top of page
Library - Portrait.png

Inclusive Digital Identity Should Verify People Without Designing Them Out

Sep 4
6 min read
BlindSpot Insights Accessibility and Universal Design branded article cover.


Inclusive digital identity should make it easier for people to prove who they are and reach the service they need. Yet identity verification is often designed around an assumed user: someone with a current photo ID, a compatible smartphone, reliable vision and dexterity, confidence with security prompts, stable access to email or mobile reception, and enough time to recover when the process fails. When any of those assumptions are wrong, the front door to a service can become the barrier.


Australia's Digital ID framework describes secure, convenient, voluntary and inclusive access as connected goals. That combination matters. A verification process is not successful simply because it resists fraud. It must also work for people who use screen readers, magnification, voice control or alternative input; people with cognitive disability; people whose appearance does not match an old document; and people who need support without surrendering privacy or independence. Security and accessibility are not competing features. Both determine whether a person can use the service safely.


Inclusive digital identity begins with more than WCAG conformance


The Digital ID (Accreditation) Rules require usability and accessibility testing for public-facing accredited services, alongside continuing attention to accessible and inclusive delivery. WCAG conformance is an important part of that work because it tests whether interfaces can be perceived, operated and understood across a range of technologies. It can identify problems such as unlabelled controls, poor focus order, inaccessible error messages and interactions that cannot be completed using a keyboard.


But conformance alone cannot tell an organisation whether its identity model excludes people. A technically accessible page may still require a document the person does not hold, a facial movement they cannot perform, a mobile device they cannot use or a support process that takes away control. Digital identity accessibility has to examine the complete service, including policy, evidence rules, technology, support and recovery. The real test is whether people with different circumstances can reach an equivalent verified outcome.


Digital identity accessibility must cover the whole verification journey


Identity verification is rarely one screen. It may involve creating an account, locating evidence, photographing documents, completing a biometric check, receiving a one-time code, accepting privacy information and returning to the service that originally asked for proof. Each handoff creates another opportunity for information, focus, context or control to be lost. A user may complete the accessible part successfully and still be blocked by a third-party camera flow or an email link that expires before they can navigate back.


Teams should therefore map verification as an end-to-end journey rather than testing individual components in isolation. Include the steps before and after the identity provider, the devices and channels people use, and what happens when confidence scores are low. Test with disabled people using their own assistive technology and ordinary settings. A laboratory can confirm that a button has a name. Only realistic use can show whether the person understands why they are being asked for evidence, can complete the sequence and knows how to recover.


Accessible identity verification needs equivalent pathways


A choice is only inclusive when each option can deliver the same outcome without unreasonable extra effort. Offering a phone number after an inaccessible online process may look like an alternative, but it is not equivalent if the caller waits for an hour, repeats sensitive information, receives reduced service or must attend in person. The accessible route cannot be a slower lane with fewer rights. It should be designed, staffed and measured as part of the core service.


Equivalent pathways also reduce operational risk. A person may be unable to use the preferred method temporarily because a camera is broken, a document is damaged, mobile coverage is poor or an account has been compromised. Designing more than one credible path helps disabled users and makes the service more resilient for everyone. The aim is not to remove assurance. It is to obtain appropriate assurance through methods that recognise real variation in bodies, technologies, evidence and circumstances.


Biometrics can reduce effort and create new barriers


Biometric verification can be convenient. It may remove the need to remember credentials or type complex information, and a one-to-one match can provide strong assurance. It can also fail in ways that are difficult for the user to understand. Camera positioning may be hard for someone with limited dexterity or vision. Instructions to turn, blink or hold still may not be possible for everyone. Facial difference, tremor, lighting, older devices and assistive equipment can affect the capture even when the person is legitimate.


