Join our Newsletter — 33% off our NHI Course

Relationship Proof

Relationship proof is documentary evidence that confirms a legal connection between a minor and the adult acting for them. It can include birth certificates, custody orders, guardianship papers, or similar records. Institutions use it to prevent unauthorised adults from controlling a child’s account or impersonating a lawful guardian.

What Relationship Proof Establishes

Relationship proof is not about proving identity in the abstract, it is about proving a specific legal relationship that gives an adult authority to act for a child. That authority boundary is what lets institutions distinguish a lawful guardian from an unrelated requester or impostor.

Because the evidence is documentary, its value depends on whether the record is current, legible, and accepted by the institution. A birth certificate, custody order, or guardianship paper may all serve the same purpose, but each carries different evidentiary weight depending on the action being requested.

Why Institutions Ask For It

Relationship proof protects account actions that should only be available to someone with parental or legal standing. It is commonly used when opening or managing a child’s account, updating contact details, approving services, or making decisions that could expose the child to financial, medical, or privacy harm.

This control is especially important where an institution must avoid unauthorised adult access that could look legitimate on the surface. A person may know a child’s details, but without documentary proof they may not have the right to control the account or receive protected information.

What Counts As Acceptable Evidence

Acceptable evidence usually comes from a government or court record that links the child to the adult’s legal role. NIST Privacy Framework is useful here because the underlying issue is not just recordkeeping, it is governance over who may legitimately access sensitive personal information.

In practice, institutions often rely on the smallest set of documents needed to establish the relationship without collecting unnecessary extra data. That means the evidence standard should be consistent, explainable, and tied to the action being authorised rather than treated as a vague administrative formality.

Why The Control Can Fail

Relationship proof fails when institutions accept outdated documents, rely on informal assertions, or do not verify whether the adult named in the record still has authority. It can also fail when staff misread custody limitations, overlook expired guardianship, or accept forged papers without a reliable review process.

Once a false relationship claim is accepted, the consequence is usually unauthorised access to a child’s account or records, along with a loss of trust in the institution’s access controls. The control is only effective when staff treat it as a legal-authority check, not a convenience check.

Risk and Threat Considerations

Relationship proof creates a clear abuse path when an impostor presents convincing but invalid documents to gain control over a minor’s account or information. The main risk is not just administrative error, it is the exposure of a child’s data or assets to someone who lacks lawful authority.

Failure mechanism: Staff may accept incomplete, stale, forged, or misunderstood documents, especially when the request appears urgent or familiar. That weakens the institution’s ability to distinguish lawful guardians from unauthorized adults.

Impact: Unauthorized account changes, disclosure of sensitive records, wrongful transfers of control, and potential harm to the child or lawful guardian can follow.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 IA-8 — Identification and Authentication (Non-Organizational Users) Relationship proof governs who may act for a child, a non-organizational user context.
AC-2 — Account Management The term affects who can be granted or retained authority over a child’s account.
AC-3 — Access Enforcement Relationship proof is used to enforce who is permitted to control protected child information.
Recommendation — Require verified evidence before allowing an adult to access or manage a child-facing record. Tie account changes to validated legal authority before approving access updates. Enforce access decisions only after the guardian relationship is documented and verified.
ISO/IEC 27001:2022 A.5.15 — Access control Relationship proof is part of deciding who may be allowed to access child-related information.
Recommendation — Define approval rules that require documentary proof before sensitive child access is granted.

Practitioner Guidance

What to watch for: The highest-risk cases are those involving partial custody, temporary guardianship, name mismatches, or documents from another jurisdiction. Those are the situations where a simple visual check is least reliable and where exceptions should be handled carefully.

Governance implication: Institutions should define in advance which documents are acceptable for which actions, so frontline review is consistent and defensible. A clear rule set is more effective than ad hoc judgment because it reduces both fraud risk and uneven treatment of families.