Join our Newsletter — 33% off our NHI Course

How should organisations design identity verification so people can complete checks both online and in person?

Organisations should treat identity verification as a service design problem, not just a digital workflow. The strongest approach offers multiple routes for the same trust outcome, so people who cannot or prefer not to use online checks still have access. That reduces exclusion, supports regulatory expectations, and avoids forcing high-risk users into a single channel that may create drop-off or friction.

Designing identity verification for online and in-person completion

identity verification works best when the organisation defines one assurance outcome and then offers more than one path to reach it. That means the online route, the in-person route, and any assisted route should all feed the same decision model, with equivalent evidence thresholds and clear escalation when a case needs manual review. The goal is continuity of trust, not channel loyalty.

That design matters because a single digital-only flow can exclude people who lack devices, stable connectivity, compatible documents, or comfort with remote checks. In practice, organisations should treat the channel as a delivery choice and the assurance standard as the constant, so people can move between routes without re-starting the process or being forced into a weaker outcome.

What has to stay consistent across channels?

The first requirement is that the same identity proofing policy governs both journeys. If online applicants are checked with document validation, liveness, and fraud screening, an in-person route should not quietly reduce the assurance bar just because a counter staff member is present. Equally, the in-person path should not become a more onerous variant that adds friction without improving confidence.

Consistent design usually means matching the evidence set to the risk, not to the channel. For lower-risk cases, a simple proofing journey may be enough; for higher-risk or higher-impact access, the organisation should require stronger evidence, tighter supervision, or a step-up review. The practical test is whether the final trust decision would be defensible if the case later became disputed.

Where the organisation uses formal identity proofing guidance, the online and offline routes should both support the same assurance logic. That is why many teams align the service design to a common policy baseline and then adapt the interaction pattern, rather than allowing each channel to invent its own verification standard.

How should the service be built so people can switch channels?

A usable design starts with shared intake, shared case records, and a common status model. If a person begins online and then needs to finish in person, the in-person staff should be able to pick up the same case, see what has already been validated, and record only the missing evidence. That avoids duplicate collection and reduces the chance of contradictory decisions.

The same principle applies in reverse. If a walk-in begins at a branch or service desk but cannot complete a step there, the organisation should preserve the case and let the person finish remotely where appropriate. A Identity Proofing and KYC Guide is useful here because the hard part is not just the check itself, but how document evidence, liveness, fraud detection, and escalation are coordinated across the journey.

Operationally, the best services make handoff explicit. Staff should know when to accept a completed online case, when to re-open it for additional evidence, and when to send it to a specialist review path. That prevents the common failure mode where the in-person route becomes a separate island with different rules, different records, and different outcomes.

Where do exclusion and fraud risks show up?

Multi-channel design reduces exclusion, but it also creates consistency risk. If identity standards drift between channels, applicants may choose whichever route is easiest, not whichever route is appropriate for the assurance level. That can create either unfair denial, where one channel is too strict, or control weakness, where another is too permissive.

Fraud pressure also changes with the channel. Online flows may be exposed to document forgery, synthetic identity, and presentation attacks; in-person flows are more exposed to impersonation, social engineering, and staff override. The practical challenge is to keep the same decision quality while recognising that the attack surface differs. Organisations that combine online and in-person routes should therefore review both the fraud model and the exception process together.

For organisations that operate under customer due diligence or regulated onboarding obligations, the multi-channel question is not just UX. It affects whether the institution can show that the verification result is reliable, repeatable, and proportionate to the risk of the relationship or transaction. The process has to be auditable even when the person chooses a non-digital path.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-63 Digital Identity Guidelines Defines assurance levels and identity proofing across channels.
Recommendation — Align both channels to the same assurance level and proofing requirements.
ISO/IEC 27001:2022 A.5.15 — Access control Identity verification determines who can be trusted to access services.
Recommendation — Set access decisions on verified identity and documented assurance rules.
NIST CSF 2.0 PR.AA-01 — Identity Management, Authentication, and Access Control Covers identity proofing and access control as a governed security function.
Recommendation — Document identity proofing rules and apply them consistently across delivery channels.

Practitioner Guidance

What to prioritise: Define the assurance outcome first, then design both channels to reach it. If the online and in-person routes do not produce the same decision quality, you do not have one service, you have two inconsistent controls.

What to verify: Check that case history, evidence capture, override rights, and escalation rules are identical across channels. If a staff member can approve an in-person case with less evidence than the online workflow would require, the design has created an avoidable control gap.

Common mistake: Teams often optimise each channel separately. The better pattern is to make the journey flexible but the trust standard fixed, so users can switch routes without losing continuity or being re-verified from scratch.

Practitioner takeaway: The strongest identity verification design is one where the channel changes, the assurance logic does not, and every route leaves behind a complete, auditable record of how trust was established.