Join our Newsletter — 33% off our NHI Course

How should insurers design video KYC so it is secure, compliant, and usable at scale?

Insurers should treat video KYC as a controlled verification workflow, not just a live call. The process needs consent, recorded evidence, time stamps, geolocation, trained staff, secure storage, and end-to-end encryption. Real-time identity checks, liveness detection, and audit logs help ensure the customer is present, the documents are valid, and the onboarding record can withstand regulatory review.

Designing video KYC as a controlled verification workflow

Video KYC works best when insurers treat it as a governed identity proofing and customer due diligence workflow, not as an informal interview. The design goal is to make each step verifiable: who attended, what evidence was shown, what was approved, and when the decision was made. That means the process must be repeatable, reviewable, and resilient to fraud tactics that target remote onboarding.

The workflow should be structured around controlled checkpoints rather than operator discretion alone. Commonly, that includes pre-session consent, session binding to the right applicant, capture of document images or screen evidence, live facial comparison, and explicit approval criteria for the reviewer. For insurers, the practical question is whether the full record can stand up later to internal audit, complaint handling, and regulatory challenge.

At scale, usability depends on narrowing the number of failure points without weakening assurance. A good video KYC design gives the customer a simple path through the session while making the operator’s task deterministic: verify the right person, verify the document, verify the session integrity, and preserve the evidence. For identity proofing and liveness controls, see Identity Proofing and KYC Guide.

Controls that make the session defensible

Security and compliance depend on controls that preserve the evidential value of the interaction. End-to-end encryption protects the session in transit, but the deeper requirement is integrity of the verification record: time stamps, operator identity, audit logs, consent artefacts, and secure retention of session material. If any of those elements can be altered without trace, the onboarding record becomes hard to trust.

Real-time verification should also be designed to resist replay and injection. Liveness detection helps distinguish a present applicant from a static image, replayed video, or synthetic media, while document checks should look for tampering, mismatched data, and signs that the document was not presented live. Staff training matters because the control is only as strong as the reviewer’s ability to spot exceptions and escalate suspicious cases.

Data handling must be minimal and explicit. If the insurer captures biometrics, geolocation, or other sensitive onboarding evidence, the retention period, purpose, and access model should be tightly defined. The control objective is not simply to collect more evidence, but to collect enough evidence to prove compliance without creating unnecessary privacy exposure or storage sprawl.

For the regulatory baseline on customer due diligence and identity verification expectations, the FATF Recommendations for AML and KYC remain a core reference, and insurers operating in the EU also need to align with the eIDAS 2.0 digital identity framework where digital identity and cross-border verification are in scope.

Scaling video KYC without turning it into a fraud factory

Scale changes the risk profile. A process that works for a pilot can fail when volumes rise, because exceptions become harder to review, reviewer consistency drops, and fraudsters learn which step is most brittle. The insurer should design for queueing, escalation, and exception handling from the start, especially where human review remains part of the control.

Operationally, the best model is a tiered workflow. Low-risk cases can pass through a standard path, while higher-risk sessions, device anomalies, document anomalies, or failed liveness checks trigger manual review or a different channel. That keeps the process usable for genuine customers while reserving human attention for the cases where judgement matters most.

Scale also increases the importance of monitoring. Insurers should look for repeated device patterns, abnormal geolocation behaviour, session interruptions, or clusters of failed checks that suggest scripted abuse or synthetic identity attempts. If the team cannot measure false accepts, false rejects, and manual override rates, it will struggle to tell whether the process is actually becoming safer or merely faster.

Risk and Threat Considerations

Video KYC is attractive to attackers because it offers a remote path into account opening, policy enrolment, or claims access with lower friction than in-person verification. The main risks are synthetic identity, deepfake-assisted impersonation, document fraud, and session manipulation, especially where staff are under pressure to clear queues quickly.

Failure mechanism: The control fails when the session proves only that a video feed exists, not that a live person controls the identity evidence being shown. Weak liveness checks, poor reviewer training, reused documents, or insecure session handling can let an attacker pass a false identity through a seemingly legitimate onboarding flow.

Impact: A compromised video KYC process can lead to fraudulent policy issuance, claims abuse, regulatory findings, customer harm, and expensive remediation across downstream policy administration and fraud operations.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-63 IAL2 — Identity Assurance Level 2 Video KYC is a remote identity proofing problem that maps to assurance level design.
Recommendation — Set assurance targets for remote proofing and require evidence strong enough for the chosen level.
ISO/IEC 27001:2022 A.5.34 — Privacy and protection of PII Video KYC captures sensitive identity evidence and biometric-like material requiring tight privacy controls.
Recommendation — Minimise collected identity data and define retention, access, and protection rules.
NIST SP 800-53 Rev 5 IA-8 — Identification and Authentication (Non-Organizational Users) Customers being verified in video KYC are external users whose identity must be established remotely.
AU-2 — Event Logging Auditability is central to proving how the video KYC decision was made.
Recommendation — Use remote identity proofing controls for external applicants and keep the proofing record. Log the session, reviewer actions, approvals, and exceptions for later audit and dispute handling.

Practitioner Guidance

What to prioritise: Define the minimum evidence set that makes a session defensible, then design the workflow around that set rather than around the live-call experience. Consent, operator traceability, document integrity, liveness, and immutable audit trails should be treated as baseline requirements, not optional enhancements.

What to verify: Check that the recorded artefacts are sufficient to reconstruct the decision later, including who approved the session, what was seen, and whether exceptions were escalated. If a reviewer can overrule the system without leaving a clear reason, the control is too weak for regulated onboarding.

Common mistake: Treating video KYC as a customer-service feature first and a control second. Usability matters, but at scale the process only works when the insurer can prove it is both efficient and defensible under audit and fraud review.

Practitioner takeaway: The strongest video KYC design is the one that reduces friction without reducing evidential quality, because compliance and fraud resistance both depend on the same thing: a session record that can be trusted after the call ends.