Organisations should apply a risk-based customer due diligence process that verifies identity, checks supporting documents, and confirms beneficial ownership where relevant. For non-face-to-face onboarding, they should use stronger evidence, tighter controls, and documented escalation paths for higher-risk cases. The goal is to satisfy Colombian compliance expectations while reducing fraud and false acceptance without slowing legitimate customers unnecessarily.
Why This Matters for Security Teams
Non-face-to-face relationships create a different fraud profile from in-person onboarding because the organisation cannot rely on a live visual encounter or a single channel of evidence. For Colombia, that means customer due diligence has to compensate with stronger identity verification, clearer documentary checks, and a defensible risk decision. The practical challenge is not just meeting AML expectations, but proving that the process can distinguish legitimate customers from synthetic identities, mule accounts, and account takeover attempts.
Current guidance in the FATF Recommendations — AML and KYC Framework supports a risk-based approach, which is especially important when the customer is never seen in person. That means lower-risk cases can move through streamlined checks, while higher-risk cases require enhanced due diligence, stronger corroboration, and escalation. The control objective is consistency: the organisation should be able to explain why it accepted a customer, what evidence it used, and what triggered any extra review.
In practice, many security and compliance teams encounter weak customer due diligence only after fraud losses, regulatory findings, or disputed account openings have already occurred, rather than through intentional control testing.
How It Works in Practice
Effective non-face-to-face due diligence combines identity proofing, document validation, sanctions and watchlist screening, and risk scoring into one decision workflow. The organisation should collect enough evidence to confirm that the applicant is real, reachable, and entitled to open the relationship. That usually includes government-issued identity data, contact verification, device or channel signals, and, where relevant, proof of address or business registration. For legal entities, beneficial ownership checks matter because the apparent applicant may not be the real controller.
A sound process usually includes:
- Identity verification against authoritative or trusted sources where available.
- Document authenticity checks for tampering, mismatch, or reuse.
- Cross-checks for sanctions, PEP, and adverse media where required by risk.
- Step-up verification when the channel, geography, or behaviour is higher risk.
- Audit logging so reviewers can reconstruct the decision path later.
Organisations should also separate identity proofing from ongoing monitoring. A customer can pass onboarding and still become risky later through account takeover, proxy use, or unusual transactional behaviour. This is where security controls overlap with fraud operations and, in some environments, with NHI governance when automation uses the same onboarding pipelines or APIs to create customer records at scale. A control baseline such as NIST SP 800-53 Rev 5 Security and Privacy Controls is useful for mapping authentication, access, logging, and integrity requirements to operational checks.
Best practice is to define explicit escalation thresholds for failed verification, mismatched data, unverifiable documents, or inconsistent geolocation and device signals. These controls tend to break down when onboarding is fully outsourced without clear evidence retention, because the receiving organisation cannot demonstrate how the due diligence decision was actually made.
Common Variations and Edge Cases
Tighter due diligence often increases abandonment and manual review workload, requiring organisations to balance fraud reduction against customer friction and conversion targets. That tradeoff is especially visible in remote onboarding, where the strongest controls can create false rejects for legitimate customers with thin files, expatriates, or people using shared devices.
There is no universal standard for every non-face-to-face scenario, so the risk model should reflect the product, customer segment, delivery channel, and jurisdictional exposure. For retail accounts, a lighter first-pass check may be acceptable if it is paired with transaction monitoring and step-up review triggers. For higher-risk products, business relationships, or politically exposed persons, current guidance suggests stronger evidence, more independent corroboration, and a clearer approval trail.
Edge cases often include cross-border applicants, digitised copies of identity documents, remote corporate onboarding, and situations where the person opening the account is not the same as the beneficial owner. In those cases, organisations should require additional corroboration and avoid treating a single data source as authoritative. The FATF Recommendations — AML and KYC Framework remains the best anchor for the risk-based principle, but local implementation must still be tailored to Colombia’s supervisory expectations and the organisation’s own fraud appetite.
Where automation is used, the main failure mode is overconfidence in score-based approvals without enough human review for exceptions, especially when identity data quality is uneven or customer records are reused across multiple onboarding attempts.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-63 set the technical controls, while PCI DSS v4.0 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-01 | Identity verification and access decisions need governance and traceability. |
| NIST SP 800-63 | IAL2 | Non-face-to-face onboarding depends on identity proofing assurance. |
| PCI DSS v4.0 | 8.2.4 | Remote identity and access assurance maps well to stronger verification controls. |
Use stronger identity proofing evidence for remote applicants and increase assurance for higher risk.
Related resources from NHI Mgmt Group
- How should organisations decide when a customer needs enhanced due diligence?
- What do organisations get wrong about customer due diligence?
- Who is accountable when wallet-based customer due diligence fails?
- What is the difference between customer due diligence and strong customer authentication here?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org