Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM How should compliance teams approach customer identification and…
Identity Beyond IAM

How should compliance teams approach customer identification and due diligence for non-face-to-face business relationships in Latvia?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 24, 2026 Domain: Identity Beyond IAM

Compliance teams should map the Latvian rules to a risk based onboarding process that verifies identity, documents source data, and applies enhanced due diligence where the customer profile or delivery channel creates higher risk. Controls should be recorded, repeatable, and aligned to local legal requirements so that evidence can support audits, investigations, and remediation if questions arise.

Why This Matters for Security Teams

Non-face-to-face onboarding shifts customer identification and due diligence away from the certainty of in-person checks and into evidence handling, channel assurance, and fraud resistance. For Latvia-based relationships, compliance teams need to show that remote verification is not just convenient, but defensible under a risk based framework that can withstand audit, regulatory review, and dispute. The practical question is not whether digital onboarding is allowed, but whether the organisation can prove who was identified, what checks were performed, and why the level of scrutiny matched the risk.

This is where teams often fail: they treat remote onboarding as a product flow rather than a controlled compliance process. Identity proofing, document validation, sanctions screening, beneficial ownership checks, and source of funds or source of wealth review need clear triggers and repeatable evidence. That evidence should be retained in a form that supports investigations and remediation, while also aligning with broader control expectations described in FATF Recommendations — AML and KYC Framework. In practice, many compliance teams encounter weaknesses only after an onboarding exception, suspicious activity review, or regulator request has already exposed gaps in the trail.

How It Works in Practice

A sound approach starts by defining the minimum evidence required to establish identity remotely, then layering additional checks when risk indicators appear. For non-face-to-face relationships, that usually means combining document verification, database corroboration, liveness or biometric assurance where permitted, device or channel risk signals, and screening against sanctions and adverse information. The control objective is not simply to collect more data, but to reduce uncertainty and create a reliable record of how confidence in identity was reached.

Compliance teams should translate the legal obligation into operational checkpoints:

  • Classify the onboarding channel and record why it is considered non-face-to-face.
  • Set standard identity verification steps for natural persons and legal entities, including beneficial ownership where relevant.
  • Apply enhanced due diligence when geography, product, transaction type, or customer profile increases risk.
  • Preserve evidence of decisions, overrides, and exceptions so the file can be reconstructed later.
  • Link onboarding controls to monitoring, since customer risk can change after the relationship begins.

From a control design perspective, this maps cleanly to the discipline described in NIST SP 800-53 Rev 5 Security and Privacy Controls, especially where recordkeeping, access restriction, and auditability matter. Mature programmes also align the onboarding workflow to ISO/IEC 27001:2022 Information Security Management and ISO/IEC 27002:2022 Information Security Controls so that identity evidence, screening outputs, and approval logs are protected against tampering and unauthorized access. These controls tend to break down when onboarding is fully outsourced, document quality is poor, and review teams rely on manual judgment without a standardised decision model.

Common Variations and Edge Cases

Tighter identity controls often increase friction, manual review time, and abandonment rates, so organisations have to balance compliance certainty against customer experience and operational throughput. That tradeoff is real, especially in cross-border digital onboarding where documents, languages, and local data sources vary.

Current guidance suggests that best practice is evolving toward risk tiering rather than one fixed verification script for every customer. For lower-risk cases, a streamlined path may be acceptable if the evidence is strong and the channel is trusted. For higher-risk cases, there is no universal standard for how many checks are enough, so firms should define escalation triggers, approval authority, and refresh intervals in policy. This is especially important where corporate structures are complex, source of wealth is hard to validate, or a customer is opened through an intermediary. In those situations, teams should also confirm whether identity governance intersects with broader onboarding controls, including fraud screening and account privilege limits. The NIST Cybersecurity Framework 2.0 is useful here because it reinforces governance, protection, detection, and recovery as linked outcomes rather than isolated checks.

For Latvian compliance teams, the operational priority is consistency: the same risk should lead to the same evidence, the same review depth, and the same retention standard. Where that consistency is missing, audit findings usually focus less on the identity method itself and more on the absence of documented rationale, exception handling, and supervisory oversight.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the technical controls, while DORA and PCI DSS v4.0 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OV-01Governance oversight supports defensible customer due diligence decisions and exceptions.
NIST SP 800-63Digital identity guidance helps calibrate remote identity proofing assurance.
NIST AI RMFRisk management principles apply to automated onboarding decisions and evidence quality.
DORAOperational resilience matters when onboarding depends on external identity and screening services.
PCI DSS v4.0Payment-related onboarding often requires stronger identity and fraud controls.

Match identity proofing strength to customer risk and preserve evidence of assurance levels.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org