When access is prioritised without usage, programmes can create bank accounts without changing livelihoods. The article points to dormant accounts, weak MSME financing, and persistent gaps in rural and informal markets. In practice, this means the system records inclusion on paper, but people still lack affordable credit, savings tools, insurance, and payment habits that improve resilience.
When access is counted but usage never follows
financial inclusion only changes outcomes when people actually use the financial rails they are given. Access without usage often means the programme has built a formal account relationship, but not the habits, trust, product fit, or affordability needed for daily transactions, savings, insurance, or productive borrowing. That is why measured inclusion can improve while economic resilience stays flat.
The gap matters because “having an account” is a weak proxy for inclusion. Dormant or underused accounts may satisfy programme reporting, yet they do little for households or MSMEs that still face cash dependence, volatile income, and thin credit histories. In practice, usage is where the value appears, through repeat deposits, payments, working capital, and a reliable place to store value.
A useful way to frame it is to distinguish distribution from adoption. Distribution expands reach; adoption shows whether people return, transact, and build financial routines around the service. Where usage stays low, the barrier is usually not just account opening. It is also fees, documentation burden, distance, poor merchant acceptance, low digital confidence, irregular income, or products that do not match how people actually earn and spend.
Why access-only programmes underperform
Access-only design tends to overestimate what infrastructure alone can achieve. If an account is opened but not funded, connected to wages, linked to a payment need, or paired with a useful savings or credit product, the account becomes administratively present but economically idle. That is especially common in rural and informal markets, where transaction patterns are episodic and trust in formal finance may be fragile.
Usage also reveals whether inclusion is broad enough to matter. A programme can onboard people at scale and still miss the harder problem of integration into real financial life. For MSMEs, for example, inclusion is not complete when an account exists; it becomes meaningful when that account supports invoicing, supplier payments, inventory purchases, and manageable financing. Without that, firms remain stuck in cash-based cycles and cannot smooth shocks or grow.
This is why policy and programme design should treat usage as a first-class outcome, not a secondary metric. If the only indicator is account opening, the system may reward distribution campaigns, agent rollouts, or subsidy-driven sign-ups while leaving untouched the structural frictions that prevent active use. The result is inclusion in name, but not in economic function.
What “real inclusion” looks like in practice
Real inclusion is visible in behaviour, not just enrolment. People regularly receive money, move it, store part of it, and use it to manage risk. They can make or receive payments cheaply, access a savings tool that fits irregular income, and obtain credit or insurance when they need it. When those behaviours become routine, financial services start to change resilience rather than merely count participation.
That also means the product mix matters. A basic account may be a starting point, but it is not the end state. Inclusion improves when accounts connect to practical use cases such as merchant payments, wage disbursement, bill pay, emergency savings, and small-ticket borrowing. The more the service fits the user’s cash flow, the more likely the account becomes active and valuable.
For practitioners, the most important signal is whether the financial system is being used as a tool for household and enterprise decision-making. If usage is absent, the programme may still be useful as infrastructure, but it has not yet become inclusive in the operational sense that matters to users.
Risk and Threat Considerations
Access-only inclusion can create a misleading sense of progress and distort where investment goes. The main risk is that organisations optimise for opening accounts while underinvesting in affordability, product design, merchant acceptance, and local trust, which are the conditions that turn access into durable usage.
Failure mechanism: Programmes measure success at enrolment, but recurring behaviour never develops because the account is too costly, too inconvenient, or too disconnected from real income and spending patterns. That leaves dormant accounts, shallow transaction histories, and weak pathways to credit or savings accumulation.
Impact: The system records inclusion on paper while households and MSMEs remain exposed to cash dependence, poor liquidity management, and limited resilience. Over time, that can also mask regional exclusion, especially in rural and informal markets where uptake is hardest to sustain.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 and SOC 2 (AICPA) define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-5 — Account Management | Access-only inclusion fails when accounts are opened but not actively used. |
| Recommendation — Measure active account use, not just account creation, to validate control effectiveness. | ||
| NIST CSF 2.0 | ID.AM-01 — Identities and credentials are inventoried | The topic depends on tracking who is onboarded versus who actually uses services. |
| Recommendation — Track enrolled and active users separately to identify dormant inclusion. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | The issue is the gap between granted access and practical, controlled use of services. |
| Recommendation — Align access provisioning with measurable service use and business need. | ||
| SOC 2 (AICPA) | CC6.1 — Logical and Physical Access Controls | The subject centres on whether access actually leads to controlled, effective use. |
| Recommendation — Review whether granted access results in meaningful, observable service activity. | ||
Practitioner Guidance
What to measure: Track active usage, not just account counts. A useful set of signals is transaction frequency, value retention, repeat deposits, merchant acceptance, and whether the account supports a real use case such as wages, payments, or short-term savings.
Decision rule: If accounts are opening but activity stays low, treat the problem as a product and distribution failure, not a communications failure. The next move is usually to reduce friction and improve fit before adding more sign-ups.
What practitioners underestimate: Low usage is often rational. People avoid products that are expensive, hard to access, or poorly matched to irregular income, so dormant accounts often indicate weak value delivery rather than user apathy.
Practitioner takeaway: Inclusion only becomes meaningful when the account changes behaviour; if usage does not improve, the programme has expanded access without improving financial capability or resilience.
Related resources from NHI Mgmt Group
- What breaks when organisations focus only on what an AI system can access and ignore what it is allowed to do?
- What happens when privileged access to a financial exchange platform is not reviewed regularly?
- What happens when financial institutions try to manage privileged access without integrating PAM into governance and incident response?
- What happens when access reviews are not automated in highly regulated financial systems?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org