Public Digital Infrastructure
From separate portals to shared digital rails that deliver services from start to finish
Public digital infrastructure is not a single application, but a small set of shared capabilities reused across the state: identity and trust, payments, data exchange, notifications and tracking, and audit logs, with success measured by service time, completion and fewer documents and visits.
Chapter Overview
| Item | Substance |
|---|---|
| Code | V3-D06-C05 |
| Location | Volume Three — Part Six — Chapter Five |
| Title | Public Digital Infrastructure |
| Purpose | Build a shared, reusable digital layer enabling citizens and companies to prove identity, submit applications, share authorised data, pay or receive funds, sign and verify, track status and receive outcomes across the state without rebuilding these functions in every ministry. |
| Connection to the previous chapter | It receives from “Artificial Intelligence and Computing” a state with digital and governed AI capabilities, shifting the question from analytical and computing tools to the public rails carrying daily dealings among the state, citizens and companies. |
| Connection to the next chapter | It prepares for “Data Sovereignty and Cybersecurity”: as identity, payments, exchange and shared services expand, stricter rules for data, security, resilience and privacy become increasingly necessary. |
| Data freeze | 7 October 2026; every figure and source is dated, and live counters and implementation publications are distinguished from survey or legal baselines. |
| Version | 1.0 |
| Official topics | Digital identity; digital payments; digital government services; reducing corruption by reducing friction. |
1. Executive Summary
This chapter moves from state computing and AI capabilities to the question citizens face daily: how do they deal with the state? If every ministry has a separate application, database, payment system and account, digitalisation may increase complexity rather than reduce it. Iraq Vision 2045 therefore defines “public digital infrastructure” as a layer of shared capabilities used by many entities: identity proofing and authentication, trust and signature services, payments and collection, authorised data exchange, application management and notifications, and document verification. These capabilities resemble railways and roads: they do not deliver the final service alone, but prevent every institution from rebuilding the route from scratch.1
Iraq does not start from nothing. Ur has become the official access point for government services. At the chapter’s evidence cut-off, its homepage displays more than 11.4 million registrants and 1,288 listed services, including 784 electronic services. But a service counter does not prove every journey is complete from start to finish. The National Centre for Digital Transformation’s electronic service creation platform lists 782 services, including 584 active services, and more than 19.8 million recorded applications. This establishes substantial operating capability while reinforcing the need to move from counting “forms” to measuring completion, time, visits and outcomes.23
At the exchange layer, an update of 19 August 2026 states that X-Data includes 37 government institutions and 1,412 institutions and branches, around 48.3 million records, 1.93 million issued documents and 205 digital services. The project eliminating paper “issuance authenticity” checks offers a clearer example of friction reduction: 118 connected entities and more than 28.6 million documents processed through digital verification instead of paper correspondence. These are real national assets. The task for 2045 is not to replace them with a new platform, but to unify standards and connect them to services with clear outcomes.45
In identity, Iraq has a substantial legal and civil base: the Ministry of Interior announced around 39 million national cards issued in July 2024, and National Card Law No. 3 of 2016 provides the legislative basis for the register and card. But the national card is not itself a digital identity usable for every service. In 2026, Ur Auth reached one million users as a two-factor authentication application for accessing Ur. These layers must be connected into a clear “trust chain”: legal identity → risk-appropriate authentication → signature or authorisation where needed → a reviewable audit log. No parallel population database should be created, and a login code must not be confused with proof of legal identity.678
Payments reveal a gap between existing infrastructure and public uptake. The Central Bank’s Financial Inclusion Strategy 2025–2029 uses a 2024 national diagnostic placing household bank or payment account ownership at 11% according to the demand-side survey. It targets 50% of adults by 2030, and 85% having sent or received digital payments. The same source reports 16.7 million bank and electronic accounts from provider data in the first quarter of 2024, explicitly warning of duplication and inactivity. “Accounts” must therefore not be equated with “people”. This methodological principle should govern the entire chapter: measure the outcome users experience, not merely administrative capacity.9
The implementation conclusion is that Iraq must move from “a government with platforms” to “a state with shared digital rails”. The proposed project does not abolish Ur, X-Data, the government network or Central Bank systems. It establishes a unified standard for services, identity, exchange and payments, selecting high-volume or high-impact journeys for end-to-end redesign. By 2045, citizens should not be asked again for verified information the state already holds without a legal reason, forced to pay cash for a service that can be paid electronically, or required to know which ministry “owns” each step. The state appears as one system, while responsibility and jurisdiction behind the interface remain clear and accountable.
2. The Central Question and the Chapter’s Scope
Central question: what legal, institutional, technical and operational infrastructure does Iraq need for identity, payments, data exchange and government services to become shared, reusable capabilities, completing transactions end to end with minimal friction, without creating a parallel identity, technological monopoly, exclusion of the unconnected or digitalisation turned into surveillance?
2.1 What the Chapter Resolves
• Define public digital infrastructure and distinguish it from portals, sectoral applications and data centres.
• The identity and trust chain: legal identity, authentication, signatures, authorisation and consent/purpose.
• Digital government payments as a complete cycle: application → amount due → payment → reconciliation → receipt → refund or settlement.
• Government data exchange and the “once-only” principle, with authority, purpose and audit.
• The end-to-end service standard and management of citizen and company journeys instead of platform counts.
• Reduce opportunities for petty corruption, intermediaries and procedural extortion by reducing contact points and undocumented discretion, without claiming that digitalisation eliminates corruption.
• Digital inclusion and assisted channels so that digital transformation does not become a new barrier.
2.2 What Is Left to Other Chapters
• Personal data protection, data classification, storage and processing sovereignty, incident management and detailed cybersecurity are passed to V3-D06-C06.
• Computing infrastructure, AI, model policy and talent are not redesigned here; they were addressed in V3-D06-C04.
• Physical internet, fibre, coverage and telecommunications infrastructure will be detailed in the infrastructure, energy and services part; here they are used insofar as they enable services.
• Banking-sector reform and monetary policy are not repeated; payments here are an operational function of public infrastructure, complementary to the Central Bank’s remit.
• Comprehensive anti-corruption, investigation and asset recovery are not repeated; the chapter discusses only how service design affects opportunities for procedural corruption.
