Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should organisations implement digital identity checks for…
Governance, Ownership & Risk

How should organisations implement digital identity checks for KYC under the updated money laundering rules?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 29, 2026 Domain: Governance, Ownership & Risk

Organisations should treat digital identity checks as a controlled verification process, not a simple onboarding shortcut. The platform must be secure from fraud and misuse, combine biometric checks with liveness testing and anti spoofing controls, and provide an appropriate level of assurance. Human oversight still matters, especially where risk is higher or the identity evidence is incomplete.

What digital identity checks need to prove under modern KYC rules

digital identity checks are there to answer a specific compliance question: can the organisation reasonably trust that the person opening or using the account is who they claim to be? Under updated money laundering expectations, the control has to support customer due diligence, not merely speed up onboarding, so the standard is assurance, traceability, and consistency rather than convenience alone.

That is why digital checks should be designed as a verification workflow with explicit evidence, decisioning rules, and fallback paths. In practice, the check needs to combine document and identity evidence, resilience against fraud, and enough confidence for the risk level of the relationship. The FATF Recommendations remain the clearest baseline for customer due diligence expectations, while eIDAS 2.0 is relevant where organisations rely on recognised digital identity wallet or cross-border identity verification.

A well-designed check should also preserve a clear audit trail of what was verified, which signals were used, and why the outcome was accepted or rejected. That matters because KYC is not satisfied by a successful form submission; it is satisfied when the organisation can demonstrate the basis for reasonable reliance on the identity evidence.

Why biometrics, liveness, and anti-spoofing have to work together

Biometric matching alone is not enough for a remote check, because a strong face match can still be generated from a stolen photo, replayed video, deepfake, or virtual camera injection. The control has to test for presentation attack and spoofing conditions at the same time as it checks identity evidence, otherwise the platform may verify the image stream rather than the person.

The most useful mental model is layered assurance: document authenticity, liveness, biometric binding, and fraud resistance are different problems. Identity Proofing and KYC Guide is the most direct internal reference for these assurance layers, including document verification, liveness detection, and injection attack patterns. For teams designing the underlying authentication and assurance model, NIST SP 800-63 Digital Identity Guidelines is the strongest external anchor for assurance-level thinking.

The practical implication is that organisations should expect false accepts and false rejects, then tune the workflow around acceptable risk. High-assurance journeys usually need stronger anti-spoofing, better escalation rules, and a human review step when the evidence is incomplete or ambiguous.

Where human review still matters in a digital onboarding flow

Digital identity checks work best when they are not treated as fully autonomous decisions. Human oversight is still important for edge cases, including poor image quality, mismatched data, unusual jurisdictional documents, repeated retries, and cases where the risk profile is higher than the average retail onboarding flow.

The strongest operational pattern is to reserve manual review for exception handling, not routine bulk checking. Identity Proofing and KYC Guide helps frame those escalation points, while EBA AML/CFT Guidance is useful where firms need a European supervisory perspective on risk-sensitive customer due diligence. Organisations that operate in regulated US environments should also consider FinCEN guidance when aligning KYC practice to AML expectations.

Good practice is to define which signals automatically pass, which always fail, and which must be reviewed. That avoids over-reliance on vendor scores and keeps accountability with the organisation rather than the onboarding tool.

Risk and Threat Considerations

Digital identity checks become a fraud-control problem as soon as they are used at scale. If the platform can be fooled by synthetic identity, spoofed biometrics, or compromised capture channels, criminals gain a low-friction way to open accounts, pass CDD, and reuse the access path for laundering or downstream abuse.

Failure mechanism: Weak spoof detection, poor document validation, or over-trusting a single biometric signal lets an attacker submit a convincing but fake identity package, especially when onboarding is optimised for speed.

Impact: The organisation can onboard the wrong customer, miss beneficial ownership or source-of-funds concerns, and create a durable compliance and financial crime exposure that is harder to reverse after the account is active.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST SP 800-63 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-8 — Identification and Authentication (Non-Organizational Users)KYC digital identity checks verify external customers' identity before access.
IA-12 — Identity ProofingDigital identity checks depend on proofing evidence and assurance level selection.
Recommendation — Require strong identity proofing and authentication for external customers before account creation. Set proofing requirements that match the account risk and retain evidence for review.
NIST SP 800-63Digital Identity GuidelinesDefines assurance, proofing, and authentication concepts for digital identity verification.
Recommendation — Align proofing, authentication, and assurance decisions to the required identity assurance level.
NIST CSF 2.0PR.AA-05 — Identities and Credentials Are Managed, Verified, and RevokedKYC relies on managed verification of identity evidence and credential lifecycle controls.
Recommendation — Verify identity evidence and revoke or reject weak credentials and failed identities promptly.
ISO/IEC 27001:2022A.5.16 — Identity managementIdentity checks are part of managing and verifying identity records in an ISMS.
A.5.17 — Authentication informationDigital checks depend on secure handling of authentication material and evidence.
A.5.15 — Access controlThe outcome of KYC identity checks determines whether access is granted or restricted.
Recommendation — Define how identity records are created, verified, updated, and retained. Protect authentication information used in digital onboarding and verification workflows. Gate account access on verified identity and documented risk acceptance.

Practitioner Guidance

What to verify: Verify that the workflow can distinguish between identity match and identity assurance, and that fraud controls cover replay, injection, and presentation attacks, not just face recognition accuracy.

Decision rule: If the check cannot show how it resists spoofing and why the assurance level is acceptable for the customer risk, treat the result as insufficient and route to manual review or step-up verification.

What good looks like: The organisation can produce a clear record of the evidence used, the controls applied, the exceptions raised, and the rationale for acceptance or rejection, so the KYC decision is explainable after the fact.

Practitioner takeaway: The control objective is not to make onboarding frictionless, it is to make remote identity evidence trustworthy enough that compliance, fraud resistance, and human accountability all remain intact.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org