Join our Newsletter — 33% off our NHI Course
Home Glossary Governance, Ownership & Risk Consumer Duty
Governance, Ownership & Risk

Consumer Duty

← Back to Glossary
By NHI Mgmt Group Updated August 27, 2026 Domain: Governance, Ownership & Risk

Consumer Duty is a regulatory expectation that firms deliver outcomes that are fair, understandable, and supportive of customer interests. In lending journeys, it pushes organisations to explain products clearly and avoid designs that pressure people into poor decisions. It is as much about communication quality as it is about product structure.

Expanded Definition

consumer Duty describes a conduct and governance expectation that firms must design, communicate, and support products so customers can reasonably understand them and pursue their interests. In practice, it reaches beyond disclosures and into journey design, digital prompts, product framing, and post-sale support. For NHI and agentic systems, the relevance is indirect but important: automated decision paths, service-to-service workflows, and identity-driven customer interactions can still shape consumer outcomes even when no human is actively approving each step.

Definitions vary across regulators and sectors, and no single technical standard governs this yet. The practical interpretation is that organisations should be able to evidence why a journey is fair, what checks prevent harmful defaults, and how they detect outcomes that degrade customer understanding. That maps well to governance thinking in the NIST Cybersecurity Framework 2.0, where accountability and risk management are operational rather than decorative. The most common misapplication is treating Consumer Duty as a disclosure exercise, which occurs when firms rely on dense terms or consent screens while the underlying journey still nudges customers toward poor decisions.

Examples and Use Cases

Implementing Consumer Duty rigorously often introduces friction in product design and approval cycles, requiring organisations to weigh customer clarity against conversion pressure and time-to-market.

  • A lending portal presents repayment scenarios in plain language, with defaults that avoid steering customers into higher-cost credit unless explicitly justified.
  • An automated service workflow uses identity-linked rules to verify entitlement before account changes, but also logs why a recommendation was shown so the customer can challenge it.
  • A digital onboarding journey limits pre-selected add-ons and uses contextual explanations so customers can understand the tradeoff before accepting.
  • A support assistant that uses policy and account context must be constrained so it cannot overpromise outcomes or obscure exclusions in a scripted interaction.
  • A firm reviewing service accounts and workflow automation checks whether identity-driven actions accidentally create misleading customer experiences, a concern highlighted in the Ultimate Guide to NHIs.

These patterns align with broader governance guidance in the NIST Cybersecurity Framework 2.0, especially where process integrity and accountability shape user trust.

Why It Matters in NHI Security

Consumer Duty matters in NHI security because machine identities increasingly influence customer-facing processes, even when they are not visible to the customer. Poorly governed API keys, service accounts, and automations can produce outcomes that are technically functional but commercially or ethically harmful, such as delayed refunds, incorrect eligibility decisions, or misleading product flows. NHIMG research shows that 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, which underscores how quickly hidden identity problems can become customer-impacting incidents. The same research also notes that only 5.7% of organisations have full visibility into their service accounts, making it difficult to prove that customer journeys are both secure and fair. The Ultimate Guide to NHIs is a useful reference point for understanding why visibility, rotation, and governance are inseparable from outcome quality. Organisations typically encounter the practical force of Consumer Duty only after complaints, mis-selling findings, or remediation exercises, at which point the term becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01Consumer outcomes depend on governance and risk decisions across digital journeys.
NIST AI RMFGOV-1Fair, understandable outcomes require AI governance around design and use.
OWASP Agentic AI Top 10LLM-05Agentic systems can mislead users when outputs or actions are poorly constrained.
CSA MAESTROTRUST-03Trusted agent behaviour requires guardrails around autonomy and customer impact.
NIST SP 800-63Identity assurance supports reliable, auditable customer and service interactions.

Document decision ownership for customer-facing automations and review them against risk objectives.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org