From Digital Identity to Digital Trust: Building a Decentralized Identity Infrastructure for India

India has built a growing set of Digital Public Infrastructure ecosystems: DigiLocker, GSTN, Bharat Trade Net, Labour Stack, Health Stack, Agri Stack and others. Each serves a distinct domain, with its own institutions, participants and data. As these ecosystems mature, the challenge is shifting. It is no longer enough for systems to connect. An ecosystem increasingly needs to trust an identity or credential issued by another ecosystem.

Bharat Trade Net may need to establish a business’s GST registration or other regulatory credentials. Labour Stack may need to verify qualifications or professional credentials. Financial institutions may need to establish licences or approvals issued by government systems. Similar requirements will emerge across sectors.

Today, this trust is often established through platform-specific APIs and database verification. As the number of ecosystems grows, this creates a web of bilateral integrations and dependencies. The next generation of DPI therefore needs a common foundation for decentralized identity and trusted verification, allowing independent ecosystems to recognise and verify one another without becoming one platform.

Decentralised Identity, Shared Trust

The India Decentralized Identity Framework (IDIF) proposes such a foundation. It establishes a shared trust framework built around three components: a Governance Framework, a National Trust Registry and Federated Identity Registries.

The model does not create a central repository of identities or credentials. Each participating ecosystem retains responsibility for its identities, credential issuance and operational infrastructure. Its Identity Registry maintains decentralised identifiers, DID Documents and public verification information, while the National Trust Registry provides the common accreditation layer.

The distinction is important: identity remains decentralized; trust becomes interoperable.


From Database verification to Cryptographic Verification

The more fundamental change is how a credential is verified. In a database-dependent model, the verifier typically goes back to the issuing system to establish whether a credential is valid. With Verifiable Credentials, the issuer can digitally sign the credential and the recipient can independently verify that signature using trusted public-key information.

The issuing ecosystem remains authoritative for issuing the credential, but its underlying database does not have to participate in every subsequent verification. The IDIF framework explicitly proposes independent cryptographic verification without direct access to the issuing platform or database.

The shift is therefore: From “connect to the source to verify” to “verify the credential issued by a trusted source.”

APIs remain important for transactions and services requiring live information. They simply no longer need to carry the entire burden of establishing trust.

How Decentralised Trust works

For decentralized identity to work at national scale, trust itself needs a common structure. IDIF separates this into three mechanisms: governance and accreditation establish which registries are trusted; identity and key resolution establish who the issuer is and where its verification information can be obtained; cryptographic verification establishes that the credential was issued by that entity and has not been altered.

A verifier can therefore establish trust without necessarily accessing the issuer’s underlying database. The National Trust Registry establishes that the relevant Identity Registry is accredited; the DID Resolution Layer retrieves the issuer’s verification information; and the verifier validates the credential cryptographically.

Trust with less data

This architecture also changes the privacy model. A verifier often needs to establish a fact rather than obtain an entire record. Verifiable Credentials can support selective disclosure and, where appropriate, zero-knowledge techniques. The broader shift is from sharing data to sharing proofs.

Credentials can therefore be independently verified while reducing unnecessary data exchange and continuous dependence on issuing databases — one of the explicit objectives of IDIF.


The Foundation for DPI 2.0

India’s first generation of DPI created foundational rails for identity, payments, documents and data. The next generation will increasingly consist of independent sectoral and institutional ecosystems that need to interact across their boundaries. That requires more than connectivity. It requires a common way to recognise trusted participants, resolve decentralized identities and independently verify the credentials they issue.

The India Decentralized Identity Framework provides this foundation through common governance, accreditation, decentralized identity, federated registries, open standards and cryptographic verification while allowing participating ecosystems to retain their institutional and operational autonomy.

The next phase of India’s DPI journey is about building a trusted digital fabric — where identity and credentials are federated, verifiable and portable across ecosystems.

Alternate Way of Doing Business: Building Connected Systems for Ease of Compliance

Every day, businesses in India spend countless hours navigating multiple government portals, repeatedly submitting the same information and managing fragmented compliance processes—not because regulations require it, but because government systems do not work together.

