Join our Newsletter — 33% off our NHI Course

How should financial institutions use digital identity to improve onboarding for excluded customers?

Financial institutions should use digital identity to make onboarding remote, faster, and more affordable while still meeting KYC and AML requirements. The strongest model is electronic KYC, which lets a provider verify identity without forcing every customer into a branch. That approach matters most in rural or underserved areas, where paper-heavy processes and physical distance create the biggest barriers to access.

Why digital identity changes onboarding for excluded customers

digital identity helps banks move from branch-bound onboarding to a remote, lower-cost process that can reach customers who struggle with travel, paperwork, or conventional proofing. The value is not simply speed, it is access with acceptable assurance. For excluded customers, the control question is whether the institution can verify identity and satisfy KYC and AML obligations without forcing a physical visit.

A well-designed digital identity flow also reduces drop-off. If the path is clear, mobile-first, and uses evidence the customer can realistically provide, more applicants complete onboarding on the first attempt. That matters in rural areas, for customers with limited documentation, and for people whose identities are hard to validate through legacy bureau-based methods.

Digital identity should therefore be treated as an access-enabling mechanism, not a convenience layer. The most effective implementations combine remote proofing, reusable credentials, and risk-based step-up checks so that the experience is lighter for low-risk customers but still resilient enough to support regulated financial services. For a broader view of the identity model, Digital Identity, eID and Identity Wallets Guide explains how wallets and verifiable credentials can support reusable identity patterns.

What eKYC changes in the onboarding model

Electronic KYC shifts the burden from paper and presence to evidence and assurance. Instead of requiring every customer to present physically at a branch, the institution can combine document checks, biometric or liveness checks, device signals, and trusted data sources to establish who the applicant is. That is the key mechanism that makes inclusion possible without abandoning control.

The practical benefit is that onboarding can be designed around the customer’s actual constraints. A customer in a remote community may have a phone but no easy branch access. A customer with limited income may not be able to spend time and travel cost on repeated in-person visits. eKYC can remove those barriers while still producing a defensible identity decision for the bank.

This only works when the identity evidence is matched to the risk of the relationship. A low-value account or low-risk product may justify a lighter onboarding journey, while higher-risk products need stronger proofing and more review. That is why institutions should align eKYC with customer risk tiering rather than applying one rigid process to everyone. Identity Proofing and KYC Guide covers the proofing methods and attack patterns that matter when onboarding is remote.

Financial institutions also need to design the digital journey so it can be reused across products where appropriate. If a customer has already been strongly verified, the institution should avoid forcing them to start from zero for every account or channel unless policy, regulation, or risk says otherwise. That reduces friction without lowering the assurance bar.

How banks can expand access without weakening compliance

The strongest model is one that pairs inclusion with clear control boundaries. Remote onboarding should collect only the evidence needed for the product and jurisdiction, preserve auditability, and make it easy for compliance teams to see why a decision was made. If the process cannot be explained after the fact, it is too opaque for regulated onboarding.

Institutions also need to distinguish identity verification from sanctioning or transaction monitoring. Digital identity helps establish the customer relationship; it does not replace AML screening, beneficial ownership checks, or ongoing monitoring. Those controls still need to run, and they need to be tuned so that they do not recreate the same exclusion problem through unnecessary false positives or manual bottlenecks.

In practice, financial institutions should look for identity tooling that supports remote proofing, progressive assurance, strong recovery, and clear evidence retention. The right target is not “fully automated for everyone”, but “fast enough for most, strong enough for regulated use, and adaptable for edge cases.” For financial-sector context, Financial Services Identity Security Guide is a useful navigation point for the identity obligations banks and payment firms must balance.

Risk and Threat Considerations

Digital identity can widen access, but it also expands the attack surface around account opening, synthetic identity abuse, document fraud, and credential theft. If onboarding is made easier without improving assurance, the institution can accelerate bad-account creation as well as legitimate access.

Failure mechanism: Weak proofing, poor liveness checks, or overreliance on a single data source can let attackers create fake or stolen identities at scale, especially where manual review has been reduced.

Impact: The result can be fraudulent account opening, downstream AML exposure, regulatory findings, and higher remediation cost if the institution later has to unwind approved customers.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST SP 800-63 Digital Identity Guidelines Digital onboarding hinges on identity proofing and authenticator assurance for remote customers.
Recommendation — Use NIST 800-63 assurance levels to match proofing strength to onboarding risk.
NIST SP 800-53 Rev 5 IA-8 — Identification and Authentication (Non-Organizational Users) Customer onboarding requires verifying external users before account access is granted.
IA-12 — Identity Proofing eKYC depends on identity proofing methods that establish applicant identity remotely.
AU-2 — Event Logging Onboarding decisions need traceable records for compliance and fraud review.
Recommendation — Apply IA-8 controls to prove external customer identity before account activation. Implement IA-12 to support remote identity proofing and retain proofing evidence. Log onboarding evidence, checks, exceptions, and approvals for later audit and investigation.

Practitioner Guidance

What to prioritise: Start by segmenting onboarding by product risk and customer need. Low-friction digital identity should be reserved for use cases where the assurance method is proportionate, while higher-risk products should retain step-up verification and tighter review.

What to verify: Check that the onboarding flow produces an auditable decision trail, including what evidence was used, what checks were passed, and why exceptions were granted. If the team cannot explain the decision in compliance language, the process is not ready for production.

Common mistake: Treating digital identity as a front-end UX project. For excluded customers, the real test is whether the institution has reduced avoidable friction without creating a weaker fraud gate or a harder compliance problem later.

Practitioner takeaway: The best onboarding designs do not ask whether digital identity is “secure enough” in the abstract, they ask whether the institution can prove the right customer was verified with proportionate effort and defensible evidence.