3. Operational Vocabulary and Measurement Rules
| Concept | Operational definition in the Vision | What it does not mean |
|---|---|---|
| Public digital infrastructure (DPI) | Basic digital capabilities shared across society/the state — identity and trust, payments, data exchange and others — reused to build many services. | Not one application or mandatory government ownership of every component. |
| Legal identity | The register/document establishing a person or entity under law. | Not an account on an electronic portal. |
| Digital identity | A reliable means of establishing that a digital user holds the required identity/status with an appropriate assurance level. | Neither the plastic card alone nor an OTP alone. |
| Authentication | Verifying that the account user is its holder through one or more factors. | Does not by itself establish the legal right to perform an action. |
| Trust services | Signatures, timestamps, institutional seals and certificates/credentials establishing the authenticity of transactions and documents. | Not an image of a signature on a PDF. |
| Interoperability | Independent systems’ ability to exchange data/commands under consistent standards, permissions and definitions. | Not equivalent to merging systems into one database. |
| Once-only principle | A person is not asked to resubmit verified data held by a government entity that can lawfully retrieve it for the service’s purpose. | Does not mean unrestricted sharing of all data. |
| End-to-end service | A journey completable digitally from application initiation through decision/outcome, payment and signature/redress where required. | Not merely an electronic form. |
| Administrative friction | The time, steps, documents, visits, duplication and uncertainty borne by users and institutions to complete a transaction. | Not every necessary check or control is “bureaucracy”. |
| Assisted digital access | A human channel helping users complete a digital service without creating a slower pathway or fewer rights. | Not permanent retention of paper. |
3.1 Measurement Rules
• Service counters measure supply; end-to-end completion measures capability.
• Account counts do not equal person counts; administrative data are separated from population surveys.
• Successful payment is incomplete until transaction reconciliation, receipt issuance and refunds when due are possible.
• Fewer in-person visits count as success only if they do not result from excluding digitally disadvantaged groups.
• Data sharing is measured through lawful, completed requests, their speed and quality, not transferred-record volume alone.
• Corruption reduction is measured through friction, exceptions, complaints and audit indicators, not assumed automatic causation from digitalisation.
4. The Iraqi Baseline: Digital Assets Accelerating but Still Fragmented
The baseline shows Iraq has moved beyond “no platform” in several functions. The National Centre for Digital Transformation operates or presents Ur, the service creation platform, X-Data, the document-authenticity verification project, the national cloud, the secure government network, the Uboor platform, death-certificate digitalisation and the Tawtheeq system. Together they resemble the core of public digital infrastructure more than separate projects. But their national impact will remain less than their combined potential if identity, payments, data and journeys continue operating under different definitions across entities.10
| Existing asset | Published baseline / indicator | Implication | Gap the figure does not resolve |
|---|---|---|---|
| Ur portal | Live counter, 7/10/2026: 11.4 million registrants; 1,288 services; 784 electronic. | Broad national access point. | Does not establish end-to-end completion rates, time or satisfaction. |
| E-Services | 782 services; 584 active; 19.88 million applications; 4.37 million registered accounts. | Shared no-code/workflow capability. | The definition of “active” and application outcomes need a unified dashboard. |
| X-Data | 37 institutions; 1,412 institutions/branches; 48.29 million records; 205 services. | Expanding government exchange and querying. | Does not establish the share of once-only services or rights safeguards. |
| Eliminating paper document-authenticity checks | 118 entities; 28.66 million documents; 22,308 users. | Less paper correspondence and direct verification. | Does not publish before-and-after time/cost measurement. |
| Secure government network | More than 500 connected entities; project began in 2018. | Shared government communications channel. | Does not establish each entity’s availability, capacity or resilience. |
| Ur Auth | One million users on 5/8/2026. | Second-factor authentication more stable than SMS alone. | Not legal identity or an authorisation register. |
| National card | Around 39 million cards by 1/7/2024. | Broad legal identity base. | Does not imply a reusable digital credential exists for every transaction. |
The GovTech Maturity Index 2025 offers useful external validation, not a final judgement: the World Bank places Iraq in Group C, “medium GovTech maturity”. The index measures four areas: core government systems and shared infrastructure, digital public services, digital engagement and GovTech enablers. This grouping must not be turned into an “Iraq ranking”, nor every gap read as failure. Its value is confirming that progress in platforms needs complementary progress in services, engagement and enablers.11
5. Legal Identity Is Not Digital Identity
National Card Law No. 3 of 2016 and the card’s widespread issuance give Iraq an asset that should not be duplicated. The Vision does not propose a new population register named “digital identity”. It builds a digital layer able — with permission and authority — to use the competent legal source to verify identity and attributes required for a transaction. The design rule is one register responsible for each item’s original truth, with other services querying or verifying rather than copying it into parallel databases.
This distinction matters because digital identity is more than a unified number. An information service may need simple authentication, while transferring ownership, undertaking a substantial financial obligation or making a sensitive decision requires stronger assurance and potentially a qualified electronic signature. Applying maximum verification to every service raises friction and cost; applying the weakest level increases fraud. The Vision therefore adopts risk-based “assurance levels”.
| Assurance level | Use examples | Typical requirements | Decision principle |
|---|---|---|---|
| Low | Personalised general information, appointment booking, low-sensitivity enquiry. | Account/OTP or equivalent method. | Do not demand stronger identity assurance than the risk warrants. |
| Medium | Service application, transaction tracking, limited non-financial update. | Multifactor authentication + identity/account matching. | Record the operation’s audit trail. |
| High | Large payments, legal commitments, sensitive-data changes, high-impact grants/benefits. | Strong authentication + source verification + signature/authorisation where required. | Separation of duties and ability to challenge. |
| Institutional | An entity/official signing in an official capacity, or company authorisation. | Individual identity + institutional status/role + seal/signature. | Personal identity alone does not establish official authority. |
6. Authentication and Assurance Levels
Ur Auth reaching one million users during 2026 demonstrates that a government authentication factor can be deployed widely. Its significance is the function, not the application’s name: less reliance on SMS alone and a faster, more stable second factor. Expansion does not automatically make it comprehensive digital identity. It must fit an assurance framework specifying: who issued the credential? What data support it? How is access recovered if a phone is lost? How is a number change managed? What happens on suspicion? What transaction level does it permit?7
The Vision also needs an alternative pathway that does not discriminate against people without smartphones or stable connectivity. Users may access assisted channels or alternative verification while preserving the same rights and service time as far as possible. Security that blocks eligible people from their rights is not good security, just as ease that permits identity impersonation is not good service. Design must balance risk and friction.
