Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM Why do KYC programs still create friction even…
Identity Beyond IAM

Why do KYC programs still create friction even when institutions try to centralise identity checks?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 26, 2026 Domain: Identity Beyond IAM

KYC programs create friction because each institution often performs its own verification, maintains its own records, and repeats the process when a customer changes providers. That approach raises cost and delays onboarding. Centralisation can reduce duplication, but it also concentrates risk, so governance, access control, and resilience become critical design requirements.

Why This Matters for Security Teams

KYC friction is rarely just a customer experience problem. It is usually a control-design problem: identity proofing, record retention, and repeated verification are often implemented as isolated checks across business units and providers. That creates duplication, inconsistent assurance, and a larger attack surface when the same identity evidence is copied into multiple systems. The risk is visible in broader NHI governance too. NHI Mgmt Group reports that 97% of NHIs carry excessive privileges, a reminder that centralisation without tight access boundaries can simply concentrate exposure instead of reducing it, as discussed in the Ultimate Guide to NHIs.

For regulated firms, KYC also has to map to external obligations rather than internal convenience. The FATF Recommendations and customer identity rules under the eIDAS 2.0 framework both push institutions toward stronger assurance, but neither removes the operational burden of governance, recertification, and data minimisation. In practice, many security teams encounter KYC drag only after onboarding queues, duplicate reviews, and access disputes have already accumulated across channels and jurisdictions.

How It Works in Practice

Centralising identity checks usually means one of three patterns: a shared identity repository, a federated verification model, or a re-usable identity credential. Each can reduce re-entry of the same documents, but each also requires strong controls over who can query, update, and trust the result. The practical challenge is not only verifying a person once. It is preserving provenance, freshness, and revocation semantics so downstream teams know when a check is still valid.

That is where many programmes stumble. Identity proofing data often becomes a high-value record set that multiple applications want to reuse, which increases the need for least privilege, auditability, and time-bound access. The same pattern appears in broader identity security research from NHI Mgmt Group: in the 52 NHI Breaches Analysis, repeated trust in long-lived credentials and overly broad access repeatedly amplifies downstream impact. For KYC, the equivalent failure mode is treating the central identity store as if it were automatically authoritative for every future decision.

  • Use a single source of truth for verified attributes, but keep strong lineage and timestamping on each field.
  • Apply role-based and context-based access to KYC data so onboarding, fraud, compliance, and support do not all see the same breadth of information.
  • Define expiry rules for high-risk attributes such as address, document validity, and beneficial ownership data.
  • Require step-up review when a customer profile changes materially, rather than relying on a one-time verification event.

For regulated operations, current guidance suggests pairing reusable identity evidence with continuous monitoring, because a central register only helps if it can be queried safely and updated reliably. These controls tend to break down when multiple subsidiaries, legacy core systems, and outsourced onboarding providers each maintain their own version of the customer record because reconciliation becomes manual and stale data persists.

Common Variations and Edge Cases

Tighter centralisation often increases governance overhead, requiring organisations to balance onboarding speed against data protection, model risk, and regulatory accountability. That tradeoff becomes more visible when institutions serve cross-border customers, minors, business entities, or politically exposed persons, where the depth of KYC checks differs and no universal standard for reuse exists yet.

There are also cases where centralisation should be partial rather than total. For example, one institution may accept another regulated institution’s identity proofing result, but still perform its own sanction screening, beneficial ownership review, or fraud scoring. That is a sensible split because the trust anchor may be shared while the risk decision remains local. The Top 10 NHI Issues research shows how quickly shared trust can fail when ownership, rotation, and revocation are unclear; KYC reuse has the same problem if governance is not explicit.

Best practice is evolving toward reusable identity credentials, selective disclosure, and policy-driven verification reuse, but institutions should avoid assuming that any central identity utility eliminates responsibility. Each relying party still needs clear rules for freshness, audit, retention, and exception handling, especially where privacy law or local banking rules limit what can be shared.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF, NIST Zero Trust (SP 800-207) and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4KYC reuse depends on least-privilege access to identity data.
NIST AI RMFCentralised identity checks need governed risk and accountability.
NIST Zero Trust (SP 800-207)AC-4Central identity services should enforce context-aware access decisions.
OWASP Non-Human Identity Top 10NHI-03Reusable identity records still need rotation and revocation discipline.
NIST SP 800-63IAL2KYC centralisation must preserve identity proofing assurance levels.

Map re-used identity evidence to proofing assurance and reverify when assurance drops.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org