Join our Newsletter — 33% off our NHI Course

How should organisations verify hard-to-verify customers without creating excessive onboarding friction?

Use layered identity verification that combines document checks, biometrics, device signals, and alternative data where appropriate. The goal is to raise confidence without excluding legitimate users who lack traditional records. Teams should tune controls by risk, avoid one-size-fits-all flows, and provide fallback paths for underserved populations so fraud prevention does not become customer abandonment.

Why This Matters for Security Teams

Hard-to-verify customers create a tension between fraud prevention, regulatory obligations, and growth. If onboarding is too strict, legitimate users drop out, especially people with thin files, limited credit history, or inconsistent documents. If it is too loose, account takeovers, synthetic identities, and mule activity slip through. NHI Management Group’s Ultimate Guide to NHIs shows how often organisations miss identity risk when visibility and governance are weak, and the same pattern appears in customer identity programs.

The right answer is not a single “stronger” check. It is risk-based verification that combines evidence sources, applies deeper scrutiny only where needed, and preserves fallback paths for people who cannot pass conventional checks. That approach aligns with the intent of NIST SP 800-207 Zero Trust Architecture, which treats trust as something to be evaluated continuously from multiple signals rather than assumed once at the front door. In practice, many security teams encounter customer abandonment only after fraud controls have already been tuned too aggressively.

How It Works in Practice

Effective verification starts by separating identity confidence from onboarding convenience. Teams should define the minimum assurance needed for each customer journey, then layer checks only as risk increases. Low-risk sign-ups may only need device reputation and email or phone validation. Higher-risk flows may add document verification, biometric liveness, bureau or consortium data, and sanctions or fraud screening where legally appropriate.

This is where the guidance in Ultimate Guide to NHIs becomes useful in a broader identity sense: visibility, lifecycle discipline, and control over trust decisions matter just as much for customer onboarding as they do for machine identities. The same operational lesson applies to human identity proofing. Controls should be evaluated at runtime, not hard-coded into a single universal flow.

  • Use tiered assurance levels tied to product risk, account value, and fraud exposure.
  • Prefer multiple weak signals that corroborate each other over one brittle gate.
  • Collect only the data needed for the stated purpose, then retain it for the shortest lawful period.
  • Offer manual review or alternate proofing for users who cannot complete automated checks.
  • Instrument drop-off, false reject, and fraud capture rates so friction can be tuned with evidence.

Frameworks such as NIST SP 800-53 Rev 5 Security and Privacy Controls are helpful when translating these goals into control expectations for access, identity proofing, logging, and privacy safeguards. These controls tend to break down when a business insists on one global onboarding path because regional documents, accessibility needs, and fraud pressure vary too widely.

Common Variations and Edge Cases

Tighter verification often increases abandonment, requiring organisations to balance fraud reduction against inclusion, conversion, and support burden. That tradeoff is especially visible in underserved populations, cross-border onboarding, and markets where government IDs are inconsistent or unavailable. Best practice is evolving, and there is no universal standard for this yet.

One common edge case is synthetic identity risk, where a customer may pass individual checks but still fail the overall trust test. Another is accessibility, where biometric or video checks can exclude users with disabilities or poor network conditions. In those cases, alternative paths such as assisted review, trusted community documentation, or payment-method based step-up checks can reduce friction without lowering assurance indiscriminately.

For regulated customer due diligence, the FATF Recommendations help frame when enhanced due diligence is warranted, while still leaving room for proportionality. Organisations should document which populations are affected by each check and measure whether verification outcomes are disproportionately failing legitimate applicants. That is the practical test of whether a friction control is protecting the business or simply blocking access.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.AA-1 Identity proofing and access decisions should be risk-based and evidence-driven.
NIST SP 800-63 Digital identity guidance directly informs proofing, authentication, and fallback paths.
NIST AI RMF Risk-based evaluation and governance support fair, explainable verification decisions.
OWASP Non-Human Identity Top 10 NHI-03 Credential lifecycle discipline parallels the need to control identity evidence and trust signals.
NIST Zero Trust (SP 800-207) §3.1 Zero trust supports continuous, contextual evaluation instead of one-time trust.

Map onboarding flows to assurance levels and provide alternate proofing for excluded users.