Well, welcome everyone and first of all, really thank you for being here. We had four days, very intense days, this is almost end of our journey and I'm super glad that you guys still have energy to be here, so really very appreciated, thank you. My name is Anna, I am Customer Identity Domain Lead at PwC Netherlands and we also act as a center of excellence for the rest of Europe. I'm an identity already for 15 years, doing multiple projects with IAM, not only Customer Identity but more general IAM, but Customer Identity is my personal passion.
I'm not alone, within PwC we have a big team, it's more than a thousand people across the globe that provide identity services and it's from strategy definition, helping to shape the governance and policies to actual implementation, implementing IAM solutions and operating them.
I think you guys been already in four days, even those who have never ever heard about Digital Identity Wallets, you probably already know a lot, you know the concept, you know why, you know different options, so I'm not going to dive into that because I just don't want to repeat what everyone else was telling and actually I was also thinking what I actually can add on top of what you already heard in these four days and I think the important part that is kind of obvious but we never explicitly talk about that is what is the role of IAM in all that, where does actually wallets and making a step back verifiable credentials, where do they fit in IAM and of course the next one is of course OK, how do we make verifiable credentials live.
So before we go into that, let's define our problem.
Today, most, well I think all organizations, they have their digital identity process, some are good, some are pretty much basic, but we all have it as an organization and we did quite a good job in digitalizing our identity, so an organization would have quite a lot of information about me, as an employee, they know a lot about me, as a service provider, they would also know all my details, but that's when I'm already a customer or an employee or a contractor, when I want to act cross organization or when I want to become a new customer to a service provider, that's when I have to go through all this onboarding processes over and over again and again proves that yes, this picture is indeed me 20 years ago, yes, something like that and that's where verifiable credentials actually close the gap and they help to use the information that is outside of the organization to actually also apply to verify who you are and to provide certain services.
To do that, we of course need to establish a certain trust framework and European Digital Identity, EIDAS, is actually a very good example of that, yes, so we define three main players within this ecosystem, which is an issuer, so someone who would create and sign certain credentials for the user, there is a holder, so basically a user is the one who holds these credentials and make a decision who they want to show it at what time and what exactly they want to show and of course there is a verifier, so basically it's the one who needs to get these credentials in order to provide certain services and need to be able to verify whether it is, well, right transverse credentials.
For them to operate, we need a trust framework like, for example, EIDAS, yes, so this framework would define the rules how all these guys will work together, so who is an issuer, what they are allowed to issue, what is the level of assurance of the credentials that's the issue, how would the verifier actually get, will be able to verify it, how do they talk to each other, how do they communicate with each other, so this all is defined in the trust framework and it's a very powerful tool, however, that would not work alone, because all these credentials, all these verifiable credentials, they need to go somewhere to make a decision and, well, stating an obvious, yes, this something will be an IAM system, so to put it in perspective, you have a verifiable credentials, they carry trust, that's something that you can trust based on the trust framework, they will be stored in identity wallet, normally identity wallet, it's not the only solution, but the most common, which is basically interface between user, verifier and issuer, and of course they go to verifier, because verifier will know what exactly they need to make a decision, but then it will be fitted to IAM system, that will actually finally decide, okay, am I allowed to log in, am I old enough, do I have sufficient certificates, for example, to perform a certain job, so that's where IAM becomes an integral part of all that ecosystem, and without having these basics, verifiable credentials will not bring you any business value, so having established that, let's also think about, okay, but what kind of use cases we can actually make with verifiable credentials, because, well, we're here to get them to production, right?
So within PwC, we collaborate with multiple vendors and representatives in the wallet ecosystem, and one of our partners is an integrator, they basically integrate multiple wallets into one solution, so that the organization doesn't need to connect to all the wallets, but only to that party.
Together with them, we made an analysis of roughly more than 50 wallets that operate, that are already available, that operate within and outside Europe, and very bad coloring, but basically, up to driving license, colors, probably you would not see all the colors, but up to driving license, these are attributes that you can normally find in wallets that are available on the market, at least those that are publicly available.
You can already make quite a lot of use cases out of them, yes, so you can leverage these attributes to improve your onboarding process, authentication process, you can use it also as an organization to onboard your employees, because, well, you have quite a lot of information about the user.
However, it makes me a little bit sad, yes, it's futuristic use cases, like I remember last year, we were discussing a lot of them, like, imagine that we can prove that we have a certain master degree, or imagine that we can prove our, I don't know, years of experience just using a wallet, that's great, but it's not yet available on the market.
