Teams should verify both the person and the business before handoff. That means checking the driver’s identity document, face match, and liveness, then confirming the licence, carrier authority, and the shipment assignment against trusted records. At pickup, the driver, vehicle, carrier, location, and time should all match the approved record before custody changes.
Why pickup verification has to bind the person, the vehicle, and the authority together
Shipment release is not just an identity check on a driver. It is a custody-control decision, so the person presenting, the carrier they represent, and the load they are collecting all need to line up before the handoff. If any one of those checks is weak, a legitimate-looking pickup can still become an unauthorized release.
Practically, that means teams should treat the driver document, face match, licence status, carrier authority, load reference, and pickup window as one verification chain. The goal is to confirm that the person is allowed to act for the business, and that the business is the one trusted for that lane, shipment, and time.
A useful way to think about this is that the verification is strongest when it is anchored in trusted records, not in a single document shown at the dock. Shipment assignment should resolve to one approved carrier record, one known collection event, and one eligible driver, so the final custody transfer is based on consistent evidence rather than convenience.
What teams should verify before custody changes
Teams usually need to validate four things in sequence. First, confirm the driver is the same person expected for pickup. Second, confirm the vehicle aligns with the approved collection record when vehicle identity is part of the operating model. Third, confirm the carrier is authorised for the shipment or route. Fourth, confirm the location and time still match the authorised pickup event.
That sequence matters because each check narrows a different fraud path. A face match without carrier authority can still allow an impostor from a real company. A valid carrier record without the assigned shipment can still send the wrong trailer or the wrong person. A correct load number without a timing and location match can still support a diverted or spoofed collection.
Where face match and liveness are used, they should support the human verification step rather than replace it. The practical objective is to reduce impersonation risk, not to turn the dock process into a biometric-only control. In higher-risk lanes, teams should also verify that the pickup details come from a trusted dispatch or transport-management source, not from an inbound message that could have been spoofed.
Risk and Threat Considerations
Pickup fraud tends to succeed when teams verify one element, then assume the rest follows. Common failure modes include fake driver credentials, spoofed carrier communications, substituted vehicles, and pickup instructions that are changed after the shipment is already staged. The security problem is custody transfer under false authority.
Failure mechanism: An attacker, or an insider with access to shipping details, presents enough correct information to pass a partial check, then exploits a missing cross-check between identity, carrier authority, and shipment assignment to obtain release.
Impact: The shipment can be diverted, stolen, or handled outside the intended chain of custody, creating loss, service disruption, and potential exposure of controlled goods or customer property. At scale, repeated weak verification also erodes auditability because the release record no longer proves who actually took possession.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207), CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA — Identity Management, Authentication and Access Control | Pickup release depends on verifying who is authorised to access the shipment. |
| Recommendation — Enforce identity and access checks before releasing custody to a carrier representative. | ||
| NIST Zero Trust (SP 800-207) | JEA — Least Privilege and Explicit Access | Shipment handoff should grant release only to the explicitly approved actor and event. |
| Recommendation — Require explicit, verified authorization for each shipment handoff decision. | ||
| CIS Controls v8 | 6 — Access Control Management | The process is an access decision over physical custody and should be tightly controlled. |
| Recommendation — Restrict release authority to approved roles, records, and collection events. | ||
| MITRE ATT&CK | T1036 — Masquerading | Fake driver or carrier presentation is a masquerading pattern used in pickup fraud. |
| T1656 — Impersonation | Driver impersonation is a direct threat to shipment release verification. | |
| Recommendation — Hunt for pickup attempts that imitate approved carriers or drivers. Treat identity mismatch at pickup as potential impersonation and block release. | ||
| OWASP Non-Human Identity Top 10 | NHI-08 — Identity Lifecycle and Revocation | Verified carrier authority and shipment assignment rely on current, valid non-human access records. |
| NHI-05 — Overprivileged Non-Human Identities | Carrier and dispatch workflows should not carry broader release authority than needed. | |
| Recommendation — Revoke stale carrier access and keep shipment-authority records current. Limit shipment-release authority to the minimum records and roles required. | ||
Practitioner Guidance
What to verify: Use one release rule for the dock team: no custody change until the driver identity, carrier authority, shipment reference, vehicle, and pickup window all match the approved record. If any one element is missing or inconsistent, hold the shipment and escalate to the transport owner before release.
Common mistake: Do not let “known carrier” become a substitute for event-level verification. Even trusted carriers can send the wrong driver, the wrong vehicle, or a driver acting on outdated instructions, so the release decision should be tied to the specific pickup event, not just the vendor relationship.
Practitioner takeaway: The strongest control is not a single strong check, it is a matched set of checks that all point to the same authorised pickup event, because custody transfer only becomes safe when the person, the business, and the shipment all agree.
Related resources from NHI Mgmt Group
- How should security teams use a software supply chain framework to verify release risk before deployment?
- How should defence and security teams verify hardware supply chain risk before deploying connected systems?
- How do teams contain a supply chain compromise before it spreads?
- How should security teams use OSINT to catch software supply chain threats before release?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 20, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org