Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM Why do organisations that already have e KYC…
Identity Beyond IAM

Why do organisations that already have e KYC in place recover onboarding activity faster during lockdowns?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 14, 2026 Domain: Identity Beyond IAM

Pre built e KYC channels reduce dependency on physical branches and dealer networks, which is why they can absorb demand when those channels shut down. The operational impact is continuity of onboarding and account activation, even under movement restrictions. Organisations that rely only on face to face verification usually lose volume immediately, while digitally enabled firms can keep serving customers remotely.

Why e KYC changes onboarding resilience during lockdowns

Organisations with e KYC already embedded can keep proving customer identity without relying on branch appointments, in-person signatures, or dealer visits. That matters most when movement restrictions disrupt physical verification channels, because onboarding stops being tied to a place and a timetable. The result is not just convenience, but a narrower operational dependency that preserves activation flow when traditional verification collapses.

That resilience is strongest when e KYC is treated as part of the onboarding operating model, not as an emergency add-on. Current guidance on identity assurance and digital verification aligns with the same basic point: if the control path is already digital, the organisation can absorb demand shifts without rebuilding process under pressure. The FATF Recommendations — AML and KYC Framework remains the clearest high-level reference for how customer due diligence expectations are structured around identity assurance.

In practice, the firms that recover fastest are usually the ones that had already standardised document capture, identity verification, and exception handling before the disruption arrived.

How e KYC keeps onboarding moving in practice

e KYC works because it replaces a branch-dependent sequence with a remote verification workflow that can be executed through web, mobile, or assisted digital channels. Instead of waiting for a physical meeting, the organisation can validate identity evidence, run screening checks, and route cases into approval or remediation queues. That allows onboarding to continue even when call centres, branches, or distribution partners are partially unavailable.

In operational terms, the main advantage is not speed alone. It is the ability to preserve volume when one channel fails. A well-run e KYC flow usually includes:

  • remote capture of identity evidence and supporting documents
  • automated validation rules for basic format and completeness checks
  • screening and risk review for higher-risk or exception cases
  • clear fallbacks when a customer cannot complete the digital path on first pass

That design matters because lockdowns do not remove demand, they remove access to physical processing capacity. Organisations that had already invested in digital identity workflows can redirect staff to review exceptions rather than manually processing every application. The same pattern is consistent with the control emphasis in the NIST SP 800-53 Rev 5 Security and Privacy Controls, where controlled verification, logging, and access discipline support more resilient service delivery.

Where e KYC breaks down is in environments that still require heavy manual review for most cases, because digital intake then becomes only a front door, not a true operating channel.

Common variations and edge cases

Tighter identity controls often increase friction, so organisations need to balance conversion against assurance. Not every onboarding flow should be fully automated, and not every customer segment can be pushed through the same digital journey on the first attempt.

There are a few common edge cases:

  • Jurisdictions may require specific evidence, audit trails, or identity assurance steps that slow remote onboarding.
  • Customers with poor document quality, limited device access, or low digital confidence may still need assisted completion.
  • Higher-risk products often need enhanced due diligence, so faster onboarding is constrained by control requirements rather than technology.

Organisations with mature e KYC usually recover faster because they have already separated routine cases from exceptions. That is especially important under lockdown conditions, where the goal is not to remove scrutiny, but to prevent the entire onboarding pipeline from depending on a single physical verification path. Where regulations demand stronger digital identity assurance, the eIDAS 2.0 , EU Digital Identity Framework is a useful reference point for how verifiable digital identity can support cross-border trust.

Risk and Threat Considerations

The main risk during lockdowns is operational concentration. If customer onboarding depends on one physical control point, any disruption to branches, agents, or dealer networks can create immediate capacity loss, delayed revenue, and backlog build-up. A second risk is control drift, where organisations relax verification too far in an effort to restore volume quickly.

Failure mechanism: When digital identity controls are immature, teams either stop onboarding entirely or push manual exceptions through with inconsistent review. Both outcomes create exposure, the first through service unavailability and the second through weaker assurance and poor traceability.

Impact: The business loses activation velocity, service continuity, and sometimes compliance confidence at the same time, which can be hard to unwind once demand returns.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC — Identity Management, Authentication and Access ControlSupports controlled identity verification and access governance in digital onboarding
Recommendation — Apply PR.AC controls to govern identity verification, approval, and exception handling in onboarding.
NIST SP 800-53 Rev 5IA-2 — Identification and Authentication (Organizational Users)Covers identity assurance controls relevant to remote customer onboarding workflows
AU-2 — Event LoggingPreserves traceability for remote onboarding and exception review decisions
AC-2 — Account ManagementConnects onboarding to controlled account activation and lifecycle handling
Recommendation — Use IA-2 aligned controls to validate identity evidence and tighten onboarding authentication steps. Log identity checks, exceptions, and approvals so remote onboarding remains auditable. Tie onboarding approvals to AC-2 processes so account activation follows verified identity checks.

Practitioner Guidance

What to prioritise: Treat remote onboarding as a continuity control, not just a customer experience feature. The highest-value step is to identify which applications can be approved end to end without physical touchpoints, then isolate the remaining exception cases for manual handling.

What to verify: Confirm that the digital path still produces a defensible audit trail under pressure, including identity evidence, exception reasons, and approval ownership. If the process only works when staff are available to compensate informally, it is not resilient enough to absorb a lockdown or similar disruption.

Practitioner takeaway: The organisations that recover fastest are the ones whose onboarding process already has a digital default, because resilience comes from removing physical dependency before the disruption arrives.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 14, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org