Join our Newsletter — 33% off our NHI Course

How should organisations approach customer due diligence for non-face-to-face business relationships in Denmark?

Organisations should align customer due diligence with the Danish rules for remote onboarding, using risk-based identity verification, document checks, and ongoing monitoring. The practical aim is to confirm who the customer is, understand the purpose of the relationship, and detect unusual patterns early. Controls should be proportionate to the customer risk, product risk, and delivery channel, especially when no in-person interaction occurs.

Why This Matters for Security Teams

Non-face-to-face onboarding changes the risk profile of customer due diligence because the organisation cannot rely on a physical meeting to validate identity, intent, or behavioural consistency. That increases exposure to synthetic identities, impersonation, document fraud, mule activity, and account misuse, which is why Danish practice should be treated as a control design problem, not a paperwork exercise. The relevant question is whether the evidence collected is strong enough to support a defensible risk decision.

For teams designing onboarding flows, the important discipline is to separate identity proofing from customer acceptance decisions. Identity verification, screening, and ongoing monitoring each answer a different question, and weak implementations often blur them together. Security and compliance leaders should also ensure that remote onboarding evidence is retained in a way that supports auditability and later investigations, consistent with baseline control expectations in NIST SP 800-53 Rev 5 Security and Privacy Controls.

In practice, many security teams encounter weaknesses only after a fraud pattern, sanctions issue, or disputed account opening has already occurred, rather than through intentional testing of the onboarding process.

How It Works in Practice

A sound approach starts with a risk assessment that considers the customer type, product, geography, funding method, and channel. For non-face-to-face relationships, organisations typically combine documentary checks, electronic verification, liveness or biometric assurance where appropriate, device or session risk signals, and screening against sanctions and adverse media. The evidence set should be strong enough to support a reasonable belief that the customer is who they claim to be, while still allowing proportionate friction for lower-risk cases.

Current guidance in the AML and KYC space, including the FATF Recommendations — AML and KYC Framework, supports a risk-based model rather than a one-size-fits-all checklist. In Denmark, that usually means documenting the controls used for remote verification, the rationale for any simplified or enhanced due diligence, and the triggers that require escalation to manual review. Ongoing monitoring should then look for changes in transaction behaviour, beneficial ownership, contact details, device patterns, and linkage to previously rejected or suspicious identities.

A practical workflow usually includes:

  • Collect core identity data and compare it against trusted sources.
  • Verify documents or digital identity evidence using tamper-resistant methods.
  • Screen customers, beneficial owners, and related parties before activation.
  • Apply enhanced due diligence for higher-risk products, geographies, or customer segments.
  • Log the decision path so a reviewer can reconstruct why the account was approved.

Where organisations use identity proofing platforms, they should also validate that integration, logging, and access controls are consistent with internal policy and oversight requirements, not just vendor defaults. These controls tend to break down when onboarding is heavily automated across multiple channels because exception handling, evidence quality, and review ownership become inconsistent.

Common Variations and Edge Cases

Tighter due diligence often increases onboarding friction, manual review volume, and abandonment risk, requiring organisations to balance fraud reduction against customer experience and operational cost. Best practice is evolving here, especially around the use of biometric checks, trusted digital identities, and automated document analysis, so firms should avoid treating any single method as universally sufficient.

Some cases justify stronger measures than the standard remote flow. Higher-risk categories may include politically exposed persons, cross-border customers, complex ownership structures, cash-intensive activity, or products that enable rapid movement of funds. In those environments, enhanced due diligence should deepen source-of-funds questions, beneficial ownership checks, and management approval paths. Privacy-sensitive organisations should also ensure that data minimisation and retention decisions remain aligned with the purpose of verification, not broad reuse.

For digital identity-heavy programmes, the identity lifecycle can overlap with access governance, especially when customer accounts can later initiate privileged workflows or automated actions. That is where identity assurance and fraud controls begin to intersect with broader IAM and NHI governance, even if the legal obligation remains AML-focused. There is no universal standard for every remote-verification design, so organisations should document local legal interpretation, decision thresholds, and escalation rules rather than assuming a generic playbook will hold across sectors.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-63 set the technical controls, while PCI DSS v4.0 define the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.AC-1 Remote due diligence depends on verifying identities before granting account access.
NIST SP 800-63 IAL2 Non-face-to-face onboarding needs stronger identity proofing assurance.
PCI DSS v4.0 12.7 Customer onboarding data often includes sensitive payment and identity information.

Require identity proofing and approval gates before any customer account is activated.