Join our Newsletter — 33% off our NHI Course

Why do digital identity programmes become more urgent during a crisis such as a pandemic?

Crisis conditions compress timelines, disrupt physical service delivery, and increase demand for remote access to trusted identity. That makes digital ID a practical control for continuity, fraud reduction, and secure service delivery. When people cannot rely on in-person verification, organisations need digital assurance that can be issued, checked, and used remotely without increasing operational friction.

Why crisis conditions make digital identity programmes a priority

digital identity becomes urgent in a crisis because the organisation has to preserve trust while the normal way of proving who someone is may be interrupted. When in-person checks, branch visits, or paper-based verification slow down or stop, digital identity becomes the mechanism that keeps access, service delivery, and fraud controls working at speed.

A practical programme response is to treat crisis readiness as an identity capability, not a temporary workaround. That means being able to issue identity remotely, verify it remotely, and rely on it across channels without rebuilding the process every time demand spikes or operations move online.

What changes in a crisis compared with normal operating conditions?

A crisis changes the operating model around identity. Service volumes move suddenly, staff and customers need remote access, and physical assurance points may be unavailable or restricted. The result is that identity becomes a continuity control, because the business still needs to know who is entitled to act, receive services, or approve transactions even when the usual verification path is broken.

This is why digital identity is not just a convenience feature. It reduces the gap between policy and execution when the environment is unstable. If a programme depends on manual checks, it tends to fail where the demand is highest: onboarding, re-verification, claims, benefits, account recovery, and any other workflow that needs trust at a distance.

The other major change is scale. In a crisis, more people are pushed into self-service and remote channels at once. Identity systems that are designed for routine loads often become the bottleneck unless they support repeatable assurance, automated verification, and clear fallback rules for exceptions.

How digital identity supports continuity, fraud control, and secure service delivery

Digital identity supports continuity by allowing an organisation to keep serving users without requiring physical presence. It supports fraud control by making verification more consistent and auditable than ad hoc manual checks. It supports secure service delivery by giving the organisation a way to raise assurance only where the transaction actually needs it, rather than forcing every interaction through the same slow process.

That balance matters. Overly strict processes can choke service when people need help quickly. Overly loose processes can open the door to impersonation, synthetic identity abuse, account takeover, and benefit or payment fraud. The right programme design uses trusted digital identity as a control point, then adjusts assurance to the risk of the interaction.

For remote verification models, the quality of proofing and the strength of authentication are decisive. NIST SP 800-63 Digital Identity Guidelines provides the assurance concepts that help organisations separate identity proofing, authentication strength, and federation decisions, while Identity Proofing and KYC Guide shows how remote proofing, document checks, and liveness control the fraud problem when face-to-face verification is not possible. For wallet-based and cross-border use cases, eIDAS 2.0, the EU Digital Identity Framework is the clearest external reference for how digital identity can be structured for broad reuse and verification.

What a resilient crisis-ready programme has to get right

A resilient programme does not assume the crisis will be short or that one channel will remain available. It plans for a mix of remote proofing, step-up authentication, exception handling, and recovery paths for users who fail automated checks but still need access. It also makes identity operations measurable, so the organisation can see where abandonment, fraud review, or manual queueing is slowing critical services.

That often requires a broader operating model than people expect. Identity policy, fraud operations, customer service, legal, and product teams need a shared decision on which transactions can be digital-first, which need stronger evidence, and which should remain restricted until the organisation can verify the user with sufficient confidence. This is where a clear identity programme is more valuable than a collection of disconnected controls.

In practice, digital identity programmes become urgent during a crisis because they sit at the intersection of availability and trust. Organisations that already have a usable digital identity layer can keep working with less disruption, while those that delay end up improvising controls under pressure.

Risk and Threat Considerations

When crisis pressure pushes more transactions online, the main risk is not only slower service, but weaker trust decisions made under time pressure. Attackers and fraudsters often exploit that moment by using stolen data, synthetic identities, or account recovery paths to bypass checks that were designed for calmer operating conditions.

Failure mechanism: Identity proofing shortcuts, overloaded manual review, or inconsistent fallback rules can let an unverified party gain access, create an account, or take over an existing one.

Impact: The organisation can see higher fraud losses, wrong-person access, customer harm, and service interruption, especially where identity is the gate to benefits, payments, regulated services, or sensitive records.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63 and NIST SP 800-53 Rev 5 set the technical controls, while EU AI Act and ISO/IEC 27001:2022 define the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-63 Digital Identity Guidelines Identity proofing and authentication assurance are central to remote crisis verification.
Recommendation — Apply assurance-level guidance to separate proofing, authentication, and federation decisions.
EU AI Act Regulatory framework Digital identity programmes may support AI-assisted or automated verification in regulated settings.
Recommendation — Document governance and accountability for any automated identity decisioning.
NIST SP 800-53 Rev 5 IA-8 — Identification and Authentication (Non-Organizational Users) Crisis identity programmes often authenticate customers or citizens remotely.
IA-5 — Authenticator Management Remote identity programmes depend on issuing, protecting, and rotating authenticators and secrets.
Recommendation — Use IA-8 to require strong identification and authentication for external users. Use IA-5 to manage authenticators through their full lifecycle.
ISO/IEC 27001:2022 A.5.16 — Identity management Identity programmes need formal identity governance when service delivery shifts online.
Recommendation — Define identity ownership, assurance, and lifecycle responsibilities under A.5.16.

Practitioner Guidance

What to prioritise: Protect the highest-risk journeys first, usually onboarding, account recovery, payment changes, and any workflow where a weak identity decision creates immediate financial or privacy exposure.

What to verify: Confirm that digital identity checks still work when staff are remote, that exception handling is documented, and that the same user cannot repeatedly fall back to weaker paths without additional scrutiny.

What good looks like: A crisis-ready programme can issue, verify, and accept identity remotely with clear assurance levels, auditable decisions, and a measured fallback path for edge cases rather than one-off manual judgment.

Practitioner takeaway: In a crisis, digital identity is valuable because it preserves both continuity and trust, but only if the organisation has already designed the identity journey to scale without quietly lowering assurance.