Join our Newsletter — 33% off our NHI Course

Physical-Document-Not-Present

Physical-document-not-present refers to identity verification carried out without inspecting the original paper document in hand. The process depends on images or scans submitted remotely, which increases exposure to copied, altered, or low-quality documents. Controls must therefore rely on image analysis, document features, and fraud checks rather than manual inspection alone.

Expanded Definition

Physical-document-not-present describes a remote document verification condition, not a specific fraud technique. The defining issue is that the verifier relies on a submitted image, scan, or capture of a document rather than holding the original item and checking tactile, optical, and physical security features directly.

That difference matters because the control environment changes. A remote process can assess image quality, tamper signals, metadata, layout consistency, and liveness or corroborating checks, but it cannot inspect ink feel, embossing, or other physical characteristics in the same way. In practice, the term is used in identity verification workflows where the document itself is only one input to a broader decision, and where policy must specify what counts as acceptable evidence.

Guidance versus consensus: there is broad agreement that remote document capture increases exposure to substitution and alteration risk, but organisations differ on how much assurance image-based review can support without a secondary control.

Examples and Use Cases

Physical-document-not-present shows up in workflows where a person uploads a document through a web or mobile channel and a verifier or automated system evaluates the image instead of the original paper item.

  • A customer onboarding flow accepts a photographed passport or driver’s licence as part of remote identity proofing.
  • A claims or account recovery workflow asks for a scan of an ID card, then pairs it with selfie comparison or database checks.
  • A contractor onboarding process uses uploaded documents when in-person review is impractical, but adds policy checks for image quality and recency.
  • A fraud review queue flags documents with cropping, glare, resolution loss, or inconsistent fonts for manual escalation.

The main tradeoff is convenience versus assurance. Remote intake improves reach and speed, but it shifts trust from the physical artefact to the capture channel, the device, and the integrity of downstream checks.

Security Implications

The core security issue is that absence of the original document removes an important layer of human inspection. When the term is misunderstood as simply a document upload, teams may overestimate how much assurance a scan provides and underweight copy quality, synthetic manipulation, and presentation attacks.

Failure commonly appears as weak detection of altered images, reused templates, mismatched document features, or submissions that pass superficial visual checks but fail deeper authenticity review. The practical consequence is identity proofing error: genuine users can be slowed by repeated review, while fraudulent applicants may slip through if the workflow depends too heavily on appearance alone.

Operationally, this creates a larger review burden for fraud teams and a governance issue for acceptance criteria. The verifier must know which evidence sources are authoritative, which cases require escalation, and which document types are unsuitable for remote-only assessment.

Domain and Governance Relevance

This term sits squarely in identity verification and fraud-resistant onboarding. Its relevance is not just that a document is being checked remotely, but that the assurance model changes when the original object is unavailable. That affects policy design, evidence thresholds, reviewer training, and the point at which an application should be stepped up to additional verification.

For NHIMG’s identity-security lens, the important question is whether the document check is being used as a standalone trust signal or as one input in a broader identity decision. Remote document capture is especially sensitive when it is the first gate to account creation, recovery, or privileged access, because weak document confidence can become a durable trust error downstream. A sound governance model therefore treats physical-document-not-present as a condition that requires explicit acceptance criteria, not as a lighter version of in-person inspection.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, CIS Controls v8 and NIST CSF 2.0 set the technical controls, while PCI DSS v4.0 define the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-63 Identity Proofing — Identity Proofing Directly governs remote identity verification and document evidence acceptance.
Recommendation — Apply identity proofing rules to set evidence thresholds for remote document submissions.
CIS Controls v8 5 — Account Management Document-based onboarding affects how new accounts are validated before creation.
Recommendation — Tighten account onboarding checks when document review is performed without the original.
NIST CSF 2.0 PR.AA — Identity Management, Authentication and Access Control Remote document verification influences identity assurance before access is granted.
DE.AE — Anomalies and Events Image tampering and inconsistent submissions are observable anomalies in review queues.
Recommendation — Align document verification decisions to identity assurance requirements before granting access. Track document-image anomalies for escalation and fraud investigation.
PCI DSS v4.0 6 — Develop and Maintain Secure Systems and Software Document capture workflows depend on secure intake systems and validation logic.
Recommendation — Secure the capture and validation application that processes uploaded identity documents.