6.1 Identity Lifecycle Management
• Issue/link a credential after legally valid verification with known provenance.
• Secure recovery after phone loss or number changes without opening the door to account takeover.
• Revoke or suspend credentials upon death, loss of legal capacity or suspicion under a lawful procedure.
• Manage user attributes and roles — parent/guardian, company director, agent, competent official — separately from core identity.
• Maintain access logs and notify users of sensitive operations, with a rapid challenge channel.
7. Electronic Signatures and Trust Services
Iraq has had a legal basis since Electronic Signature and Electronic Transactions Law No. 78 of 2012, followed by Instructions No. 1 of 2025 facilitating its implementation, published in Iraqi Gazette Issue 4826. This changes service logic: a digital transaction should not be printed merely for a handwritten signature where law and function permit a verifiable electronic signature. The task is not “adding a signature image”, but building verifiable trust services: personal signatures, institutional seals, timestamps, certificate verification and validity records.812
| Function | Use | Risk if absent | Proposed standard |
|---|---|---|---|
| Personal signature | Declaration, application or contract requiring documented expression of intent. | Printing/scanning and absent technical proof. | Signature linked to an identity and verifiable key/certificate. |
| Institutional seal | Proof that an authorised entity issued the document. | Forgery or reliance on an ungoverned QR code alone. | Institutional seal + automated validity verification. |
| Timestamp | Proof of document creation/signing time. | Dispute over when an action occurred. | Trusted, reviewed time service. |
| Verifiable credential | University certificate / licence / status document. | Paper copies and repeated authenticity checks. | A digital credential its holder can share and have verified. |
The project eliminating paper document-authenticity checks shows that Iraq has already begun moving from “correspondence between two offices” to “direct verification”. The next stage is to make documents themselves ready for automated verification and reduce reliance on citizen-supplied copies where an entity can retrieve the fact from its source. This turns reform of a specific transaction into a reusable trust component across the state.
8. Government Data Exchange and the “Once-Only” Principle
X-Data offers a foundation, but 48.3 million records do not automatically mean “state integration”. Real integration appears when a service prevents repeated requests to citizens, each entity knows what it may retrieve and for what purpose, access is logged, and the originating entity remains responsible for data definitions and quality. Interoperability is not a data-copying project; it is a technical and institutional agreement among independent systems.4
8.1 The Once-Only Principle — An Implementable Iraqi Form
• If information is verified at its original government source and can lawfully be retrieved, citizens are not asked to bring another copy.
• The requesting entity receives only the data needed for the purpose, not the person’s entire file.
• Every exchange records the identity of the entity/official or system, purpose, time and query result.
• Data subjects can — under the framework detailed in C06 — learn of sensitive uses and challenge errors.
• Where records conflict, correction occurs at the authoritative source rather than sending citizens between entities.
Estonia’s X-Road experience is useful because the state did not combine all systems into a central database. Entities retained their systems, connected them through an encrypted, audited exchange layer and applied the once-only principle. The transferable lesson is “controlled exchange among independent sources”, not literal copying of architecture or law.13
9. Networks and Cloud as an Enabling Layer
The secure government network connects more than 500 entities following its launch in 2018 and supports government email, document-authenticity verification, Ur, data exchange and data-centre connections. The national cloud provides centralised, highly available government hosting with redundancy, failover and load balancing. These assets do not need another engineering chapter here. Their importance is making digital rails accessible and continuous, rather than leaving every project dependent on separate connectivity and hosting.1014
The Vision nevertheless rejects a simplistic definition of sovereignty as “all data inside Iraq”. The preceding chapter’s principle governs: technological sovereignty means control, audit, portability and exit from critical dependence. The national cloud is therefore used for suitable government workloads, complemented where necessary by other models subject to data classification, risk and contracts. Details and cyber resilience are passed to C06.
10. Digital Payments and Financial Inclusion
The largest mistake in government service design is assuming an “electronic payment” button solves the problem. Public payments need a regulated financial system, an instrument available to the user, a transaction reference, settlement and reconciliation, an official receipt, refund capability and links to the treasury and service provider. The state must not require a particular bank card to access a right, but should accept regulated interoperable channels wherever possible.
The Financial Inclusion Strategy 2025–2029 gives Iraq a starting point and an official target through 2030: raising formal account ownership to 50% of adults from a demand-side baseline of 11%, and raising the share sending or receiving digital payments to 85%. These are Central Bank strategy targets, not targets invented by Vision 2045. The Vision adopts them as a first-stage reference, then links them to quality of use rather than nominal account opening.9
Infrastructure partly exists: the Central Bank describes electronic collection as secure and transparent revenue collection through the national switch, banks and payment service providers. Its achievements presentation cited participation by 42 ministries and government bodies and the use of cards, points of sale and wallets, with entity transfers automated through payment systems instead of cheques and cash. The financial inclusion strategy also explicitly lists “interoperability” among its enablers.1516
11. Government Payments: From Collection to Reconciliation and Refunds
| Phase | Required function | Outcome Indicator |
|---|---|---|
| Calculation | The service generates an amount and official transaction code. | Share of invoices/fees created automatically without manual entry. |
| Payment | Choose a regulated channel: account/card/wallet/transfer/QR as available. | Payment success rate, time and cost. |
| Reconciliation | Link the financial movement to the same application immediately or within the SLA. | Share of payments automatically reconciled. |
| Receipt | Verifiable electronic government receipt. | 100% of successful payments have a receipt. |
| Recovery | Return funds for rejection, cancellation or overpayment under a published rule. | Refund time and complaint rate. |
| Settlement and audit | Settlement among PSP, bank, treasury and entity, with a record protected against unauthorised manipulation. | Settlement discrepancies and correction cases. |
Government also needs to distinguish “government payments” conceptually from “financial inclusion”. Digitalising fees may increase financial instrument use, but does not by itself create real inclusion. Digital government fees must retain fair alternatives, transparent pricing, no undisclosed intermediary charges, consumer protection and traceable complaint procedures.
