Join our Newsletter — 33% off our NHI Course

How should conveyancers implement digital identity checks for high value property transactions?

Conveyancers should follow a staged process: obtain acceptable evidence, check its authenticity, match the evidence to the person presenting it, and then confirm the person is linked to the property transaction. The practical goal is to reduce manual document handling, improve consistency, and create a defensible identity verification trail for conveyancing work.

How to structure a conveyancing identity check workflow

For high value property work, the strongest pattern is a four-step workflow: collect acceptable evidence, validate that the evidence is genuine, match it to the individual, and confirm that the individual is connected to the transaction. That sequence matters because a single yes-no check is usually too weak for fraud-resistant conveyancing, especially when clients, introducers, and documents may all arrive remotely.

The first decision is what counts as acceptable evidence for the risk level and transaction type. Conveyancers should define the evidence set in advance, then apply the same rules consistently so staff are not improvising under pressure. The identity check should end with a defensible record of what was presented, what was verified, who reviewed it, and why the case was allowed to proceed.

For online or hybrid journeys, the process should still create a clear audit trail. That usually means capturing the document type, the authenticity checks performed, the match result, any exceptions, and the reason any manual override was approved. For a broader model of how digital identity evidence and reusable credentials are changing assurance, see Digital Identity, eID and Identity Wallets Guide.

Why evidence authenticity and person matching both matter

High value property transactions are exposed to impersonation, forged documents, and social engineering, so the core control is not just “did we see an ID”, but “did we test whether the ID is authentic and belongs to the right person”. That is why the evidence review and the face-to-document or person-to-record match should be treated as separate control steps, not merged into one informal judgement.

Authenticity checks look for altered fields, suspicious image quality, inconsistent fonts, mismatched metadata, expired documents, and signs of tampering. The matching step then tests whether the presenting individual reasonably corresponds to the evidence and the transaction file. When these are separated, the firm can spot cases where a real document is being used by the wrong person, which is a common failure mode in remote property fraud.

Conveyancers should also decide when a standard check is enough and when the matter needs escalated review. If the transaction is high value, urgent, cross-border, or involves unusual payment instructions, the identity assurance threshold should rise accordingly. The practical benchmark is whether a third party could later understand why the firm trusted this person for this property matter.

How to make the process defensible in practice

Defensibility comes from consistency, ownership, and evidence retention. A good workflow has a named owner, a recorded decision point for exceptions, and a standard file note that shows the chain from evidence received to final approval. That helps reduce manual document handling while preserving enough proof to answer a dispute, complaint, or regulator query later.

For conveyancers, the most useful control question is whether the identity check would still be understandable if a transaction were challenged months later. If the answer is no, the firm probably relied too heavily on staff judgement without enough recorded evidence. Identity Proofing and KYC Guide is useful here because it explains the checks that strengthen remote identity assurance, including document review, liveness-style checks, and attack resistance.

At scale, the goal is not to eliminate human review, but to reserve it for genuine exceptions. Firms should measure how many cases are completed without rework, how many are escalated, and how many fail because the evidence is incomplete or inconsistent. Those signals show whether the process is actually reducing friction while improving assurance, rather than just creating a new administrative layer.

Risk and Threat Considerations

High value property matters attract impersonation, forged documentation, and account or inbox compromise because the transaction value justifies effort from fraudsters. The main risk is that a weak digital check creates false confidence: staff may believe the identity has been verified when they have only reviewed a visually plausible image or a copied document.

Failure mechanism: The check fails when authenticity, matching, and transaction linkage are not performed as separate controls, or when exceptions are approved without sufficient evidence. Remote submissions, rushed completions, and poor recordkeeping make it easier for a forged or borrowed identity to pass through the process.

Impact: A failed check can expose the firm and client to property fraud, misdirected funds, professional negligence claims, and a difficult evidential dispute after completion. It also weakens the firm’s ability to show that it applied a consistent and proportionate verification standard.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-63 IAAL — Digital Identity Assurance Digital conveyancing checks rely on identity proofing and assurance levels.
Recommendation — Set assurance expectations for remote identity proofing and evidence verification.
NIST SP 800-53 Rev 5 IA-8 — Identification and Authentication (Non-Organizational Users) Conveyancing clients are external users whose identity must be authenticated.
AU-2 — Event Logging Identity checks need an audit trail of evidence, review, and exceptions.
Recommendation — Apply external-user authentication controls and retain verification evidence. Log identity-check decisions and exception approvals for later review.
ISO/IEC 27001:2022 A.5.16 — Identity Management The process needs governed identity verification and ownership.
A.8.24 — Use of cryptography Digital identity evidence and remote verification often depend on integrity and trust mechanisms.
Recommendation — Define ownership for identity verification and keep it consistently enforced. Protect digital identity evidence and verification exchanges with strong cryptographic controls.

Practitioner Guidance

What to prioritise: Start by defining a single workflow for acceptable evidence, authenticity review, person matching, and transaction linkage, then use the same standard across all conveyancing teams. Inconsistent local practice is usually more dangerous than a slightly stricter control.

What to verify: Make sure the file contains enough evidence to reconstruct the decision, including what was checked, what was rejected, and who approved any exception. If that cannot be shown, the control may have worked operationally but not defensibly.

Practitioner takeaway: The real test is not whether digital identity checks are performed, but whether they create a repeatable, reviewable record that materially lowers impersonation risk in high value transactions.