Join our Newsletter — 33% off our NHI Course
Home› FAQ› Authentication, Authorisation & Trust› What are the signs that human review in…
Authentication, Authorisation & Trust

What are the signs that human review in video KYC is too shallow?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 10, 2026 Domain: Authentication, Authorisation & Trust

Warning signs include approvals that cannot be tied to specific recorded evidence, reviewer decisions that are not logged, and exception handling that bypasses the normal verification path. If the file does not explain why the applicant passed, the control is not audit-ready.

How shallow review shows up in the record

human review becomes too shallow when the outcome is effectively detached from the evidence trail. If reviewers are approving files without a traceable basis, the review is no longer functioning as a verification control. That is especially true in KYC, where the review should explain not just the final decision, but why the identity evidence, document checks, and liveness results were accepted.

Another sign is that reviewers are reducing the work to a quick visual check of the submitted images. A shallow review usually misses whether the document is authentic, whether the selfie is linked to a live person, and whether the file contains enough evidence to support the decision later.

A useful test is whether the reviewer can reconstruct the reasoning from the case file alone. If the file does not show what was checked, what failed, and what justified the override, the process is leaning toward approval by habit rather than review by evidence. For broader identity proofing expectations, see the Identity Proofing and KYC Guide.

Where shallow review usually breaks the control

The control most often weakens at the exception layer. When unusual cases bypass the normal verification path, reviewers may treat the override as a routine queue decision instead of a higher-risk judgment that needs separate justification.

Shallow review also shows up when logging is too sparse to distinguish reviewer discretion from automation. If the team cannot tell who made the decision, what evidence they saw, and why they approved or rejected the file, the control is not strong enough for audit or dispute handling.

This matters because KYC is not just about passing an onboarding task. It is about making a defensible decision that can survive internal challenge, external audit, and post-incident review. FATF’s customer due diligence expectations are a useful reference point for that standard, and the FATF Recommendations remain the core AML/KYC baseline. In regulated operations, the review should also align with jurisdictional expectations such as FinCEN guidance and the EBA AML/CFT Guidance.

What strong review looks like instead

Good human review is not exhaustive manual inspection. It is targeted verification that resolves uncertainty, documents the basis for the decision, and escalates cases that do not fit the normal path. The reviewer should be able to show which evidence was checked, which anomalies were resolved, and which ones were accepted as exceptions.

The practical difference is traceability. Strong review leaves a file that another trained reviewer can understand without guessing. Weak review leaves only an outcome, with no defensible rationale attached to it.

At scale, teams should look for consistency between case complexity and review depth. Straight-through or low-risk cases may justify a lighter touch, but anything with document anomalies, image quality problems, or exception handling should produce more evidence, not less. Where identity assurance is central, the control should also reflect the expectations in the broader digital identity ecosystem, including eIDAS 2.0 - EU Digital Identity Framework.

Risk and Threat Considerations

Shallow review creates a false sense of assurance. It can let synthetic identities, document fraud, or replayed selfie evidence pass because the reviewer is checking for completeness rather than authenticity and linkage between the person, the document, and the recorded evidence.

Failure mechanism: The review process stops at surface-level confirmation and fails to test whether the evidence actually supports the identity decision. Exceptions then slip through with minimal scrutiny, and the file no longer proves why the applicant was accepted.

Impact: The organisation inherits weak onboarding decisions, poor auditability, and higher exposure to fraud, account abuse, and regulatory challenge. When a case cannot be reconstructed, the control is effectively non-defensible even if the application was formally approved.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 and GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AU-3 — Content of Audit RecordsShallow review is exposed when audit records do not capture the decision basis and evidence.
IA-12 — Identity ProofingVideo KYC is an identity proofing process, so review quality affects proofing assurance.
Recommendation — Record who reviewed the case, what evidence they used, and why the decision was made. Tie approval decisions to the proofing evidence required for the intended assurance level.
ISO/IEC 27001:2022A.5.1 — Policies for information securityKYC review needs policy-defined evidence and exception handling to stay consistent and auditable.
Recommendation — Define evidence and exception requirements for reviewer decisions and enforce them consistently.
GDPRArt. 32 — Security of processingVideo KYC processing includes personal and biometric data that must be protected with appropriate controls.
Recommendation — Protect KYC evidence and review records with controls proportionate to the sensitivity of the data.

Practitioner Guidance

What to verify: Require every approval to point to specific recorded evidence, such as document checks, liveness results, or exception rationale. If the reviewer cannot show the basis for the decision in the case file, treat the file as incomplete rather than approved.

What to measure: Track the share of approvals with no exception notes, no reviewer identity, or no linked evidence artifacts. A rising rate of “clean” approvals with thin documentation is often a sign that review quality is drifting downward rather than improving.

Decision rule: If the case required judgment to pass, the review must be auditable enough for a second reviewer to reach the same conclusion or challenge it with evidence. If it cannot, widen the review path before the process becomes dependent on individual discretion.

Practitioner takeaway: The key signal is not whether humans touched the case, but whether the human decision is still tied to verifiable evidence and a defensible exception path.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 10, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org