Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM How should charities verify volunteers for safeguarding without…
Identity Beyond IAM

How should charities verify volunteers for safeguarding without creating too much friction in recruitment?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 28, 2026 Domain: Identity Beyond IAM

Charities should use a risk-based identity verification flow that proves who a volunteer is before access is granted, while keeping onboarding simple enough to avoid drop-off. The goal is to reduce safeguarding risk for vulnerable beneficiaries, support volunteer confidence, and make the process reusable across multiple opportunities. Verification should be fast, private, and tied to role access, not treated as a one-time checkbox.

Why This Matters for Security Teams

Volunteer onboarding sits at the point where safeguarding, privacy, and recruitment collide. Charities need enough assurance to confirm a person is who they claim to be, especially when they may work with children or vulnerable adults, but a heavy process can slow recruitment and deter good volunteers. The practical goal is not maximum friction, it is proportionate assurance tied to the level of access required.

Current guidance suggests treating verification as a risk decision, not a formality. That means separating low-risk activities from roles that involve direct contact, sensitive records, lone working, or transport. A lighter flow may be fine for public-facing fundraising, while higher-trust roles need stronger checks, tighter review, and better auditability. This is consistent with NIST SP 800-207 Zero Trust Architecture, which prioritises continuous verification rather than one-time trust.

NHI Management Group’s research also shows how often weak identity handling becomes an incident multiplier: Ultimate Guide to Non-Human Identities notes that 97% of NHIs carry excessive privileges and 80% of identity breaches involved compromised non-human identities. The same pattern applies here: when access is granted too broadly, the process may feel efficient until something goes wrong. In practice, many charities discover verification gaps only after a safeguarding concern or access misuse has already exposed the weakness.

How It Works in Practice

The most effective model is a tiered verification flow. Start with a simple identity proofing step that confirms the volunteer is a real, reachable person, then add checks only when the role requires them. That keeps the front door easy to enter while preventing unnecessary friction for low-risk roles. For higher-risk placements, charities should tie verification to the exact duties being assigned, not to a blanket organisation-wide trust decision.

Practically, this means using a small set of controls that can be reused across placements: document verification, contact confirmation, reference review, DBS or equivalent screening where legally and operationally appropriate, and manager approval for elevated access. The key is that identity proofing should feed access decisions. If a volunteer only needs event support, they should not inherit access to case notes, safeguarding logs, or internal systems. If they later move into a role with vulnerable beneficiaries, verification can be stepped up at that point.

  • Use one intake flow, then branch by risk level and role sensitivity.
  • Capture only the data needed for safeguarding and compliance, then minimise retention.
  • Make verification status portable across multiple volunteer opportunities where policy allows.
  • Use time-limited approval for systems access, especially for seasonal or short-term roles.
  • Record who approved access and why, so safeguarding teams can review decisions later.

This approach aligns with identity-first trust models and with the broader NHI lesson that standing access is dangerous when the actor’s behaviour can change over time. The same lesson appears in NHIMG’s McDonald's McHire AI Chatbot Default Credentials research: weak or default access is often the fastest route to unnecessary exposure. These controls tend to break down when charities run one manual process for every role because high-risk checks become too slow and low-risk checks become too shallow.

Common Variations and Edge Cases

Tighter verification often increases recruitment time and administration, so organisations have to balance safeguarding assurance against volunteer drop-off and staff workload. There is no universal standard for this yet, especially across jurisdictions with different disclosure regimes and privacy rules. The best practice is evolving toward proportionate, role-based checks rather than a single mandatory funnel for everyone.

Edge cases matter. A returning volunteer may already be known to the charity, but that does not automatically mean their access should continue unchanged. A trusted person moving from reception support to youth mentoring needs a fresh risk review. Short-term event volunteers may only need light proofing, while remote or system-admin volunteers may need stronger identity assurance and tighter privilege boundaries.

Charities should also avoid storing more verification data than necessary. Identity evidence, references, and screening outcomes should be protected like sensitive records, with access limited to those who need it for safeguarding or compliance. Where decisions are borderline, it is better to delay a specific placement than to dilute the standard for everyone. The right balance is not perfection, it is enough assurance to protect beneficiaries without turning recruitment into a barrier.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01Identity proofing and access scoping mirror NHI onboarding risk.
NIST CSF 2.0PR.AC-1Access is granted based on verified identity and role need.
NIST Zero Trust (SP 800-207)3.1Zero Trust supports continuous, risk-based verification instead of blanket trust.
NIST AI RMFGovernance and accountability help formalise risk-based volunteer checks.
CSA MAESTROGOV-02Risk-based controls and auditability align with governed access workflows.

Use policy-driven approval gates so higher-risk volunteer roles trigger stronger checks.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org