Join our Newsletter — 33% off our NHI Course

Why do banks need stronger onboarding controls after pandemic-era fraud spikes?

Pandemic relief programs widened the fraud surface by giving criminals new opportunities to exploit weak identity checks. Banks should treat onboarding as a high-risk control point, not a one-time formality. Stronger verification, fraud screening, and step-up review help stop synthetic or stolen identities before accounts are opened and abused. The goal is to catch suspicious applicants early, before downstream losses and remediation costs grow.

Why onboarding became a fraud choke point for banks

When fraud pressure rises, onboarding stops being a clerical step and becomes the first real control barrier. The practical issue is not just whether an application is complete, but whether the bank can trust the person, business, or device behind it. Weak entry checks let synthetic identities, stolen credentials, mule accounts, and rapidly opened shell relationships move into the system before fraud teams can act.

That is why stronger onboarding controls are usually about layered verification, not a single stronger field check. Banks need to distinguish between low-risk applicants and cases that warrant additional review, because a successful false acceptance at the start is cheaper for the attacker than a later takeover, and more expensive for the bank to unwind.

A useful way to think about the problem is that onboarding is where identity evidence, fraud signals, and account-opening authority converge. If those checks are thin, a bank is effectively granting access on trust and hoping downstream monitoring will catch misuse later. For a broader identity-governance view of that lifecycle, the IAM and IGA Basics resource explains how onboarding, access review, and entitlement control fit together.

What stronger onboarding controls should actually change

Stronger onboarding controls should reduce the chance that an applicant can open an account with fabricated, recycled, or stolen identity attributes. In practice, that means more confidence in who is applying, better checks on the consistency of the application, and a clear trigger for step-up review when the risk picture is abnormal. The control is not only about identity proofing, it is also about fraud resistance.

For banks, the most important change is that onboarding decisions become risk-based instead of purely workflow-based. A low-friction path may still work for clearly low-risk applicants, but unusual patterns should force extra verification before the account is opened or activated. That is especially important when fraud actors are using the application process itself as an entry channel.

Lifecycle discipline matters because onboarding and offboarding are connected. If a bank cannot reliably establish identity at entry, it also weakens later account governance, recovery, and investigations. NHIMG’s NHI Lifecycle Management Guide covers the broader control logic of provisioning, visibility, and rotation, which is useful here as a lifecycle model even outside the NHI context.

How banks should tune verification, screening, and review

Banks usually get better results by combining several modest controls rather than relying on one perfect check. Verification should look at document authenticity, attribute consistency, device and channel signals, velocity, and evidence of prior abuse. Fraud screening should catch high-risk patterns early, while step-up review should be reserved for cases where automation flags inconsistency, impersonation risk, or unusual account-opening behaviour.

The main operational question is where to draw the threshold for manual intervention. Too many manual reviews create delay and abandonment, while too few allow risky applicants through. The best practical approach is to define clear triggers for when an application must be paused, escalated, or rejected, and to keep those triggers aligned with fraud loss data rather than with convenience alone.

When banks need a governance model for joiner, mover, and leaver-style controls, the Joiner-Mover-Leaver (JML) Guide is relevant because it shows how lifecycle controls should remove stale access and identity residue before it can be abused. For onboarding, the same principle applies in reverse, establish confidence early or accept that the account may become a future fraud remediation case.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, CIS Controls v8 and OWASP ASVS set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 IA-8 — Identification and Authentication (Non-Organizational Users) Onboarding banks' external customers requires strong identity proofing and authentication.
IA-5 — Authenticator Management Onboarding fraud often depends on weak handling of credentials and recovery factors.
AC-6 — Least Privilege Newly onboarded accounts should receive only the minimum access needed to limit blast radius.
Recommendation — Apply IA-8 to strengthen identity proofing before account opening and activation. Apply IA-5 to manage authenticators and reduce misuse during enrollment and recovery. Apply AC-6 to limit initial account access until trust is established.
CIS Controls v8 CIS-5 — Account Management Onboarding is where account creation, verification and lifecycle controls must be enforced.
CIS-6 — Access Control Management Fraud-resistant onboarding depends on restricting and reviewing access paths for new accounts.
Recommendation — Use CIS-5 to govern account creation and enforce review before activation. Use CIS-6 to restrict access until onboarding checks are complete.
ISO/IEC 27001:2022 A.5.15 — Access control Onboarding fraud is an access-control problem because it governs who can enter the bank environment.
A.5.16 — Identity management Banks must reliably establish and manage customer identities at onboarding.
A.8.5 — Secure authentication Step-up onboarding controls depend on stronger authentication checks and verification signals.
Recommendation — Apply A.5.15 to require approval and verification before granting access. Apply A.5.16 to ensure identities are verified and recorded consistently. Apply A.8.5 to strengthen onboarding authentication and verification.
OWASP ASVS V6 — Authentication The question centers on stronger verification before account creation, an authentication concern.
V8 — Authorization Onboarding should constrain what a newly created account can do until risk is accepted.
Recommendation — Use V6 to improve identity proofing and authentication at onboarding. Use V8 to limit newly onboarded account privileges until trust is established.

Practitioner Guidance

What to prioritise: Prioritise the applicant attributes and channels that are easiest to fake at scale, then add human review only where the combined signal is uncertain. If every case gets the same treatment, the control becomes expensive without becoming more effective.

What to verify: Verify that the onboarding step can distinguish a legitimate new customer from a synthetic or stolen identity case before account activation, not after the first transaction. A control that only detects abuse downstream is a detection control, not a prevention control.

Decision rule: If the identity evidence is inconsistent, recently altered, or supported by weak signals, treat the case as elevated risk and require step-up review before opening the account. If the evidence is stable and corroborated, keep the process fast enough that friction does not push good customers away.

Practitioner takeaway: The goal is not stronger onboarding for its own sake, it is to make the first acceptance decision reliable enough that the bank does not inherit avoidable fraud, remediation, and account-governance debt later.