Accountability usually sits with the provider operating the onboarding process, supported by fraud, identity, compliance, and customer operations teams. The right question is whether the organisation designed controls that match the risk of digital account creation. When scams succeed, the failure is often control design, not a single missed verification step.
Why This Matters for Security Teams
Fake service subscriptions are not just a billing nuisance. They expose weaknesses in identity proofing, signup friction, device and payment risk checks, and post-onboarding monitoring. When those controls fail, accountability usually lands with the provider because the provider defined the trust boundary and the onboarding workflow. That is why NHI Management Group treats account creation as a security control surface, not a product-only journey.
This is also where governance and fraud operations overlap. The same control stack that should stop synthetic identities, automated abuse, and low-quality signups must also be able to explain why a suspicious account was accepted. NIST SP 800-53 Rev 5 Security and Privacy Controls is useful here because it frames access, auditing, and monitoring as operational controls rather than one-time gates. For identity-heavy environments, the Ultimate Guide to NHIs - Standards section reinforces that lifecycle control matters as much as initial verification.
Current guidance suggests the organisation should be able to show which signals were checked, which were ignored, and what escalation path existed when risk was elevated. In practice, many security teams encounter the failure only after subscription abuse has already scaled, rather than through intentional control testing.
How It Works in Practice
Accountability depends on which team owns the control design, but the operating model usually spreads across fraud, identity, compliance, and customer operations. The provider is accountable for the onboarding architecture, while individual teams are accountable for the specific checks they control. That means the right response is not to blame a single reviewer after the fact, but to map the full onboarding chain from intake to activation.
Practically, strong programs combine layered controls rather than a single decision point. That often includes email and phone validation, risk-based payment checks, device reputation, velocity limits, behavioural signals, and post-signup review for higher-risk cohorts. Where regulated services are involved, the FATF Recommendations - AML and KYC Framework are relevant because they emphasise customer due diligence and ongoing monitoring, not just initial collection of identity data.
- Define a control owner for each onboarding step, not just for the overall product.
- Log the exact evidence used to approve, delay, or reject a subscription.
- Separate fraud review from compliance approval when the risk signals differ.
- Escalate anomalous signups into monitoring rather than treating them as closed cases.
When teams need a deeper NHI lens, the Ultimate Guide to NHIs is useful because it shows how identity lifecycle controls, visibility, and revocation discipline shape real-world assurance. These controls tend to break down when onboarding is optimised for conversion-first growth funnels because risk review becomes too shallow to distinguish legitimate customers from organised abuse.
Common Variations and Edge Cases
Tighter onboarding controls often increase friction and support load, requiring organisations to balance abuse prevention against conversion, accessibility, and customer experience. That tradeoff is especially visible in markets with high false-positive risk, shared devices, prepaid payment methods, or thin identity footprints.
Best practice is evolving, but there is no universal standard for how much friction is appropriate at signup. Some organisations push more checks into step-up verification after account creation, while others prefer upfront gating for high-risk geographies or products with financial exposure. The key question is whether the control design matches the loss model. If a fake subscription can activate privileges, consume resources, or access restricted features before review, accountability still sits with the provider that allowed that pathway.
One useful operational signal from NHI Management Group is that only 5.7% of organisations have full visibility into their service account, which shows how often identity control gaps persist once an entity is onboarded. That same pattern appears in subscription fraud: if the onboarding path is opaque, ownership becomes unclear and exceptions multiply. The answer is not to assign blame after the incident, but to make the decision trail auditable and the control owner explicit.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-1 | Onboarding controls govern who gets access and under what conditions. |
| NIST SP 800-63 | IAL2 | Identity proofing strength determines how much trust an onboarding decision deserves. |
| OWASP Non-Human Identity Top 10 | NHI-01 | Weak onboarding often creates unmanaged identities and stale authorization paths. |
| NIST AI RMF | Risk governance is needed when automated or AI-assisted onboarding decisions are used. |
Treat every newly created subscription or service identity as a governed identity with lifecycle ownership.
Related resources from NHI Mgmt Group
- Who is accountable when forced verification or document fraud slips through onboarding controls?
- Who should be accountable for account setup, vault access, and onboarding controls in a business password manager programme?
- Who is accountable when fraud occurs after onboarding in a regulated financial service?
- Who is accountable when onboarding and verification controls fail in regulated payments?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org