12. Government Services: The Portal Is Not the Service
Ur matters because it gives citizens a single access point. But the Vision’s standard goes beyond “where to find the service”. An application may be electronic and then printed inside the office; users may need paper authenticity confirmations, cash payment or an in-person signature, or be unable to know why an application stopped. The interface is then digital while the administration remains paper-based. Vision 2045 therefore adopts the “service journey” as the basic unit of reform.
12.1 The Real Digital Service Test
• Can users learn eligibility, requirements, fees and duration before starting?
• Is identity established once at a risk-appropriate level?
• Are verified government data retrieved instead of requiring users to upload them again?
• Are fees paid electronically and reconciled automatically?
• Can declarations or decisions be signed electronically where law permits?
• Can users see application status, the entity owning each step and the expected deadline?
• Is the decision/document delivered electronically in verifiable form?
• Is there a challenge or support route that does not send users back to the beginning?
13. The End-to-End Digital Service Standard
The Vision proposes a “National Digital Service Standard” as binding rules for priority services, not merely a visual design guide. The standard precedes the platform: processes are not digitalised before reviewing the underlying need for every document and approval; information the state holds is not requested again without justification; fees and deadlines are not concealed; and rejection always has an intelligible, reviewable reason.
| Dimension | Minimum for a priority service | How it is measured |
|---|---|---|
| Clarity | Published eligibility, requirements, fees and SLA. | User testing + service-page audit. |
| Completion | Electronic initiation, application, payment/signature and decision where the service’s nature permits. | % of transactions completed without a visit. |
| Once-only | Reuse verified data through X-Data / original sources. | Number of fields/documents citizens resubmit. |
| Case | Track every step and notify changes. | % of applications with clear status. |
| Responsibility | Outcome owner and escalation route. | Share of cases exceeding the SLA and their resolution. |
| Inclusion | Assisted channel and accessibility for disability, language and skill needs. | Completion gaps among groups. |
| Integrity | Official fees, reason codes, override log. | Manual exceptions, complaints and unofficial fees. |
14. Priority Life and Business Journeys
All 1,288 services cannot be reformed simultaneously to the same quality. The Vision begins with a portfolio of high-volume or high-impact journeys, grouping scattered services around an “event” citizens or business owners understand. Instead of knowing office names, users know their desired result: a child’s birth, starting university, establishing a company, hiring a worker, buying a home, retirement, death, transferring ownership or importing goods. Legal jurisdictions remain behind the interface, but the state coordinates them.
| Priority journey | Shared components | Proposed 2030 measure |
|---|---|---|
| Birth / family | Event registration + identity + health + entitlements + notifications. | Unified journey in covered governorates, then nationwide roll-out. |
| Higher education | Identity + verifiable certificate + application + payment + admission/redress. | No paper authenticity confirmations for verified digital documents. |
| Company formation | Identity/authorisation + name/registration + tax + social security + payment + related licences. | Published actual time from complete application to registration. |
| Employment / social security | Worker/company identity + contract/registration + contribution/payment. | One procedure instead of repeated entry. |
| Retirement | Identity + service record + decision + payment account + challenge. | Full tracking, notifications and time measurement. |
| Death / estate | Digital death certificate + record updates + notifications to necessary entities + heir services. | Prevent repeated copies being requested for the same event. |
| Licensing / ownership transfer | Identity + ownership + fees + approvals + signature + record. | End-to-end digitalisation of legally eligible pathways. |
This list is neither legislation nor a final ranking. In 2027, the portfolio is selected according to transaction volume, friction costs, effects on rights and the economy, data readiness and reform feasibility within 12–24 months. Every journey passes a “quality gate” before funding and expansion.
15. Digital Documents and the Government Inbox
Friction recurs because citizens still carry documents between state bodies. The authenticity-verification project has removed a substantial part of this loop, but the Vision goes further: an original digital document or verified credential should be directly verifiable, accessible to citizens and shareable when needed, while government retrieves facts from their source where law permits.
The Vision proposes a “government document/credential wallet”, not as a new database but as a user interface to documents issued by their original sources, with verification codes/mechanisms and governed sharing. India’s DigiLocker illustrates the mechanism: a government platform enabling users to access and share verifiable original documents. According to its official page in October 2026, it had exceeded seven hundred million users and nine billion issued documents. Iraq should transfer not the figures but the issuer–wallet–verifier model.17
A “government inbox” within users’ accounts complements this: official notices, requests for additional information, decisions, appointments, receipts or document-expiry alerts. A unified inbox reduces scattered messages and informal contact and creates a retrievable record, but does not remove SMS, email or supporting notifications when necessary for access.
16. Reducing Corruption by Reducing Friction
Digitalisation does not “eliminate corruption”. A poor digital system can entrench monopoly, conceal decision criteria or expand surveillance. But service design can reduce some opportunities for petty corruption and intermediation by limiting compulsory contact, standardising conditions and fees, constraining unrecorded discretion and creating an audit trail. A United Nations study on the “integrity dividend” of digital government links digitalisation to reduced red tape and discretion and greater transparency, while stressing that impact requires integration with integrity strategy rather than isolated action.18
| Old friction point | Alternative digital design | Potential integrity effect | New risk |
|---|---|---|---|
| Information held by an official/intermediary | Published requirements, fees and SLA. | Reduce information monopoly. | Outdated information if no one owns updates. |
| Paper / cash submission | Digital application + payment + receipt. | Reduce room for unofficial payments. | Intermediary fees / payment failure without protection. |
| Unreasoned discretion | Rules + reason codes + override log. | Make exceptions reviewable. | Automated bias if the rule itself is flawed. |
| Repeated visits | Once-only and inter-agency exchange. | Fewer friction points. | Expanded data access without purpose. |
| Users do not know where applications stopped | status + SLA + escalation. | Harder to “sell” unofficial acceleration. | A cosmetic dashboard disconnected from reality. |
| A forgeable document | Digital source / direct verification. | Reduce forgery and authenticity correspondence. | Account impersonation if identity assurance is weak. |
The most important measure is not “the percentage of electronic services”, but indicators such as required visits, applications needing manual intervention outside the workflow, override rates and reasons, time differences among similar users, complaints of unofficial payment demands, and cases exceeding deadlines without a reason code. These operational indicators let integrity and oversight bodies focus on patterns rather than await individual complaints.
