QUICK ANSWER
The verifiable LEI (vLEI) is a cryptographically secured, machine-readable digital credential that extends LEI functionality beyond regulatory compliance into digital identity and automated trust. In addition, vLEI role credentials can be issued to the individuals who hold roles within an organisation (executives, board members, other officers), cryptographically linked to the organisation's LEI, enabling automated verification of who holds which role at a legal entity in digital interactions. The term 'GLEIF 2.0' is sometimes used informally to describe this development, but it is not GLEIF terminology.


Traditional LEIs remain fully valid and mandatory. The vLEI is an extension — not a replacement.

                            
The LEI system has always been about one thing: knowing who you are dealing with in financial markets. For over a decade, the traditional LEI has served that purpose well — providing a globally unique, standardised code that identifies legal entities in regulated transactions. But financial markets are changing. Digital contracting, automated reporting, AI-driven compliance workflows, and remote onboarding have created demand for something the traditional LEI was not designed to provide: a machine-readable, cryptographically verifiable identity credential that can be trusted in real time, without human intervention.

That is exactly what the verifiable LEI, or vLEI, is designed to deliver. This article explains the evolution of the LEI system, what the vLEI is and how it works, and what compliance teams and regulated entities need to know right now.


A Brief History of LEI System Versions

Understanding the vLEI requires a brief look at where the LEI system has come from:

Period




Development






2012











G20 mandate for a global LEI system following the 2008 financial crisis. Regulatory Oversight Committee (ROC) established.













2014













GLEIF founded in Basel, Switzerland. First GLEIF-accredited LOUs begin issuing LEIs. ISO 17442-1 standard published.












2017












MiFID II makes LEI mandatory for financial market participants in the EU. The 'no LEI, no trade' rule enters into force.













2018–2020













EMIR Refit and SFTR expand LEI requirements. LEI adoption accelerates globally beyond the EU. ISO 17442-2 (parent relationships) introduced.










2022




GLEIF publishes the vLEI Ecosystem Governance Framework. First vLEI credentials issued. The verifiable LEI becomes an official GLEIF product.




2024–2025











DORA introduces LEI for ICT third-party service providers. vLEI pilots expand in financial services. GLEIF continues to expand the network of Qualified vLEI Issuers (QVIs).










2025+











Growing adoption of vLEI in digital contracting, regulatory reporting automation, and digital identity frameworks.










What Is the vLEI (Verifiable LEI)?

The verifiable LEI — or vLEI — is a new category of digital credential introduced by GLEIF that extends the LEI system into the domain of digital identity. While a traditional LEI identifies a legal entity (an organisation), the vLEI goes further: alongside the legal entity itself, it can identify the individuals who hold roles within it — executives, board members, other officers — and cryptographically link those roles to the organisation's LEI. There are two types of role credential: the Official Organizational Role (OOR) credential, for official roles defined in the ISO 5009 standard, and the Engagement Context Role (ECR) credential, for roles within a specific business context. A role credential establishes the role a person holds; whether that person may commit the organisation to a particular act still depends on the organisation's own mandates and authorisation controls.

The vLEI framework is built on Key Event Receipt Infrastructure (KERI), an open protocol for managing cryptographic identifiers and keys. Its credentials are issued as Authentic Chained Data Containers (ACDCs), with Composable Event Streaming Representation (CESR) used for their cryptographic proofs. Each vLEI credential is:

  • Cryptographically signed: it cannot be forged or tampered with after issuance.
  • Machine-readable: it can be verified automatically by software without human review.
  • Decentralised: it does not require a central verification database — verification is performed using public cryptographic keys.
  • Role-specific (role credentials): it encodes the individual's role within the organisation (e.g., CEO, CFO, board director) alongside the organisation's LEI.
  • GLEIF-anchored: every vLEI credential carries the organisation's LEI — issued by a GLEIF-accredited LEI Issuer — and its chain of issuance traces back to GLEIF as the root of trust of the vLEI ecosystem.

