Join our Newsletter — 33% off our NHI Course
Home› FAQ› Authentication, Authorisation & Trust› How should banks implement video KYC when physical…
Authentication, Authorisation & Trust

How should banks implement video KYC when physical onboarding is impractical or restricted by regulation?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 29, 2026 Domain: Authentication, Authorisation & Trust

Banks should treat video KYC as a controlled identity proofing workflow, not a casual video call. The process needs informed customer consent, live document capture, face matching, liveness checks, timestamped recordings, audit logs, and secure storage. It also works best when questions are randomized, location is recorded, and only trained officials conduct the session.

What video KYC is meant to prove

Video KYC is not just a remote interview. It is a remote identity proofing control that has to establish who the customer is, whether the presented documents are genuine, and whether the person on camera is the same person who should be onboarded. The control is compensating for the fact that the bank cannot rely on an in-branch physical check.

That means the workflow should be designed around evidence, not convenience. A bank needs a structured sequence for document capture, face comparison, liveness testing, and recording the full session so the review can be replayed or audited later. Identity Proofing and KYC Guide is a useful reference point for the document, liveness, and synthetic identity controls that make remote onboarding defensible.

The practical test is whether the session creates enough assurance for the bank’s onboarding decision. If it does not produce durable evidence, measurable checks, and a clear audit trail, then it is only a video call with compliance decoration.

How to design the workflow so it holds up under review

A bank should treat the process as a controlled sequence with defined gates. Start with customer consent, then capture an acceptable identity document, verify document authenticity, compare the live face to the document image, and perform liveness checks that resist replay, injection, and deepfake-style abuse. The session should be timestamped, recorded, and tied to an operator identity so every step can be traced.

Randomized challenge questions and controlled prompts matter because they reduce predictability and make scripted fraud harder. Recording location signals, where permitted, adds another verification layer, especially when the bank has jurisdictional restrictions on where onboarding may occur. The objective is not to collect more data for its own sake, but to make each check independently useful to the final decision.

Process ownership also matters. Banks should use trained officials, not general customer service staff, because the operator has to recognize document defects, inconsistent behavior, and signs that the session is being coached or manipulated. If the institution cannot explain who approved the session and why, the workflow is too weak for regulated onboarding.

Which regulatory and control constraints shape the bank’s decision

Video KYC sits at the intersection of customer due diligence, record retention, privacy, and cross-border digital identity rules. The right implementation depends on the jurisdiction, but the common theme is that the bank must be able to justify how the remote process meets the same assurance objective as in-person onboarding. For European banks, eIDAS 2.0, the EU Digital Identity Framework is relevant when digital identity verification and wallet-based trust services enter the onboarding path.

In AML-driven environments, video KYC must also support customer due diligence obligations, beneficial owner checks where relevant, and evidence retention for future review. The bank should be able to demonstrate not only that the customer was seen, but that the identity evidence was captured in a way that can survive challenge by auditors or regulators. That is why clear timestamps, secure storage, and complete logs are not optional extras.

When biometrics are used, privacy and data minimisation become part of the control design. A bank should store only what it needs for the legal and operational purpose, protect recordings and images with strong access controls, and define retention periods that are consistent with local law and internal policy.

Risk and Threat Considerations

Video KYC fails when the bank confuses visibility with assurance. Fraudsters can exploit weak document checks, scripted answers, replayed video, virtual camera injection, and synthetic or deepfake facial material to pass a session that looks legitimate at a glance.

Failure mechanism: The bank accepts a remote session without strong liveness testing, operator discipline, or immutable evidence, so the attacker can present stolen or fabricated identity material as if it were a real customer.

Impact: The bank may onboard a fraudulent account, expose itself to money laundering or account takeover risk, and create an evidentiary gap that makes later investigation or remediation far harder.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and OWASP ASVS set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-8 — Identification and Authentication (Non-Organizational Users)Video KYC is remote customer identity proofing for external users.
IA-12 — Identity ProofingThe workflow depends on proving a remote customer's real-world identity.
AU-2 — Event LoggingRecorded sessions and audit trails are central to defensible video KYC.
Recommendation — Apply IA-8 to verify external-user identity before granting account access. Use IA-12 to structure evidence, checks, and assurance for remote onboarding. Log each onboarding step so the identity decision is reconstructable later.
OWASP ASVSV6 — AuthenticationRemote onboarding uses face match, liveness, and proofing-like checks.
V16 — Security Logging and Error HandlingVideo KYC needs durable logs and records for audit and dispute handling.
Recommendation — Verify that remote authentication steps resist replay, fraud, and impersonation. Retain session logs and evidence needed to review onboarding decisions.

Practitioner Guidance

What to prioritise: Build the process around the hardest-to-fake checks first, document authenticity, liveness, and traceable session evidence. Convenience should come after assurance, not before it.

What to verify: Confirm that the recording, audit log, operator identity, and approval trail are sufficient to reconstruct the session end to end. If a reviewer cannot tell what was checked, by whom, and in what order, the control is not ready.

Common mistake: Treating a successful video call as proof of identity. The practical standard is not whether the customer was visible, but whether the bank can defend the onboarding decision under challenge.

Practitioner takeaway: The right question is whether the remote session creates durable identity assurance, not whether it merely reduces branch dependency.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org