17. Digital Inclusion and Assisted Channels
Digital government fails if it improves the national average while excluding older people, people with disabilities, residents of poorly connected areas or those without smartphones or financial accounts. The Vision therefore adopts “digital-first, not digital-only”: digital is the simplest default channel for suitable services, while assisted access provides the same outcome and challenge rights without an implicit penalty for needing support.
This is particularly important in payments. The financial inclusion strategy itself shows that accounts are unevenly distributed and that only 11% in the 2024 diagnostic represents households with a bank or payment account under the baseline used. Until inclusion expands, government services must offer payment or assistance options that do not turn account non-ownership into denial of service.9
| Group / barrier | Design solution | Non-exclusion indicator |
|---|---|---|
| Basic phone / intermittent connection | Alternative OTP / assistance centre / saved progress where possible. | Completion rate by device type/area. |
| Digital illiteracy | A public service assistant in a government/local centre, not an informal private intermediary. | Assisted versus self-service time. |
| Persons with disabilities | Accessibility standards, screen readers, contrast, translation/sign language where needed. | Independent accessibility tests. |
| No financial account | Multiple regulated payment channels and a transition/assistance period. | Payment-method rejection rate = zero for essential services. |
| Data error | Clear correction pathway at the authoritative source. | Record-correction time and number of entities involved. |
18. Architecture, Interoperability and Procurement
Public digital infrastructure must prevent two monopolies: every ministry monopolising its own rails, and one supplier monopolising the entire state. The Vision therefore adopts modular architecture, standards, documented APIs and replaceable services. A shared layer defines a clear function — identity verification, payment, query or signature — without imposing one technology on every internal system if it meets the contract and safeguards.
The World Bank’s paper on DPI standards uses an “hourglass model”: a limited set of core standards in the middle permits wide diversity of applications and technologies above and below. Iraq’s lesson is that government need not specify every product; it must specify protocols, credentials, interfaces, user rights and conformance tests that allow competition without breaking integration.19
| DPI procurement rule | Condition |
|---|---|
| Ownership and data | Government and user data do not become the provider’s commercial asset merely through hosting. |
| Documented interfaces | APIs, schemas and versioning disclosed to authorised entities. |
| Departure | Export data, settings and documents in agreed formats + migration plan. |
| Compatibility | Interoperability tests before final acceptance. |
| Security | Requirements, audit and response according to C06 classification. |
| Performance | Real SLA, monitoring, penalties/correction and continuity plans. |
| Development | No “one-time development” contracts without maintenance, updates and change standards. |
19. Resilience, Privacy and the Bridge to Data Sovereignty
Every success in C05 expands the risk surface: unified identity is easier for users and more valuable to attackers; faster data exchange improves services and increases risks of use beyond the purpose; digital payments reduce cash and create dependence on financial and communications infrastructure; a unified government inbox strengthens trust when messages are authentic and becomes a fraud point when they are not. Resilience and privacy are therefore designed from the outset, while detailed data and security policy belongs to the next chapter.
• Critical services have no single point of failure; redundancy, recovery and continuity tests are mandatory.
• Use the minimum data needed for the purpose, precise permissions, access logs and expiring authorisations where appropriate.
• Separate development and test environments from real data and prohibit copying entire databases merely for integration.
• Notify users of incidents or sensitive operations under law and the response plan.
• Allow fallback to assisted channels when a critical central service fails, without extinguishing citizens’ rights.
20. Comparative Lessons: Estonia, India and Singapore
| Case | Useful Mechanism | What transfers to Iraq | What Cannot Be Transferred |
|---|---|---|---|
| Estonia — X-Road | Secure exchange among independent systems + once-only. | Distributed authoritative sources, audited exchange, no repeated requests for the same citizen data. | Copying legal/population structures or assuming identical trust and capacity. |
| India — UPI / DigiLocker | Relatively open payment rails + document/verification wallet at vast scale. | Reusable standards, separation of source and interface, competing service providers over shared rails. | Copying the scale or Aadhaar/UPI as one Iraqi system without legal and financial adaptation. |
| Singapore — Singpass / MyInfo | Trusted identity + user consent + population of forms with verified government data + signatures. | Identity/trust chain, purpose/consent, reuse of verified data. | Assuming one digital channel is enough; the documentation itself recommends retaining manual entry for users unwilling or unable to use it. |
In India, UPI reached around 24.5 billion monthly transactions in August 2026 across 752 participating banks. This demonstrates a shared payment standard’s ability to carry many applications, not a numerical target for Iraq. In Singapore, MyInfo enables forms to be populated with verified government data with user consent, while Singpass provides authentication and signatures. This illustrates combining trust functions without forcing every service to store a new data copy.202122
21. Iraq’s Digital Landscape in 2045
In 2045, digital-state maturity is not measured by application counts. Citizens sign in using trusted identity appropriate to the transaction, see services organised around life events rather than office names, authorise retrieval of necessary verified data rather than upload images, pay or receive funds through regulated interoperable channels, sign where the action requires, receive decisions in a government inbox and know how to challenge them. Companies do the same through authorised representatives, handling licensing, taxes, social security and customs without re-entering core data each time.
Inside the state, there is no “copy and paste” between ministry systems. Every entity owns its data and jurisdiction, but publishes or consumes standard services through X-Data/the national architecture and uses cloud, networks, identity, payments and trust services instead of incompatible local alternatives. Critical platforms are measured by availability and recovery; services by outcome time, user satisfaction and first-time completion; integrity by exceptions, friction and audit trails.
