Join our Newsletter — 33% off our NHI Course

Non-Face-To-Face Business Relations

Non-face-to-face business relations are customer relationships established without in-person interaction, such as digital or remote onboarding. These journeys require stronger evidence and layered controls because the firm cannot rely on physical presence alone. Jurisdictional rules often require additional checks to offset that added risk.

Expanded Definition

Non-face-to-face business relations describe a relationship lifecycle that begins and continues without a physical, in-person meeting. In practice, this usually means remote onboarding, app-based verification, web journeys, or agent-assisted digital sign-up where the institution must decide whether the customer is real, present, and entitled to the account. The concept sits at the intersection of identity verification, fraud prevention, and AML/KYC governance, because the absence of physical presence removes a traditional trust signal.

Definitions vary across vendors and jurisdictions, but the common security theme is consistent: the organisation must compensate for lost presence with stronger documentary, biometric, device, or behavioural evidence. That makes the control problem less about the channel itself and more about the assurance built into the journey. Guidance in NIST SP 800-53 Rev 5 Security and Privacy Controls is useful here because it frames identity, auditability, and risk treatment as control outcomes rather than assumptions about how a customer arrived.

The most common misapplication is treating a remote sign-up flow as lower risk than an in-branch process, which occurs when teams rely on convenience signals instead of verified identity evidence.

Examples and Use Cases

Implementing non-face-to-face business relations rigorously often introduces onboarding friction, requiring organisations to weigh conversion speed against assurance and regulatory defensibility.

  • Digital bank onboarding where a customer uploads identity documents, completes liveness checks, and is screened before the account is activated.
  • Insurance signup through a mobile app where the firm must validate identity remotely and retain evidence for later audit or dispute handling.
  • Cross-border account opening where the organisation must reconcile local KYC expectations with remote verification methods and document retention rules.
  • Small-business onboarding where the relationship may involve both a legal entity and an authorised representative, increasing the need for entity-resolution and signer verification.
  • Contact-centre assisted onboarding where a human agent guides the process, but the firm still needs controls to prevent impersonation, synthetic identity abuse, or credential stuffing.

Remote business relationships are especially sensitive when they are paired with digital identity proofing requirements in standards such as NIST SP 800-63A, because the strength of the evidence collected directly affects downstream trust decisions.

Why It Matters for Security Teams

Security teams need to understand non-face-to-face business relations because the control burden does not end once the account is opened. Remote relationships create a persistent attack surface for impersonation, account takeover, mule activity, and laundering through compromised or fabricated identities. They also create governance pressure: if the organisation cannot explain how identity was established remotely, it may struggle to defend its KYC decisions, respond to audits, or justify account closures.

This term matters beyond compliance because it shapes how identity evidence is collected, scored, retained, and revisited over time. In identity-led environments, especially where NHI and delegated access are involved, the same remote trust logic can affect service accounts, managed identities, and agentic workflows that are provisioned without any human meeting. Controls around logging, step-up verification, and periodic review become critical when a relationship is opened digitally and later reused across channels.

For practitioners, the key question is not whether a customer was never seen in person, but whether the organisation can still demonstrate sufficient assurance, traceability, and accountability. Organisations typically encounter the operational cost of this term only after a fraud loss, a failed audit, or a disputed account opening, at which point non-face-to-face business relations become operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST CSF 2.0, NIST AI RMF and NIST SP 800-53 Rev 5 set the technical controls, while DORA define the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-63 IAL2 Digital identity proofing levels define assurance expectations for remote onboarding.
NIST CSF 2.0 PR.AC-1 Access control outcomes support verified identity before granting service access.
NIST AI RMF Risk governance principles apply when automated checks influence remote identity decisions.
NIST SP 800-53 Rev 5 IA-2 Identification and authentication controls underpin trusted remote customer relations.
DORA Operational resilience expectations cover remote onboarding processes and evidence handling.

Document decision logic, human oversight, and risk acceptance for automated onboarding checks.