Common signs include high drop-off during identity verification, repeated abandonment at the same step, and a gap between visitor interest and completed registrations. If support teams see many users asking how to resume verification or if low-risk users fail before reaching account activation, the process is probably too burdensome. The fix is usually to simplify steps without removing essential controls.
What friction looks like when trading verification is too heavy
In trading onboarding, verification becomes too burdensome when legitimate applicants repeatedly stall at the same checkpoint rather than completing the full journey. That usually shows up as slow completion, repeated document rework, users failing basic identity checks that seem disproportionate to their risk, or strong intent that never turns into an activated account. The issue is not only conversion loss. Excess friction can also push customers into unsafe workarounds, create support load, and undermine trust in the platform’s onboarding process. For regulated trading environments, the challenge is to preserve assurance without turning verification into a barrier that screens out low-risk users unnecessarily. In practice, many teams discover the process is over-engineered only after abandonment patterns and support contacts have already become normalised.
That pattern is especially visible where the same friction point affects many otherwise similar applicants, because it suggests the problem is structural rather than individual. For a useful baseline on control expectations, see NIST SP 800-53 Rev 5 Security and Privacy Controls.
How verification friction develops in practice
onboarding friction usually builds from a mismatch between the assurance the business thinks it needs and the evidence the process actually requires. A trading platform may ask for too many documents, request the same data more than once, or require steps that are technically sound but poorly sequenced for a first-time user. The result is not just delay. Each extra handoff increases the chance of confusion, mis-entry, and abandonment, especially when applicants are moving from intent to action and expect a quick route to activation.
- Repeated identity failures often point to weak document guidance, poor capture quality, or validation rules that are stricter than the risk justifies.
- Long pause times at a single step often indicate a burdened workflow rather than a user simply “not finishing.”
- Multiple support contacts about resuming verification usually suggest the journey is not self-explanatory.
- A large gap between started applications and funded or active accounts can indicate that the process is losing viable users before completion.
In regulated onboarding, some friction is unavoidable because firms must establish who they are dealing with and meet KYC and AML obligations. The practical question is whether each control adds meaningful assurance or merely adds effort. A useful way to test the design is to ask whether low-risk applicants are being forced through the same depth as higher-risk cases without clear justification. Where that happens, a better approach is often progressive verification, clearer evidence requests, or conditional escalation rather than one fixed path for everyone. Where verification depends on multiple external checks or manual review queues, delays can also reflect dependency risk, not just process design. The guidance breaks down when a product must support complex jurisdictional rules or high-risk customer segments that legitimately require a more rigorous path.
For the regulatory context behind customer due diligence and onboarding expectations, the FATF Recommendations page provides the broader AML and KYC baseline: FATF Recommendations — AML and KYC Framework.
Where to draw the line between due diligence and user drop-off
Tighter verification often improves assurance but increases abandonment risk, so firms have to balance regulatory confidence against completion rates and operational drag. That tradeoff is most visible in low-risk segments, where a heavy process can reduce fraud exposure only marginally while disproportionately harming conversion and customer experience. The question is not whether more checks are good in the abstract, but whether they are appropriately targeted to the applicant’s risk profile and the firm’s legal obligations.
One common edge case is when friction is mistaken for normal caution because the organisation assumes serious applicants will tolerate any process. That assumption is weak. Some applicants will tolerate extra checks if the reason is clear and the path is predictable, but they are far less forgiving when the process feels repetitive, opaque, or inconsistent. Another edge case is document failure caused by poor capture conditions, such as mobile upload issues or mismatched naming conventions, which can look like user resistance even when the real problem is usability. Guidance-vs-consensus note: there is broad agreement that verification should be risk-based, but there is less consensus on how aggressively to streamline for different trading segments, especially where cross-border rules vary.
The practical threshold for concern is when the same onboarding step becomes a recurring point of abandonment across a material share of users, or when support and review teams spend more time recovering incomplete applications than completing substantive checks. At that point, the workflow is no longer just protective. It is acting as a barrier to legitimate access.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-1 — Identity and Access Control | Trading onboarding verification establishes who may access the platform. |
| GV.RM-1 — Risk Management Strategy | Verification friction is a governance tradeoff between assurance and conversion. | |
| DE.CM-8 — Monitoring for Anomalies | Drop-off and repeated abandonment are operational signals that the flow is misfitting users. | |
| Recommendation — Align onboarding checks to the access risk of each applicant. Set a risk-based threshold for how much onboarding friction is acceptable. Monitor abandonment patterns to detect over-burdensome verification steps. | ||
| CIS Controls v8 | 5.1 — Establish and Maintain an Inventory of Accounts | Onboarding quality determines whether eligible users are cleanly created and tracked. |
| Recommendation — Use account inventory data to spot incomplete onboarding and stalled registrations. | ||
Practitioner Guidance
What to prioritise: Look first at the exact step where legitimate users stop, not at the overall conversion number alone. The strongest signal is a repeated failure pattern at one gate, because that usually means the burden sits in the workflow design rather than in user intent.
What to verify: Check whether the same verification depth is being applied to all applicants regardless of risk, jurisdiction, or product type. If low-risk users are forced through high-friction treatment without a clear reason, the process is probably over-controlled rather than appropriately assured.
Common mistake: Teams often respond to abandonment by adding explanations instead of reducing unnecessary effort. Better copy helps, but it does not fix duplicated data entry, excessive document requests, or review queues that create avoidable waiting time.
What good looks like: A well-tuned onboarding flow gives users a clear path, asks for evidence only once where possible, and escalates only when the risk profile justifies it. The result is not friction-free onboarding, but friction that is proportionate, understandable, and stable.
Practitioner takeaway: If verification is causing friction, the real test is whether each extra step improves assurance enough to justify losing legitimate users at that point in the journey.
Related resources from NHI Mgmt Group
- How should financial institutions secure remote onboarding without creating too much friction?
- How should security teams implement customer due diligence without creating too much onboarding friction?
- What are the warning signs that MFA is creating too much friction?
- What are the signs that a customer verification process is too slow or creating unnecessary friction?