A support programme receives digital evidence that a business meets one condition. Before relying on it, the programme needs to know who issued the statement, what that organisation checked, whether the evidence is current and who handles a disputed result.

Governance establishes the responsibilities and rules behind those questions. It determines how organisations participate, how authority is recognised and how people receive support when a system or decision fails. A trustworthy service combines reliable technical checks with institutions that can explain and correct their actions.

What governance covers

Co-Develop's Learn DPI Governance treats governance as measures taken across an infrastructure's lifecycle to support trust, safety and inclusion. It highlights the contribution of civil society, legal actors and the media in shaping public-interest outcomes.

UNDP's The DPI Approach: A Playbook brings governance into planning alongside technology and community. The World Bank's DPI and services approach connects enabling rules, institutional capacity and safeguards with service delivery.

For a particular service, these perspectives can be translated into six questions:

  1. Who may join, and what must they demonstrate?
  2. Which statements may each participant issue or rely on?
  3. Which information may be requested, used and retained?
  4. Who makes the final service decision?
  5. Who maintains operations and manages incidents?
  6. How can someone challenge an error and obtain a remedy?

The answers should be available to participating organisations and understandable to people using the service.

Establish roles before connecting participants

The following role map is a MOSAIC teaching tool. Several roles may sit within one organisation, but their responsibilities still need to be explicit.

Role Responsibility to define
Infrastructure steward Sets participation rules, coordinates changes and oversees the shared capability
Source-record custodian Maintains underlying records and handles corrections
Issuer or evidence provider Makes statements within its authority and manages issuance and updates
Wallet or application provider Protects access and presents requests clearly within its agreed role
Verifier Checks evidence under a documented acceptance policy
Service owner Applies programme rules, communicates decisions and provides review
Operator Maintains reliability, security, recovery and support
Oversight and user representatives Examine compliance, risks, exclusion and improvement opportunities

A technical supplier can implement several functions without becoming the institution authorised to make a programme decision. Document both delivery responsibilities and institutional authority.

Define participation and continued eligibility

A participation policy describes a participant's function, entry conditions and conditions for remaining active. Requirements should fit the role and risk involved.

For a credential ecosystem, entry assessment might cover issuer authority, evidence quality, signing-key protection, supported interfaces and complaint handling. A wallet provider may instead demonstrate secure access, an understandable presentation flow and conformity with the exchange profile.

Plan for change. Establish who approves a participant, how organisations update keys or endpoints, and how suspension or exit affects outstanding transactions. Publish rules clearly enough for another qualified institution to understand how to join.

CDPI's Implementation & Execution Guidance emphasises governance and participants' incentives. An onboarding exercise can test whether organisations understand their responsibilities and can meet them in practice.

Trust an issuer for a defined purpose

An organisation can be authoritative for one statement and unsuitable for another. A training provider may confirm course completion. A registration authority may confirm a business-registration record. A lender may provide evidence of a customer's relationship or repayment history within agreed rules. These are different scopes of authority.

The W3C VC Data Model leaves the choice of which issuers to trust, and for which purposes, to the receiving ecosystem. A compatible format does not create that policy.

An issuer register or trust list can distribute recognised identities and verification material. CDPI's Trust Infra explains signatures, PKI and consent as supporting capabilities. Institutions still agree how authority is assessed and which statements they accept.

For a proposed pilot, a trust record could contain:

  • The organisation's identity and recognised role.
  • Statement types and service purposes it may support.
  • The basis for recognising its authority.
  • Verification material or an agreed route for resolving it.
  • Effective dates, update responsibilities and status.
  • Contacts for incidents, corrections and disputes.

Each entry needs a responsible maintainer. A stale list can cause valid evidence to be rejected or withdrawn authority to remain accepted.

Separate evidence checks from the service decision

A verifier can establish that evidence passes its configured technical checks. The service owner also decides whether that evidence satisfies the applicable rule.

