Join our Newsletter — 33% off our NHI Course
Home› FAQ› Authentication, Authorisation & Trust› How should organisations verify staff, suppliers, and service…
Authentication, Authorisation & Trust

How should organisations verify staff, suppliers, and service users when physical contact needs to be reduced?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 29, 2026 Domain: Authentication, Authorisation & Trust

Organisations should use contactless identity verification that allows people to prove who they are without exchanging paper documents or handling cards. The core control is to collect only the minimum data needed, validate it through a trusted system, and preserve an audit trail. That approach reduces contamination risk, supports scaling under pressure, and keeps identity checks consistent across remote and in-person workflows.

What contactless verification changes for staff, suppliers, and service users

When physical contact needs to be reduced, the main change is not the identity standard, it is the channel used to prove it. Organisations should move from hand-to-hand document checks and card handling to remote or touch-minimised verification that still confirms identity against a trusted source. That keeps the check defensible while reducing friction, contamination risk, and queue pressure.

The practical question is whether the verification method can still establish enough assurance for the use case. For lower-risk interactions, a lightweight check may be enough; for onboarding, access issuance, or regulated services, the process needs stronger validation, better auditability, and a clearer link between the person presenting and the record being accepted.

Good contactless verification also needs consistent handling across channels. If the same staff member, supplier, or service user can be checked one way in person and another way remotely, organisations should make sure the assurance level, evidence captured, and exception handling are equivalent enough for the decision being made.

How to preserve assurance without exchanging paper or cards

The core control is to collect only the minimum data needed, validate it through a trusted system, and preserve an audit trail. That can mean using remote identity proofing, live video-assisted checks, secure portals, signed digital records, or credential-based confirmation, depending on the population and the service being delivered.

For staff and suppliers, the verification method should connect to the organisation’s own approved records so that status changes, expiry, and authorisation can be checked centrally rather than relying on a one-time visual inspection. For service users, the control should be proportionate to the transaction, with stronger evidence required when the outcome affects access, payments, records, or regulated entitlement.

In practice, the strongest designs reduce manual handling without losing traceability. A contactless process should still tell you who was checked, when the check happened, what evidence was used, and who approved any exception. Without that, the workflow may be convenient but it is not operationally reliable.

Where the process fails if it is designed too loosely

Contactless verification becomes weak when teams treat convenience as proof. If identity is accepted from screenshots, forwarded documents, or informal confirmation, the process can be fooled by recycled evidence, impersonation, or inconsistent reviewer judgement. The same problem appears when remote checks are allowed but no one defines what counts as a valid source of truth.

There is also a governance failure mode: organisations sometimes reduce contact but keep the same manual approval habits. That creates delays, inconsistent outcomes, and poor auditability, especially when staff or suppliers are verified at scale or during disrupted operations. For that reason, NIST SP 800-63 Digital Identity Guidelines is a useful reference for thinking about assurance, proofing, and authenticator strength when you replace a physical check with a digital one.

When the workflow depends on a web service or portal, the reliability of the verification path matters as much as the identity claim itself. A breakdown in the trust source, the intake form, or the approval queue can stop legitimate access just as effectively as a false acceptance can let the wrong person through.

Risk and Threat Considerations

Reduced-contact verification lowers contamination and handling risk, but it can increase identity fraud risk if teams over-trust remote evidence or allow inconsistent review practices. The biggest exposure is usually not the absence of face-to-face contact, it is the loss of strong, repeatable assurance about who was actually verified and on what basis. For a security-first operating model, NIST SP 800-207 Zero Trust Architecture reinforces the principle that trust should be verified at the point of access, not assumed from the channel.

Failure mechanism: weak evidence, poor source validation, or reviewer inconsistency lets an impersonator pass the check, or causes legitimate users to be rejected because the process has no stable assurance threshold.

Impact: organisations can issue access, approve services, or record status against the wrong person, which creates fraud, privacy, operational, and compliance exposure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63Digital Identity GuidelinesDefines assurance and proofing expectations for remote identity verification.
Recommendation — Align proofing and authenticator strength to the assurance needed for each verification decision.
NIST Zero Trust (SP 800-207)Zero Trust ArchitectureSupports verify-before-trust handling when access or entitlement depends on identity checks.
Recommendation — Verify identity at the point of decision and avoid assuming trust from the channel or location.
ISO/IEC 27001:2022A.5.15 — Access controlContactless verification supports controlled access decisions and consistent approval boundaries.
A.5.34 — Privacy and protection of PIIVerification should minimise data collection and limit unnecessary handling of personal data.
Recommendation — Define access decision criteria so remote verification produces consistent outcomes. Collect only the minimum identity data needed for the specific verification purpose.
NIST SP 800-53 Rev 5IA-8 — Identification and Authentication (Non-Organizational Users)Applies when verifying external users or service users through remote identity proofing.
IA-2 — Identification and Authentication (Organizational Users)Applies to staff verification and internal access decisions.
AU-2 — Event LoggingAudit trails are central to contactless verification traceability.
Recommendation — Use stronger proofing and authentication for external users when the outcome affects access or entitlement. Require consistent identity verification for staff before granting access or approving actions. Log who was verified, what evidence was used, and when the decision was made.

Practitioner Guidance

What to prioritise: decide the assurance level first, then choose the least-contact method that can still support the decision. Do not let the preferred channel, such as video, portal, or QR code, define the standard.

What to verify: confirm the trusted source of truth, the minimum evidence set, the exception path, and the audit record before you treat the process as operationally safe. If a reviewer cannot reconstruct why the identity was accepted, the control is too loose.

Common mistake: replacing face-to-face checks with a lighter process but keeping the same downstream authority. If the identity check now feeds access, payment, or entitlement decisions, the verification step must be strong enough for that consequence.

Practitioner takeaway: the goal is not contact avoidance at any cost, it is to reduce physical handling while preserving a verification standard that remains trustworthy, auditable, and proportionate to the decision being made.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org