Accountability usually sits with the platform operator, because it defines the onboarding rules, verification thresholds, and access controls. If the platform delegates checks to a third party, it still remains responsible for choosing appropriate controls, monitoring exceptions, and enforcing policy. Regulators and insurers will look at whether the operator exercised reasonable identity assurance before granting access.
Why This Matters for Security Teams
Carsharing looks like a transportation problem, but the security issue is identity assurance. If a platform allows an unverified or underage driver to unlock a vehicle, the failure is usually not the car itself but the control plane that granted access. That is why accountability generally sits with the operator: it sets onboarding policy, decides what evidence counts as proof, and determines when to deny, step up, or revoke access.
This is the same pattern NHIMG documents across identity-heavy environments, where weak controls and poor revocation practices turn an access decision into an incident. In the Ultimate Guide to NHIs — The NHI Market, NHI Mgmt Group notes that 92% of organisations expose NHIs to third parties, which is a useful warning here: delegation does not remove accountability. For identity assurance controls, security teams still look to governance standards such as NIST SP 800-53 Rev 5 Security and Privacy Controls for evidence that access decisions were designed, monitored, and enforced.
In practice, many teams discover the control gap only after an unauthorised rental has already been completed, rather than through deliberate policy testing.
How It Works in Practice
Accountability is usually shared in execution, but not in ownership. The platform operator remains accountable for the identity workflow even if it uses a vendor for document checks, age verification, or fraud scoring. The operator must define the trust threshold, require appropriate evidence, and make the final allow or deny decision. If a third party is used, the operator still needs to validate the vendor’s reliability, log the result, and set exception handling for edge cases.
Practically, that means the control design should look like an access governance flow rather than a one-time signup screen. Strong programmes use:
- identity proofing rules that are explicit about what is required for each vehicle class or jurisdiction;
- step-up verification when the signal quality is low or the risk score is elevated;
- time-bound approvals and revocation paths when documents expire or eligibility changes;
- audit logs that show who approved access, what evidence was used, and when the decision was made;
- continuous monitoring for fraud indicators, replayed documents, and account sharing.
The same principle appears in NHI governance, where NHI Mgmt Group’s Ultimate Guide to NHIs — The NHI Market warns that third-party exposure creates material risk when trust is not actively governed. For operators, the operational lesson is simple: outsourced checks can inform the decision, but they cannot own the decision. Mature identity assurance programmes align this pattern with NIST SP 800-53 Rev 5 Security and Privacy Controls by requiring documented control responsibility, evidence retention, and exception review.
These controls tend to break down when the platform scales across regions with different age, licensing, and privacy rules because the verification logic becomes inconsistent and hard to audit.
Common Variations and Edge Cases
Tighter verification often increases friction and abandonment, requiring organisations to balance safety against customer conversion. That tradeoff matters because not every rental requires the same level of assurance, and current guidance suggests the control should match the risk of the vehicle, the duration of the rental, and the legal regime in the user’s jurisdiction.
There is no universal standard for this yet, but several edge cases appear repeatedly. A minor who uses a parent’s payment method is still not an authorised driver. A user who passes document checks once may still be ineligible if the licence expires or a local restriction applies. A marketplace that merely “connects” drivers and vehicle owners still carries responsibility if its system determines who gets access to the vehicle. If a third party fails to verify identity correctly, the platform may share liability, but it does not shed accountability for the control choice.
For practitioners, the practical test is whether the platform can prove that it knew the access rules, applied them consistently, and acted when assurance was weak. That is the same governance logic NHIMG applies to identity risk more broadly in the Ultimate Guide to NHIs — The NHI Market: if access is granted through delegation, the operator still owns the policy outcome.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-1 | Access rights must be approved and enforced before vehicle use. |
| NIST SP 800-63 | IAL2 | Identity proofing strength determines whether the driver can be trusted. |
| NIST AI RMF | Accountability, transparency, and human oversight are central to AI-assisted verification. | |
| OWASP Non-Human Identity Top 10 | NHI-02 | Third-party delegation without strong governance mirrors identity trust failures. |
Require documented approval criteria and verify access decisions before any rental is granted.
Related resources from NHI Mgmt Group
- Who should be accountable when platform claims do not match the actual identity security architecture?
- Who is accountable when fraud slips through an online testing platform?
- Who is accountable when an MSP adopts new platform features without updating controls?
- Who is accountable when an identity platform accepts unverified email claims for linking?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org