In a proposed small-business support programme, a registration credential may provide one accepted piece of evidence. The programme might also assess location, business activity, previous assistance or another condition. Those decisions remain with its authorised owner.

Record the evidence used, rule applied and reason for the outcome, with appropriate access and retention controls. Give the applicant enough information to understand the decision and seek correction. A green result on a verifier screen should have a defined meaning that staff can explain.

Make information use understandable and bounded

Define what each party can request and receive. Describe purpose, applicable authority, retention, access controls and onward use. Explain the process when information is requested, in language the person can understand.

Where consent is used, specify what the person can choose and how it is recorded. Distinguish withdrawing permission for future access from changing information already used in a decision. Obligations depend on the applicable rules and service context.

The Universal DPI Safeguards initiative examines technical, normative and organisational risks. A governance review should therefore consider the interaction between the interface, institutional procedures and the person's ability to obtain help.

Correct errors and provide review

People should be able to seek help without understanding the infrastructure. An accessible support route can direct an issue to the responsible party.

Problem First responsibility to identify Resolution to plan
Incorrect source record Record custodian Correct the record and update affected evidence
Incorrect credential issuance Issuer Review issuance, change status where appropriate and provide replacement evidence
Valid evidence fails a technical check Verifier and operator Investigate configuration, trust material or exchange failure
Lost wallet access Wallet or access-service provider Provide agreed recovery and assisted access
The programme rejects an application after accepting evidence Service owner Explain the rule and provide the relevant review route
Information is exposed or used improperly Responsible controller or operator, with relevant oversight Investigate, contain the issue and provide the required response

A project should agree contacts, response targets, escalation and follow-up for its own institutions. Plan how someone continues a time-sensitive application while a problem is investigated.

Govern operations and ecosystem changes

Governance continues after launch. A changed claim definition, API version, recognised issuer or programme condition can affect several organisations. Agree a process covering notice, testing, transition and treatment of earlier evidence.

Co-Develop's research on building and sustaining DPI highlights institutional capacity to make strategic technical decisions and manage suppliers. A service owner needs that capacity when assessing upgrades, incidents and operating costs.

Invite affected users and public-interest organisations into reviews where they can contribute to concrete decisions. Co-Develop's governance learning platform provides resources for building participation. Examine recurring exclusion, unresolved complaints and whether the stated service purpose matches actual use.

A proposed MOSAIC learning exercise

Use a hypothetical business-support programme involving one issuer, two wallet providers and one verifier. Prepare a short trust agreement covering:

  1. The condition being evidenced and the issuer's authority.
  2. Accepted format, exchange profile and checks.
  3. Requested information and purpose of use.
  4. Programme decision owner and acceptance rules.
  5. Source correction, credential updates and complaints.
  6. Participant onboarding, suspension and exit.
  7. Support, change management and continuing funding.

Test the agreement with an unrecognised issuer, a changed or compromised key, an incorrect record and an applicant unable to use the preferred wallet. Examine whether each team knows its next action and whether the applicant has a workable route forward.

Guided reading list

Co-Develop — Learn DPI Governance. Begin here for public-interest participation and resources for policymakers, practitioners, legal actors and civil society. Select a resource suited to the institution's role and question.

UNDP — The DPI Approach: A Playbook, 2023. Organise governance alongside technical and community work. Identify choices requiring an authorised decision, consultation or further evidence.

United Nations — Universal DPI Safeguards Framework. Examine harm, exclusion and responsibility across the lifecycle. Record the version used and the actions assigned in the project.

World Bank Group — Digital Public Infrastructure and Development: A World Bank Group Approach, 2025. Relate governance to public benefit and service functions that different providers reuse.

CDPI — Trust Infra and Implementation & Execution Guidance. Identify supporting technical capabilities, then examine institutional and adoption arrangements around them.

Co-Develop — Enabling governments to build and sustain DPI. Consider strategic capacity, supplier management and continuing ownership.

Related pages: DPI Principles and Resources · Verifiable Credentials and Digital Wallets