
The onboarding question is not “How much information can we collect?” It is “What confidence do we need before allowing this customer to do this?”
01 Onboarding is a risk decision
Every onboarding step exists for a reason.
Identity verification.
Address.
Business information.
Source of funds.
Device intelligence.
Sanctions screening.
Fraud signals.
The problem begins when teams stop remembering which reason belongs to which step.
The result is one giant onboarding form designed around organisational anxiety rather than actual customer risk.
02 Start from capability
Before deciding what information to collect, define what the customer will be allowed to do.
Can they receive money?
Hold funds?
Send domestically?
Send internationally?
Access credit?
Increase limits?
Different capabilities create different exposure.
Your assurance model should follow that.
03 Separate mandatory from conditional
Some controls are required before the relationship begins.
Others become relevant only under particular conditions.
Designing those together produces unnecessary friction.
A cleaner model distinguishes:
baseline assurance,
capability-based checks,
risk-triggered checks,
and ongoing monitoring.
My framework is
Name: The Risk-Led Onboarding Model
CAPABILITY
What will we allow?
EXPOSURE
What can go wrong?
ASSURANCE
What confidence is required?
FRICTION
What is the minimum customer burden consistent with that assurance?
MONITORING
What signals could change the decision later?
04 Risk should continue after onboarding
A customer is not permanently low-risk because they looked low-risk at registration.
Behaviour matters.
Transaction patterns matter.
Device changes matter.
New information matters.
That means onboarding should not be expected to predict the customer forever.
A stronger product establishes sufficient confidence to start the relationship and then keeps learning.
05 Measure the journey as both risk and product
Track conversion.
But also track:
false positives,
manual reviews,
time to decision,
fraud outcomes,
re-verification,
support contacts,
and downstream risk.
A “high-converting” onboarding flow that creates enormous risk is not successful.
Neither is an ultra-safe flow that rejects legitimate customers indiscriminately.
The product problem is to find the appropriate point between them.
Responses
Responses are reviewed before they appear.