If a business insists on in-person checks while demand and operations move online, onboarding slows, fraud controls become inconsistent, and essential services can stall. The organisation may also expose staff and customers to avoidable contact risk. A workable digital model preserves trust, reduces friction, and keeps the process usable when face-to-face verification is no longer practical.
Why In-Person Checks Become a Bottleneck in Online Operations
When a business keeps requiring face-to-face verification after customers and staff have moved online, the control no longer fits the operating model. The result is usually slower onboarding, more manual exceptions, and a gap between the process the organisation wants and the one it can actually sustain. That gap often becomes the real source of friction, not the verification step itself.
In practice, teams start deferring requests, processing them unevenly, or creating ad hoc workarounds so the business can keep moving. Those workarounds preserve short-term continuity, but they also make the process harder to measure, harder to audit, and harder to scale.
Trust, Fraud Control, and Service Availability Under Digital Pressure
The main problem is not simply inconvenience. A verification step that depends on physical presence can weaken trust because it is applied inconsistently across channels, locations, or customer groups. It can also create a false sense of security if the organisation assumes the old control still protects the new online journey in the same way.
As operations shift online, the business needs controls that can be applied consistently at the point of digital access. That usually means moving from manual presence checks to verifiable digital evidence, risk-based review, or layered authentication and approval flows that still preserve business usability.
How to Tell Whether the Old Check Has Outlived Its Usefulness
A control has usually outlived its usefulness when it is slowing the process more than it is reducing genuine risk. Common signs are rising abandonment, longer turnaround times, repeated exceptions, and staff using judgement to override the rule because the rule no longer matches the channel. At that point, the organisation is not operating a strong control, it is operating a fragile one.
The better test is whether the check still reduces the specific fraud, account takeover, or impersonation risk it was meant to address in an online journey. If it only works in person, but the business now runs mostly online, the organisation needs a replacement control that still fits the threat model and the user experience.
Risk and Threat Considerations
Keeping an in-person check after operations move online creates operational and security risk at the same time. It can slow onboarding enough that users bypass the intended process, while inconsistent exceptions create openings for fraud, impersonation, and weak auditability.
Failure mechanism: The organisation applies a control that depends on physical presence to a workflow that now runs digitally, so staff improvise exceptions, fraud screening becomes uneven, and the control loses consistency at scale.
Impact: Delays, abandoned journeys, and uncontrolled workarounds can reduce service availability and increase the chance that bad actors find the weakest exception path instead of the intended verification path.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-5 — Account Management | Manual in-person checks often fail as account onboarding shifts online. |
| Recommendation — Standardize digital verification and reduce manual exception handling for new accounts. | ||
| NIST CSF 2.0 | ID.AM-01 — Identities and access are managed | The question is about control fit as business operations and access move online. |
| Recommendation — Review whether the current verification method still manages access effectively in the online channel. | ||
| NIST SP 800-53 Rev 5 | IA-8 — Identification and Authentication (Non-Organizational Users) | Online customer verification depends on authenticating external users without in-person contact. |
| IA-2 — Identification and Authentication (Organizational Users) | Staff handling of manual checks and exceptions depends on reliable operator authentication and accountability. | |
| Recommendation — Adopt remote identity and authentication controls for external users. Ensure staff actions in exception handling are attributable and authenticated. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | The issue is a control design mismatch between physical checks and online access decisions. |
| Recommendation — Align access-control design with the online operating model and the risk it must address. | ||
Practitioner Guidance
What to prioritise: Reassess the business purpose of the in-person check before redesigning the process. If the real objective is trust, fraud reduction, or proof of eligibility, define the control outcome first and then choose a digital method that achieves it without depending on physical attendance.
What to verify: Check whether the current process is producing measurable assurance or just delaying transactions. If the team cannot show consistent outcomes, clear audit evidence, and acceptable cycle times, the control is probably functioning as a bottleneck rather than a safeguard.
Practitioner takeaway: The right question is not whether to preserve the old check, but whether the control still meaningfully reduces risk in the channel where the business now operates.
Related resources from NHI Mgmt Group
- What breaks in a bank's operating model if it keeps relying on legacy IT during the wallet shift?
- How should security teams make NHI best practices usable across the business?
- Why do online identity verification workflows create more governance pressure than in-person checks?
- What happens when a business adopts digital tools in only a few departments but keeps older systems elsewhere?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org