Organisations should remove unnecessary manual steps, make data capture work on the applicant’s own device, and keep identity checks integrated into one continuous flow. The goal is not to dilute verification, but to reduce friction caused by repeated handoffs, branch visits, and static forms. A smoother process improves completion rates while preserving controls needed for KYC, fraud prevention, and compliance.
Why This Matters for Security Teams
Digital account opening fails when organisations force applicants through controls that feel like separate checkpoints instead of one trusted journey. Every extra handoff, duplicate data entry, or branch-only verification step increases abandonment, but removing those steps blindly can weaken KYC, fraud detection, and auditability. The real challenge is to preserve evidentiary strength while reducing friction on the applicant’s own device.
That is why identity orchestration, device-aware verification, and progressive data capture matter more than a single “stronger” check. Current guidance suggests balancing assurance with usability through risk-based controls, not through longer forms. NIST’s NIST SP 800-53 Rev 5 Security and Privacy Controls supports this kind of control selection, while NHIMG’s Ultimate Guide to NHIs shows how excessive friction in identity workflows often hides deeper governance gaps rather than solving them.
In practice, many security teams only discover the abandonment problem after application drop-off is already high, rather than through intentional testing of the identity journey.
How It Works in Practice
The most effective account-opening journeys reduce friction by making verification continuous, contextual, and device-native. Instead of splitting checks across portal, branch, and back-office review, the process should capture information once, reuse validated data where permitted, and request only the next highest-value control when risk warrants it. This approach shortens the path without lowering assurance.
Practitioners typically combine a few controls:
- Pre-fill fields from trusted sources where consent and local rules allow it.
- Use document capture, selfie/liveness, or biometric checks only when the risk score requires them.
- Keep the applicant on one device and one session to avoid trust breaks and re-entry errors.
- Apply step-up review only for anomalies such as device mismatch, velocity spikes, or inconsistent identity data.
- Design the flow so failed checks are recoverable, not terminal, where policy permits.
This is where identity proofing and access governance intersect. NIST’s security control catalog supports layered verification, while NHIMG’s 52 NHI Breaches Analysis is a reminder that weak lifecycle discipline and fragmented control points are what attackers exploit once credentials or process boundaries are exposed. For account opening, the same principle applies: reduce the number of places where the applicant can fail, but increase the quality of the checks that remain.
One relevant NHIMG data point: 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage, which underscores why sensitive identity data should not be copied into scattered workflow systems. These controls tend to break down when legacy core banking, outsourced KYC utilities, and manual review queues force repeated re-authentication because the customer journey is no longer stateful end to end.
Common Variations and Edge Cases
Tighter identity verification often increases operational overhead, requiring organisations to balance higher assurance against completion rates and support cost. There is no universal standard for the “right” amount of friction, so current guidance suggests tuning the journey by product risk, customer segment, and regulatory exposure rather than applying one rigid flow to every applicant.
For low-risk products, best practice is evolving toward progressive verification: collect minimal data first, then deepen checks only if transaction value, geography, or fraud signals justify it. For higher-risk or regulated products, the threshold for step-up review should be lower, but the user experience can still be streamlined by avoiding duplicate document submission and by preserving session continuity across channels.
Edge cases matter. Applicants with poor connectivity, unsupported devices, no camera access, or name mismatches across data sources often trigger abandonment if the fallback path is too strict. In those environments, a safe exception process is essential: alternative verification, assisted review, or deferred completion can preserve both conversion and control. NHIMG’s Top 10 NHI Issues highlights a broader governance lesson: fragmented identity operations create failure points that are invisible until users hit them. The practical test is whether the organisation can explain, audit, and reproduce each decision without forcing the applicant to start over.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-1 | Identity checks should be risk-based and least-friction while preserving access assurance. |
| NIST SP 800-53 Rev 5 | IA-2 | Account opening depends on verified identity proofing and authenticators before issuance. |
| NIST AI RMF | Risk-based account opening needs governance over decisions, exceptions, and escalation paths. | |
| OWASP Non-Human Identity Top 10 | NHI-03 | Identity workflows should avoid overexposed secrets, tokens, and brittle handoffs. |
| CSA MAESTRO | GOV-01 | Orchestrated, contextual identity journeys need explicit governance and control ownership. |
Map account-opening steps to access controls and remove duplicate checks without weakening verification.
Related resources from NHI Mgmt Group
- How should organisations use government digital identity systems to reduce onboarding friction without weakening identity assurance?
- How should organisations reduce friction in airport identity checks without weakening security?
- How can organisations reduce false positives without weakening identity controls?
- How should organisations reduce identity verification friction without weakening FINTRAC compliance?