Mandatory video interviewing adds time, coordination, and user effort to the onboarding journey. That extra friction can increase abandonment, especially when applicants must wait for an operator or repeat steps. In practice, the risk is not only slower processing but also lower conversion and lost revenue. Teams need a controlled flow that keeps verification rigorous without turning onboarding into a barrier.
Why mandatory video interviewing changes the conversion equation
Mandatory video interviewing shifts remote identity verification from a mostly self-serve flow into a guided, synchronous process. That matters because onboarding conversion is often shaped less by the identity check itself than by the effort required to complete it. When a user must wait for an operator, prepare a camera-enabled session, or repeat steps after a failed connection, the verification journey becomes a queue rather than a transaction. For regulated onboarding, the control can be valid and still commercially costly if it is not matched to the user journey.
For identity teams, the practical issue is not whether video is inherently secure, but whether it is proportionate to the assurance level actually needed for the applicant. Some use cases justify live interaction because the trust decision is high stakes, the fraud pressure is high, or the regulatory rule set expects stronger evidence. Other use cases do not, and forcing every applicant through the same process can create avoidable drop-off. eIDAS 2.0 — EU Digital Identity Framework is useful here because it reflects how assurance and user access need to be balanced in a governed identity journey. In practice, many teams discover the conversion penalty only after queue times, device failures, and rework have already started to affect completion rates.
Where the friction appears in a remote verification flow
Mandatory video introduces friction at several points in the journey, and each one can reduce completion. The first is scheduling, because synchronous review creates a dependency on operator availability. The second is device readiness, since users may lack a stable connection, a suitable camera, or a private setting to continue. The third is retry cost, because any failed capture, interrupted session, or mismatch forces the applicant to invest more time before they see a finish line.
That combination changes behaviour. Users who would have completed a simpler flow may defer, abandon, or switch to a competing service. The risk is especially visible in high-volume onboarding, where even a modest increase in friction can materially affect total completions. For that reason, teams should treat video as a control with a service-design cost, not just a verification step. Identity governance frameworks such as FATF Recommendations — AML and KYC Framework matter because they push organisations to think about assurance, customer due diligence, and the defensibility of the process, not only the technology used to deliver it.
- Queueing creates uncertainty, and uncertainty increases drop-off.
- Extra steps are cumulative, so small delays can become a meaningful conversion drag.
- Operator-dependent checks can improve assurance but make throughput harder to scale.
- When users fail once, the reattempt burden can be enough to end the journey.
Where this guidance breaks down is when the onboarding decision genuinely depends on live review and no alternative control can achieve acceptable assurance.
When video is necessary and when it is just overhead
Tighter verification often increases abandonment risk, requiring organisations to balance assurance against completion. The key edge case is that mandatory video is not always the wrong answer. It can be justified for higher-risk populations, regulated products, disputed identity evidence, or fraud patterns that make unattended flow unsafe. In those cases, the conversion cost may be acceptable because the downstream loss from weak verification would be worse.
The more common mistake is applying the strictest route to every applicant by default. That approach assumes the same level of friction is suitable for all risk tiers, which is rarely true. A better pattern is to reserve mandatory video for exception handling or elevated-risk cohorts, while allowing lower-friction paths for lower-risk cases. Where the market or regulatory environment is still evolving, teams should be explicit that this is a design choice, not settled consensus.
Another edge case is accessibility. A control that seems operationally simple can become exclusionary if users cannot reliably participate in real time because of bandwidth, language, time zone, disability, or privacy constraints. Those constraints do not make the control invalid, but they do change its commercial and governance impact. NIST Cybersecurity Framework 2.0 is relevant at the broader governance level because it reinforces the need to align controls with outcomes, resilience, and user impact rather than treating security steps as isolated gates.
Risk and Threat Considerations
Mandatory video interviewing creates a business risk pattern that is closely tied to operational friction, service availability, and trust calibration. The exposure is not only reduced conversion but also the possibility that legitimate users abandon the flow while adversaries adapt to the process by forcing teams into slower, less scalable review paths.
Failure mechanism: The risk materialises when synchronous review, queueing, or repeated capture attempts add enough delay that users disengage before completion. Where the process is rigid, bad actors can also exploit the fact that operators are needed for every decision, increasing reviewer load and making the system easier to bottleneck through volume rather than technical compromise.
Impact: The immediate consequence is lower completion rates. Over time, that can reduce revenue, create uneven access for legitimate applicants, and push teams toward weaker workarounds or inconsistent exception handling that undermines both assurance and user trust.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-63 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-1 — Identity Management, Authentication, and Access Control | Video interviewing changes onboarding authentication and access gating. |
| PR.IP-1 — Baseline Configuration and Standardized Procedures | Mandatory video is a process design choice that affects consistency and completion. | |
| DE.CM-8 — Monitoring for Anomalous Activity | Abandonment spikes and retry patterns reveal friction and abuse in the flow. | |
| Recommendation — Align assurance level to applicant risk before forcing a live verification step. Standardise when video is required versus when lower-friction paths are acceptable. Track drop-off and retry patterns to detect when verification becomes a bottleneck. | ||
| NIST SP 800-63 | IAL2 — Identity Assurance Level 2 | Remote identity proofing decisions depend on assurance strength versus user friction. |
| AAL2 — Authenticator Assurance Level 2 | The flow should preserve usable authentication outcomes after identity proofing. | |
| Recommendation — Match the proofing method to the required assurance level instead of defaulting to live video. Design the journey so stronger proofing does not create unnecessary authentication friction. | ||
| CIS Controls v8 | 5 — Account Management | Identity onboarding is an access-entry process that should avoid unnecessary friction. |
| 6 — Access Control Management | Mandatory video is an access decision point that should be scoped by necessity. | |
| Recommendation — Define risk-based onboarding paths so account creation does not rely on one rigid control. Apply the least disruptive verification method that still supports the access decision. | ||
Practitioner Guidance
What to prioritise: Separate assurance level from delivery mode. If the real objective is strong identity evidence, mandatory live video should be reserved for the cases where it materially changes the trust decision, not used as a universal front door.
What to verify: Check where applicants actually fail. If abandonment clusters around waiting, device setup, or repeat attempts, the conversion problem is probably process-driven rather than fraud-driven. That distinction matters because the fix may be routing, triage, or fallback design rather than stricter review.
Common mistake: Treating friction as a useful security signal. Extra effort does not automatically mean better assurance, and in onboarding it often means more drop-off. The right question is whether the added step improves decision quality enough to justify the lost completions.
Practitioner takeaway: The safest onboarding design is not the most restrictive one, but the one that applies live review only where it changes the risk decision and keeps everyone else on a faster, defensible path.
Related resources from NHI Mgmt Group
- Why do remote MCP servers create more identity governance risk than local ones?
- Why does hybrid work create more identity governance risk than fully remote work in some organisations?
- Why do remote employees create more identity risk than office-based users?
- How should security teams handle identity verification in high-risk video calls?