Join our Newsletter — 33% off our NHI Course

How should financial institutions improve identity access for people who lack traditional documents like a driver’s licence or passport?

Financial institutions should separate identity assurance from paper based onboarding where possible. Digital identity systems can help people without traditional documents prove who they are, open accounts, and access basic financial services. The practical goal is to reduce exclusion without weakening fraud controls, using stronger verification, better data linkage, and governance that supports inclusion and compliance together.

Identity proofing for excluded customers needs alternatives, not weaker standards

For this question, the core design choice is to keep identity proofing rigorous while broadening the evidence sources that can support it. Financial institutions should treat traditional documents as one input, not the only path. That means using alternative identity evidence, trusted data sources, and risk-based assurance so the institution can open access without turning inclusion into an invitation for fraud.

The strongest programmes are built around NIST SP 800-63 Digital Identity Guidelines style thinking: assurance should match the account use case, the transaction risk, and the confidence available from the available evidence. In practice, that means combining documentless onboarding with step-up checks, corroborating attributes across sources, and tighter controls when the account can move money, change payees, or alter recovery details.

Institutions also need a clear understanding of where the control boundary sits. If a bank replaces paper documents with digital signals, it must still be able to show how those signals were verified, what fallback path exists for edge cases, and how exceptions are reviewed. Inclusion works when the process is predictable, explainable, and auditable, not when it is informal or entirely manual.

Use data linkage, recovery paths, and governance to expand access safely

The practical answer is to link identity to multiple reliable signals, not to a single artifact. That can include mobile-number ownership, device history, transaction history, trusted reference data, biometrics where lawful and appropriate, and community or institutional attestations when policy allows them. The objective is to build enough confidence for access while keeping account recovery, fraud response, and ongoing monitoring aligned.

This is where cross-border digital identity and financial crime controls often intersect. Standards and policy frameworks such as eIDAS 2.0 and FATF Recommendations reinforce the same operational idea from different angles, identity should be verifiable, risk-aware, and usable for lawful access. For institutions, the key is to map those obligations to onboarding, account recovery, exception handling, and review of higher-risk cases.

Where organisations need a broader implementation lens, CIS Controls v8 is useful for the operational side of account management, logging, and access control. The point is not to copy a generic control set into a customer journey, but to make sure alternative onboarding methods still produce the evidence and traceability needed for fraud investigation, dispute handling, and regulatory review.

Risk and Threat Considerations

The main risk is that inclusion controls can be abused if alternative identity paths are treated as lower-trust shortcuts. Weak verification, poor data quality, or overreliance on a single digital signal can let synthetic identities, impersonators, or collusive actors pass onboarding and later exploit the account for fraud, mule activity, or laundering.

Failure mechanism: institutions accept an alternative signal without understanding its assurance level, then permit account creation, recovery, or limit changes that exceed the real confidence in the identity.

Impact: the organisation widens access for legitimate customers, but also widens the attack surface, increases false accepts, and creates harder-to-detect abuse across onboarding, account recovery, and transactional monitoring.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63 and CIS Controls v8 set the technical controls, while EU AI Act define the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-63 Identity Proofing and Assurance Levels — Digital Identity Assurance Defines risk-based identity proofing for opening accounts without standard documents.
Recommendation — Align onboarding assurance to account risk and available evidence before granting access.
CIS Controls v8 6 — Access Control Management Supports least-privilege account setup and restricted capabilities during identity uncertainty.
8 — Audit Log Management Logging is needed to investigate alternative onboarding decisions and abuse patterns.
Recommendation — Limit newly opened accounts to the minimum needed until identity confidence is raised. Record onboarding evidence, exceptions, and recovery actions for review and fraud response.
EU AI Act GPAI/High-Risk Governance — High-Risk System Governance If automated identity decisions use AI, governance must cover accountability and oversight.
Recommendation — Add human review and governance controls wherever automated identity decisions materially affect access.

Practitioner Guidance

What to prioritise: separate the question of “Can this person be included?” from “What level of account capability should they receive on day one?” A person who lacks a passport may still be suitable for a low-risk account, but that should not automatically unlock high-risk functions.

What to verify: make sure every alternative onboarding route has an evidence trail that can be reviewed later. If the institution cannot explain why a case was accepted, or cannot reproduce the assurance logic, the process is too loose for regulated financial use.

Decision rule: if the institution cannot corroborate identity through multiple independent signals, keep the initial account narrow, require step-up verification for sensitive actions, and avoid building recovery processes that depend on the same weak evidence used at onboarding.

Practitioner takeaway: the right target is not document-free trust, it is document-flexible assurance, with account scope and fraud controls scaled to the quality of identity evidence actually available.