Join our Newsletter — 33% off our NHI Course

What happens when customer onboarding still depends on physical presence during a lockdown?

Onboarding slows or stops because dealers, branches, and agents cannot complete the required in person steps. That creates an immediate commercial bottleneck, especially for prepaid activation and other high volume journeys. The practical consequence is lost sales, delayed customer acquisition, and pressure on organisations to accelerate digital registration capabilities after the disruption has already begun.

Why Physical-Presence Onboarding Fails During a Lockdown

When onboarding depends on someone showing up in person, the process inherits every constraint on movement, office access, branch staffing, and third-party availability. During a lockdown, that turns a normal operational step into a hard gating dependency. The result is not just inconvenience, but a direct interruption to customer acquisition, account activation, and revenue recognition.

For organisations that still rely on dealers, branches, or agents to complete mandatory checks, the bottleneck often appears first in the highest-volume journeys. Prepaid activation, assisted registration, and other routine flows can stall at scale, because the control point was designed for a world where physical access was always available. In practice, teams discover the dependency only when queues build and exceptions start multiplying.

How It Works in Practice

Physical presence usually exists because some step in the onboarding chain has been treated as inherently manual: identity proofing, document inspection, wet signatures, biometric capture, or local attestation. Once that step is mandatory, the process cannot complete unless the customer, staff member, or trusted intermediary can physically meet the requirement.

During a lockdown, the failure mode is straightforward:

  • Branch closures or restricted opening hours remove the primary completion channel.
  • Dealers and agents may still be operational, but their movement and customer contact are constrained.
  • Backlogs accumulate because upstream demand continues while the final approval step slows.
  • Customers abandon the journey if activation takes too long or requires repeated rescheduling.

The operational question is whether the organisation has a digitally complete fallback path, not whether it can temporarily improvise around the blockage. NIST SP 800-53 Rev 5 Security and Privacy Controls is useful here because the onboarding process needs controls that remain effective when physical workflows are unavailable, especially around access approval, auditability, and secure handling of registration data.

This matters because a physical-only design can also force organisations to accept weaker manual workarounds under pressure, such as deferred verification, ad hoc exception handling, or inconsistent document review. Those shortcuts create uneven customer treatment and can undermine the very assurance the original in-person step was meant to provide. Ultimate Guide to NHIs also reinforces a broader operational point: when critical lifecycle steps are not designed for resilience, organisations lose visibility and control exactly when scale and urgency increase.

These controls tend to break down when onboarding is built around one physical verification route and no parallel digital alternative exists.

Common Variations and Edge Cases

Tighter onboarding controls often increase friction, so organisations have to balance assurance against continuity. The right answer depends on what the in-person step was actually protecting: fraud prevention, regulatory verification, or simply a legacy preference for human review.

Some journeys can be partially digitised without removing assurance, while others need staged onboarding, where low-risk access is granted first and higher-risk actions are delayed until full verification is possible. Best practice is evolving here, and there is no universal standard for every industry. The key test is whether the fallback path preserves decision quality rather than merely speeding up approval.

A useful distinction is between mandatory physical proof and physical convenience. If the physical step is only a legacy habit, it should be re-engineered. If it exists because the customer segment, product risk, or regulatory regime truly needs stronger assurance, then the organisation should design a controlled exception process instead of pretending the lockdown never happened. In heavily regulated onboarding, FATF Recommendations, AML and KYC Framework helps frame why verification obligations still matter even when the operating model changes.

When the business depends on high-volume activation, the edge case becomes the norm very quickly: what began as an exception path can become the only viable path for weeks or months, so any manual workaround must be sustainable.

Risk and Threat Considerations

The main risk is not only lost throughput, but control erosion. When physical onboarding is unavailable, organisations may feel pressure to relax verification steps, widen exception handling, or accept delayed validation, all of which can increase fraud exposure and create inconsistent approval standards.

Failure mechanism: A lockdown breaks the assumption that the final trust decision can always be completed face to face. Attackers, or simply opportunistic applicants, benefit when teams start substituting speed for assurance, because rushed manual processing is harder to audit and easier to manipulate.

Impact: The immediate impact is customer acquisition delay and commercial backlog. The downstream impact can be weaker identity assurance, more review debt, and a larger correction effort once normal operations resume.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.AA — Identity Management, Authentication and Access Control Onboarding continuity depends on controlled identity proofing and access decisions.
RC.RP — Response Planning Lockdown onboarding disruptions require a tested continuity response for customer activation.
Recommendation — Define fallback onboarding controls that preserve identity assurance and approval integrity. Plan and test alternate onboarding procedures before physical access is disrupted.
CIS Controls v8 5 — Account Management Customer activation often depends on creating and validating accounts at scale.
Recommendation — Establish repeatable account provisioning steps that do not rely on physical presence.
NIST SP 800-63 3 — Identity Assurance Physical presence is one way to achieve identity assurance when onboarding customers.
Recommendation — Match the assurance level to the risk and choose digital proofing where it is acceptable.

Practitioner Guidance

What to prioritise: Identify which onboarding steps are truly physical, and which only became physical through habit. The first priority is to separate assurance requirements from location-dependent workflows so that continuity planning targets the real control point.

Decision rule: If the journey cannot complete without a site visit, treat it as a business continuity dependency, not just an operations issue. That means the fallback design should be explicit, approved, and measurable before the next disruption, rather than improvised under pressure.

What to verify: Check whether the digital alternative can handle the same customer segment, fraud threshold, and audit evidence as the in-person route. If it cannot, document the gap and define the exact exception conditions instead of quietly lowering standards.

Practitioner takeaway: The strongest onboarding designs are the ones that preserve assurance without assuming physical access will always exist, because resilience in customer acquisition is a control property, not an emergency patch.