Join our Newsletter — 33% off our NHI Course

Who should own fake worker risk in an organisation?

HR, IAM, security operations, and insider-risk teams all own part of it, but no single group can manage it alone. Recruitment decides who enters the process, identity proofing decides whether the person is real, and security decides what happens when the identity looks suspicious or compromised.

Why fake worker risk is an ownership problem, not a single-control problem

Fake worker risk sits at the intersection of people risk, identity proofing, access governance, and fraud or insider misuse. One team may own recruiting checks, another may own identity verification, and a third may own access response, but the real failure mode is a gap between handoffs. If ownership is unclear, suspicious workers can enter, blend in, and keep access longer than they should.

That makes the question less about “who has the ticket” and more about who is accountable for the full lifecycle from application to onboarding to monitoring to offboarding. The organization needs a named owner for coordination, but the controls themselves remain distributed across functions that see different parts of the risk.

Worker authentication and access decisions should be treated as shared control points, especially where a person can request systems access, identity documents, payroll setup, or privileged support routes before their legitimacy has been established. The more a workflow depends on trust in submitted information, the more important it becomes to align HR process, identity proofing, and security escalation around the same risk model.

How responsibility should split across HR, IAM, security, and insider-risk

HR typically owns the front end of the process: recruitment, employment records, onboarding timing, and evidence that a person is expected to exist in the organization. IAM or identity teams own the controls that decide whether the person can be provisioned, what proof is required, and when access is removed or revalidated. Security operations and insider-risk teams own anomaly handling, correlation, and response when the identity signal does not match the expected worker profile.

The practical division is best understood as a chain of accountability. HR validates the business need and employment context, identity teams verify and govern the digital identity, and security teams act when behavior, device posture, or access patterns suggest the worker may be fabricated, reused, coerced, or compromised. If any one of those functions is missing, the others inherit more uncertainty than they can safely absorb.

For larger organisations, NIST Cybersecurity Framework 2.0 is useful because it forces ownership to span governance, protection, detection, response, and recovery rather than stopping at onboarding. That same lifecycle view is reinforced by NIST Privacy Framework when worker data, verification data, or identity evidence are being collected and retained.

What good ownership looks like in practice

Good ownership is visible when one function is accountable for coordination and several functions are accountable for controls. The coordinator should be able to answer: who approves hiring exceptions, who verifies the person, who grants access, who reviews suspicious cases, and who can stop access immediately. If those answers differ by geography, business line, or contractor type, the organisation should expect inconsistent outcomes unless the decision rules are documented and enforced.

Identity proofing deserves special attention because it is often the point where a fake worker can be distinguished from a legitimate one before any meaningful access exists. NIST SP 800-63 Digital Identity Guidelines is directly relevant here because it frames assurance around proofing and authenticator strength, while ISO/IEC 27002:2022 Information Security Controls provides the control discipline needed to tie onboarding, access restriction, and periodic review together.

Security operations and insider-risk teams should not own hiring decisions, but they should own escalation thresholds. When an identity looks inconsistent across HR data, device data, network behavior, or login geography, the right response is usually to pause access, validate the worker through a stronger channel, and then decide whether the case is fraud, error, or compromise. That separation keeps business decisions from being made inside an incident workflow.

Risk and Threat Considerations

Fake worker risk becomes material when an organisation assumes that employment records, submitted documents, or early-stage access requests are enough to establish trust. The common failure is not one dramatic breach, but a sequence of weak checks that let a fabricated or impersonated worker acquire credentials, internal visibility, or privileged assistance.

Failure mechanism: Gaps between recruiting, proofing, provisioning, and monitoring allow a malicious or fabricated worker to inherit legitimate-looking access, then exploit that trust to access systems, data, or payroll processes before detection.

Impact: The result can be fraud, unauthorized access, insider-style abuse, exposure of sensitive data, and slower response because the organisation initially believes the person is genuine.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-63 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.OC-01 — Organizational Context Fake worker ownership depends on cross-functional accountability and lifecycle context.
Recommendation — Define which teams own recruitment, identity proofing, access approval, and escalation.
NIST SP 800-63 Digital Identity Guidelines Identity proofing and authenticator assurance are central to distinguishing real from fake workers.
Recommendation — Set proofing and authenticator assurance levels before provisioning access.
ISO/IEC 27001:2022 A.5.18 — Access rights Fake worker risk is reduced by controlled provisioning, review, and removal of access rights.
A.6.1 — Screening Worker legitimacy begins with people-risk checks before onboarding or access.
Recommendation — Review and revoke access promptly when worker legitimacy is uncertain. Use pre-employment screening proportionate to role risk and access scope.
NIST SP 800-53 Rev 5 IA-8 — Identification and Authentication (Non-Organizational Users) External workers and contractors need strong identity assurance before system access.
Recommendation — Require stronger proofing for non-organizational workers before granting access.

Practitioner Guidance

What to prioritise: Assign a single coordinating owner for the end-to-end fake worker process, then make HR, IAM, and security owners for their own control points rather than joint owners of everything. That avoids a gap where everyone is aware of the issue but nobody is accountable for the decision.

What to verify: Confirm that the worker’s identity proofing standard, hiring evidence, access approval path, and escalation path all line up. If a person can receive production access before identity confidence is high, treat that as a control design flaw rather than a one-off exception.

Practitioner takeaway: Fake worker risk is managed best when the organisation treats it as a shared lifecycle with clear handoffs, not as an HR problem with a security afterthought.