Remote relationships remove the benefit of in-person verification, so firms must rely more heavily on document authenticity checks, data validation, and due diligence controls. That increases exposure to synthetic identities, forged documents, and incomplete risk assessment. The practical answer is to strengthen verification, apply step-up review where needed, and document decisions so the organisation can show reasonable control.
Why This Matters for Security Teams
Remote onboarding changes the risk profile because the organisation loses the strongest informal control in identity assurance: direct, face-to-face corroboration. In Switzerland, that matters for financial crime prevention, customer due diligence, and evidence quality. When a relationship begins entirely online, the business must prove that identity data, documents, and intent were checked to a defensible standard, not merely accepted at face value. That is why remote onboarding often increases scrutiny under AML and KYC processes, especially where the customer presents higher inherent risk or the relationship is likely to involve payments, beneficial ownership, or cross-border activity. Guidance from the FATF Recommendations - AML and KYC Framework is often used as the baseline for this kind of control design.
Practitioners sometimes assume that a good document scan is enough. It is not. Non-face-to-face relationships increase exposure to forged identity documents, synthetic identities, mule activity, account takeover, and weak beneficial owner verification. They also create more pressure on staff to accept incomplete evidence because the customer journey is digital and time-sensitive. In practice, many compliance teams encounter the weaknesses only after an attempted fraud, sanctions issue, or audit challenge has already exposed the gap in verification discipline rather than through intentional control design.
How It Works in Practice
Strong remote onboarding controls combine identity verification, fraud detection, sanctions and watchlist screening, and recordkeeping. The control objective is not to recreate face-to-face checks exactly, but to compensate for what physical presence used to reveal naturally: document anomalies, inconsistency in behaviour, and signs of coercion or impersonation. A mature process usually includes layered validation, with automated checks followed by manual review when confidence is low or the customer risk rating is elevated.
Typical control patterns align with the NIST SP 800-53 Rev 5 Security and Privacy Controls approach to identity, access, auditability, and evidence retention. They also map well to the NIST Cybersecurity Framework 2.0 emphasis on governance, identity management, and risk response.
- Verify the identity document and the person presenting it using liveness or equivalent assurance methods where allowed.
- Cross-check biographical data, contact details, and source-of-funds information for internal consistency.
- Escalate higher-risk cases to a human reviewer before account activation or transaction enablement.
- Retain evidence of what was checked, what failed, and why the decision was accepted or rejected.
- Apply periodic refresh checks for customers whose risk profile changes after onboarding.
For regulated firms, the key question is whether the control set is proportionate to the inherent risk and whether it can be demonstrated to auditors and supervisors. Alignment with ISO/IEC 27001:2022 Information Security Management and ISO/IEC 27002:2022 Information Security Controls helps organisations treat onboarding as a governed control process rather than a one-time form-filling exercise. These controls tend to break down when onboarding is fully automated for high-risk customers because exception handling, evidence capture, and review ownership become ambiguous.
Common Variations and Edge Cases
Tighter onboarding controls often increase friction, cost, and abandonment risk, requiring organisations to balance assurance against customer experience. That tradeoff is real, especially in Switzerland where remote channels may be necessary for cross-border customers, expatriates, or digital-first services.
Current guidance suggests there is no universal standard for the exact verification mix that must be used in every case. The right design depends on the customer type, product risk, jurisdictional exposure, and whether the firm can independently validate information from reliable sources. For low-risk relationships, streamlined checks may be defensible if supported by a documented risk model. For higher-risk cases, best practice is evolving toward stronger step-up checks, enhanced due diligence, and clearer escalation paths for ambiguous evidence.
Edge cases matter. A customer may pass document checks but still present risk because the beneficial owner cannot be verified, the source of funds is weak, or the device and behavioural signals suggest impersonation. Similarly, a legitimate customer may fail automated checks because of poor image quality, name transliteration, or limited digital footprint. In those situations, the compliance decision should be explainable, consistent, and tied to policy rather than intuition. Organisations that can show why a remote relationship was accepted, rejected, or deferred are in a stronger position than those that rely on a single verification outcome.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-63 set the technical controls, while DORA and PCI DSS v4.0 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM-01 | Remote onboarding needs risk-based governance and documented control decisions. |
| NIST SP 800-63 | IAL2 | Identity assurance level drives how much evidence is needed without face-to-face checks. |
| DORA | Digital onboarding controls affect operational resilience and third-party dependent processes. | |
| PCI DSS v4.0 | 12.3 | Where payment services are involved, governance over remote onboarding procedures matters. |
Document onboarding procedures, exceptions, and oversight when remote customer setup supports payment activity.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org