Join our Newsletter — 33% off our NHI Course

Why does relying too heavily on ID scanning increase customer abandonment and cost?

Heavy reliance on ID scanning adds friction at the exact moment legitimate customers want to complete onboarding quickly. When the scan is finicky, slow, or repeatedly fails, users drop out. Because scanning is often priced by volume, low pass rates also make the control expensive. The result is more friction, higher cost, and weaker conversion.

Why scanning friction drives abandonment

ID scanning tends to fail at the worst possible moment: when a legitimate customer has already decided to onboard, buy, or open an account. If the check is slow, rejects a valid document, or requires repeated retries, the user experience shifts from “confirm my details” to “justify why I should keep going.” That creates a direct conversion penalty, especially on mobile journeys where friction is more visible and patience is lower.

The business impact is not only lost completions. Every failed attempt forces support handling, manual review, or a second verification path, which stretches the onboarding funnel and adds operating cost. When the control is positioned as a gate rather than a smooth verification step, it becomes a source of drop-off instead of a trust builder.

Two patterns usually matter most: first, the control is too sensitive to document quality, lighting, camera performance, or user error; second, the process is applied uniformly even when risk is low. In both cases, the organisation pays for the scan but does not consistently get the intended conversion outcome.

Why low pass rates make the control expensive

ID scanning is often priced per attempt, per verification, or by usage tier, so weak pass rates can quickly turn into a cost multiplier. A poor pass rate means more retries, more fallback checks, and more cases that require manual intervention. That means the unit economics get worse exactly when the user experience gets worse.

The cost problem is also architectural. If you rely on scanning as the primary control for every customer, you concentrate spend in one step and make the onboarding funnel dependent on a single vendor workflow. That can be acceptable for high-risk cases, but it is expensive for low-risk customers where lighter verification would have been sufficient. The control becomes a broad tax on the entire population rather than a targeted measure for the segment that needs it most.

Practitioners should also watch for hidden downstream costs: manual review queues, customer support contacts, abandoned applications that later require re-engagement, and false rejections that create rework. These costs do not always appear in the scanner invoice, but they often dominate the true cost of the process.

For teams building identity checks into regulated onboarding flows, it helps to pair the scanning workflow with broader customer due diligence design rather than treating it as a standalone gate. Guidance such as FATF Recommendations is useful because it frames verification as risk-based, not uniformly maximal.

How to reduce abandonment without weakening assurance

The practical fix is not “remove scanning”, but match the control to the risk. High-risk or regulated cases may justify a stricter path, while low-risk segments often need a faster route with less friction. The onboarding design should ask whether scanning is required for every user, or only for the cases where the incremental assurance is worth the conversion loss.

Teams should also measure the process as a funnel, not just a security step. Track completion rate, retry rate, false rejection rate, manual review rate, and time to complete. If the scan adds more friction than assurance for a given population, the data will usually show it quickly. At that point, the better answer is often to redesign the decision tree, not to push users through more retries.

Where scanning is retained, better capture quality, clearer instructions, and a graceful fallback path can materially reduce abandonment. That includes making the customer journey resilient to bad lighting, camera failures, and document-edge cases, while preserving a stronger review path for truly suspicious or high-risk submissions.

Practitioner Guidance: The best outcomes usually come from using ID scanning selectively, not universally. If the control is lowering conversion faster than it is lowering risk, it has become a business and security liability rather than a safeguard.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
CIS Controls v8 CIS Control 6 — Access Control Management ID scanning is a gating control for onboarding access decisions.
Recommendation — Apply access control rules so only cases that need stronger verification are forced through the scanning step.
NIST CSF 2.0 PR.AC-1 — Identities and credentials are issued, managed, verified, revoked, and audited Customer identity verification is central to onboarding assurance.
ID.AM-1 — Physical devices and systems are inventoried Document capture and verification depend on reliable device and channel handling.
Recommendation — Use identity verification workflows that balance assurance with user friction. Inventory and monitor the devices and capture paths that affect scan reliability.