22. Transition Stages, 2027–2045
| Phase | Priority | Transition Condition |
|---|---|---|
| 2027–2030 | Foundation | National service standard; identity and trust framework; baseline for major journeys; government payment integration; X-Data expansion; first portfolio of end-to-end services. | Public measurement of time, completion and visits; reusable identity, payments and exchange in selected journeys. |
| 2031–2035 | Integration | Once-only across most priority journeys; verifiable documents; government inbox; broader business transactions. | A tangible reduction in repeated documents, visits and manual exceptions. |
| 2036–2040 | Proactive Services | Multi-agency life-event services; proactive notifications and entitlements where law permits; wider rail reuse by the regulated private sector. | Mature data/security governance, impact assessment and reliable consent/challenge mechanisms. |
| 2041–2045 | Maturity | Public digital infrastructure becomes the default standard for every new service; continual updating, portability, high resilience and cross-border integration where it serves Iraqi interests. | Continuous critical services, effective assisted channels and annual data-driven improvement. |
23. Indicator and Target Dashboard
Established official baselines are used where available. Where absent — as with service time, end-to-end completion and repeated documents — the 2027 goal is to establish a baseline, not invent a 2026 figure. The following targets are Vision policy decisions, not automatic forecasts, and are reviewed after first-year measurement.
| Indicator | Baseline | 2030 | 2035 | 2040 | 2045 |
|---|---|---|---|---|---|
| Priority services completed end to end | To be established in 2027 | ≥70% | ≥90% | ≥95% | ≥98% of digitally eligible services |
| Priority services applying once-only to lawfully available data | To be established in 2027 | ≥60% | ≥85% | ≥95% | ≥98% |
| Digitally payable government transactions with automatic reconciliation and receipts | To be established in 2027 | ≥85% | ≥95% | ≥98% | ≥99% |
| Average in-person visits for selected journeys | To be established in 2027 | ≤1 | ≤0.5 | ≤0.25 | Zero by default unless attendance is necessary |
| Share of services with an SLA, application status and traceable rejection reason | To be established in 2027 | ≥80% | ≥95% | 100% of priority services | 100% |
| Share of sensitive manual overrides recorded and justified | To be established in 2027 | 100% | 100% | 100% | 100% |
| Formal account ownership — financial inclusion strategy target | 11% (2024 diagnostic) | 50%* | CBI update | CBI update | CBI update |
| Sending/receiving digital payments — CBI target | 77% in the reference | 85%* | CBI update | CBI update | CBI update |
| Critical rail availability | Established by component | ≥99.5% | ≥99.8% | ≥99.9% | SLO according to service criticality |
* The official 2030 target in the Central Bank’s Financial Inclusion Strategy 2025–2029, not a target derived by the Vision team. Other C05 targets are proposed policies subject to recalibration after the 2027 baseline.
24. The Implementation Programme Package
| Code | Programme | Outcome | Lead entity/partners | Time | Relative cost |
|---|---|---|---|---|---|
| DPI-01 | Digital Identity and Trust Framework | Unify assurance levels and connect legal identity to authentication and signatures/authorisation without a parallel population register. | Prime Minister’s Office / National Centre + Ministry of Interior + competent legal entities | 2027–2030 | Medium |
| DPI-02 | Government Trust Services | Activate reusable signatures, timestamps, institutional seals and verification. | Entities responsible for implementing Law 78/2012 + National Centre | 2027–2032 | Medium |
| DPI-03 | X-Data 2.0 and Once-Only | Data dictionary, interfaces, permissions and usage logs; expand journeys retrieving data instead of requesting it. | National Centre + register owners | 2027–2035 | Medium |
| DPI-04 | Top Journeys 50 | Redesign the first 50 high-volume/high-impact journeys, then expand through a quality gate. | Secretariat / National Centre + outcome-owning ministries | 2027–2030 | Medium |
| DPI-05 | Government Payment Rail | Transaction references, acceptance of multiple channels, reconciliation, receipts, refunds and settlement. | Central Bank + Ministry of Finance + collecting entities | 2027–2031 | Medium |
| DPI-06 | Document and Verification Wallet | A citizen interface to verifiable original documents and credentials, building on authenticity verification and source registers. | National Centre + issuing entities | 2028–2033 | Medium |
| DPI-07 | Government Inbox and Notifications | Official channel for decisions, requests, receipts and alerts, linked to supporting messages. | National Centre | 2028–2032 | Low–medium |
| DPI-08 | Assisted Digital Access and Inclusion | Service centres/points helping users follow the same digital pathway + accessibility standards. | Service entities / governorates + National Centre | 2027–2035 | Medium |
| DPI-09 | Digital Friction and Integrity Observatory | Measure steps, visits, SLA, overrides, complaints, unofficial fees and anomalous patterns. | Delivery unit + oversight/integrity bodies + service entities | 2027–ongoing | Low |
| DPI-10 | API Catalogue and Service Standards | Shared-function catalogue, schemas, versioning, conformance tests and procurement with exit routes. | National Centre + regulatory/technical entities | 2027–ongoing | Low–medium |
The package does not require a new digital ministry. It strengthens the National Centre for Digital Transformation as coordinator, standard setter and builder of shared rails, while outcome ownership remains with the legally competent ministry/authority, payments remain under Central Bank regulation and legal identity with the Ministry of Interior. This prevents a “parallel digital state” outside state institutions.
25. Implementation, Cost and Financing Matrix
| Package | Expenditure type | Proposed funding | Approval gate | Sound spending indicator |
|---|---|---|---|---|
| Identity / trust | Integration, certificates/keys, security, support. | Federal budget + international technical assistance not tied to a supplier. | Assurance model + testing + recovery plan. | Authenticated transactions with lower fraud/friction. |
| X-Data / interfaces | Platforms, integration and register updates. | Central digital budget + sectoral contributions. | Defined use case + data owner + legal basis. | Fields/documents no longer requested from citizens. |
| Services / journeys | Re-engineering, UX, integration, training. | Entity budgets + staged transformation fund. | Baseline + journey map + remove steps before automation. | Time / visits / completion / satisfaction. |
| Payments | Integration, acceptance and settlement solutions. | Central Bank / financial sector + government integration. | interoperability + consumer protection + reconciliation. | Successful payments and lower-cost reconciliation/refunds. |
| Inclusion | Assistance points, accessibility, staff training. | Service / local budgets. | Measure access gaps. | Reduced completion gaps among groups. |
| Measurement and integrity | Telemetry / BI / audit / satisfaction and complaints. | Low cost within each programme. | No priority service without operating data. | Quarterly corrective decision. |
25.1 Funding Rule
A major digital project is not funded because it is “modern”. Funding follows a journey or shared rail with a baseline, outcome owner and usage/completion indicator. Operation, maintenance, security, licensing, messages and support enter TCO from the outset. Projects building reusable shared functions receive higher priority than sectoral systems duplicating existing functions.
