Skip to content
Regulation•September 22, 2026•5 min read

A standard becomes real when others qualify for it

The market has learned to ask whether a person is real. It is still weaker at asking whether an organisation, role and authority are bound to a legal root that another party can verify.The point is not to claim a new product has gone live. The point is to name the standard a serious market should us

A standard becomes real when others qualify for it

The market has learned to ask whether a person is real. It is still weaker at asking whether an organisation, role and authority are bound to a legal root that another party can verify.The point is not to claim a new product has gone live. The point is to name the standard a serious market should use before it lets automation, money or data move under regulated conditions.

Most digital systems start with an internal answer. They ask whether an account is active, whether a key signs, whether a process ran, or whether a customer record contains the right documents. Those checks matter, but they are local. They tell one venue enough to proceed inside its own boundary. They do not create a shared basis that another venue, regulator, bank, issuer or auditor can consume without rebuilding the same trust work from the start.

That is why organisational identity is a governance problem before it is a cryptography problem. A key can be valid and still be attached to the wrong authority. A certificate can be current and still fail to answer which legal entity stands behind a role. The vLEI matters because it starts from the global LEI system and binds entity, role and credential into a chain that a relying party can test without accepting a private vendor's word for it.

It is building a Qualified vLEI Issuer capability and is in the process of obtaining the GLEIF accreditation. The application was submitted on 15 April 2026, and a working KERI/ACDC platform has been demoed to GLEIF. That is enough to argue for the standard. It is not permission to call LTIN accredited, certified, or already a QVI.

The test for organisational identity is therefore simple. Can a third party verify the legal root, the authority to act, and the evidence for the action without joining a private club or trusting a private summary? If the answer is no, the system may still be useful. It is not yet shared infrastructure for regulated markets.

A claim that is almost true is the one that costs trust.The result is less dramatic and more durable: a path from identity to policy to settlement where accountability is not added later, but designed into the venue from the start.

This is the practical reason to keep the language narrow. A venue can buy tools, hire reviewers and collect documents, yet still leave every counterparty doing the same work again. Shared infrastructure should reduce that repetition. It should give each participant a verifiable object rather than another private assurance. The discipline is not slower communication; it is faster reliance, because the proof travels with the action instead of sitting in a presentation, a policy folder or an after-the-fact report.

Tags

IdentityRoot

Share this article