The response to a failed biometric check should never imply that the person is the problem. Explain what happened in plain language, avoid repeated attempts that increase frustration, and offer an equivalent route before the user is locked out. Privacy must remain visible as well. The Office of the Australian Information Commissioner treats biometric information used for automated verification as sensitive information, and Australia's Digital ID safeguards place limits around its handling. An inclusive service collects only what it needs and does not force people to trade unnecessary personal information for access.


Security controls should not become cognitive tests


Authentication often adds mental effort in the name of security. People may be asked to remember passwords, transcribe short-lived codes, solve visual puzzles, recognise objects or move rapidly between devices. These steps can exclude people with cognitive disability, low vision, reading difficulty, fatigue or limited dexterity. They can also create failures for anyone under pressure. A control that legitimate users cannot complete reliably is not delivering a good security outcome.


WCAG 2.2 includes Accessible Authentication at Level AA. Its intent is to avoid requiring people to solve, recall or transcribe information unless an alternative or an assisting mechanism is available. Password managers, correctly identified fields and the ability to paste a code can reduce cognitive load without weakening the control. Clear error messages and consistent help matter just as much. Users should know what went wrong, whether their evidence was retained and what they can safely try next.


Assisted support is part of the service, not an exception


Australian accreditation rules recognise assisted digital support as part of accessible digital identity. That is a useful design principle beyond accredited providers. Some people will need help because the process is unfamiliar, the technology is inaccessible or their evidence does not fit the standard path. Support should be easy to find before failure, available through more than one channel and capable of resolving the issue rather than simply reading the same instructions aloud.


Good support preserves agency. Staff need clear authority, privacy-safe ways to confirm consent and procedures for working with interpreters, nominees or trusted supporters where appropriate. They also need an escalation route when the system repeatedly rejects a legitimate person. Recording these contacts as service evidence can reveal patterns that automated completion data misses. If the same step generates recurring support demand, the answer is not always more training for users. It may be a design defect.


What an inclusive verification service should include


  • More than one verification pathway: Provide credible options that achieve equivalent assurance and access, including a clear route when documents, devices or biometrics cannot be used.

  • Accessible authentication: Support password managers, copy and paste, properly identified fields, keyboard operation and alternatives to cognitive or visual puzzles.

  • Plain-language decisions: Explain what evidence is required, why it is needed, what failed and what the person can do next without exposing security-sensitive detail.

  • Early assisted support: Make help visible throughout the journey and ensure staff can resolve non-standard cases while protecting privacy, dignity and control.

  • Testing with disabled people: Include participants with varied access needs, devices, evidence and confidence levels, then test recovery paths as carefully as the preferred journey.

  • Accountable exception handling: Give named teams authority to review repeated failures, identify systemic patterns and change rules or technology when legitimate users are being excluded.


Measure who completes the journey and who disappears


A high overall completion rate can hide concentrated exclusion. Organisations should examine where users abandon the process, how many attempts they make, which devices or methods fail and how often people need manual support. Qualitative evidence is essential because a dashboard cannot explain whether someone left due to an inaccessible instruction, fear about biometrics, an expired code or the absence of acceptable evidence.


Feedback and complaints should be connected to service ownership, not treated as isolated support cases. The accreditation framework expects feedback on usability and accessibility to inform design where appropriate. That turns accessibility into continuous improvement rather than a periodic audit. Measures should also include the quality of the alternative path: waiting time, successful resolution, privacy impact and whether the person ultimately received the same service.


Identity should open the door, not become the barrier


Identity verification sits at a powerful point in a service. If it works, people may barely notice it. If it fails, nothing beyond it matters. The application, account, payment, entitlement or appointment remains out of reach, even when every later screen is accessible. That is why inclusive digital identity needs ownership across security, accessibility, privacy, operations and customer service rather than being left to one technical team.


The better design question is not whether most people can pass the preferred check. It is whether the organisation can verify legitimate people securely across the real range of human circumstances. When equivalent pathways, accessible authentication, respectful support and evidence-led improvement are built in from the beginning, identity can do what it is meant to do: establish trust and let people move forward.


References

bottom of page