The Moresburg Model for Trust Frameworks and Schemes provides the comprehensive structure for establishing, evolving, and operating a digital trust ecosystem.
At the national level, this framework includes key policy areas such as Principles, Legislation, Overarching Rules, Trustmark usage, Certification processes, Good Practice Guidance, and a Code of Conduct.
Governance is a critical component, often involving an independent regulator with statutory powers granted through legislation to ensure participants are legally obligated to follow the rules and to allow for enforcement against "bad actors".
Beneath the national framework operate Schemes, managed by Scheme Operators through Governance Manuals and specific Procedures. Scheme procedures detail contractual agreements for participants and cover areas like the Commercial Model, Certification, Assurance Framework, Operational Procedures, Liability, Financial Management, Regulatory Compliance, Reporting, and managing Acceptance/Relying Parties.
The overall model aims to build trust and ensure the reliability and integrity of the digital identity ecosystem through defined roles, rules, accreditation, monitoring, redress, and enforcement.
Our consultants use the Moresburg Model to guide our clients in the development of nation-scale digital trust infrastructure.
The Moresburg Model is a comprehensive methodology designed for governments and organisations to establish, govern, and scale national digital trust ecosystems. It outlines a comprehensive structure for establishing and operating national digital identity trust frameworks and the individual schemes that operate within them. It defines the key components, policies, governance, and procedures required to ensure the security, reliability, and trustworthiness of digital identity systems. The model emphasizes principles like inclusion, user control, security, and privacy, and details how these are implemented through accreditation, monitoring, redress, and enforcement mechanisms.
Governance is a critical element of the Moresburg Model. At the national Trust Framework level, it is typically overseen by an independent regulator with statutory powers granted through legislation. This ensures enforceability and aligns with principles of trust and privacy. The governance authority maintains the framework, updates it, and may act as an arbitrator. At the Scheme level, governance can be handled by various entities, including an operational entity appointed by the Trust Framework authority, a government entity, a commercial entity, or a consortium of participants. Scheme governance is primarily enforced through commercial contracts between participants.
The Moresburg Model for Trust Frameworks and Schemes
Accreditation and certification are fundamental to building trust in the Moresburg Model. The National Trust Framework sets the requirements for certifying participants and monitors their conformance. A National Accreditation Service, appointed by the government, assesses and accredits Certification Assessment Bodies (CABs). These CABs, accredited to ISO/IEC 17065, are responsible for certifying that providers' services meet the Trust Framework rules through audits. Certified Providers receive a written assurance of compliance, building trust in the reliability of their services. At the Scheme level, the Scheme Operator defines its own certification process, ensuring participants meet both Trust Framework and extended Scheme-specific rules.
The Moresburg Model emphasizes user rights and provides mechanisms for redress. The Trust Framework outlines participant obligations and minimum standards users can expect. While not primarily focused on financial liability at the national level, it ensures mechanisms for identity repair, allowing users to correct inaccuracies and restore their identity following errors. Scheme rules further detail requirements for identity repair and define procedures for addressing inaccuracies or invalid use of identity, including potential suspension or removal of participants in cases of negligence or systemic failures.
A trustmark is a visual signal, typically a logo, indicating that a Trust Framework is in operation and that the associated provider complies with its rules and associated Schemes. It signifies trust and compliance to users and other participants. The Trust Framework defines the rules for using the trustmark and the governance authority is responsible for policing its use to prevent misuse and fraud. It's important to note that a trustmark is not an acceptance-mark; displaying the trustmark shows participation in the framework, but acceptance of services at a Relying Party is governed by commercial relationships.
A National Trust Framework in the Moresburg Model includes several key policy documents. These cover foundational principles (such as inclusion, user control, and security), the legislative basis for the framework, overarching rules defining participant roles and fundamental requirements, the governance and use of a trustmark, certification procedures, good practice guidance for specific areas like identity proofing and attribute assurance, and a user-facing code of conduct summarizing the framework's policies and user rights.
A critical role for a Scheme Operator in the Moresburg Model is creating an acceptance network of Relying Parties. The Scheme may create an acceptance-mark to inform users where their digital identity can be used. The model suggests strategies for building acceptance, including a commercial model and go-to- market strategy, and potentially acting as a market-maker to incentivize participation. Building user advocacy through repeated positive experiences in various contexts over a sustained period is also highlighted as a way to encourage adoption and usage.
Scheme Operators have significant responsibilities regarding liability and financial management. They must establish a clearly defined liability model outlining when liability occurs, who is obligated, and the limits of liability. This model needs to be commercially viable and scalable. The Scheme Operator also manages financial aspects, including establishing billing frameworks, issuing invoices to Relying Parties, collecting payments, distributing fees to participants, and reconciling financial records. They may also be involved in dispute resolution processes for Scheme participants.
The primary difference is that TOGAF and BIZBOK are general-purpose enterprise frameworks used to design internal organisational landscapes, while the Moresburg Model is a domain-specific methodology created to establish and scale national digital trust ecosystems. While BIZBOK focuses on mapping broad enterprise value streams and TOGAF governs general IT domains, Moresburg focuses specifically on the governed exchange of verified assertions between independent ecosystem participants. Unlike general models, Moresburg provides specialised architectures for dual-layered governance, which strictly separates statutory Policy from operational Procedures, and a dedicated Liability Framework designed to convert distributed trust into manageable, bounded commercial risk.
