Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk What do compliance teams get wrong about verifying…
Governance, Ownership & Risk

What do compliance teams get wrong about verifying customers online?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 27, 2026 Domain: Governance, Ownership & Risk

A common mistake is treating identity verification as a one-time check instead of an ongoing risk decision. Remote onboarding also fails when teams rely on weak evidence, skip escalation paths, or ignore the difference between identity proofing and regulatory due diligence. Effective programmes connect verification outcomes to sanctions, fraud, and AML controls across the customer lifecycle.

Why This Matters for Security Teams

Compliance teams often reduce online verification to a pass or fail event, but customer onboarding is really a sequence of risk decisions. That matters because identity proofing, sanctions screening, fraud detection, and AML obligations do not all ask the same question. A document may be authentic while the person is still high risk, or a low-risk customer may later become suspicious through account behaviour or device changes.

Current guidance from the FATF Recommendations — AML and KYC Framework and NIST Cybersecurity Framework 2.0 both point toward ongoing risk treatment rather than a one-time checkpoint. NHIMG research also shows why static controls fail at scale: only 5.7% of organisations report full visibility into their service accounts, and that same visibility gap shows up in customer trust workflows when evidence, exception handling, and lifecycle reviews are scattered across teams. The common failure is not a lack of verification tools, but a lack of decision ownership after the initial onboarding step.

In practice, many compliance teams discover weak escalation paths only after a fraudulent account has already been opened and used.

How It Works in Practice

Effective online verification starts with separating three distinct activities: identity proofing, screening, and ongoing monitoring. Identity proofing asks whether the applicant is who they claim to be. Screening checks whether that person appears on sanctions, watchlists, or internal risk rules. Ongoing monitoring determines whether the customer remains acceptable as new signals arrive. When teams merge these into a single “verified” status, they lose the ability to apply different thresholds over time.

Operationally, mature programmes set risk-based decision paths. Low-risk applicants may clear with standard evidence, while higher-risk cases trigger stronger checks, manual review, or step-up verification. That aligns well with the lifecycle view in Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs and the audit perspective in Ultimate Guide to NHIs — Regulatory and Audit Perspectives, even though the customer context is different. The principle is the same: controls must survive onboarding, not stop at it.

  • Use evidence quality scoring, not just document presence.
  • Link verification outcomes to sanctions, fraud, and AML workflows.
  • Record why a case was escalated or approved so reviewers can trace the decision.
  • Reassess customers when device, geography, payment, or behaviour changes materially.

For implementation, NIST SP 800-207 Zero Trust Architecture is useful because it reinforces continuous evaluation instead of implicit trust after first contact. These controls tend to break down when onboarding spans multiple vendors and the organisation cannot reconcile who owns the final risk decision.

Common Variations and Edge Cases

Tighter verification often increases customer friction and review cost, so organisations must balance conversion rates against fraud exposure and regulatory tolerance. There is no universal standard for how much friction is enough; current guidance suggests the answer should vary by channel, product, geography, and customer risk tier.

Remote onboarding for consumers usually tolerates lighter evidence than business account setup, but that does not mean lower governance. Business verification can require beneficial ownership checks, authority validation, and screening of controllers, not just the named applicant. In higher-risk sectors, step-up checks may be justified even when the initial proofing signal is strong. The most common mistake is treating a successful document check as proof of trustworthiness, which it is not.

NHIMG’s Top 10 NHI Issues highlights a broader governance lesson: weak lifecycle controls create hidden risk. In customer verification, the parallel failure is stale KYC records, untracked exceptions, and manual overrides that are never revisited. Best practice is evolving toward continuous, risk-based review rather than fixed recertification dates alone. Where this guidance becomes fragile is in low-data environments, such as thin-file customers, cross-border onboarding, or legacy channels that cannot support reliable step-up checks and audit trails.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-63, NIST AI RMF, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OVGovernance and oversight fit ongoing verification decisions across the customer lifecycle.
NIST SP 800-63IAL2Identity proofing assurance levels map directly to remote customer verification rigor.
NIST AI RMFRisk management guidance supports continuous decisioning for customer verification.
NIST Zero Trust (SP 800-207)Continuous VerificationZero trust principles support re-evaluating trust instead of relying on onboarding alone.
NIST SP 800-53 Rev 5IA-8Identity proofing control is central to proving remote customer identity.

Define ownership, escalation, and review cadence for customer verification outcomes under governance oversight.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org