Multi-factor onboarding reduces risk because each method tests a different proof point. An OTP checks possession of a device or number, while a selfie or biometric check helps confirm the person presenting the application is physically present. When banks combine these methods, they raise the cost of fraud and make it harder for attackers to rely on stolen data alone.
Why Multi-Factor Onboarding Lowers Account Opening Risk
Multi-factor onboarding reduces exposure because it makes fraud harder to execute with a single stolen artifact. digital account opening is attractive to attackers because application data is often assembled from breached records, reused credentials, or synthetic identity components. Adding separate proof points forces the applicant to satisfy more than one trust test, so a compromised data set is less useful on its own. That matters most when the business wants speed without turning onboarding into a blind acceptance channel.
In practice, the strongest value comes from combining factors that verify different things: device possession, contact reachability, and applicant presence. A one-time code can show control of a phone number or device, while a selfie or other liveness step can reduce replay and impersonation risk. For teams designing controls, the key question is not whether one factor is “strong,” but whether the factors are materially independent and resist the same fraud path. The FATF Recommendations — AML and KYC Framework is useful here because account opening controls often need to satisfy both security and customer due diligence expectations. In practice, many organisations learn the weakness of single-proof onboarding only after fraud patterns have already adapted to the easiest verification step.
How the Control Works in Practice
Effective onboarding uses layered checks to reduce the chance that one compromised signal determines the outcome. The design goal is not to collect as many checks as possible, but to combine checks that fail differently. If an attacker can intercept an OTP, that does not automatically help them defeat a live selfie challenge. If they can deepfake a face image, that does not by itself prove they control the claimed phone or device. This is why multi-factor onboarding is more useful than a single, high-friction control applied everywhere.
Operationally, the sequence usually matters. Teams often begin with document capture or identity data entry, then add a reachability or possession test, and then add a presence or liveness check before account approval. The control is strongest when each stage contributes an independent signal and when exceptions are rare, reviewed, and measured. Current guidance suggests organisations should also watch for signals that the same device, number, or image pattern is being reused across many applications, because repeated reuse is a common indicator of organised fraud rather than isolated applicant error. The Ultimate Guide to NHIs — Key Challenges and Risks is relevant as a practitioner reference because it shows how weak proof and poor lifecycle control create broad abuse conditions in identity systems.
- Use one factor to prove possession, not just knowledge of biographical data.
- Use a separate factor to reduce replay, impersonation, or synthetic enrolment risk.
- Treat mismatched device signals, repeated contact points, and failed liveness checks as escalation triggers.
- Review any manual override path, because onboarding fraud often targets the exception process rather than the normal flow.
These controls tend to break down when organisations treat each factor as a checkbox instead of testing whether the full path resists coordinated fraud.
Common Variations and Edge Cases
Tighter onboarding often increases customer friction, review load, and abandonment, so organisations need to balance fraud resistance against conversion and accessibility. That tradeoff is real: high-assurance steps can be appropriate for higher-risk products, but they may be excessive for low-risk, low-value accounts. Best practice is evolving, and there is no universal standard for how many checks every onboarding flow must use.
Some cases also need different treatment. A first-party payroll account, a small consumer wallet, and a regulated financial account do not carry the same exposure, so the verification mix should reflect the risk of misuse and the value of the account. Likewise, factors that work well against synthetic identity fraud may add less value against credential-stuffing abuse if the primary weakness is downstream account takeover rather than initial enrolment. The NIST Cybersecurity Framework 2.0 is helpful for framing this as a governance and risk decision rather than a pure controls exercise. Where regulated onboarding is involved, the control set should be tuned to the fraud model, not just the technology stack.
Risk and Threat Considerations
Digital account opening is a high-value target because attackers can combine stolen personal data, synthetic identities, and automation to pass weak verification steps at scale. The risk is not just account fraud at sign-up; weak onboarding can create durable trusted access that later supports money movement, abuse, or laundering activity.
Failure mechanism: Single-factor or low-independence onboarding fails when one compromised signal is enough to establish trust. Reused phone numbers, intercepted one-time codes, deepfake selfies, and manual-review shortcuts can let an applicant appear legitimate even when the underlying identity is fraudulent.
Impact: Organisations can open accounts for impostors, absorb chargebacks or losses, increase compliance exposure, and weaken downstream monitoring because the account entered the system through an apparently valid path.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA — Identity Management, Authentication, and Access Control | Onboarding verifies applicant identity and access legitimacy before account issuance. |
| GV.RM — Risk Management Strategy | Onboarding friction, fraud loss, and review depth require explicit risk trade-off decisions. | |
| Recommendation — Strengthen identity proofing and authentication checks before granting account access. Align onboarding verification depth to the organisation's fraud risk appetite. | ||
| CIS Controls v8 | 6 — Access Control Management | Onboarding establishes initial access paths and should limit excessive or unverified account access. |
| Recommendation — Enforce access approval and least privilege during account creation and activation. | ||
| NIST SP 800-63 | IAL — Identity Assurance Level | Account opening risk depends on the strength of identity proofing performed during onboarding. |
| Recommendation — Set the required identity assurance level based on the account's fraud and compliance exposure. | ||
Practitioner Guidance
What to prioritise: Test whether your onboarding factors are actually independent. If every step can be satisfied with the same stolen data set, the control is weaker than it looks and should be redesigned before more friction is added.
What to verify: Confirm that escalation paths are reviewed, logged, and measurable. The hidden failure is often not the factor itself but the exception path, where fraud analysts override controls without consistent evidence thresholds.
Decision rule: If the account can enable payments, credit, or regulated access, treat onboarding as a fraud gate with strong review discipline. If the account is low-impact, a lighter pattern may be acceptable, but only if the residual misuse risk is explicitly understood.
Practitioner takeaway: The real control objective is not to make onboarding harder for everyone; it is to make it materially harder for an attacker to satisfy the whole trust chain with one compromised identity story.
Related resources from NHI Mgmt Group
- How should security teams reduce account takeover risk in digital identity programmes?
- How should organisations reduce identity theft risk in digital onboarding?
- How should security teams reduce account takeover risk in high-friction digital channels?
- Why does two-factor authentication reduce account takeover risk when passwords are compromised?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 9, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org