Join our Newsletter — 33% off our NHI Course
Home FAQ Architecture & Implementation What are the signs that identity verification is…
Architecture & Implementation

What are the signs that identity verification is too cumbersome for legitimate users?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 1, 2026 Domain: Architecture & Implementation

Common signs include high enrollment abandonment, repeated drop-off during document capture, complaints about slow or confusing steps, and a large number of users failing before account creation is complete. If the process asks for too much data, too many handoffs, or disconnected checks, friction is probably too high. A good programme reduces that friction without weakening assurance.

Why This Matters for Security Teams

When identity verification feels too heavy, legitimate users do not simply “push through” it. They delay, abandon, or route around it, which creates a second problem for security teams: the control starts selecting for the most determined users rather than the right users. That is especially risky in regulated onboarding, account recovery, and any workflow where human friction directly affects conversion and fraud loss.

The challenge is not to remove assurance, but to align it with actual risk. Current guidance suggests that strong identity programmes should scale the level of checking to the sensitivity of the action, not force every user through the same high-friction path. In practice, that means using evidence from device signals, session context, and transaction risk to decide when step-up verification is justified. NIST’s control baseline for access and identity processes in NIST SP 800-53 Rev 5 Security and Privacy Controls supports this kind of risk-based design, while identity programmes should also account for the policy expectations shaping digital onboarding under eIDAS 2.0 — EU Digital Identity Framework.

For teams managing broader identity risk, the same pattern appears in NHI environments: complexity pushes users and operators toward unsafe shortcuts. NHIMG’s Ultimate Guide to NHIs notes that only 5.7% of organisations have full visibility into their service accounts, a reminder that poor UX and poor control design often surface together. In practice, many security teams discover friction problems only after abandonment rates, support tickets, or fraud workarounds have already become normal.

How It Works in Practice

The clearest sign of excessive friction is not one complaint, but a pattern: users repeatedly fail at the same checkpoint, support teams keep reissuing verification instructions, and conversion drops sharply when the process moves from “light” to “proof-heavy.” Security leaders should look at the full journey, not only the final pass rate. A process can be technically strong and operationally broken if it requires too many document rescans, too many handoffs, or too many re-entry steps.

Good identity verification uses progressive assurance. Low-risk actions should require the minimum evidence needed to keep the flow moving, while high-risk events such as account recovery, payout changes, or credential resets trigger step-up checks. This is similar to how access governance works in high-risk environments: continuous evaluation rather than one-time approval. In NHI and agentic systems, the same principle shows up as runtime authorisation and short-lived credentials, because static rules cannot predict every future action. NHI teams often pair this with operational analysis from Top 10 NHI Issues and breach patterns documented in 52 NHI Breaches Analysis to understand how over-control and under-control both create risk.

A practical review should cover:

  • Where users abandon most often: registration, document upload, selfie match, or knowledge-based checks.
  • Whether the flow asks for data that is not tied to the actual risk level.
  • Whether users can resume after interruption without starting over.
  • Whether alternative paths exist for users with limited documents, accessibility needs, or poor connectivity.
  • Whether verification outcomes are consistent across devices and geographies.

The control is usually working when the system reserves the heaviest checks for the highest-risk events and keeps routine journeys simple. These controls tend to break down in high-volume consumer onboarding, cross-border identity proofing, and mobile-first environments because document capture, liveness checks, and manual review introduce too much latency and failure at scale.

Common Variations and Edge Cases

Tighter verification often increases drop-off and support load, requiring organisations to balance fraud reduction against conversion, accessibility, and operational cost. There is no universal standard for the “right” level of friction, because the answer depends on the user, the transaction, and the legal environment.

One common edge case is regulated onboarding, where teams may accept more friction because the legal and fraud consequences are higher. Another is low-value consumer signup, where the same level of scrutiny can be counterproductive and may even create a worse security outcome by pushing users toward disposable accounts or delayed completion. Best practice is evolving toward adaptive verification, but the industry has not fully standardised how to score risk across every channel.

Teams should also watch for false signals. A low abandonment rate is not always good if it reflects a weak process that lets almost anyone through. Likewise, a high failure rate does not always mean the flow is too hard if the rejected population is genuinely risky. The right interpretation comes from pairing user-friction metrics with fraud outcomes, manual review rates, and downstream account quality.

For compliance-heavy use cases, FATF Recommendations — AML and KYC Framework may shape what evidence must be collected, but it does not remove the need to simplify the user journey wherever possible. In practice, teams see the sharpest failures when verification is designed as a one-size-fits-all gate rather than a risk-based decision path.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-1Identity proofing friction affects how access is granted to legitimate users.
NIST SP 800-63Digital identity assurance covers balancing proofing strength and user burden.
NIST AI RMFRisk-based decisions help justify adaptive verification instead of one fixed flow.
OWASP Non-Human Identity Top 10NHI-03Overly cumbersome verification often leads to unsafe shortcuts in identity workflows.
NIST Zero Trust (SP 800-207)3.4Adaptive verification aligns with continuous, context-aware trust decisions.

Apply context-based trust decisions instead of forcing every user through the same gate.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 1, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org