Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM How should organisations handle customer identification and due…
Identity Beyond IAM

How should organisations handle customer identification and due diligence for non-face-to-face business relationships in Thailand?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 24, 2026 Domain: Identity Beyond IAM

Organisations should build a risk-based onboarding flow that verifies identity, assesses customer risk, and records due diligence evidence in a way that matches Thailand’s legal requirements. For remote relationships, controls should cover document review, authenticity checks, sanctions screening where relevant, and auditability. The goal is to balance access with defensible compliance, not to treat every customer path the same.

Why This Matters for Security Teams

Non-face-to-face onboarding creates a higher-risk trust decision because the organisation is asked to accept an identity claim without in-person confirmation. For Thailand-facing customer journeys, that makes customer identification, due diligence, and evidence retention part of the control design rather than a back-office compliance task. The practical challenge is not only confirming who the customer is, but also proving that the checks were applied consistently and proportionately.

Current guidance suggests a risk-based approach that distinguishes between low-risk and higher-risk relationships, especially where the customer is remote, the product can be opened quickly, or the account can be used for movement of funds. That means stronger checks for identity document integrity, liveness or equivalence controls where appropriate, and escalation when signals conflict. The policy intent is familiar across AML and fraud programs, but the operational reality is often fragmented across onboarding, sanctions screening, case management, and records retention. For control design, NIST SP 800-53 Rev 5 Security and Privacy Controls is useful as a control mapping reference for access, audit, and evidence handling.

In practice, many security and compliance teams encounter weak customer due diligence only after an account has already been opened and used to move risk through the business.

How It Works in Practice

A defensible non-face-to-face process starts with a clearly defined customer risk model. That model should determine what evidence is required, when enhanced due diligence is triggered, and which cases need manual review. The onboarding flow should not rely on a single document check. It should combine identity proofing, document authenticity review, sanctions or watchlist screening where relevant, and risk scoring that can be explained later to auditors or regulators.

Operationally, the best design separates collection, validation, decisioning, and retention. Collection gathers the customer’s identity data and supporting evidence. Validation checks whether the identity evidence is credible and consistent. Decisioning applies rules for acceptance, rejection, or escalation. Retention stores the evidence, timestamps, reviewer actions, and policy version used at the time. This separation matters because investigations often focus on whether the organisation followed its own process, not only whether the final decision was correct.

  • Use step-up checks when data quality is poor, the customer is higher risk, or the channel is unusually exposed to fraud.
  • Record why a case was approved, rejected, or escalated, including the rule or reviewer rationale.
  • Keep evidence linked to the specific relationship lifecycle event, not just the original application.
  • Review access to onboarding records so only authorised staff can alter or approve due diligence outcomes.

For identity proofing and evidence strength, it is useful to align the remote verification journey with NIST SP 800-63 Digital Identity Guidelines, while treating local legal obligations as the governing requirement. Organisations should also ensure their screening and case workflows can be audited end to end, because a strong decision without a traceable record is still a control failure. These controls tend to break down when onboarding is outsourced, because evidence quality, reviewer discipline, and retention practices become inconsistent across service providers.

Common Variations and Edge Cases

Tighter customer due diligence often increases onboarding friction and operational cost, requiring organisations to balance conversion speed against defensible risk treatment. That tradeoff becomes sharper in digital-first products, where customers expect immediate activation and business teams push for fewer drop-offs.

There is no universal standard for every remote onboarding scenario, so the right control depth depends on the customer type, product risk, delivery channel, and jurisdictional obligations. For lower-risk relationships, current guidance suggests streamlined checks may be acceptable if the organisation can still show accountability, record integrity, and trigger-based escalation. For higher-risk cases, enhanced due diligence should be explicit rather than improvised, especially when the customer is a legal entity, a politically exposed person, or a relationship with cross-border exposure.

Another edge case is when identity verification is partially automated. Automation can improve consistency, but it can also hide weak assumptions if teams do not review false acceptances, false rejections, and override rates. In privacy-sensitive journeys, customer data minimisation must be balanced against the need to retain enough evidence for audit and dispute resolution. Where payment or card-related onboarding is involved, PCI DSS v4.0 becomes relevant for handling account data and protecting supporting records.

For organisations operating across multiple countries, the biggest risk is assuming that one global onboarding rule set will satisfy every regulator. Local legal thresholds, document expectations, and retention duties can diverge, so the control framework should allow country-specific treatment without losing governance.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-63 set the technical controls, while PCI DSS v4.0, DORA and NIS2 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-01Identity proofing and access approval depend on accountable authentication and authorisation.
NIST SP 800-63IAL2Remote onboarding needs identity proofing assurance proportionate to the relationship risk.
PCI DSS v4.03.2.1Where payment data is involved, supporting records and sensitive data handling need protection.
DORAArticle 15Digital onboarding resilience matters when identity and due diligence workflows are service-dependent.
NIS2Article 21Risk management and incident handling support trustworthy digital onboarding operations.

Test onboarding continuity so identity and due diligence checks survive outages and supplier issues.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org