When customer verification depends on insecure video conferencing, organisations risk privacy leakage, session disruption, and weaker evidence for compliance reviews. Fraudsters and miscreants can exploit loose controls, while sensitive data may move through systems the institution cannot fully govern. The result is a higher operational burden, more remediation work, and less confidence in the integrity of the onboarding record.
Why insecure video conferencing weakens customer verification
customer verification is only as strong as the channel, evidence trail, and control set behind it. If a video call is treated as “good enough” without strong identity proofing, secure capture, and tamper-resistant recordkeeping, the process becomes easier to spoof, interrupt, or dispute later. A banking-grade workflow is designed to make each step attributable and reviewable.
Video itself is not the problem. The risk comes from using it as a substitute for a controlled verification process that checks who is present, what evidence is captured, and whether the interaction can be reliably audited. In practice, that means weak platform controls, unstable session handling, and poor linkage between the customer, the evidence, and the final onboarding decision.
Banking-grade verification typically requires stronger authentication, clearer evidence standards, and more consistent handling of session records. OWASP ASVS is useful here because it reinforces that authentication, session handling, and access control are not optional details, they are core design requirements for any process that must stand up to review.
Where the operational and compliance failures show up
Loose video verification workflow often fail in the same places: the session may be interrupted, the evidence may be incomplete, or the operator may have too little confidence that the person on screen is the same person tied to the application. That creates rework, delays, and a higher rate of exceptions that must be reconciled manually.
There is also a governance problem. If customer data, screenshots, transcripts, or recordings pass through an unmanaged platform, the institution may lose visibility over retention, access, and downstream sharing. For regulated onboarding, that weakens the evidence package used for compliance review and can complicate later challenge, audit, or dispute handling.
For institutions handling regulated customer due diligence, identity proofing needs to map to a defensible standard rather than an ad hoc conversation. eIDAS 2.0, the EU Digital Identity Framework illustrates the direction of travel toward stronger, more structured digital identity assurance, while FATF Recommendations reinforce that customer due diligence must be supported by evidence that is fit for compliance purposes.
Why fraudsters prefer weak verification channels
When verification is lightweight, attackers do not need to defeat the whole institution, they only need to exploit the weakest part of the session. That may be a shared link, an unvetted conferencing tool, a poorly controlled handoff between support staff, or a recording process that leaves too much room for impersonation or replay.
Weak channels also make it easier to abuse trust. A fraudster can appear cooperative, rush the operator, or manipulate the conversation so that the institution accepts incomplete evidence. Even when no direct compromise occurs, the outcome can still be a false acceptance that later exposes the bank to account takeover, mule activity, or remediation costs.
Attacks against the verification step are often about the workflow, not the video feed itself. MITRE ATT&CK Enterprise Matrix is helpful for thinking about the attacker’s objective, especially credential access, social engineering, and post-compromise abuse, while GDPR highlights why weak handling of personal and biometric data can become both a security and privacy issue when verification artefacts are stored or shared without adequate protection.
Risk and Threat Considerations
Insecure video conferencing raises the chance that an impostor can be accepted as a legitimate customer, and it also increases the likelihood that sensitive identity evidence is exposed to a platform the institution does not fully control. The more the process depends on convenience rather than assurance, the easier it is for fraud, replay, and evidence disputes to take hold.
Failure mechanism: Weak session control, unmanaged evidence capture, and poor identity proofing let an attacker exploit the verification step without having to breach the core banking platform.
Impact: The institution can end up with false onboarding decisions, privacy leakage, higher remediation cost, and weaker audit evidence when the verification record is challenged.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP ASVS and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP ASVS | V6 — Authentication | Verification depends on strong proof of who the customer is. |
| V7 — Session Management | Insecure conferencing weakens session integrity and evidence continuity. | |
| V8 — Authorization | The workflow must limit who can view, handle, and approve customer evidence. | |
| Recommendation — Require stronger authentication and proofing before accepting a verification outcome. Protect session integrity and bind the live interaction to the recorded evidence. Restrict access to verification artefacts and approval actions to authorised staff only. | ||
| NIST SP 800-53 Rev 5 | IA-8 — Identification and Authentication (Non-Organizational Users) | Customer verification is about proving external user identity. |
| AU-2 — Event Logging | Verification needs a defensible audit trail for review and dispute handling. | |
| Recommendation — Use stronger external-user identity proofing and authentication before onboarding. Log verification events and retain evidence needed to reconstruct the decision. | ||
Practitioner Guidance
What to verify: Confirm that the workflow proves who joined, preserves an auditable evidence trail, and binds the recorded artefacts to the onboarding decision. If the platform cannot support those three outcomes consistently, it is not a banking-grade control path.
Decision rule: If the video call is only a convenience layer, keep it secondary to stronger identity proofing and controlled evidence capture. If it is the primary verification method, treat the platform, session control, and record retention model as part of the control itself, not as a communications detail.
Practitioner takeaway: The key question is not whether video was used, but whether the verification process remains defensible, attributable, and reviewable when the session is challenged.
Related resources from NHI Mgmt Group
- What happens when remote hiring relies on video calls instead of strong identity verification?
- What happens when help desk verification is left to the agent instead of the workflow?
- What happens when identity verification relies on poor capture quality instead of authenticated document signals?
- What happens when a company relies on broad access instead of continuous verification?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 29, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org