Think of the traditional LEI as the corporate 'passport' — identifying the organisation. The vLEI adds an 'official identity card' for individuals holding roles at that organisation, with cryptographic proof of the role they hold. Proof of role is not, on its own, proof of authority to commit the organisation: that rests on its mandates and internal authorisation controls.

How the vLEI Differs from the Traditional LEI

Dimension





Traditional LEI











vLEI (Verifiable LEI)

What it identifies
















The legal entity (organisation)
















The legal entity AND the individuals holding defined roles within it

Format














20-character alphanumeric code (ISO 17442)















ACDC credentials issued on KERI infrastructure, with CESR-encoded cryptographic proofs

Verification method















Manual lookup in GLEIF Global LEI Index
















Automated cryptographic verification — no database query needed

Machine-readable
















Code only — reference data requires database lookup










Fully machine-readable and self-contained

Forgery risk







Low (issued by accredited LOU)







Negligible (cryptographically secured — cannot be altered after issuance)

Who issues it














GLEIF-accredited LOUs (e.g., Euronext Dublin)














Qualified vLEI Issuers (QVIs), qualified by GLEIF through its vLEI Issuer Qualification Program

Regulatory mandate

Mandatory (MiFID II, EMIR, SFTR, DORA, etc.)



Currently voluntary — adoption growing; some jurisdictions exploring mandates

Primary use case

Counterparty ID, regulatory reporting, trade execution




Digital contracting, automated KYC, regulatory reporting automation, digital signing

Annual renewal required

Yes

Yes (organisational vLEI is tied to the underlying LEI renewal)

What the vLEI Means for Regulated Entities

For compliance officers and legal teams, the rise of the vLEI has several practical implications — some immediate, some medium-term.

Regulatory Reporting Automation

Regulatory reporting under MiFID II, EMIR, and SFTR is currently a largely manual process: compliance teams gather LEI codes, validate them against the GLEIF database, and submit reports through designated reporting mechanisms.The vLEI is designed to enable this process to be significantly automated: a counterparty's vLEI credential can be machine-verified in milliseconds at the point of transaction, without any manual lookups or data reconciliation.

Digital Contracting and e-Signature

As organisations move toward digital contracting platforms and electronic signatures, the vLEI provides a critical piece of infrastructure: a cryptographically verifiable way to confirm that a signatory is who they claim to be and holds the stated role at the named legal entity. Establishing that the signatory is authorised to execute a specific document still depends on the organisation's own mandate and authorisation controls, such as delegations of authority, powers of attorney and signing policies, which can rely on the vLEI as verified proof of role. This is particularly relevant for financial institutions executing high-value digital contracts and for corporate secretaries managing board resolutions and execution documents.

KYC and AML Workflow Acceleration

Client onboarding is one of the most resource-intensive compliance workflows in financial services. The vLEI has the potential to significantly reduce onboarding friction: a client presenting vLEI credentials provides machine-verifiable proof of its legal identity and of the roles held by the individuals representing it — all traceable back to GLEIF as the root of trust of the vLEI ecosystem.

DORA and Digital Third-Party Risk

The Digital Operational Resilience Act (DORA), which entered into force in January 2025, requires financial entities to maintain registers of ICT third-party service providers identified by LEI. As DORA compliance programmes mature, the vLEI is increasingly being evaluated as a mechanism for automated ICT provider identity verification within digital supply chain risk management frameworks.

The Role of LOUs in the vLEI Ecosystem


The vLEI ecosystem introduces a new category of issuer: Qualified vLEI Issuers (QVIs). QVIs are organisations qualified by GLEIF, through its vLEI Issuer Qualification Program, to issue vLEI credentials — they operate alongside the GLEIF-accredited LEI Issuers (LOUs) within the Global LEI System. Traditional LOUs — including Euronext Dublin — continue to play a foundational role: the vLEI credential is always anchored to the underlying LEI issued by an accredited LOU. This means that maintaining a valid, active LEI with a trusted LOU like Euronext Direct is a prerequisite for any organisation wishing to participate in the vLEI ecosystem in the future.

