Organisations should build a risk-based onboarding process that verifies identity, screens customers, and records evidence in line with Nigerian AML expectations. For non-face-to-face relationships, controls should include reliable identity verification, document review, sanctions and PEP screening where required, and clear escalation for exceptions. The process should be documented, repeatable, and tied to ongoing monitoring so higher-risk customers receive stronger checks.
Why This Matters for Security Teams
Non-face-to-face onboarding creates a gap between the declared identity and the evidence used to trust it, which is why customer due diligence has to be designed as a control system, not a paperwork exercise. For organisations operating in Nigeria, the practical challenge is to verify the customer without degrading user experience, while still meeting AML, fraud prevention, and recordkeeping expectations. The strongest programmes treat identity proofing, sanctions screening, and exception handling as linked parts of one workflow, with clear ownership and audit evidence. Guidance from the FATF Recommendations — AML and KYC Framework is useful here because it reinforces the need for risk-based due diligence rather than a one-size-fits-all approach.
Security teams often underestimate how quickly weak onboarding becomes a fraud, compliance, and account recovery problem at the same time. If identity confidence is low at the point of entry, downstream monitoring has to work harder, and manual remediation costs rise sharply. In practice, many security teams encounter onboarding weaknesses only after synthetic identities, mule activity, or account takeovers have already exposed the control gap, rather than through intentional design.
How It Works in Practice
A robust process starts by defining customer risk tiers and mapping each tier to the evidence required for onboarding. For lower-risk customers, that may mean documentary verification, automated checks, and basic sanctions screening. For higher-risk or ambiguous cases, organisations should add step-up verification, manual review, source-of-funds checks where appropriate, and stronger approval thresholds. The goal is not to collect every possible attribute, but to collect enough reliable evidence to support a defensible decision.
Current guidance suggests that non-face-to-face due diligence should combine identity proofing, liveness or possession checks where technology is used, document authenticity review, and screening against sanctions and politically exposed person lists when the customer profile requires it. Control design should also preserve the evidence trail. That means logging what was checked, what matched, what failed, who overrode the decision, and why. Where identity data is processed at scale, organisations should also align access, retention, and evidence integrity controls with NIST SP 800-53 Rev 5 Security and Privacy Controls to reduce tampering and unauthorised disclosure risk.
- Define onboarding risk tiers before selecting verification methods.
- Use reliable identity evidence, not just typed-in data fields.
- Screen customers at onboarding and again when risk changes.
- Escalate exceptions to trained reviewers with documented criteria.
- Store evidence so the decision can be reconstructed later.
Organisations should also tie onboarding to ongoing monitoring, because a low-risk customer at entry can become higher risk through transactional behaviour or adverse intelligence. These controls tend to break down when identity proofing is outsourced without clear accountability, because the organisation cannot explain or defend the quality of the original verification decision.
Common Variations and Edge Cases
Tighter due diligence often increases abandonment, manual review load, and onboarding friction, so organisations have to balance fraud reduction against conversion and operational cost. That tradeoff is especially visible when customers lack stable formal documentation, when names appear differently across records, or when device and network signals are inconsistent. There is no universal standard for this yet; best practice is evolving toward risk-based combinations of documentary, biometric, device, and database checks rather than reliance on any single method.
Edge cases also matter. Corporate onboarding may require beneficial ownership checks and delegated authority validation, while diaspora or cross-border customers may require additional scrutiny around address evidence and source-of-funds. Where personal data is involved, privacy and retention design must be considered alongside AML obligations, not after the fact. If an organisation introduces biometrics or advanced digital identity tools, it should ensure the method is proportionate, legally supportable, and independently auditable. For operational control design, the core principle remains the same: prove who the customer is, prove why the decision was made, and retain enough evidence to support challenge later. In some environments, especially agent-assisted onboarding at scale, this guidance breaks down because automated exception handling is too coarse to separate genuine edge cases from fraud attempts.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63 and NIST CSF 2.0 set the technical controls, while PCI DSS v4.0 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | Digital identity guidance informs assurance, proofing, and binding in non-face-to-face onboarding. | |
| NIST CSF 2.0 | PR.AA | Identity and authentication governance supports controlled access to customer onboarding processes. |
| PCI DSS v4.0 | Financial services onboarding often intersects with regulated payment environments and identity controls. |
Implement identity and access controls so onboarding decisions and evidence are protected end to end.
Related resources from NHI Mgmt Group
- How should organisations decide when a customer needs enhanced due diligence?
- What do organisations get wrong about customer due diligence?
- How should security teams implement customer due diligence without creating too much onboarding friction?
- How should organisations govern API partner onboarding as a non-human identity process?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org