Overview
ISO 17442-3:2024 specifies how the Legal Entity Identifier (LEI) (as defined in ISO 17442-1) is used inside Authentic Chained Data Container (ACDC) credentials to create verifiable LEIs (vLEIs). The standard defines the governance, credential types, data schema requirements and trust model to enable decentralized, cryptographically verifiable organization identities anchored to the Global LEI System managed by GLEIF.
Key topics and technical requirements
- Scope: Use of the LEI code in ACDC credentials to produce verifiable LEIs (vLEIs).
- Governance: The vLEI Ecosystem Governance Framework (maintained by GLEIF) establishes GLEIF as the root of trust. GLEIF issues a root autonomic identifier (AID) and delegated AIDs to qualified issuers.
- vLEI credential categories:
- Entity credentials (e.g., qualified vLEI issuer credential, legal entity vLEI credential) that bind an LEI to an entity.
- Role credentials (official organizational role and engagement context role) that bind persons and roles to an LEI; official roles follow ISO 5009 where applicable.
- Authorization credentials (qualified vLEI issuer authorization) used to authorize issuance/revocation of role credentials.
- Chaining and provenance: vLEIs use ACDC chaining to link credentials and trace provenance back to GLEIF as the root of trust.
- Technical backbone: The infrastructure is based on KERI (Key Event Receipt Infrastructure) and supports composable proof signatures via CESR (Composable Event Streaming Representation). vLEIs are portable across ledgers and cloud infrastructures.
- Schema and normative references: vLEI schemas and credential frameworks are defined and required to include assigned LEIs (ISO 17442-1) and roles per ISO 5009. Implementers should follow referenced ACDC, KERI and CESR specifications.
Applications and users
- Who will use ISO 17442-3 (vLEI):
- Financial institutions, fintechs and market infrastructures seeking decentralized, verifiable organization identity.
- GLEIF and qualified vLEI issuers responsible for issuing/revoking vLEI credentials.
- Identity providers, wallet vendors and developers building self-sovereign identity (SSI) solutions that need organization-level verification.
- Regulators, compliance teams and auditors requiring cryptographic provenance and role-based assertions for reporting and oversight.
- Practical uses:
- Decentralized verification of corporate identity in KYC, onboarding and regulatory reporting.
- Role-based authorization (e.g., signatory or approver roles) tied to an LEI for document signing, transaction authorization and audit trails.
- Cryptographic signing of facts, reports or transactions with CESR proof signatures to create verifiable chains of provenance.
Related standards
- ISO 17442-1:2020 - LEI assignment (normative for LEI values)
- ISO 17442-2 - LEIs in X.509 certificates (complementary approach)
- ISO 5009:2022 - Official organizational roles (used for role credential semantics)
- Supporting specifications: KERI, ACDC and CESR (technical components referenced by the standard)
Keywords: ISO 17442-3, vLEI, LEI, verifiable LEI, ACDC credentials, GLEIF, KERI, CESR, decentralized identity, self-sovereign identity, qualified vLEI issuer, ISO 5009.