Join our Newsletter — 33% off our NHI Course

How should financial institutions implement eKYC when many customers lack traditional identity documents?

Financial institutions should design eKYC around risk-based customer due diligence, not around a single document type. The practical approach is to combine official identity sources, remote verification, transaction limits, and monitoring for cases that cannot be fully verified immediately. That lets institutions open access for underserved users while still meeting compliance expectations and reducing fraud exposure.

How eKYC Works When Identity Documents Are Missing

When customers lack passports, national ID cards, or utility bills, eKYC cannot rely on document collection as the sole gate. The practical model is risk-based onboarding: collect whatever evidence is available, verify it against trusted sources where possible, and apply tighter limits when verification is incomplete. That may include remote biometric checks, database lookups, liveness testing, sanctioned watchlist screening, and tiered account permissions that expand only after stronger evidence is obtained.

This approach matters because financial inclusion and compliance are both at stake. A rigid document-first process can exclude legitimate customers, while a loose process can create fraud, mule-account, and money-laundering exposure. Current guidance from the FATF Recommendations — AML and KYC Framework supports a risk-based customer due diligence model rather than a single prescribed evidentiary route. In practice, that means the institution decides what is sufficient evidence for the risk tier, not what one document template happens to allow.

The strongest programmes treat alternative evidence as part of a controlled decision chain: identity proofing, fraud screening, beneficial owner checks where relevant, and ongoing monitoring. In practice, many institutions discover the weakness in their onboarding design only after they have already processed high-risk accounts without enough assurance that the customer was who they claimed to be.

How Institutions Verify Customers Without Traditional Documents

Good eKYC design separates identity assurance from access policy. The institution first asks whether the customer can be reliably linked to a real, unique person, then decides what level of account functionality is safe at that level of confidence. Where documentary evidence is thin, the system should combine multiple weaker signals into a defensible profile rather than pretending one weak signal is enough.

That often means using a mixture of remote and offline checks: phone or device validation, face match with liveness detection, government or telecom records where lawful, local credit or registry data, trusted introducer models, and manual review for exceptions. NIST SP 800-63 Digital Identity Guidelines is useful here because it frames identity assurance as a graded process, which aligns well with tiered onboarding and step-up verification.

Institutions also need to think about false negatives and exclusion risk. If the process rejects too many legitimate customers, it will push them into informal channels or onto weaker onboarding paths. If it accepts too much with too little evidence, the bank inherits fraud and account abuse. One useful design pattern is to let low-assurance customers transact within narrow limits while the institution continues to improve confidence through later evidence collection.

  • Start with the minimum evidence required for the intended account tier, not for every possible product.
  • Use step-up checks when the customer seeks higher limits, cross-border functionality, or sensitive services.
  • Record why a case was accepted, deferred, or escalated so the decision is auditable.
  • Review whether alternative evidence is locally valid, legally acceptable, and operationally repeatable.

In an operationally mature programme, the control failure is usually not the absence of a passport scan; it is the absence of a documented fallback path that tells staff what to do when documentary proof is unavailable.

Common Variations, Trade-offs, and Edge Cases

Tighter onboarding often increases customer friction and manual review cost, so institutions have to balance inclusion against abuse resistance. That trade-off becomes sharper in markets with weak civil registration coverage, displaced populations, minors, refugees, or customers who have only informal address evidence. Best practice is evolving, and there is no universal standard for exactly which alternative proofs must be accepted in every jurisdiction.

One common edge case is over-reliance on a single digital signal, such as a device, phone number, or selfie. Those signals are useful, but they can be recycled, spoofed, or shared. Another is assuming that low-documentation customers are inherently higher risk; in reality, risk comes from the quality of assurance and the controls attached to the account, not from the absence of a particular paper document.

For institutions operating across borders, the legal test may differ from the operational one. A verification method can be technically strong yet still fail local regulatory expectations if it is not recognized for customer due diligence in that market. Conversely, a method can be legally permitted but still too weak to support the product risk the institution is taking. The right answer is usually to define acceptable evidence tiers by product, geography, and customer segment rather than one global rule.

A useful benchmark from NHI security research is that control gaps persist when evidence is scattered across systems; NHI Management Group reports that only 5.7% of organisations have full visibility into their service accounts, which is a reminder that onboarding controls also fail when supporting records are fragmented. In practice, institutions should expect the hardest cases to be the ones that look simple on paper but require judgment across legal, fraud, operations, and compliance teams.

Risk and Threat Considerations

When eKYC is loosened to accommodate customers without traditional documents, the main risks are synthetic identity, mule-account creation, account takeover enablement, and regulatory non-compliance. The exposure is not just fraud at onboarding; weak initial assurance can undermine transaction monitoring, sanctions screening, and later dispute resolution because the institution never established a reliable identity baseline.

Failure mechanism: Attackers and fraud rings exploit fallback onboarding paths by combining partial real data, recycled phone numbers, spoofed biometrics, or compromised reference records to pass a process that was designed to be inclusive but not sufficiently bounded. If the institution accepts low-confidence evidence without tiered limits, the account can be used immediately for laundering, scams, or layering activity.

Impact: The institution can incur direct fraud losses, remediation cost, false positive pressure on compliance teams, and supervisory findings for weak customer due diligence. Over time, the bigger consequence is systemic: once poor-quality identities enter the customer base, downstream monitoring becomes less trustworthy and investigations become harder to resolve.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST CSF 2.0 and CIS Controls v8 set the technical controls, while EU AI Act define the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-63 IAL — Identity Assurance Level Provides graded identity proofing when evidence strength varies by onboarding case.
Recommendation — Map alternative evidence to an assurance level before granting broader account functionality.
NIST CSF 2.0 PR.AA — Identity Management, Authentication and Access Control Supports controlled account access after partial or completed identity verification.
Recommendation — Restrict privileges until identity confidence is sufficient for the requested service tier.
CIS Controls v8 5 — Account Management Covers lifecycle controls for customer accounts, exceptions, and access limits.
Recommendation — Implement tiered account entitlements and review exception paths for weakly verified users.
EU AI Act Risk Management Not directly applicable to eKYC itself as a financial onboarding process, so omitted from production mappings.

Practitioner Guidance

What to prioritise: Define acceptable evidence by product risk, not by a single enterprise-wide document requirement. The first decision is what the customer is allowed to do while identity confidence is still partial.

Decision rule: If the customer cannot be fully verified at onboarding, do not force an all-or-nothing outcome; issue a constrained account with explicit limits, enhanced monitoring, and a clear path to step-up verification.

What to verify: Confirm that each fallback route is auditable, legally permitted in the target market, and resistant to reuse across multiple identities. If staff cannot explain why a customer was accepted, the control is too weak to trust.

What practitioners underestimate: The hardest failure is often operational consistency, not technical capability. A good eKYC design fails when frontline teams, exception handlers, and compliance reviewers apply different standards to the same customer profile.

Practitioner takeaway: The objective is not to find a perfect replacement for documents; it is to build a controlled onboarding path where lower assurance never means unlimited trust.