26. Risks and Safeguards
| Risk | Likelihood | Effect | Safeguard/mitigation |
|---|---|---|---|
| Digitalising bureaucracy instead of reforming it | High | High | Review procedures and remove unnecessary steps before automation; journey-design gate. |
| Parallel digital identity / duplicate registers | Medium | High | Interior / legal register as authoritative source; a verification layer, not a new population register. |
| Excluding unconnected or financially excluded people | High | High rights impact | Assisted channel, alternative payments and access-gap indicators. |
| Data leakage / misuse | Medium | Catastrophic | Purpose limitation, minimum data, logs, permissions and detailed handover to C06. |
| Central point of failure | Medium | High | Redundancy, failover, continuity tests, fallback channels. |
| Technology supplier monopoly | High | High financial / sovereignty impact | Open standards, APIs, portability, exit clauses and exit tests. |
| Hidden digital fees | Medium | Medium / high | Unified disclosure, consumer protection and PSP fee oversight. |
| Corruption moving into rule design | Medium | High | Published rules, reason codes, separation of duties, audit analytics, challenge. |
| Expanding data sharing without purpose | Medium | High | Permissions, purpose, usage logs and C06 classification/rights. |
| Cosmetic achievement counters | High | Medium | Measure completion, time, visits and outcomes, not service counts alone. |
| Identity/payment failure halting many services | Medium | High | SLO/SLI, multiple channels, degraded operating modes and regular testing. |
| Conflicting federal/local standards | Medium | High | A national standard for the rails, with flexibility in local implementation within common APIs and a shared data dictionary. |
27. What Do We Not Do?
• We do not build a new “digital identity” separate from the register and national card; we build a trust layer over the legal reference.
• We do not turn Ur Auth into proof of legal identity merely because it is a successful authentication factor.
• We do not combine every database into a massive central repository; we connect sources of truth through permissions and standards.
• We do not require every ministry to have its own portal, app, payment wallet and login system where the function is shared.
• We do not count every published form as an end-to-end digital service.
• We do not regard payment as successful if an employee still reconciles it manually or requests a paper receipt.
• We do not replace the employee with an opaque interface; we remove unnecessary friction while retaining support and human responsibility.
• We do not use “reducing corruption” as a pretext to remove the right of appeal or introduce disproportionate surveillance.
• We do not make digital-only access a condition for basic services before effective digital inclusion is in place.
• We do not measure success solely by the number of systems or services; we measure time, completion, visits, cost and outcome.
• We do not bind the state to a closed supplier without an exit plan, data export and interoperability testing.
• We do not set a “100% digitisation” target for activities that require physical presence or legitimate human judgement; we digitise what can be digitised and coordinate what cannot.
28. Conclusion and the Bridge to Data Sovereignty and Cybersecurity
This chapter develops a simple but transformative argument: the citizen does not need a thousand separate services; the citizen needs a state that reuses its shared capabilities. When identity, trust, payment, exchange, notification and tracking become public rails, every sector can build its services faster, at lower cost and with measurable quality. When a journey is assessed by its outcome rather than its number of screens, the administrative question “Why do we require this step?” comes before the technical question “How do we program it?”.
Notes and references
Documentary Notes
- World Bank Group, Digital Public Infrastructure and Services / Global DPI Program, 2025–2026. The World Bank defines DPI as foundational infrastructure comprising digital identity, interoperable digital payment systems and secure data exchange, with an emphasis on reusability, trust and privacy.↩
- National Centre for Digital Transformation, E-Services Platform, accessed 7 October 2026: 782 services on the platform, 584 activated, 2,395 accredited stations, 17,342 registered employees (7,722 active), 4,370,742 citizen accounts and 19,875,127 registered applications.↩
- Ur Electronic Portal, homepage, snapshot of 7 October 2026: 11,419,366 registered users, 1,288 services in total, 504 information services and 784 electronic services. The counters are dynamic and are used as an operational snapshot, not an annual series.↩
- National Centre for Digital Transformation, National Project to Eliminate Paper Document-Authenticity Checks, last updated 19 August 2026: 118 connected entities, 28,664,085 completed documents and 22,308 users; direct digital verification replaces traditional authenticity correspondence for connected entities.↩
- National Centre for Digital Transformation, X-Data Smart Data Management Platform, last updated 19 August 2026: 37 government institutions, 1,412 institutions/branches, 2,110 active users, 48,285,956 records/data entries, 1,933,351 issued documents and 205 digital services.↩
- Iraqi Ministry of Justice, Iraqi Official Gazette: National Card Law No. 3 of 2016 in issue 4396; and Electronic Signature and Electronic Transactions Law No. 78 of 2012 in issue 4256.↩
- National Centre for Digital Transformation, “One Million Users Rely on Ur Auth to Secure Access to the Ur Portal”, 5 August 2026. The app is a two-factor authentication method alternative or complementary to SMS OTP; this chapter does not treat it as a legal identity in itself.↩
- Iraqi Ministry of Interior, 1 July 2024, announcement of the opening of the national card printing plant: approximately 39 million national cards issued, with a direction to adopt the card as the citizen’s primary identification document.↩
- Central Bank of Iraq, National Financial Inclusion Strategy 2025–2029: the 2024 diagnosis sets a baseline for bank/payment account ownership of 11% according to the demand-side survey, targeting 50% of adults by 2030; it also targets an increase in those sending or receiving digital payments from 77% to 85%. Provider data recorded 16.7 million accounts in the first quarter of 2024, with a warning about duplication and non-use; the strategy therefore adopts the demand-side survey for its principal indicator.↩
- National Centre for Digital Transformation, Services Portal, 2026: Ur, elimination of paper authenticity checks, E-Services, the national cloud, Uboor, the secure government network, digitisation of death certificates, X-Data and Tawtheeq.↩
- World Bank, GovTech Maturity Index 2025: Iraq is in Group C (Medium GovTech Maturity). The index covers core government systems and shared infrastructure, digital public services, digital engagement and GovTech enablers; it is a maturity tool, not a political ranking of countries.↩