These models complement each other by bridging the gap between broad enterprise strategy and specialised trust infrastructure. BIZBOK and TOGAF provide the organisational language, while the Moresburg Business Architecture Blueprint delivers the specific functional and logical designs required for a decentralised identity system. Organisations can integrate Moresburg's unique trust capabilities directly into their existing enterprise capability maps or technical architectures. Using them in conjunction ensures that digital trust initiatives are not treated as isolated technical projects but are established as coordinated national assets deeply integrated into the strategic business architecture of the organisation.
The Moresburg Model is a strategic governance methodology rather than a technical specification or a legal code. It is designed to be technology-neutral, which means it provides the overarching blueprint for trust while relying on established international standards such as NIST, ISO and OIDF to handle the specific mechanics of identity proofing and cryptographic exchange. By not including its own proprietary designs or proofing rules, the model ensures that national ecosystems remain compatible with global infrastructure and can adapt as new technical protocols emerge without the need to rewrite the underlying policy foundations.
This approach allows the Moresburg Model to complement existing regulatory and technical frameworks such as eIDAS or the UK Digital Identity and Attributes Trust Framework. While these frameworks define the specific rules for how a credential is proofed or secured, Moresburg provides the vital human and institutional layer that manages the commercial risk, liability and national stewardship required to scale those services. It acts as the coordinating substrate that transforms various technical standards and regulatory requirements into a single, predictable and commercially viable national trust economy.
The Moresburg Model is distinct from technical standards and regulatory frameworks because it functions as a strategic governance methodology designed to coordinate these various components into a viable national economy. While the other models define the specific rules for identity proofing or data exchange, the Moresburg Model provides the human and institutional layer required to manage commercial risk, liability and national stewardship.
1. NIST-800-63 (Identity Assurance)
NIST-800-63 provides the technical and procedural requirements for identity proofing and authentication through established Identity Assurance Levels (IAL).
Moresburg Model uses these standards as a common language to define confidence in assertions but adds a Liability Framework that determines the commercial consequences if those processes fail. It converts the technical "levels of confidence" into **manageable and insurable risk.
2. eIDAS and UKDVSTF (National Trust Frameworks)
eIDAS (EU) and the UK Digital Verification Services Trust Framework (UKDVSTF) are statutory foundations that set the legal rules for digital identity within their respective jurisdictions.
Moresburg Model acts as a complementary methodology that operationalises these frameworks. It introduces a strict separation of Policy from Procedures, where the national framework (like UKDVSTF) provides the legitimacy, and Moresburg’s Scheme Operators provide the day to day operational predictability and commercial contracts needed for scale.
3. ISO 18013-5 and OID4VCI/VP (Technical Standards)
ISO 18013-5 (mDocs) and OID4VCI/VP (OpenID Foundation) are specific technical protocols and formats for issuing and presenting digital credentials.
Moresburg Model is deliberately technology-neutral and does not compete with these standards. Instead, it mandates their use to ensure international interoperability and prevent vendor lock-in, acting as the governance substrate that allows multiple different formats to coexist within a single trusted network.
4. Trust over IP (ToIP)
ToIP is a conceptual stack that defines four layers of technical and governance interoperability for decentralised trust.
Moresburg Model utilises a seven-layered National Reference Model. While ToIP focuses on the architecture of a trust relationship, Moresburg focuses on the national implementation roadmap, establishing the specific Stewardship, Confidence and Sovereignty Gates a nation must pass to move from a pilot to a permanent national utility.
In summary, where these other frameworks provide the "what" (technical specs and legal rules), the Moresburg Model provides the "how" (commercial governance and implementation strategy) to transform them into a coordinated national asset.
The Moresburg Model is unique because it is the only methodology that provides a full commercial and implementation blueprint alongside statutory law and governance. While technical standards from bodies like the W3C, ISO, IETF and the OpenID Foundation provide the vital mechanics for how information is signed and exchanged, they are not designed to address institutional stewardship or financial sustainability.
Similarly, statutory frameworks like eIDAS or the UKDIATF provide essential legal legitimacy but often leave delivery gaps regarding how the private sector should manage commercial risk and liability at scale. The Moresburg Model fills these gaps by establishing the human and institutional substrate that allows various technical standards and regulatory requirements to function as a single, coordinated national asset.
The Moresburg Model is deliberately technology-neutral and does not compete with technical specifications. Instead, it acts as the governance substrate that mandates their use to ensure international interoperability. While standards from bodies like the W3C, IETF or ISO define how a credential is cryptographically signed and exchanged, Moresburg provides the commercial and institutional layer that manages the risk, liability and stewardship required for those technical exchanges to occur at national scale.
Yes, because the Moresburg Model is designed to operationalise those statutory foundations. Frameworks like eIDAS or the UKDIATF provide the vital legal legitimacy (the Policy layer), but they often leave delivery gaps regarding how participants should manage commercial risk and financial liability. Moresburg fills these gaps by providing the Scheme Operator layer. This layer translates high level policy into predictable operational procedures and commercial contracts, enabling the private sector to scale with confidence.
These frameworks are highly complementary. TOGAF and BIZBOK provide the general purpose organisational language and IT governance for an individual enterprise, whereas the Moresburg Model is a domain-specific methodology for building a national trust economy. Organisations can use BIZBOK to map their internal value streams and then integrate Moresburg's High-Level Business Architecture Blueprint to handle the unique functional and logical designs required for decentralised identity and the governed exchange of verified assertions.
Standard frameworks such as NIST SP 800-63 focus on identity assurance levels and the specific requirements for proving an identity. The Moresburg Model is a holistic methodology for national implementation. It includes specialised architectures that go beyond assurance, such as a dedicated Liability Framework to convert distributed trust into manageable commercial risk, a ten-year implementation roadmap and a dual-layered governance model that strictly separates national stewardship from operational management.