Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What happens when banks skip the audit and…
Governance, Ownership & Risk

What happens when banks skip the audit and recording controls in video KYC?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 29, 2026 Domain: Governance, Ownership & Risk

When banks skip audit and recording controls, they lose the evidence needed to prove that onboarding was consent-based, live, and properly supervised. That creates compliance risk, weakens fraud investigation, and makes disputes harder to resolve. It also increases the chance that an identity check was completed without reliable proof of who participated or what was actually verified.

Why audit and recording controls matter in video KYC

Audit and recording controls are what turn a video KYC session into verifiable evidence rather than an unsupported assertion. They let the bank show that the customer was present, the interaction was live, the checks were supervised, and the onboarding decision can be reconstructed later. Without that record, the process becomes harder to defend to compliance teams, investigators, and regulators.

They also matter because video KYC is not just a screening step, it is an evidence-producing control. If the bank cannot replay or review what happened, it cannot reliably prove that the identity check met its own standards or that any exceptions were handled appropriately.

What is lost when the session is not auditable

When banks skip audit trails and recordings, they lose the ability to verify the chain of events after the fact. That affects both assurance and investigation: a reviewer may know an account was opened, but not whether the person on camera matched the submitted identity documents, whether prompts were answered live, or whether the interaction was interrupted, coached, or manipulated.

This is especially important in remote onboarding, where the control environment depends on what the operator saw and recorded in real time. A missing record also weakens escalation decisions, because exceptions cannot be reviewed consistently and suspicious onboarding cases are harder to compare across teams or branches.

For banks operating under AML and KYC obligations, the evidence trail is part of the control outcome, not an optional administrative extra. Resources such as FATF Recommendations and the EBA AML/CFT Guidance show why customer due diligence must be demonstrable, not merely asserted.

Where the operational and fraud risks show up

Skipping recording controls creates a dispute gap: if a customer later denies consent, challenges the quality of the check, or claims they were not properly verified, the bank has little objective evidence to rely on. That can complicate remediation, reverse bad onboarding decisions, and prolong fraud or compliance investigations.

It also increases exposure to identity fraud techniques that exploit weak remote onboarding workflows, including synthetic identity, injected video, or coached participation. A control failure here is often less about one missed recording and more about the institution losing the ability to distinguish genuine live verification from a replayed, proxied, or poorly supervised session.

That is why practical guidance in identity proofing treats liveness, evidence capture, and reviewability as linked controls. The Identity Proofing and KYC Guide and the external eIDAS 2.0 framework both reflect the broader requirement for trustworthy, verifiable identity processes, even though the exact operational model differs by jurisdiction.

What good practice looks like in bank video KYC

A defensible setup usually includes session recording, time-stamped audit logs, operator identity, decision notes, exception handling, and retention rules that match the institution’s risk and regulatory obligations. The recording should be good enough to support later review of the face-to-face interaction, the artefacts presented, and the final approval decision.

Practitioners should also verify that the recording is not just stored, but retrievable, protected from tampering, and linked to the specific onboarding case. If the bank cannot locate a session quickly, or cannot prove the record was preserved intact, the control is only partially functioning.

For broader control design, SOC 2 Trust Services Criteria, NIST SP 800-53 Rev 5 Security and Privacy Controls, and CIS Controls v8 all reinforce the same practical idea: evidence, logging, and reviewability are core control properties, not optional documentation.

Risk and Threat Considerations

Removing audit and recording controls does more than weaken compliance posture. It also gives fraudsters and accomplices a cleaner path to conceal how an onboarding decision was influenced, especially when remote identity checks are being used at scale. The institution may still open accounts, but it loses the forensic record needed to challenge manipulation or detect repeated patterns.

Failure mechanism: The bank cannot reconstruct who appeared on camera, what was verified, whether the session was live, or whether the operator followed the required process, so disputes and investigations lose evidentiary support.

Impact: False approvals become harder to detect and unwind, legitimate disputes take longer to resolve, and the institution faces greater compliance, fraud, and remediation exposure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AU-2 — Event LoggingVideo KYC needs auditable session evidence and decision logs.
AU-12 — Audit Record GenerationSession recording and timestamps depend on generated audit records.
IA-8 — Identification and Authentication (Non-Organizational Users)Customer video KYC is external-user identity proofing and verification.
Recommendation — Log onboarding events and reviewer actions for later reconstruction. Generate complete records for each remote identity verification session. Verify external user identity before account activation.
CIS Controls v8CIS-8 — Audit Log ManagementRecorded KYC sessions need protected logs and reviewable evidence.
Recommendation — Centralize, protect, and review KYC audit logs consistently.
ISO/IEC 27001:2022A.8.15 — LoggingKYC session evidence requires logging and traceability.
Recommendation — Record verification activity and retain it for investigation and audit.

Practitioner Guidance

What to verify: Confirm that every video KYC case has a retrievable recording, a complete audit trail, and a clear link between the session, the reviewer, and the final decision. If any of those three are missing, treat the onboarding record as incomplete.

Decision rule: If the session can establish identity but cannot preserve evidence, do not treat the control as fully effective. Escalate cases with missing or corrupt recordings, because the issue is not just operational, it affects whether the bank can defend the onboarding decision later.

Practitioner takeaway: In video KYC, the recording is part of the control outcome, so the real test is not whether a check happened, but whether the bank can prove it happened correctly and live.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org