Join our Newsletter — 33% off our NHI Course
Home› Glossary› Authentication, Authorisation & Trust› Identity Verification Friction
Authentication, Authorisation & Trust

Identity Verification Friction

← Back to Glossary
By NHI Mgmt Group Updated September 27, 2026 Domain: Authentication, Authorisation & Trust

Identity verification friction is the delay, effort, or inconvenience added when a merchant asks a customer to prove who they are. Excessive friction can suppress conversion, frustrate travellers, and create operational overhead. The practical goal is to verify risk without interrupting the purchase journey unnecessarily.

What identity verification friction actually is

identity verification friction is not just “extra checks.” It is the measurable effort a customer must spend proving who they are, often through document capture, liveness checks, one-time codes, knowledge questions, or manual review. The term matters because friction changes behaviour: too little can weaken assurance, while too much can disrupt legitimate purchases.

In practice, friction sits at the boundary between fraud control and customer experience. That makes it a design problem as much as a security problem, especially in channels where a merchant must balance conversion, chargeback exposure, and regulatory expectations. For customer onboarding and payment flows, identity assurance is often shaped by Identity Proofing and KYC Guide and by external identity standards such as NIST SP 800-63 Digital Identity Guidelines.

Why friction appears in the verification journey

Friction is usually introduced to raise confidence that the person or account is real, present, and authorised to proceed. The common triggers are higher-value purchases, travel-related bookings, account recovery, unusual device or location signals, and regulatory obligations that require stronger assurance before a transaction or onboarding step can continue.

Not all friction is identical. A lightweight step-up challenge may be enough for a low-risk purchase, while stronger identity proofing is appropriate when a merchant must resist synthetic identity, document forgery, or remote fraud. That is why merchants often distinguish between ordinary authentication and deeper identity proofing, as reflected in resources such as Ultimate Guide to NHIs — Standards for control alignment and OpenID Connect Core 1.0 for federated authentication patterns.

How to think about the trade-off

The central trade-off is assurance versus abandonment. If the merchant removes too much friction, fraudsters may get through with less resistance. If the merchant adds too much, honest customers may abandon the flow, contact support, or defer the purchase. The right level depends on the value of the transaction, the trust history of the customer, and the confidence already available from signals such as prior sessions, device reputation, or payment history.

Well-designed friction should feel proportionate, not arbitrary. The best flows use step-up checks only where needed, and keep the burden as low as possible elsewhere. That principle is consistent with broader security controls that favour risk-based verification over blanket escalation, including OWASP ASVS for authentication and access control expectations and eIDAS 2.0, the EU Digital Identity Framework for cross-border identity verification.

Where identity verification friction becomes operationally significant

Identity verification friction is often visible first as conversion loss, but the operational impact can be broader. More manual reviews increase support volume, delay order completion, and create backlogs for fraud or compliance teams. In travel and other time-sensitive journeys, the same friction can become a customer-service issue because the user experience is tightly coupled to timing and certainty.

That is why organisations usually treat friction as a tunable control rather than a fixed compliance hurdle. It should be measured against outcomes such as completion rate, review rate, false reject rate, and the cost of exceptions. For governance and risk framing, the related assurance logic aligns with Identity Security Programme Guide and, where customer due diligence is central, with FATF Recommendations, the AML and KYC framework.

Risk and Threat Considerations

Excessive identity verification friction can become a security and business risk in its own right. It can push legitimate users out of the journey, increase abandoned carts, and create pressure to weaken checks later, which is a common way stronger controls erode over time.

Failure mechanism: Poorly calibrated verification adds repeated or ambiguous steps, causing false rejects, manual-review backlog, and customer workarounds that bypass the intended assurance path.

Impact: The merchant loses conversion and customer trust, while attackers may benefit if frustrated users migrate to weaker fallback channels or support-assisted recovery paths.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, OWASP ASVS and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63Digital Identity GuidelinesDefines identity assurance and step-up verification used to manage friction.
Recommendation — Use assurance levels to tune verification strength to transaction risk.
OWASP ASVSV6 — AuthenticationCovers authentication strength and step-up verification patterns that shape user friction.
Recommendation — Verify only as much as the risk and session context require.
NIST SP 800-53 Rev 5IA-8 — Identification and Authentication (Non-Organizational Users)Applies when customer identity verification creates access friction for external users.
IA-12 — Identity ProofingDirectly addresses proving a customer's identity before granting access or completing onboarding.
Recommendation — Apply external-user authentication controls proportionate to customer risk. Use identity proofing commensurate with the assurance required by the flow.
ISO/IEC 27001:2022A.5.17 — Authentication informationSupports control over verification material and authentication handling in identity journeys.
Recommendation — Protect authentication information so verification steps do not weaken assurance.

Practitioner Guidance

Why practitioners should care: The practical question is not whether verification is present, but whether the burden is proportionate to the risk being managed. A good flow preserves confidence without turning every purchase into a high-friction event.

Governance implication: Ownership should sit with fraud, identity, and product teams together, because the correct threshold depends on both assurance need and commercial tolerance. If those teams work in isolation, the result is often either over-verification or under-verification.

Practitioner takeaway: Treat friction as a control to tune, not a badge of rigor to maximise.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org