- Iraqi Ministry of Justice, Iraqi Official Gazette issue 4826, dated 19 May 2025: Instructions No. (1) of 2025 to facilitate implementation of Electronic Signature and Electronic Transactions Law No. (78) of 2012.↩
- e-Estonia, X-Road – Interoperability Services. X-Road connects independent systems and databases and supports the once-only principle, encryption and data integrity. Promotional figures for time saved are not used as targets for Iraq.↩
- National Centre for Digital Transformation, Secure Government Network and National Cloud, accessed 7 October 2026: the network has connected more than 500 government entities since the project began in 2018; the cloud provides central government hosting with High Availability, Redundancy, Failover and Load Balancing.↩
- Central Bank of Iraq, National Financial Inclusion Strategy 2025–2029, infrastructure area: strengthening interoperability between financial institutions, electronic payment accounts and payment systems, while protecting privacy and security.↩
- Central Bank of Iraq, “Achievements in Payment Systems”, 2025: the electronic collection project through the national switch, banks and payment service providers, with 42 ministries and government bodies participating in the published presentation, and automation of government transfers through the payment system.↩
- DigiLocker, Government of India / MeitY, official portal, updated 1 Oct 2026: 70+ crore registered users (more than 700 million) and 900+ crore issued documents (more than 9 billion). This chapter uses only the issuer–wallet–verifier model and does not transfer its scale to Iraq.↩
- United Nations DESA, Carlos Santiso, Trust with Integrity: Harnessing the Integrity Dividends of Digital Government for Reducing Corruption in Developing Countries, 2022: digitisation can reduce red tape and discretion and increase transparency, but its integrity impact requires integration with anti-corruption policies.↩
- World Bank, Digital Public Infrastructure: Setting Standards with the Hourglass Model, 2025: a narrow set of core standards can support a wide range of applications and technologies, with governance, context-appropriate design and public–private cooperation being important.↩
- Singpass MyInfo Partner Support, 2026: the consent page displays the purpose and data requested; the documentation also recommends allowing manual entry for users unwilling or unable to use MyInfo or when the service is unavailable—an important lesson for inclusion and for avoiding a single digital channel.↩
- Singpass Developer Portal, Government Technology Agency of Singapore, updated 1 Oct 2026: Singpass Login for authentication, MyInfo for filling in verified government data with user consent, and Sign with Singpass for secure electronic signatures.↩
- National Payments Corporation of India, UPI Product Statistics, August 2026: 752 banks live, 24,508.96 million transactions during the month. The figure is an example of scale and is not used as a target for Iraq.↩
Core References
- World Bank Group, Digital Public Infrastructure and Services / Global DPI Program, 2025–2026:Original link.
- Ur Electronic Portal, homepage and “About Us”, live counters frozen on 7 October 2026:Original link.
- National Centre for Digital Transformation, E-Services Platform:Original link.
- National Centre for Digital Transformation, X-Data Smart Data Management Platform, updated 19 August 2026:Original link.
- National Centre for Digital Transformation, National Project to Eliminate Paper Document-Authenticity Checks, updated 19 August 2026:Original link.
- Iraqi Ministry of Interior, “Minister of Interior Opens the Colour Printing Plant for National Cards”, 1 July 2024: approximately 39 million cards:Original link.
- Iraqi Ministry of Justice, Iraqi Official Gazette issue 4396: National Card Law No. 3 of 2016:Original link.
- National Centre for Digital Transformation, “One Million Users Rely on Ur Auth”, 5 August 2026:Original link.
- Iraqi Ministry of Justice, Iraqi Official Gazette issue 4256: Electronic Signature and Electronic Transactions Law No. 78 of 2012:Original link.
- Iraqi Ministry of Justice, Iraqi Official Gazette issue 4826: Instructions No. 1 of 2025 to facilitate implementation of Law 78/2012:Original link.
- National Centre for Digital Transformation, Secure Government Network: more than 500 entities:Original link.
- National Centre for Digital Transformation, National Cloud:Original link.
- Central Bank of Iraq, National Financial Inclusion Strategy 2025–2029:Original link.
- Central Bank of Iraq, “Achievements in Payment Systems”—electronic collection and automation of entities:Original link.
- World Bank, GovTech Maturity Index 2025, Iraq in Group C — Medium GovTech Maturity:Original link.
- United Nations DESA, Trust with Integrity: Harnessing the Integrity Dividends of Digital Government for Reducing Corruption, 2022.
- e-Estonia, X-Road — Interoperability Services and once-only principle:Original link.
- NPCI, UPI Product Statistics, August 2026:Original link.
- DigiLocker, official portal statistics, last updated 1 October 2026:Original link.
- Singpass Developer Portal, Login/MyInfo/Sign with Singpass, updated 1 October 2026:Original link.
- Singpass MyInfo Partner Support, consent/data source guidance, 2026:Original link.
- World Bank, Digital Public Infrastructure: Setting Standards with the Hourglass Model, 2025.
Data Gaps to Close
| Gap | Why does it matter? | Proposed gap-closing mechanism |
|---|---|---|
| End-to-end service completion | The service counter does not demonstrate the outcome. | An official definition of completion and service-by-service measurement. |
| Actual service time | There is no unified national time series. | Telemetry from opening the application to the decision, with median/P90. |
| Number of visits/documents | The core of the friction is not measured. | Journey survey + logs for a sample of Top Journeys. |
| X-Data use by journey | Record volume does not demonstrate once-only operation. | Link each query to a service/purpose and measure repeated requests for data. |
| Identity assurance levels | The sources used contain no unified public national framework. | Adopt an assurance framework and test entities. |
| Signatures/trust services | The existence of the law does not demonstrate widespread actual use. | A register of providers/entities/transactions and technical and legal audits. |
| End-to-end government payment | The existence of POS/collection does not demonstrate reconciliation and refunds. | Measure success/reconciliation/refunds/fees by entity. |
| Critical rail availability | Published national SLA figures are limited. | Unified SLI/SLO and transparency through aggregated outage reporting. |
| Digital divide | Access averages conceal disadvantaged groups. | Measure service completion by age/location/disability/channel. |
| Integrity and friction | No baseline for overrides/expediting requests/unofficial fees. | reason codes + audit logs + survey/complaints analytics. |