0:04 – Excellent. Thank you. Okay. Good afternoon all. Apologies for being your
0:11 remote speaker of the day. Unfortunately, I couldn't get across from the UK to join
0:15 for this. But I'd like to spend the next 10 minutes looking at something slightly
0:19 different in terms of the presentations that have happened so far. We've heard an
0:24 awful lot today about what SEDI can protect from the fraud, making sure
0:29 everything is assured, making sure we have the assertions, making sure child age
0:34 verification and adult age verification can be put in place. I'd like to spend a
0:38 few minutes looking at the flip side of that and looking at economic benefit as a
0:42 result of a state-endorsed digital identity and what can be achieved there
0:45 and bring forwards a proof point to show that this has happened and the sort of
0:50 values that can be expected from that. So, Simon Wood, I've been involved in identity
0:56 systems for a long time now. Most recently, Group CEO of Ubisecure.
1:00 Ubisecure is a UK company but deploys a lot in the Nordics. Ubisecure has deployed
1:05 a number of platforms in Finland and Sweden and the case study is taken from
1:09 there. One of the things I'd just like to touch on before getting into that is a
1:14 differentiator that McKinsey makes on digital identity versus advanced identity.
1:19 Everything that has been spoken about today, I would say falls in that advanced
1:23 identity category as defined by McKinsey. In the UK, we're obviously reeling at the
1:28 moment from the brick card announcements and so on. And the McKinsey report is
1:33 often rolled out as one of the values for having an identity and it's referred to as
1:38 digital identity in the general sense. But if you read that report in detail, you'll
1:43 see that to benefit from the advanced capabilities and the returns and the GDP
1:48 increases that are positioned there specifically for the US and for the UK, it
1:53 needs to be advanced identity, which brings in additional attributes,
1:57 additional information, and additional features as well. You've already seen a
2:01 number of demonstrations of those today in a SEDI context. And that's what we're
2:05 looking at here. We're looking at those advanced capabilities beyond just
2:09 authentication and authorization, which is McKinsey's classical definition of digital
2:14 identity. I want to run you through a very quick scenario. You've seen a couple of
2:19 diagrams like this already today where we have a chain of delegation. Fiknish's
2:26 example here, we'll look at setting up new company in Utah. So, the CEO of that
2:32 company to be contacts the Utah division of corporations, goes online and uses
2:38 their steady identity to register that company. The Utah division of corporations
2:43 automatically passes that across to the state tax commission because there will be
2:47 taxes to pay and collect from that organization. And the tax commission will
2:53 send a request back to the CEO using let's assume that there's a secure mailbox
2:57 capability from a SEDI implementation. So you can securely contact people who have
3:03 that identity and request that tax registration. The CEO will obviously go to
3:08 that website, register to submit the taxes, but then the CEO themselves will
3:13 not be undertaking that work. They will delegate that capability to the CFO of the
3:18 organization. So that delegation will be done through the website. The CEO will
3:22 invite the CFO to that system using their SEDI identity as well. And so a delegation
3:28 chain is built. You've seen examples of such a delegation chain already in a
3:32 couple of the demos that have been delivered today. But if we consider that
3:36 tax is reasonably complex, you might have three different types of sales tax,
3:40 corporation tax, employment tax. Maybe the employment tax is outsourced to an
3:45 organization. So that organization can be invited in and delegated to. The
3:50 administrator in the organization can pick that up and then onwards delegate to an
3:54 internal accountant. So we've got a chain of delegations running through individuals
3:57 and organizations using an identity that's highly assured and available to them. This
4:03 delegation chain builds and allows all of the tax to take place and not once as the
4:09 state tax commission being involved in that they've just provided that service to
4:13 allow it to happen. Now this seems like a great scenario. If that were true, what
4:17 would deliver us? Well, that does happen already in Finland. There is a platform
4:25 delivered in 2008 Wait. Hi.
4:32 I believe so. Are they not coming through? That will help.
4:44 How's that? So, just to reiterate that previous slide so you can see what was
4:52 there. It's a delegation chain across individuals and through an organization
4:57 there towards the bottom as we have around here. Chris, I assume that's coming
5:02 through now.
5:18 Is that okay?
5:24 I think that's okay. So, So this platform was delivered or it is delivered in
5:30 Finland. It's called the Katso platform delivered in 2008. It is a state operated
5:35 platform as opposed to state endorsed back in 2008. There was not this distinction
5:39 and this understanding of privacy and how important that that is as we acknowledge
5:43 today. State operated platform integrates with the business registry to generate
5:49 that link to the tax office. In 2018, the Finnish government published stats on the
5:55 savings as a result of of having that platform. And when they published that at
5:59 that time there were 450,000 users registered on there, the 420,000
6:04 organizations and 104 different online government services using that platform.
6:10 One of those services was the tax office and it worked exactly as I just described
6:15 in that delegation chain that's there. In terms of the stats that were collected on
6:20 that, a significant reduction in physical service points because everything was
6:24 online and everything was driven by the organization that was registering, they
6:30 could massively reduce the physical points of presence that allowed them to make a 20
6:34 % year-on-year tax admin staff reduction, repurpose them to more profitable areas
6:39 and the cost of servicing the tax transactions when they went from the old
6:43 physical base to an online basis dropped from 35 euros per tax transaction to 30
6:49 euro cents. That's a 99% reduction in cost per transaction measured by the Finnish
6:55 government. That's the value that they achieved deploying a highly assured
7:00 identity that has delegation capabilities, that has the ability to work across
7:06 individuals and organizations.
7:10 Within that, you've heard me talking about organizations. Organizations are an
7:14 important part of the identity chain. Incorporating an organization identity
7:19 enables the really advanced identity use cases and that's where we see a lot of the
7:23 economic benefit coming from. Now, it would be wrong to assume that
7:27 organizations are just legal entities. We get a lot of utility and benefit from
7:31 lower assurance levels of organizations. Just like individual identities, there can
7:35 be low assurance and high assurance, and we see economic savings at higher
7:39 assurance levels. You've heard multiple times today that SB260 already considers
7:44 organization identity in the form of family units and family structures. That
7:49 is an organization. There's no reason not to have the ability ultimately to extend
7:54 that to bring in private sector legal entities as well to take advantage of that
7:59 massive uplift in utility and economic potential that comes from there. So to
8:06 conclude from there, we've seen already that SEDI has phenomenal potential for
8:14 protection for implementing privacy and for making sure that state citizens, the
8:20 public gets the protection and the facilities that they need need. But once
8:25 that's up and running, then extending that to organization identity will bring
8:30 significant benefit as well. We've heard again a number of times that we shouldn't
8:37 let private sector define this and I fully agree it needs to be run at the policy
8:42 level, generating the privacy that's needed, ensuring that's first and then
8:46 bringing utility and benefit to public sector organizations afterwards. But
8:51 incorporating those public sector organizations and allowing them to
8:55 leverage that information and be involved in there and integrate their platforms and
8:59 their systems to that will bring significant benefit. And what has already
9:03 happened in the Nordics and in the Baltics gives very strong proof points to show
9:07 what can be done and the level of savings and level of return that can be achieved
9:11 there. I've run through this very quickly. I realize this is remote and a little bit
9:15 more complicated. But I believe the slides in this recording will be out later. So
9:21 you can always contact me afterwards or Chris can put you in contact and I can
9:24 provide more information if that's useful. Thank you very much.