Document-not-present describes an onboarding or verification scenario where the business cannot inspect a physical identity document in person. The customer submits images or scans instead, often through a mobile device or webcam. This model increases convenience, but it also shifts trust to software controls that must detect fakes, edits, and impersonation.
Expanded Definition
Document-not-present is a verification method used when a business cannot inspect a physical identity document face to face and instead relies on uploaded images, scans, or live capture from a device. It is common in remote onboarding, age checks, and account recovery flows where convenience and reach matter more than in-person assurance.
The key boundary is that the term describes the verification condition, not the broader identity programme around it. It is different from document-present checks because the assessor cannot examine tactile features, lighting, or document handling directly. It also differs from generic eKYC, which may combine document-not-present evidence with database checks, biometrics, or liveness review. Guidance on how much assurance is acceptable varies by use case, so industry practice is not fully uniform; the required evidence should be set by the risk of the transaction, not by convenience alone.
A common misunderstanding is to treat a clear image as proof of authenticity. In practice, the image quality may be excellent while the document itself is synthetic, altered, or misused by a proxy applicant.
Examples and Use Cases
Document-not-present appears wherever onboarding must happen remotely and the organisation needs a defensible way to compare submitted evidence against expected identity attributes. It is a workflow pattern, not a single technology choice.
- Digital bank account opening that requests a passport or national ID upload before the first transfer limit is enabled.
- Insurance or telecom enrolment that accepts a front-and-back scan of an identity document through a mobile app.
- Age verification for a regulated service where the user submits a document image and the system checks expiry, format, and field consistency.
- Customer recovery flows that re-verify identity after a device reset or address change using remote document capture.
The main tradeoff is friction versus assurance. Faster capture improves completion rates, but it can also reduce the amount of human scrutiny available when the document has been tampered with or when the applicant is presenting a legitimate document that does not belong to them.
Security Implications
Document-not-present creates a narrower trust surface than in-person verification, because the business must infer authenticity from media and metadata rather than from the original document itself. That makes image quality checks, forgery detection, and identity binding controls central to the process.
When the workflow is weak, the practical failure modes are predictable: edited images can pass manual review, reused document photos can be replayed across services, and lookalike or proxy applicants can exploit review teams that rely on visual familiarity instead of structured checks. The result is fraudulent onboarding, account takeover support, or downstream abuse of a verified account.
A useful practitioner observation is that many failures occur at the handoff between automated screening and manual exception handling. If reviewers do not see why a submission was flagged, they may approve the same weak evidence the machine already questioned.
Domain and Governance Relevance
Document-not-present matters most in identity verification and customer onboarding because it changes the evidential standard used to establish trust. The organisation is no longer assessing a person and a document together in the same physical moment; it is assessing a remote representation, which makes provenance, tamper detection, and policy thresholds more important.
That shift also affects governance. Teams need explicit rules for what evidence is sufficient, when to step up to stronger checks, and when to reject or retry a submission. In higher-risk journeys, remote document capture is rarely enough on its own and should be paired with risk-based review, fraud signals, or stronger identity proofing. For NHI Management Group readers, the NHI lesson is indirect rather than central: when onboarding feeds privileged customer tooling or delegated access, weak remote verification can become the first link in a broader trust failure.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, NIST CSF 2.0, CIS Controls v8 and NIST IR 8596 set the technical controls, while PCI DSS v4.0 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | IAL2 — Identity Assurance Level 2 | Remote document checks often support moderate identity proofing. |
| Recommendation — Use IAL2 when remote evidence must establish a stronger proofing baseline than self-asserted identity. | ||
| NIST CSF 2.0 | PR.AA — Identity Management, Authentication and Access Control | Document-not-present affects how identity is established before access is granted. |
| Recommendation — Apply PR.AA controls to bind remote proofing outcomes to downstream access decisions. | ||
| CIS Controls v8 | 5 — Account Management | Verified onboarding governs whether an account should be created or trusted. |
| Recommendation — Use Control 5 to ensure only validated identities are converted into active accounts. | ||
| NIST IR 8596 | Identity Proofing and Verification | Directly addresses identity proofing when documents are submitted remotely. |
| Recommendation — Treat remote document capture as proofing evidence that needs verification and escalation rules. | ||
| PCI DSS v4.0 | 12.3.3 — Targeted Risk Analysis for Custom Controls | Where payment onboarding relies on remote document checks, the control needs risk-based justification. |
| Recommendation — Perform a targeted risk analysis before relying on document-not-present checks for card-related onboarding. | ||
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 10, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org