Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What happens when conveyancers do not have a…
Governance, Ownership & Risk

What happens when conveyancers do not have a defensible digital identity process in place?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 30, 2026 Domain: Governance, Ownership & Risk

They face higher fraud exposure, more inconvenience for clients, and less consistent verification outcomes across transactions. Without a defensible process, the conveyancer also loses the ability to demonstrate compliance with the standard, which can undermine confidence in the identity checks supporting the property transfer.

Why a Defensible Digital Identity Process Matters in Conveyancing

A defensible process is not just a compliance checkbox. In conveyancing, identity proofing underpins trust in who is instructing the transaction, who is receiving funds, and whether the file can withstand challenge later. When the process is weak, the firm is left relying on inconsistent judgement, which increases fraud exposure and makes outcomes harder to defend across cases.

The practical issue is consistency. A defensible process creates repeatable checks, documented decision points, and evidence that can be explained to clients, counterparties, auditors, and insurers. That matters because property transactions are high-value, time-sensitive, and attractive to impersonation and payment diversion attempts. Where the process is ad hoc, the same apparent identity risk can be handled differently by different staff, which is exactly where mistakes and disputes emerge.

For this reason, digital identity in conveyancing should be treated as part of transaction integrity, not as an optional admin step. A process that cannot be explained, repeated, and evidenced will usually be too fragile to support reliable risk decisions when the transaction is under pressure.

What Fails When the Identity Process Is Not Defensible

Without a defensible process, the failure is usually not one dramatic breakdown, but a chain of smaller weaknesses: incomplete checks, uneven escalation, poor recordkeeping, and inconsistent acceptance of identity evidence. That creates two problems at once, first it weakens fraud prevention, and second it makes it difficult to prove that the firm acted with appropriate care if the transaction is later questioned.

Client experience also degrades. People are asked for repeated documents, different staff request different evidence, and the verification standard varies from one matter to the next. Over time, that inconsistency undermines confidence in the firm and can slow completions because the team keeps revisiting identity questions instead of closing them decisively.

For digitally mediated identity checks, the control needs to be more than a screenshot or a one-time approval. It should be tied to clear evidence of what was checked, what the result was, and why the decision was acceptable for that transaction. A process that cannot produce that trail is vulnerable to challenge even when the underlying check seemed reasonable in the moment.

Why Compliance, Evidence, and Trust Are All Affected

In practice, conveyancers are judged on whether they can show that the identity process was defensible, not merely whether they attempted a check. That includes the ability to demonstrate a standardised approach, preserve evidence of the verification outcome, and show that exceptions were handled consistently. The eIDAS 2.0 framework for European digital identity is a useful reminder that digital identity systems increasingly depend on assurance, portability, and trust properties that can be explained and verified.

The operational consequence is that poor identity process design becomes a governance issue, not just a technical one. If staff cannot prove how a decision was reached, then the firm may still have performed some checks but lacks the evidence needed to demonstrate that the checks were reliable, proportionate, and consistently applied.

That is why identity workflow design matters so much in conveyancing: the goal is not to maximise friction, but to make fraud resistance and evidential quality rise together. A defensible process should reduce ambiguity, not create it.

Risk and Threat Considerations

Weak digital identity handling in conveyancing creates an attractive opening for impersonation, account takeover, and payment redirection. The risk is amplified because property transfers move large values and involve trusted communication patterns, so a small verification failure can produce outsized financial loss or a disputed transfer.

Failure mechanism: attackers exploit inconsistent verification, weak evidence retention, or over-reliance on manual judgement to pass as a legitimate client or counterpart, then push changes that benefit the fraudulent transaction.

Impact: the firm faces higher fraud exposure, possible client harm, remediation cost, and an evidential gap if it later has to explain why the identity checks were good enough.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 and GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
ISO/IEC 27001:2022A.5.16 — Identity ManagementDefensible client identity verification depends on governed identity records and proofing.
A.5.15 — Access ControlConveyancing identity checks determine who may instruct and receive transaction actions.
Recommendation — Define and enforce a consistent identity verification workflow with retained evidence for each matter. Restrict transaction actions until identity checks meet the required assurance level.
NIST SP 800-53 Rev 5IA-8 — Identification and Authentication (Non-Organizational Users)Clients and external parties need stronger identity assurance in transfer workflows.
AU-2 — Event LoggingA defensible identity process needs an audit trail of verification decisions.
Recommendation — Apply external-user identity assurance controls before accepting transaction instructions. Log identity verification steps, exceptions, and approvals for later review.
GDPRArticle 5 — Principles relating to processing of personal dataIdentity evidence handling must stay lawful, minimal, and purpose-bound.
Recommendation — Limit identity data collection to what is necessary and retain only justified evidence.

Practitioner Guidance

What to prioritise: standardise the identity decision path before you optimise convenience. The first question is whether every matter follows the same minimum evidence threshold, escalation route, and recordkeeping standard, because that is what makes the process defensible under scrutiny.

What to verify: confirm that the process records who was checked, what evidence was used, how the result was reached, and what exception handling occurred. If the file cannot show those four things quickly, the process is probably too weak for a high-value transfer environment.

What good looks like: the team can explain the identity decision in the same way across matters, clients experience fewer repeat requests, and the firm can reconstruct the verification trail without relying on memory or informal notes. NHIMG’s Identity Proofing and KYC Guide is a useful reference point for assurance, liveness, and fraud-resistant verification patterns, while the Digital Identity, eID and Identity Wallets Guide helps when the firm needs to understand reusable digital identity and wallet-based verification flows.

Practitioner takeaway: in conveyancing, a defensible digital identity process is not mainly about speed or convenience, it is about making the identity decision repeatable, auditable, and hard to spoof.

Identity Proofing and KYC Guide and NHIMG’s NHI Lifecycle Management Guide are relevant because the same disciplines that govern verification, ownership, and evidence also govern whether identity processes stay reliable over time.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 30, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org