are 10 RFCs that are published on GitHub of the EWC consortium. That's a lot of text, just describing all the processes and things and formats and standards and that. So I think we have a long way to go to get that whole wallet thing going on. But if we could have the legal identity registration and issuance to individuals, if we could start with that, I think that would also be very valuable for small to medium businesses who are not going to have their own company wallet. So what would be the happy flow?
I'm really curious to see next year in the same room what the statistics would be from real-life production environments. I don't think I've seen any so far. Maybe not European compliant, but maybe there could be other ones who are not in Europe or not EU compliant. So that's going to be the big challenge, the big surprise. So I'm not keeping you from lunch now. Thanks for your attention.