Join our Newsletter — 33% off our NHI Course

Why does lack of economic identity still block access to formal financial services?

Without reliable identity evidence, institutions cannot confidently open accounts, assess eligibility, or comply with onboarding requirements. That is especially true for refugees, displaced people, and others who lack conventional documents. In practice, financial exclusion is not only about poverty or distance. It is also about whether a person can prove who they are well enough to enter the formal system.

Why “No Identity” Means No Formal Access Path

Formal financial services are built to answer a simple institutional question: who is this customer, and are they eligible to be served? If a person cannot present reliable identity evidence, the institution cannot safely create an account, issue credentials, or bind the relationship to a known customer record. That is why the barrier is structural, not just administrative.

In practice, the identity requirement protects the institution as much as the customer. Banks and payment providers need enough confidence to satisfy onboarding, fraud prevention, sanctions screening, and recordkeeping obligations. When identity proof is weak or absent, the service cannot reliably distinguish a legitimate applicant from a fabricated or duplicate one.

Why Poverty Alone Does Not Explain Financial Exclusion

Lack of money can prevent someone from using a service, but lack of identity can prevent them from entering the system at all. A person may have income, need payments, or want to save, yet still be blocked because the institution cannot verify legal name, date of birth, address, or other required attributes. That is why displaced people, refugees, and informal workers often face exclusion even when they are economically active.

The issue is especially acute where onboarding rules assume documents that many people do not possess or cannot easily replace. Utility bills, permanent addresses, and stable national records are common verification anchors, but they are not universally available. The result is a mismatch between real-world lives and the evidentiary model used by formal finance.

What Institutions Actually Need to Trust the Relationship

Financial firms do not need perfect certainty, but they do need sufficient evidence to create a defensible customer identity and manage ongoing risk. That usually means identity proofing, account ownership, and a way to keep records accurate over time. In NIST SP 800-63 Digital Identity Guidelines, identity assurance is treated as a graded decision, which is useful here because many exclusion problems arise when institutions apply one rigid standard to everyone.

For financial services, that requirement also connects directly to access control and customer onboarding governance. FATF Recommendations make customer due diligence central to opening and maintaining accounts, while eIDAS 2.0 shows how formal digital identity can reduce friction when the identity evidence itself is trustworthy and portable. In other words, the access problem is not just about willingness to serve, it is about whether the system can bind a person to an account with enough assurance.

Risk and Threat Considerations

When identity evidence is weak, financial institutions face two opposite failure modes: false exclusion of legitimate customers and false acceptance of fraudulent ones. The first creates access barriers and social harm. The second creates account opening abuse, mule activity, and compliance exposure, which is why firms often default to stricter evidence requirements than vulnerable applicants can satisfy.

Failure mechanism: rigid onboarding rules assume documentary stability, so applicants without conventional records cannot pass verification even when they are legitimate, while any relaxation must still preserve fraud, AML, and sanctions controls.

Impact: the institution either excludes valid customers or increases exposure to impersonation, duplicate identities, and weak customer due diligence, both of which damage trust in the formal financial system.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST SP 800-53 Rev 5 and OWASP ASVS set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-63 Digital Identity Guidelines Identity proofing and assurance determine whether a person can open a formal financial account.
Recommendation — Apply graded identity assurance so lower-risk services accept proportionate evidence.
NIST SP 800-53 Rev 5 IA-8 — Identification and Authentication (Non-Organizational Users) Financial customers are external users whose account access depends on reliable identification and authentication.
IA-12 — Identity Proofing The blocker is the inability to establish a trusted customer identity from evidence.
Recommendation — Use IA-8 to require dependable external-user identity proofing before account creation. Use IA-12 to define acceptable proofing evidence and escalation paths for weak documentation.
ISO/IEC 27001:2022 A.5.16 — Identity management Customer identity must be established and maintained before formal financial access can be granted.
A.5.15 — Access control Access to financial services depends on trustworthy access decisions tied to identity evidence.
Recommendation — Define an identity management process that supports onboarding, updates, and revocation. Enforce access control rules that require sufficient identity evidence before service entry.
OWASP ASVS V6 — Authentication Account opening and subsequent access depend on the assurance that the applicant is who they claim to be.
Recommendation — Require strong authentication and proofing steps that match the account risk.

Practitioner Guidance

What to prioritise: treat identity proofing as the gating control, not the customer’s economic need. If the service can support tiered onboarding, use proportional assurance levels so low-risk products can be opened with less friction than high-risk accounts.

What to verify: confirm that alternative evidence paths are still anchored to a verifiable person and an auditable record. The practical test is whether the institution can defend the account later, not whether the applicant can produce the most conventional document set.

Practitioner takeaway: financial inclusion improves when institutions separate “ability to prove identity” from “ability to pay,” but they still need a trustworthy method to bind a real person to an account before formal access can be granted.