Join our Newsletter — 33% off our NHI Course

Who is accountable when non face to face customer due diligence does not meet regulatory requirements?

Accountability usually sits with the regulated business, its compliance leadership, and the control owners running onboarding and monitoring. Teams need clear ownership for policy design, verification thresholds, exception handling, and recordkeeping. If controls fail, regulators typically look for governance evidence showing who approved the process, who monitored it, and how issues were escalated.

Why This Matters for Security Teams

When non face to face customer due diligence falls short, the issue is rarely just a paperwork defect. It can expose weaknesses in onboarding governance, identity verification, sanctions screening, suspicious activity escalation, and evidencing that the business applied a risk-based approach. Regulated firms are expected to prove who owned the control, who approved exceptions, and whether the process matched the customer risk profile. That is why accountability matters as much as the technical checks themselves.

For teams operating in AML, fraud, and digital identity workflows, the core question is not only whether a customer was verified, but whether the process can survive supervisory review. The FATF Recommendations — AML and KYC Framework set the baseline for customer due diligence, but local regulators usually expect firms to translate those obligations into named control owners, documented thresholds, and escalation paths. If that mapping is unclear, accountability tends to drift between operations, compliance, and technology teams. In practice, many firms discover that they cannot explain a failed control until after an audit finding or enforcement review has already created the exposure.

How It Works in Practice

In a well governed onboarding model, accountability is shared but not diluted. Senior management and compliance leadership define the policy, risk appetite, and approval standards. Operations teams execute the checks, while control owners validate that identity evidence, liveness or document verification, sanctions screening, and adverse media review all meet the required threshold. Where automation is used, the business still retains responsibility for the outcome, including model tuning, exception handling, and human review of low confidence cases.

A practical accountability model usually includes:

  • named policy owners for customer due diligence requirements;
  • defined verification criteria for different customer and product risk tiers;
  • documented escalation for failed checks, overrides, and edge cases;
  • recordkeeping that shows what was checked, when, and by whom;
  • periodic testing of the control to confirm it still works as designed.

This is where security and identity governance intersect. If the organisation uses digital identity tools, non human identity controls, or agentic workflow automation, the business must ensure those systems are configured, monitored, and access restricted like any other regulated control. The NIST SP 800-53 Rev 5 Security and Privacy Controls is useful for translating accountability into control ownership, logging, review, and audit evidence. For broader governance alignment, the NIST Cybersecurity Framework 2.0 reinforces that governance, risk management, and control assurance should be explicit rather than implied. These controls tend to break down when onboarding is outsourced across multiple vendors because no single party can produce a complete evidence trail.

Common Variations and Edge Cases

Tighter due diligence oversight often increases onboarding friction and operational cost, requiring organisations to balance customer experience against regulatory defensibility. That tradeoff becomes sharper in cross-border onboarding, delegated verification, and low-risk product journeys where teams want faster approvals but still need defensible controls.

Best practice is evolving for AI-assisted onboarding and identity verification, especially where automation supports document checks, fraud scoring, or customer risk triage. The EU AI Act regulatory framework matters when AI materially influences regulated decisions, because accountability cannot be transferred to the model or the vendor. The regulated firm still needs governance over data quality, decision thresholds, override authority, and monitoring for false positives or false negatives. Current guidance suggests treating these tools as controlled inputs to the due diligence process, not as a substitute for it.

There is also a practical distinction between accountability and task execution. A third-party identity verification provider may perform checks, but the regulated business remains responsible for the adequacy of the process, the retention of evidence, and the quality of exceptions handling. The same applies when workflow is partially automated through internal platforms or agentic systems. For this reason, firms should document which teams own policy, which teams operate controls, and which teams review outcomes. In complex environments with multiple legal entities, fragmented customer journeys, or high volumes of manual override, accountability often becomes unclear exactly where supervisory scrutiny is strongest.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the technical controls, while EU AI Act and PCI DSS v4.0 define the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.OV-01 Governance and oversight define who owns due diligence control outcomes.
NIST SP 800-63 Digital identity assurance informs how remote customer checks are validated.
NIST AI RMF AI risk management applies when automation influences onboarding decisions.
EU AI Act AI-driven decision support in onboarding still requires human accountability.
PCI DSS v4.0 Where payment onboarding is involved, control ownership and evidence are closely scrutinised.

Assign named governance owners and keep oversight evidence for due diligence controls.