Join our Newsletter — 33% off our NHI Course
Home› FAQ› Authentication, Authorisation & Trust› How should organisations design identity verification processes against…
Authentication, Authorisation & Trust

How should organisations design identity verification processes against GPG 45 without creating unnecessary user friction?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 30, 2026 Domain: Authentication, Authorisation & Trust

Organisations should treat GPG 45 as a control framework, not just a checklist. Build verification journeys that collect enough evidence to reach the required confidence level, but avoid forcing every applicant through the same path. Use risk-based routing, allow multiple evidence combinations, and keep the process proportionate to the trust decision being made.

How to design identity verification journeys around GPG 45

GPG 45 works best when organisations treat it as an assurance model, not a rigid script. The design question is how to reach the required confidence in the applicant’s identity with the least unnecessary burden. That means allowing different evidence paths, using risk signals to route cases, and reserving the most intrusive checks for the cases that actually need them.

The practical aim is proportionality. A low-risk customer or transaction should not experience the same journey as a higher-risk case, but both paths still need to produce evidence that supports the trust decision. That is why identity verification design is as much about control design and decisioning as it is about document capture.

Good journeys are built around evidence combination, not single-point dependence. Organisations should design for multiple acceptable routes, such as document checks, liveness checks, address evidence, device or fraud signals, and, where relevant, corroborating records. The objective is to reduce false rejects and avoid forcing users into a dead end when one evidence type is unavailable or weak.

That approach aligns with the way assurance standards are normally implemented in practice. Identity Proofing and KYC Guide is useful here because it frames identity proofing as a confidence-building process, including document checks, liveness and remote proofing choices. For organisations comparing vendor or control options, the Identity Verification Buyer's Guide helps translate that design problem into practical evaluation criteria.

How to reduce friction without weakening assurance

Reducing friction does not mean reducing assurance. The best designs remove avoidable repetition, collect only evidence that changes the decision, and avoid asking users to prove the same fact more than once. They also make the process legible, so users understand why a higher-friction step appears in a particular case.

A useful design pattern is progressive evidence collection. Start with the lowest-friction path that can satisfy the required confidence level, then step up only when the initial evidence is incomplete, inconsistent, or riskier than expected. This keeps the common case fast while still protecting the edge cases that drive fraud and account-opening abuse.

In practice, the biggest friction reductions often come from better orchestration rather than lighter control. Reusing validated data, avoiding duplicate uploads, reducing failed retries, and presenting clear fallback options will usually improve completion rates more than simply shortening the form. Organisations should also test whether the process is failing because of policy, product design, or vendor performance before changing the assurance threshold itself.

For standards-based implementation, NIST SP 800-63 Digital Identity Guidelines provides a strong reference point for assurance levels and identity proofing decisions, while eIDAS 2.0, the EU Digital Identity Framework is relevant where cross-border digital identity and wallet-based verification affect the journey design.

Which controls matter most when identity proofing must stay proportionate?

The most effective identity verification programmes balance three controls: evidence sufficiency, step-up logic, and outcome quality. Evidence sufficiency ensures the organisation gathers enough proof for the trust decision. Step-up logic ensures extra friction appears only when the risk warrants it. Outcome quality ensures the process does not simply become easier to complete, but still resists impersonation, synthetic identity, and other onboarding fraud.

That balance is easiest to lose when teams optimise only for conversion rate or only for fraud prevention. A design that is too permissive can create downstream account compromise and regulatory exposure. A design that is too strict can push legitimate users out of the funnel, increase abandonment, and encourage manual workarounds. Both are control failures, just in different directions.

Where identity verification is tied to AML, customer due diligence, or regulated onboarding, the control boundary is broader than UX alone. FATF Recommendations matter because they anchor customer due diligence and beneficial ownership expectations, while EU General Data Protection Regulation matters where identity evidence includes personal data or biometrics that must be handled proportionately.

Risk and Threat Considerations

When identity verification is over-engineered, the main risk is not just user drop-off. It is that users and staff start finding shortcuts, while attackers exploit predictable exceptions, weak fallback paths, or manual review overload. When it is under-engineered, the risk shifts to impersonation, synthetic identity, and account opening abuse.

Failure mechanism: A rigid journey forces all applicants through the same evidence path, which increases abandonment for legitimate users and can create unsafe workarounds, while a weak journey accepts insufficient evidence and allows fraud to pass as identity.

Impact: Organisations can see higher onboarding loss, more manual review, more fraud losses, and weaker auditability of why a trust decision was made.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63 sets the technical controls, while GDPR and EU AI Act define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63Digital Identity GuidelinesIdentity proofing assurance levels directly shape proportional verification journeys.
Recommendation — Use assurance-level guidance to right-size evidence and step-up checks for each risk tier.
GDPRGeneral Data Protection RegulationIdentity verification often processes personal and biometric data under GDPR.
Recommendation — Minimise evidence collection and document lawful, proportionate processing for identity checks.
EU AI ActEU AI ActAutomated identity verification and decisioning can fall within AI governance and high-risk controls.
Recommendation — Assess automated verification for transparency, oversight, and risk controls before deployment.

Practitioner Guidance

What to prioritise: Design the journey around the trust decision, not around a preferred vendor flow. Decide which evidence combinations are acceptable for each risk tier before you design the UI, otherwise the process will drift into a one-size-fits-all path.

What to verify: Verify that the fallback route is genuinely equivalent in assurance, not merely more convenient. If a user can bypass stronger checks through an exception path, the process is not proportionate, it is inconsistent.

What good looks like: Low-risk users complete quickly with minimal rework, higher-risk cases receive step-up checks automatically, and reviewers can explain why a given identity was accepted or rejected from the evidence record alone.

Practitioner takeaway: The right balance is achieved when friction is removed from the process, not from the assurance decision, so users experience fewer unnecessary steps while the organisation still knows exactly why it trusted them.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 30, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org