Information

You appear to be using an unsupported browser, and it may not be able to display this site properly. You may wish to upgrade your browser.

Service catalogue

If you adopt ScotAccount for your service, it will reduce complexity for your users, saving them time while reducing the cost to your organisation in delivering your service.

We are continually developing the offering that’s outlined in this Service Catalogue. We would be delighted to speak to you about your particular requirements. Get in touch to discuss.

What ScotAccount offers

ScotAccount provides:

  • a system built to modern privacy and ethics respecting standards that’s permissions-based at all times
  • smooth access to public services whilst promising that end users’ information will never be used by private organisations for other purposes
  • two-factor authentication (2FA) for extra account security
  • self-service password reset & recovery
  • data minimisation, including ethical and privacy protecting measures for users
  • ongoing support and security monitoring
  • an experience that meets Digital Scotland Service Standards and is in line with the Digital Scotland Design System
  • a service that meets Scottish Government Identity Management and Privacy Principles
  • time and cost savings across the public sector

ScotAccount is also compliant with current security and technical benchmarks. This includes:

  • OpenID Connect (OIDC) authentication
  • WCAG 2.1 level AA accessibility
  • Good Practice Guidance 44 & 45 Medium
  • Scottish Public Sector Cyber Resilience Framework (Advanced Tier)
  • National Cyber Security Centre Cyber Assurance Framework (NCSC CAF)
  • alignment with CSA STAR

Authentication

ScotAccount authenticates each new and returning user, so your service does not have to.

When authenticating your users, your service will be provided with a unique reference for each individual. This means you’ll always know the only people accessing your service through ScotAccount are people who have been authenticated.

As part of setting up a ScotAccount, data minimisation is maintained at all times. ScotAccount only requires an email address and phone number to create their ScotAccount.

ScotAccount does not control what your user can do within your service. You will continue to manage authorisation within your systems.

Test/integration environment

Before your service moves into a production environment, there is a separate process for support in our integration environment.

Before going into production, you will be onboarded to our integration environment for two purposes:

  • familiarisation with our service
  • to allow you to test your own integrations and service connections

Our integration environment is currently available 24/7.

Verify your identity

You can also opt to include an identification check for your users, if it’s necessary for your service. This allows you to verify that your users are who they say they are.

Identity verification can be requested at any point in your service’s user journey.

While our initial service uses photo ID and facial matching to verify a user’s identity, alternative routes are being added, starting with knowledge-based verification. Knowledge based verification involves asking a series of questions that only the individual user would know the answers to.

Charges

There is currently no charge to use ScotAccount, either for you or your users.

Availability, Support & Escalation

ScotAccount will be available for use 24 hours a day, 365 days per year.

At the moment:

  • core support is currently provided between 09:30 and 16:30 Monday to Friday
  • your call handlers and customer service staff can use our level one support to report any problems your users have to us
  • ICT staff can use level two support to raise incidents and issues to our ICT Ops directly

We run Priority 1-Priority 4 Incident Management processes, each with their own SLA/SLO targets.

Escalation processes ensure that calls are not overlooked and to highlight where additional resources may be required.

How to get involved

The more services that use ScotAccount, the more value it will have for users. If you are responsible for an online public service and would like to learn more about opportunities for integrating ScotAccount with your services, get in touch: ScotAccount@gov.scot.

Back to top