For years, reforms have focused on improving the Ease of Doing Business (EoDB) by simplifying regulations and reducing procedural burden. While these efforts remain important, the next leap requires a different mindset—an Alternate Way of Doing Business (AWDB), where businesses no longer act as the integration layer between disconnected government systems. AWDB is about redesigning the digital experience of regulation—not changing the regulations themselves.

India’s businesses face a double compliance challenge

Every business in India—whether a startup, MSME, manufacturer, exporter, hospital or large enterprise—operates within a complex regulatory landscape. As they grow, they interact with a wide range of regulators, including GSTN, MCA, EPFO, ESIC, FSSAI, RBI, DGFT, Pollution Control Boards, labour departments, municipal bodies and numerous state authorities. Each regulator serves an important public purpose, yet the overall landscape is difficult to navigate. Businesses often struggle to determine which regulations apply to them, when obligations arise, and how requirements vary across sectors, jurisdictions and stages of their lifecycle. This information asymmetry is the first layer of friction. The second layer begins once these obligations are understood. The regulatory ecosystem largely functions as a collection of independent digital silos, each with its own portal, identifiers, workflows and data requirements. Businesses repeatedly submit the same information, upload identical documents, undergo multiple verifications and manage separate compliance journeys for different regulators. Systems that should exchange information seamlessly instead rely on businesses to bridge the gaps between them.

Regulatory Cholesterol: The hidden friction that arises when regulatory systems operate in silos, requiring businesses to repeatedly bridge information gaps and duplicate compliance efforts.

The result is invisible friction that slows businesses without improving regulatory outcomes. Time and effort are spent navigating disconnected systems rather than meeting substantive compliance obligations. This unnecessary overhead created by fragmented regulatory systems rather than regulation itself is what we call regulatory cholesterol.. Removing it is not just about reducing regulation; it is also about making regulation discoverable, interoperable and significantly easier to comply with.

The DPI Playbook: Connect Systems, Not Interfaces

India’s Digital Public Infrastructure (DPI) journey has demonstrated that systemic inefficiencies are best addressed through shared digital infrastructure rather than isolated digitisation of departments. UPI did not replace banks, it connected them through common protocols. DigiLocker did not replace document issuers, it enabled trusted exchange of verifiable digital documents. API Setu did not replace government systems, it provided a common interface for secure data exchange.

The success of these platforms stems from a common design philosophy: preserve institutional autonomy while enabling interoperability through shared standards, protocols and trust frameworks. The next frontier is to apply the same design philosophy to India’s regulatory ecosystem—connecting regulators rather than consolidating them. This is the vision behind the proposed National Regulatory Compliance Grid (NRCG).

Single Window Access Is Only the Beginning

Over the past few years, initiatives such as the National Single Window System (NSWS) have made it easier for businesses to discover approvals and access government services through a common interface. This is an important step towards reducing information asymmetry. However, a single entry point does not, by itself, make the underlying regulatory ecosystem interconnected. Behind the window, businesses still encounter multiple systems, each with its own data model, identifiers, workflows, evidence requirements and integration mechanisms.

The real challenge is structural. Every regulator continues to evolve independently, resulting in bespoke integrations, duplicated data exchanges and fragmented compliance journeys. Each new integration adds to the ecosystem’s technical debt, while businesses remain responsible for repeatedly providing the same information across agencies. Governments incur the cost of maintaining overlapping digital infrastructure, and technology providers build and maintain countless point-to-point integrations. The problem is therefore not one of access alone—it is fundamentally one of interoperability.

From Fragmented Systems to Connected Regulatory Systems

Imagine a regulatory ecosystem where regulators continue to operate independently, but their digital systems speak a common language. Instead of functioning as isolated digital silos, regulatory platforms are connected through common standards and shared digital building blocks. An enterprise establishes its identity once and can be recognised consistently across regulatory interactions. Digital credentials become reusable, compliance evidence becomes machine-verifiable, and common regulatory services can be leveraged across agencies.

