Generic conferencing tools create risk because they are built for broad collaboration, not identity assurance. They may expose personal data, allow disruptive access, and lack controls needed for regulated onboarding, such as restricted functionality and auditability. In financial services, that gap can weaken evidence quality, increase fraud exposure, and make compliance harder to demonstrate consistently.
Why generic conferencing breaks regulated onboarding
Generic video conferencing platforms are optimised for meetings, not regulated identity proofing. That means the organisation often has to bolt on identity checks, evidence capture, access restriction, and recordkeeping around a tool that was never designed to make those controls first-class. The result is usually weaker assurance, more manual handling, and more room for inconsistent operator behaviour.
For onboarding and customer verification, the key issue is not whether a call can be held, but whether the interaction can be trusted as part of an auditable verification workflow. A platform that cannot reliably restrict features, preserve evidence, or separate the verification session from ordinary collaboration creates avoidable control gaps.
Which controls are usually missing?
Regulated verification normally needs tighter controls than a standard meeting. Practitioners usually need session locking, restricted participant actions, clear capture of supporting evidence, durable audit trails, and a way to show exactly who attended, what was shown, and what decision was made. Generic tools may provide some of those capabilities, but rarely in a way that is purpose-built for compliance-grade onboarding.
That is why Identity Proofing and KYC Guide is a better reference point for the verification workflow itself: it frames the control objectives around assurance, document checks, liveness, and fraud resistance rather than around collaboration convenience. In parallel, identity lifecycle and access governance matter because onboarding evidence, reviewer access, and downstream account activation should be tied to a controlled process, not an ad hoc meeting.
The same principle shows up in broader identity governance guidance, where IAM and IGA Basics helps explain why access review, entitlement control, and governance over people and machines are part of the control environment. Generic conferencing tools can sit outside that control plane, which makes it harder to prove that the verification step was consistent and appropriately authorised.
How the risk shows up in practice
The first risk is evidence quality. If the session cannot be captured in a controlled, repeatable way, the organisation may end up with fragmented notes, inconsistent screenshots, or recordings that do not meet policy expectations. The second risk is exposure of personal data, because onboarding sessions often reveal documents, contact details, and biometric or quasi-biometric cues that should not be widely accessible. The third risk is operational abuse, where an uninvited participant, a screen-share mistake, or a misconfigured recording setting undermines the integrity of the verification process.
Those failure modes are not hypothetical. They line up with customer onboarding fraud, weak assurance, and inconsistent evidence handling, which is why identity proofing guidance remains central. They also align with access-control failures and overexposure of sensitive information, which is why regulated teams need tighter session governance than a normal collaboration call provides.
For the verification step itself, OWASP ASVS is useful as an external benchmark for authentication, session handling, and access-control discipline, even though the onboarding workflow is broader than application security. The broader regulatory expectation also points toward customer due diligence, which is why FATF Recommendations and EBA AML/CFT Guidance are relevant when onboarding is tied to financial crime controls and demonstrable customer due diligence.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AU-2 — Event Logging | Verification sessions need traceable evidence and auditability. |
| IA-8 — Identification and Authentication (Non-Organizational Users) | Customer verification concerns external user identity assurance. | |
| AC-6 — Least Privilege | Restricting session and reviewer capabilities reduces onboarding exposure. | |
| Recommendation — Log onboarding events and retain reviewable evidence for each verification decision. Apply external-user identity assurance controls before granting onboarding access. Limit participant and reviewer permissions to the minimum needed for verification. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Regulated onboarding needs controlled access to sessions and evidence. |
| A.5.33 — Protection of records | Verification evidence must be protected and retained for compliance. | |
| Recommendation — Define and enforce access control for onboarding systems and verification records. Protect onboarding records so verification evidence remains intact and reviewable. | ||
Practitioner Guidance
What to prioritise: Treat the verification workflow as a governed control, not a meeting. The platform decision should start with evidence retention, participant restriction, and auditability, then move to usability.
What to verify: Confirm that the tool can restrict who joins, what they can do, whether the session can be recorded or exported under policy, and whether the resulting evidence can be retained in a way that supports review and challenge.
Common mistake: Teams often assume a video call plus manual notes is “good enough” because the process looks interactive. In regulated onboarding, the control question is whether the session can be reproduced, reviewed, and defended after the fact.
Practitioner takeaway: If the tool cannot support controlled evidence and consistent access discipline, it should be treated as a communications channel, not as the verification control itself.
Related resources from NHI Mgmt Group
- Why do collaboration tools create such a large secrets risk?
- Why do consumer grade chat and video tools create risk for confidential or regulated communications?
- Why do non-human identities create more audit risk than human accounts?
- Why do non-human identities create audit risk in modern environments?