Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM Who is accountable when identity verification or due…
Identity Beyond IAM

Who is accountable when identity verification or due diligence fails in a Nigeria compliance programme?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 24, 2026 Domain: Identity Beyond IAM

Accountability usually sits with the organisation that controls onboarding, risk acceptance, and ongoing monitoring, not with the customer. Compliance, operations, and senior management each have a role in setting policy, approving exceptions, and ensuring controls are implemented consistently. Regulators expect the firm to evidence that its processes align with applicable laws and internal governance.

Why This Matters for Security Teams

Accountability in a Nigeria compliance programme is not a theoretical governance point. It determines who owns customer onboarding rules, who signs off on exceptions, and who is responsible when identity verification or due diligence gaps lead to fraud, sanctions exposure, AML failures, or weak audit evidence. Under the FATF Recommendations — AML and KYC Framework, firms are expected to implement risk-based controls that are demonstrably effective, not merely documented.

For practitioners, the mistake is often treating IDV and due diligence as a vendor problem or a front-office task. In reality, accountability usually sits with the regulated entity that chooses the control design, accepts residual risk, and supervises the process over time. Compliance defines the standard, operations executes it, and senior management is expected to ensure governance is working. If the evidence trail is weak, regulators will still look for the accountable firm, not the outsourced tool or the customer.

That same logic appears in control frameworks such as the NIST Cybersecurity Framework 2.0, where governance and risk ownership are not optional extras. In practice, many security teams encounter accountability only after a failed onboarding review has already created a suspicious account, a frozen transaction, or a reportable compliance incident, rather than through intentional governance design.

How It Works in Practice

Accountability is usually distributed, but not diluted. The organisation remains answerable to regulators and auditors, while specific functions own distinct parts of the control chain. A useful way to think about it is that policy ownership, operational execution, exception approval, and oversight should be separated, documented, and reviewable. Where the programme handles regulated onboarding or high-risk customers, this should also align with the control discipline reflected in NIST SP 800-53 Rev 5 Security and Privacy Controls and the management system approach in ISO/IEC 27001:2022 Information Security Management.

  • Compliance typically defines KYC, AML, and due diligence requirements, including what evidence is acceptable and when enhanced checks are required.
  • Operations or onboarding teams execute the checks, collect evidence, and escalate anomalies or mismatches.
  • Risk or compliance leaders approve exceptions, document residual risk, and decide whether to accept, reject, or exit the relationship.
  • Senior management provides oversight, ensures resources are adequate, and reviews control performance and remediation.
  • Internal audit or assurance functions test whether controls are consistently followed and whether records are defensible.

Good practice also requires clear evidence of who made each decision and why. That matters because identity verification is only as strong as the record supporting it: source documents, liveness or biometric checks where used, sanction and PEP screening results, manual review notes, and approval timestamps all become part of the accountability story. The control environment should map to recognised principles in ISO/IEC 27002:2022 Information Security Controls, especially around traceability, access restriction, and supplier oversight when third parties support onboarding.

Where identity systems are digitally federated or rely on third-party assurance, governance becomes more complex, not less. The organisation still owns the final decision, even if it consumes external identity proofs or verification services. These controls tend to break down when onboarding is heavily outsourced but exception authority remains informal, because no single accountable owner can prove that the required checks were applied consistently.

Common Variations and Edge Cases

Tighter due diligence often increases onboarding friction and operational cost, requiring organisations to balance customer experience against regulatory exposure and fraud loss. That tradeoff is especially visible in Nigeria programmes that serve cross-border customers, high-volume retail flows, or business clients with complex ownership structures.

Best practice is evolving on how much accountability can be delegated to vendors, agents, or automated verification platforms. There is no universal standard for this yet, but current guidance suggests that delegation does not transfer ultimate responsibility. If a third party performs screening or document capture, the regulated firm still needs contractual oversight, quality assurance, escalation routes, and the ability to evidence independent challenge.

Edge cases also arise where beneficial ownership is opaque, documents are inconsistent, or the customer operates through multiple jurisdictions. In those scenarios, the accountable organisation should treat the case as higher risk, apply enhanced due diligence, and record why the decision was made. Where digital identity assurance is used, lessons from eIDAS 2.0 — EU Digital Identity Framework can be informative, but they do not replace Nigeria-specific legal and supervisory obligations.

The practical rule is simple: if the firm can benefit from a relationship, it must also be able to explain the controls that justified it. That accountability becomes most visible after an adverse event, when regulators ask for the decision trail and the organisation cannot show who approved the risk.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-63, NIST SP 800-53 Rev 5 and ISO/IEC 27001:2022 set the technical controls, while NIS2 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01Governance clarifies who owns risk acceptance and oversight for IDV failures.
NIST SP 800-63IALIdentity assurance levels shape how much verification is required before onboarding.
NIST SP 800-53 Rev 5PS-7Personnel and accountability controls support traceable approval and review duties.
ISO/IEC 27001:20225.3Roles and responsibilities must be assigned for compliance and control execution.
NIS2Article 20Management body accountability reinforces senior oversight for control failures.

Match verification depth to the required identity assurance level and document the result.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org