Organisations should combine identity verification, document checks, risk-based screening, and ongoing monitoring rather than relying on a single control. For remote onboarding, they need clear evidence that the customer is who they claim to be, that the relationship is permitted under local rules, and that exceptions are escalated. Good practice also includes audit trails and jurisdiction-specific policies.
Why This Matters for Security Teams
Non-face-to-face customer due diligence is a control point, not a single checkbox. In the United States, teams have to show they collected enough evidence to reasonably believe the customer is real, screened them against applicable risk indicators, and preserved a defensible audit trail. That becomes harder when onboarding is remote, documents are digital, and exceptions move quickly through operations. Guidance from FATF Recommendations — AML and KYC Framework is useful because it frames due diligence as risk-based and ongoing, not one-time verification.
This is also where identity and secrets governance intersect. The same discipline that NHI Management Group recommends for credential lifecycle control in Ultimate Guide to NHIs applies here: organisations need repeatable evidence, clear ownership, and revocation paths when risk changes. A weak onboarding flow often looks acceptable on paper until the first fraud event, sanctions hit, or account takeover forces a retrospective review. In practice, many security teams encounter control failures only after suspicious activity has already passed through remote onboarding.
How It Works in Practice
Effective non-face-to-face due diligence usually combines four layers: identity proofing, documentary validation, sanctions and adverse-media screening, and ongoing monitoring. The first layer is about establishing that the person or business exists and is plausibly tied to the account request. The second checks whether submitted documents are consistent, current, and not obviously altered. The third looks for risk indicators that make the relationship inappropriate or higher risk. The fourth makes due diligence continuous, because a customer can become risky after onboarding.
Organisations typically operationalise this with policy-driven workflows rather than ad hoc analyst judgment. A practical design includes:
- risk scoring that assigns enhanced due diligence to higher-risk geographies, industries, or ownership structures
- document validation controls that flag mismatched names, expired IDs, and forged patterns
- review queues for manual escalation when automation cannot reach a defensible conclusion
- case notes and evidence retention so auditors can trace each decision
That approach aligns with NIST SP 800-53 Rev 5 Security and Privacy Controls, especially the emphasis on access control, auditability, and continuous monitoring. It also reflects the operational reality highlighted in Ultimate Guide to NHIs: controls fail when there is no reliable inventory of what is being approved and who is responsible for it. These controls tend to break down when onboarding is fully automated without a manual escalation path for mismatched identities, beneficial ownership complexity, or jurisdiction-specific exceptions.
Common Variations and Edge Cases
Tighter due diligence often increases onboarding friction, requiring organisations to balance fraud prevention against customer abandonment and operational cost. That tradeoff is especially visible in small-business onboarding, cross-border relationships, and low-risk consumer accounts where too much review can create avoidable delays. Current guidance suggests a risk-based model, but there is no universal standard for exactly how much evidence is enough in every scenario.
One common edge case is beneficial ownership. For companies, the visible applicant may be legitimate while the control risk sits several layers deeper in the ownership chain. Another is alternative evidence when a customer lacks standard government-issued documentation, which may require enhanced review rather than automatic rejection. For higher-risk cases, organisations should also apply stronger monitoring after onboarding, not just at intake.
Another practical issue is jurisdictional overlap. A U.S.-based relationship can still implicate foreign screening obligations, correspondent banking rules, or internal policies that are stricter than local minimums. The best practice is to document the local rule set, the escalation threshold, and the exception approval chain so that analysts do not improvise under pressure. In the real world, remote onboarding problems usually surface when exceptions are handled inconsistently across products, channels, or business units.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-01 | Identity proofing and approval evidence support authenticated, accountable customer onboarding. |
| NIST SP 800-63 | IAL2 | Remote due diligence depends on how strongly an identity is proofed before account opening. |
| NIST AI RMF | Risk-based due diligence mirrors AI RMF governance, measurement, and monitoring expectations. |
Require documented identity checks and approval evidence before activating remote customer relationships.
Related resources from NHI Mgmt Group
- How should organisations handle customer identification and due diligence for non-face-to-face business relationships in Thailand?
- How should organisations structure customer identification and due diligence for non-face-to-face business relationships in Germany?
- How should organisations handle customer identification and due diligence for non-face-to-face business relationships in France?
- How should organisations approach customer identification and due diligence for non-face-to-face business relationships in Argentina?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org