This does not require replacing existing regulatory systems or centralising regulatory data. Each regulator continues to own its legislation, business rules, applications, databases and approval processes, while adopting common digital infrastructure where collaboration and connectivity create value. The result is a federated regulatory ecosystem—autonomous regulators connected through shared digital rails.

This is the design philosophy behind the National Regulatory Compliance Grid (NRCG). NRCG is not another government portal or a centralised compliance application. It is a Digital Public Infrastructure (DPI) for regulation—a lightweight connectivity layer that provides common standards, shared digital building blocks and reusable public services, enabling independent regulatory systems to work together. Just as UPI enables seamless payments across independent banks without replacing their core banking systems, NRCG enables seamless compliance across independent regulators without centralising regulatory functions or data. It provides the connective fabric that allows businesses, regulators and service providers to participate in a trusted regulatory ecosystem.

The architecture of NRCG is Guided by five design principles:

  • Choice of access: Businesses should be able to interact with regulatory services through the channel of their choice—government portals, private compliance platforms, ERP systems, APIs or AI agents. Compliance should be accessible wherever businesses already work, rather than requiring every interaction to occur through a single government application.  
  • Reuse of common digital capabilities: Regulators should be able to leverage shared digital building blocks—such as enterprise identity, authorisation, registrations, filings, payments, certificates and notifications—instead of independently developing similar capabilities. Reusable public digital infrastructure reduces duplication, improves consistency and accelerates digital transformation across government.
  • Shared trust infrastructure: Trusted regulatory interactions require common foundations. Shared enterprise identity, delegated authorisation, harmonised identifiers, verifiable digital credentials and reusable compliance evidence should establish trust across regulatory boundaries, enabling information to be accepted once and reused wherever appropriate.
  • Standards-based connectivity: Independent regulatory systems should interoperate through common metadata standards, canonical data models, open APIs and machine-verifiable evidence. Rather than relying on bespoke point-to-point integrations, systems should speak a common digital language that enables secure, seamless and scalable information exchange
  • Federated by design: NRCG should strengthen—not replace—existing regulatory institutions. Each regulator continues to own its legislation, policies, business rules, applications and data while participating in a common digital ecosystem through shared standards, trusted services and interoperable digital infrastructure. The objective is connected systems, not centralised systems.

Towards Frictionless Regulatory Infrastructure

Ease of Doing Business is often viewed as a policy challenge. Increasingly, it is becoming a systems challenge. When regulatory systems cannot communicate with each other, businesses become the integration layer. They repeatedly submit the same information, upload documents across multiple portals, prove their identity to different agencies, reconcile conflicting records and navigate fragmented workflows that often ask essentially the same questions in different ways.

Technology should eliminate this burden—not merely automate existing processes.  NRCG shifts compliance from document exchange to trusted data exchange; from manual verification to machine-verifiable evidence; and from fragmented regulatory workflows to coordinated digital journeys. The objective is not fewer regulations. The objective is frictionless regulation.  The impact of NRCG extends beyond improving government efficiency. An interoperable regulatory infrastructure creates the foundation for a broader innovation ecosystem. Software providers can build compliance platforms without integrating separately with every regulator. AI assistants can help enterprises understand and fulfil regulatory obligations across agencies. Professional service firms can deliver end-to-end digital compliance solutions. Industry bodies can create sector-specific applications, and startups can innovate on standard APIs rather than reverse-engineering government systems.

This is the same pattern that has emerged across India’s Digital Public Infrastructure journey. Shared infrastructure such as identity, payments, document exchange and consent layers have enabled new forms of innovation by allowing public and private actors to build on common digital rails. Regulatory interoperability represents the next evolution of this journey. The vision is not one regulator, one database or one portal. It is one connected regulatory network—where regulators retain their autonomy while participating in a trusted digital ecosystem; where compliance becomes predictable, programmable and increasingly invisible; and where businesses spend less time navigating systems and more time creating value, generating employment and driving economic growth.  Removing regulatory friction is not about reducing regulation. It is about enabling government systems to work together as one. That is the promise of the National Regulatory Compliance Grid (NRCG).