Organisations should provide alternative verification routes, such as in-person or paper-based options, so identity proof is not forced into a single digital path. They should also support inclusion by keeping terms clear, avoiding mandatory-by-default adoption, and designing for people with lower digital confidence. The goal is parity of acceptance, so choice remains with the individual.
How to keep identity access inclusive without lowering assurance
When digital identity services are not accessible to everyone, the control objective should shift from “digital only” to “trusted and usable for the whole population.” That means offering equivalent non-digital routes, keeping the acceptance rules clear, and avoiding designs that assume every user can or wants to complete the process online. Parity of acceptance matters more than channel uniformity.
Organisations should treat alternative verification as a design requirement, not a fallback exception. If one route is too slow, costly, or intimidating, people with limited connectivity, disabilities, low literacy, or low digital confidence are effectively excluded even when the service is formally available.
Choice also has a governance dimension. When adoption is made mandatory by default, people may comply without real consent or understanding, which can undermine trust in the identity process and increase abandonment, complaints, or unsafe workarounds.
Why access barriers become a security and trust problem
A digital identity programme can fail operationally if it only works for the most digitally capable users. The risk is not just inconvenience, it is unequal access to essential services, lower completion rates, and pressure on support teams to improvise manual exceptions. The result can be inconsistent identity decisions and uneven assurance.
Well designed alternatives reduce the chance that people reuse someone else’s device, ask a third party to complete steps on their behalf, or submit poor-quality information just to get through the process. Clear terms and accessible routes help prevent the identity journey from becoming a barrier that users try to bypass.
For cross-border or regulated identity schemes, alignment with eIDAS 2.0 is relevant because the framework is built around digital identity that must still support real-world interoperability and user choice. The broader lesson is that identity assurance must be usable across different populations, not only across different systems. See eIDAS 2.0, the EU Digital Identity Framework and NHIMG’s Digital Identity, eID and Identity Wallets Guide for the wallet and cross-border context.
Designing for inclusion while preserving verification quality
Good practice is to separate the question of assurance from the question of channel. A paper-based, in-person, assisted, or hybrid route can still support strong verification if the process is defined clearly, the evidentiary standard is understood, and the decision remains consistent.
What practitioners often underestimate is the difference between an “available” process and an “accessible” one. If users need specialist knowledge, a modern smartphone, or perfect digital confidence to proceed, the service may be technically online but socially exclusive.
Where identity proofing is part of the journey, organisations should keep the policy language simple enough that people can understand what is required before they start. NHIMG’s Identity Proofing and KYC Guide is useful here because the same clarity that helps prevent fraud also helps legitimate users complete the process without avoidable friction.
Risk and Threat Considerations
When organisations force a single digital path, the main risk is exclusion followed by insecure workaround behaviour. Users may delegate the task to others, provide incomplete evidence, or abandon the process altogether, which weakens both assurance and service reach.
Failure mechanism: A narrow channel design creates dependency on one device type, one skill level, or one connectivity model, so legitimate users cannot complete identity verification even when they are eligible.
Impact: The organisation sees lower completion, more manual exceptions, weaker trust, and a greater chance that people will seek unofficial shortcuts that undermine the control environment.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022, GDPR and EU AI Act define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | Digital Identity Guidelines | Guides accessible, assurance-based identity proofing and verification across channels. |
| Recommendation — Use accessible identity proofing options that preserve the required assurance level for each user population. | ||
| NIST CSF 2.0 | PR.AA-01 — Identity Management, Authentication, and Access Control | Identity access must work for intended users without forcing a single unusable path. |
| Recommendation — Design identity verification so legitimate users can complete it through approved accessible routes. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Access control must remain usable and consistent when multiple verification routes exist. |
| Recommendation — Define and operate access decisions so alternative identity routes remain controlled and auditable. | ||
| GDPR | Data protection by design and by default | Inclusive identity journeys should minimise unnecessary data collection and avoid exclusionary defaults. |
| Recommendation — Apply privacy and usability by design so identity processes remain fair and proportionate. | ||
| EU AI Act | Transparency and human oversight | If automated identity decisions are used, users need understandable, contestable pathways. |
| Recommendation — Provide understandable, contestable identity routes when automation affects access decisions. | ||
Practitioner Guidance
What to prioritise: Make parity of acceptance the target. The user should be able to complete the identity journey through more than one verified route without the organisation treating non-digital access as a lesser option.
What to verify: Check that the alternative route produces the same decision quality, auditability, and escalation path as the digital route. If the fallback cannot support those properties, it is not an equivalent control.
What good looks like: Clear instructions, multiple accessible channels, and a consent model that allows the individual to choose the path that fits their situation. NHIMG’s Public Sector Identity Security Guide is relevant where inclusive access is part of citizen-facing service delivery.
Practitioner takeaway: Inclusion is not a soft overlay on identity assurance, it is part of control design. If a path cannot be used by the intended population, the identity service is not truly complete.
Related resources from NHI Mgmt Group
- How should organisations govern reusable digital identity across multiple services?
- What do organisations get wrong about digital identity in financial services?
- Why do organisations need to verify identity at every access request for high-risk digital services?
- How should organisations design digital identity systems so people can prove who they are across services and borders?