← All Making

Built proposition · Digital identity · Red Dot, 2024

HSBC Trusted Identity

Proving what matters without revealing everything.

HSBC Trusted Identity project
What it was
An identity proposition built on selective disclosure, proving only what a specific exchange requires instead of handing over a full identity record.
Why it mattered
Digital services routinely ask for more personal information than an interaction needs, because verification and disclosure have historically been bundled together.
My role
Initiative Lead, Product Lead, within HSBC Emerging Tech, Innovation and Ventures.
Year
2024 (Red Dot Design Concept award year).
Status
Technology built and validated end to end, proven through integration with PayX. Submitted to Red Dot in the Design Concept category by design, not because the work stopped at prototype.
Strongest proof point
HSBC's first Red Dot design award, for technology that passed internal technical and governance review.

Verification and disclosure never had to be the same act

Every proof of identity usually reveals more than it needs to. Prove you are over eighteen, and a system asks for your full birth date. Prove you are an employee, and it asks for your whole HR record. Verification and disclosure get treated as one action, so every exchange leaks more than it should.

HSBC runs know-your-customer checks at a scale most institutions never touch. If a telecom's verified number or a government-issued ID can already stand in for part of someone's identity, a bank holding decades of verified relationships can stand in as a verifier too, not only as a consumer of other institutions' proof. Selective disclosure was the answer: prove only what a specific exchange requires, nothing more. I led it as Initiative Lead and Product Lead, within HSBC Emerging Tech, Innovation and Ventures, from the concept and the wallet to the business case and the specific fields a user would be asked for.

Three understandings, held together

My approach to emerging technology rests on three understandings, held together, not one instinct pushing the others.

The first is the technology itself, treated as a genuine set of new characteristics, not a tool applied to a preexisting problem. I distilled this from Trusted Identity into an internal DLT product playbook afterward, on my own initiative: on a distributed ledger, latency is a native property, not a bug; anonymity is something to design for, not around; consent can involve multiple parties and a time window, not a single click; and there is a state between done and pending that needs its own word, inflight. These are not limitations to route around. They are what a distributed ledger actually is, and product decisions should start from them, not treat them as friction to hide.

The second is the business the technology touches: KYC as a function inside a bank, its cost, its friction, and where selective disclosure actually changes that economics.

The third is the wider social and economic system the business sits inside, and where we stand within it: the trust fabric that decides who gets to vouch for a person's identity or creditworthiness, and whether a bank at HSBC's scale has standing to raise that question, not only to answer it.

None of the three produces a new direction alone. Holding all three together is what gives the confidence to propose one. Trusted Identity is where I tested this against a real product, not just a proposition.

What became real

The zero-knowledge-proof verification sequence is where the method met the work: the optimisation I tracked cut the wait time from roughly seventy seconds to roughly ten. I deployed the identity wallet and integrated it end to end with PayX, from bank-side verification through to a user opening and registering an account. The technology passed HSBC's internal technical and governance review, and it became HSBC's first Red Dot design award, entered deliberately as a Design Concept: a bank showing live production capability in a public award risks reading as a claim to investors, so the category is caution about optics, not a statement of how far the work had gone. It was not rolled out broadly, for regulatory reasons, a limit worth stating plainly rather than leaving implied.

The question this leaves open

As more of daily life runs through verified digital relationships, who gets to vouch for a person, and on what evidence. A bank holding decades of verified relationships has standing inside that trust fabric to raise this question, not only to answer whatever regulators or platforms eventually decide. Identity can support access and movement without turning a person into a transparent record, but only if restraint is designed into what a system asks to know from the start. That is still an open agenda, not a solved one, and it is the one I carried out of this project.

Continue exploring

Return to all Making →