Identity Proofing of Vendors
The Credential Belongs to Alex Chen. Who Is Alex Chen?
7 min read · 26 June 2026 · Security
A financial services firm maintained strict identity verification requirements for all internal employees , background checks, government ID verification, and in-person identity confirmation before system access was granted. For vendor staff accessing their systems, the process was considerably lighter: the vendor submitted a list of names and email addresses, the firm created accounts, and the accounts were distributed to the vendor's named contacts. During a routine vendor security review, the firm asked the vendor to confirm which team members currently had active access. The vendor's account manager provided a list that differed from the firm's active account list , five names on the firm's list were not on the vendor's current team roster. Investigation found that three were former vendor employees whose access had not been deprovisioned, one was a subcontractor name that the vendor had no record of, and one account had been created in response to a request that the vendor's account manager had no recollection of authorising. The firm's identity verification process for vendor staff had assumed that a name and email address submitted by a vendor contact was sufficient proof of identity. It was not.
What is Identity Proofing for Vendor Access, Really?
Identity proofing is the process of verifying that the individual requesting access or for whom access is being requested is who they claim to be , establishing a reliable binding between a digital identity (an account and credential) and a specific real-world person with a confirmed identity. For internal employees, identity proofing typically occurs at hiring through background checks, government ID verification, and in-person or video-verified onboarding. The proofing event establishes that the account belongs to a real, verified individual whose identity has been confirmed. For vendor staff, most organisations have no equivalent proofing process.
The vendor nomination gap is the structural source of vendor identity proofing risk. Vendor staff access is typically initiated through a nomination from the vendor's account team , a name and contact detail submitted to the customer for account provisioning. The customer confirms the vendor relationship is active, creates the account for the nominated name, and distributes the credential. No element of this process verifies that the nominated name corresponds to a real current employee of the vendor, that the account manager making the nomination has authority to do so, or that the person who ultimately uses the account is the person whose name appeared on the nomination.
The impersonation and delegation risk is where the identity proofing gap creates concrete harm. Vendor staff accounts are sometimes used by individuals other than the named account holder , a colleague covers for someone who is out, a subcontractor operates under a vendor employee's credential, or in more malicious scenarios, a former employee's credential is used by someone who was not intended to have access. Without identity proofing, the customer has no reliable mechanism to confirm that the person accessing their environment is the person whose account they are accessing it from. The account name is the fiction the customer accepts as the identity.
- Vendor nomination as substitute for identity proofing , accepting a name from a vendor contact without verification that the name corresponds to a current employee
- No employment verification at onboarding , accounts created without confirming current employment status of the named individual
- Credential sharing and delegation , vendor staff accounts used by individuals other than the named holder
- Subcontractor access under vendor employee credentials , subcontractors accessing customer environments with vendor employee account names
- No periodic identity re-verification , initial proofing (where it exists) not repeated to confirm ongoing validity
Why this matters
Identity proofing of vendors matters for TPRM because the security properties of vendor access , least privilege, individual accountability, behavioral monitoring , all depend on the assumption that the account holder identity is accurate. Least privilege assigned to 'Alex Chen' is only meaningful if the person accessing the account is actually Alex Chen with Alex Chen's job function and authorization. Individual accountability for access events attributed to 'Alex Chen' is only meaningful if the person performing those actions is actually Alex Chen. Behavioral monitoring baselines established for Alex Chen are only useful if the account behavior is actually Alex Chen's behavior.
The subcontractor access scenario is particularly relevant in supply chain risk contexts. Vendors frequently use subcontractors or third-party specialists for portions of their work , and those subcontractors may access customer environments under the vendor's employees' credentials if the customer has not established access pathways for subcontractors. The customer's risk assessment covers the vendor. It may not cover the subcontractor operating under the vendor's credential who has different security posture, different governance, and different accountability than the named account holder.
For TPRM practitioners, identity proofing for vendor staff does not require the same rigor as employee background screening , but it requires more than accepting a nomination list from a vendor contact. At minimum, it requires confirmation that nominated individuals are currently employed by the vendor at the time of account creation, that the account creation was authorized by an appropriate level of the vendor organization, and that subcontractor access is disclosed and governed separately from vendor employee access.
Where most teams get this wrong
The most consistent failure is treating vendor account nomination as equivalent to identity proofing. A list of names submitted by a vendor account manager confirms that the account manager submitted those names. It confirms nothing about the employment status, identity, or authorization of the nominated individuals. The nomination is the request. The proofing is the verification. Most vendor access processes have the former without the latter.