And that actually makes also the process of thinking for many organizations, how we are going to implement or leverage wallets over verifiable credentials, because it's not only about the use cases that you really want to implement, it's also about what is available, either already on the existing wallets, or you might potentially decide to create your own wallet, for example, it makes a lot of sense for organizations, for complex organizations who have multiple partners, multiple third party providers, and for them to manage the third parties is always a nightmare, being in the field for very long, this is one of the biggest problems for many companies.
Or take another example, when there is one company, but with multiple operational units that normally work in silos, but they still need to use services from each other. In these cases, you can actually also think about implementing wallets for your own purposes. But then you still get back to the same question, okay, what data do I have available? What can I use to actually do the use cases that I want? And also like, okay, I have certain data, how does it help me to make a better decision? And do these efforts actually to improve this user journey, do these efforts worth it?
Because in all honesty, if you look on the complex organizations, again, the next challenge that is very common everywhere is basically data, they're fragmented, they're not always trustworthy, they're in completely multiple different sources. And before you even think about verifiable credentials, you need to fix the data. Because if you start building your solution based on this fragmented data, well, you will not get the outcomes that you want. And there is not only things that you need to think about.
So within PwC, we have a couple of big projects inside and outside of Europe, where we help our clients to implement wallets to, well, yeah, to leverage basically either already existing frameworks, or even to create new frameworks for the wallet, for verifiable credential ecosystem. And we see certain common decision points. So that's what we summarized.
And it is like a small part of the framework, where we summarized all the decision points that an organization needs to go through when they either want just to implement a wallet, or they actually want to build their own ecosystem, including the wallet. And I believe in both cases, wallet is not the only thing you need to worry about.
So if you're considering about leveraging a wallet, and basically implementing a wallet ecosystem in your system, the first thing is that you need to say, obviously, data, but then also all the decisions about the issuers, who are the issuers in your organization? How do you do a lifecycle of information? What is the level of assurance, basically, how much you can trust the data that you as a verifier will receive? And then of course, you move to a wallet, yes, there are available wallets, there are white labeled wallets, you can implement your own wallet.
But basically, as I mentioned before, wallet is an interface between the user and other systems and other parties. And that means that you need to answer the same questions as we normally ask in customer identity. So what is the user experience for this wallet? What is the security around this wallet? How would I as an organization onboard my user to the wallet, not only to your system and services, to the wallet? How would customer authenticate? What if they lost access to the wallet? How would it be? How would he be able or she will be able to recover the access?
And on top of that, okay, how a user can add new attributes, how they can update it, how they can recall it, and so on, so on. And plus to that, how they can control all the attributes that they provided to multiple systems. So that's a wallet part. And then of course, as I mentioned before, we go to IAM, the basic of all of that. And then you already think about, okay, how is my process of onboarding, authentication or recovering is impacted by this new source of data that they have? Because what is changing, you are not owning this data anymore within your organization.
They're somewhere else. So how do I make a decision based on the data I have?
When do I, for example, trigger a security alarm? Or when do I trigger additional authentication? Or how I can actually leverage to improve the UX of my, I don't know, customers or employees? And on top of all that, you of course think about the governance and how you're going to operate all this ecosystem. So there are multiple decision points that you need to take, you need to design, before you actually start thinking about, well, let's apply it in life. And when you have that, then you have two easy remaining steps, basically implement and scale.
Well, I'm joking a little bit here, yeah? It's not that easy, of course. But and you probably, and probably that's not a rocket science. But most of the projects that you work on, they go more or less through the same steps. You need to discover your use cases, you need to do some certain gap analysis, you need to do design and implement and operate it. The thing is that I speak with multiple organizations who actually really happy to jump into POC and they really try to do something with verifiable credentials. And they actually do and it works. And the thing is that they stop on POC.
It never goes farther than that. And the reason for that, because organization is not ready, their data is not ready, they cannot scale it. So they took a small use case, it works, that's great. But other data doesn't work. And the most important, the basic one, this layer is not ready to accommodate the verifiable credentials.
So here, if you want to get them to production, you really need to look on your basics first. And really understand, okay, what do I need to improve within IAM or add additional features there? How do I can, how can I actually improve my data so that then I can get the best value out of verifiable credentials? That's it. Perfect.
Thank you, Anna. Yeah. We have a question. Okay. It is related to that slide. I think it is, which part is the, in the key decision is currently underestimated most technology governance or operational integration? It's the most important one. The one that is currently underestimated. Underestimated.
Well, I'm a business consultant. So I always say that governance is always underestimated, but it's really true. Because if you have a proper governance setup, if you have really advocated advocates in your organization who really want to push that forward, you will get to the result. Eventually technology, you will figure it out. But if you don't have this common understanding within organizations that yes, this is a way forward and you don't have supporters and you don't know who's responsible for what, none of the project will fly. 100% true. Thank you.