There is no action required now for organisations to 'switch' to vLEI — traditional LEIs remain mandatory and fully operational. The important step is ensuring your existing LEI is active, accurate, and managed by a trusted, accredited LOU that is positioned to support vLEI adoption as the ecosystem matures.

How to Prepare: What Your Organisation Should Do Now

The vLEI ecosystem is still developing. Full regulatory mandates for vLEI are not yet in place in most jurisdictions. But compliance-forward organisations can begin preparing now:

  1. Ensure your LEI is active and your reference data is accurate. The vLEI is anchored to your LEI — any inaccuracies in your LEI reference data will propagate into your vLEI credentials. Review your GLEIF record today at search.gleif.org.
  2. Consolidate LEI management with a trusted, accredited LOU. Fragmented LEI management across multiple LOUs increases complexity. Working with a single, GLEIF-accredited LOU like Euronext Direct simplifies future readiness for vLEI adoption.
  3. Monitor GLEIF's vLEI governance publications. GLEIF regularly publishes updates to its vLEI Ecosystem Governance Framework and to the requirements of its vLEI Issuer Qualification Program. Subscribe to GLEIF's updates and assign a compliance owner to track LEI system developments.
  4. Evaluate vLEI use cases for your workflows. Identify which of your compliance or onboarding workflows — KYC, contract execution, regulatory reporting — could benefit from automated vLEI verification, and begin scoping the business case.
  5. Engage your technology vendors. If you use regulatory reporting platforms, KYC/AML tools, or digital contracting software, ask your vendors about their plans to support vLEI credentials. Early engagement ensures your technology stack is ready when adoption accelerates.

Euronext Direct: Your LEI Partner for Today and Tomorrow

Euronext Direct is operated by Euronext Dublin — a GLEIF-accredited LOU with a long track record of reliable, compliant LEI issuance across 90+ jurisdictions. As the LEI system evolves to include the vLEI ecosystem, Euronext Direct is positioned to support regulated entities through every stage of that evolution: from issuing and renewing traditional LEIs today, to supporting vLEI credential anchoring as the ecosystem matures.

Starting with a solid LEI foundation is the right first step. Make sure your LEI is active, accurate, and managed by a provider you can trust.



Keep your LEI current and future-ready

manage it with Euronext Direct.

 

cta-banner-default-placeholder

Related Topics

Frequently Asked Questions

Is my existing LEI still valid now that the vLEI has been introduced?

Yes, absolutely. Traditional LEIs remain fully valid, mandatory, and unchanged. The vLEI is an extension of the LEI system — not a replacement. Your 20-character LEI code continues to be the standard for regulatory reporting under MiFID II, EMIR, SFTR, DORA, and all other regulations that currently require LEIs. The vLEI adds new capabilities; it does not deprecate existing ones.

Do I need to upgrade to a vLEI?

No regulatory mandate currently requires entities to obtain a vLEI. The vLEI is a voluntary extension of the LEI system at this stage. However, as digital contracting, automated KYC, and regulatory reporting automation become more prevalent, early adopters of the vLEI ecosystem are likely to gain operational advantages. The most important step today is ensuring your traditional LEI is active and accurate — the vLEI builds on that foundation.

When will vLEI be mandatory?

No firm dates have been set for mandatory vLEI adoption in any major jurisdiction as of early 2026. GLEIF continues to develop the ecosystem governance framework and expand the network of Qualified vLEI Issuers. Regulatory interest in the vLEI is growing — particularly in the context of DORA and digital identity frameworks — but formal mandates are expected to take several years to materialise. Monitor GLEIF's official publications at gleif.org for the latest updates.

How is the vLEI related to my existing LEI?

The vLEI is directly anchored to your existing LEI. Every vLEI credential issued for your organisation includes your 20-character LEI code as its authoritative root identifier. This means your existing LEI — and its accuracy — is the foundation of any future vLEI credentials your organisation may issue. Keeping your LEI accurate and active is the essential prerequisite for vLEI readiness.

Share this post