- Treating vendor nomination as equivalent to identity proofing
- No employment verification at nomination , accepting names without confirming current employment
- No disclosure or governance of subcontractor access
- No periodic identity re-verification for long-tenured vendor access
- No authorization level requirement for nomination , any contact can nominate any name
What good looks like
Mature vendor identity proofing programs establish verified identity at account creation through employment confirmation, require authorized nomination with an appropriate seniority level, disclose and separately govern subcontractor access, and periodically re-verify that active account holders remain current employees of the vendor organization.
- Employment confirmation at nomination , confirmation that named individuals are currently employed by the vendor before accounts are created
- Authorized nomination requirement , nomination must be made by a named, authorized vendor contact at an appropriate seniority level
- Subcontractor access disclosure , any subcontractor accessing the environment under vendor credentials disclosed and separately assessed
- Periodic re-verification , identity confirmation repeated periodically for long-term vendor access relationships
- Video-verified onboarding for high-privilege access , video call identity confirmation for vendor staff receiving privileged access
Tooling
Identity Verification , Jumio, Persona, Onfido
Digital identity verification platforms provide automated ID document verification, facial recognition matching, and liveness detection that can be integrated into vendor onboarding workflows. For high-privilege vendor access, requiring vendors to submit staff through a digital identity verification step provides a proofing mechanism that exceeds nomination-only processes. For TPRM practitioners, asking whether the vendor has verified the identity of the staff they nominate for customer environment access provides the identity proofing question.
Vendor Management Platforms , ProcessUnity, OneTrust, Prevalent
Vendor management platforms with personnel tracking features maintain records of approved vendor staff with employment verification , enabling systematic tracking of which individuals have been verified and when verification was last performed. For TPRM practitioners, asking whether the vendor's personnel records for customer-access staff include employment verification dates provides a specific identity proofing documentation question.
Governance challenges
The governance challenge with vendor identity proofing is the proportionality question. Internal employee identity proofing is a comprehensive, resource-intensive process because the stakes of hiring the wrong person are high and the relationship is long-term. Vendor staff identity proofing that is equally comprehensive for every contractor and temporary vendor contact would be operationally burdensome. The governance resolution is risk-tiered proofing , lighter verification for low-privilege, short-term vendor contacts, more rigorous proofing for staff receiving privileged or long-term access to sensitive environments.
- Require employment verification for all vendor staff receiving customer environment access
- Require authorized nomination from a named, verified vendor contact
- Require subcontractor disclosure before subcontractor accesses customer environment under vendor credentials
- Implement periodic re-verification for vendor staff with long-term access
- Require video-verified onboarding for privileged vendor access
If you are a small team
Add one verification step to your vendor staff onboarding: before creating accounts for vendor-nominated staff, send a confirmation email to the vendor's named security or HR contact , not the account manager who made the nomination , asking them to confirm that the nominated individuals are currently employed by the vendor. That single verification step closes the most common identity proofing gap: accepting a name from a single vendor contact without any cross-check of employment status. For privileged access, add a video call confirmation before the account is activated.
- Add employment confirmation to vendor staff onboarding , email to HR or security contact, not the nominating account manager
- Require authorized nomination from a named, senior vendor contact
- Add subcontractor disclosure requirement to vendor access agreements
- Implement video-verified onboarding for vendor staff receiving privileged access
What to require
Ask directly:
"For staff you nominate for access to our environment, what confirmation do you provide that each named individual is currently employed by your organization , and is the nomination authorized by a specific named contact at an appropriate seniority level?"
"Will any access to our environment be performed by subcontractors or third-party specialists rather than direct employees of your organization , and if so, are those individuals disclosed to us and governed under separate access provisions?"
Expect as evidence
- Employment verification confirmation for nominated staff
- Authorized nomination process documentation , who can nominate and at what level
- Subcontractor disclosure policy and access governance
- Periodic re-verification process for long-term vendor access
A vendor who confirms their standard onboarding process should be asked what specifically verifies that each nominated name corresponds to a currently employed individual , and whether subcontractor access under employee credentials is disclosed. The nominaton is the request. The employment confirmation is the proofing.
How to evidence it
- Employment verification records for vendor staff with customer environment access
- Authorized nomination documentation
- Subcontractor disclosure records
- Periodic re-verification records for long-term vendor access
Key Takeaway
The credential belongs to Alex Chen. Who is Alex Chen is the question that identity proofing answers. A name on a nomination list submitted by a vendor account manager is a name. Identity proofing makes it a verified person , currently employed by the vendor, authorized for the access they are receiving, not a subcontractor operating under a vendor employee's credential, and confirmed to be the person who actually uses the account rather than a proxy. Vendor access programs that skip identity proofing are granting access to names. Identity-verified access programs are granting access to people. The distinction matters when something goes wrong and attribution requires knowing who the person behind the account actually was.
Speak to It™
The term you nodded along to, explained in ninety seconds, so you can speak to it professionally. It is how most readers find these articles.
Join the Association