Who was admitted

Identity and verification control testing

Examining the checks that are supposed to confirm a person and an organisation before the onboarding application grants a tenant.

Three to five weeks

Person writing in a notebook beside a laptop during a review

Onboarding applications often treat a clicked link as identity. That may be enough for a low-risk tool. It is not enough if the tenant then receives personal data, payment instruments, or admin rights over other people’s accounts.

We reconstruct a sample of admissions from the event log: what was requested, what was presented, who approved an exception, and whether the tenant was created before the check completed. “The customer was in a hurry” is an explanation only if the override role is named and logged.

Where the flow collects NRIC numbers, company SSM details, or copies of documents, we test whether consent and purpose were recorded in the same application, not in a separate form that nobody can join to the tenant.

Who it is for

Risk, compliance, and operations leads who rely on email, phone, or document checks inside the onboarding flow.

Typical fee note

From RM 15,000. Combined with a full application audit when verification is material to access. Fees are quoted in writing after scoping. This page is not a checkout.

Scope we usually test

  • Email, phone, and domain-verification steps and whether they can be bypassed
  • Staff “verify on behalf” functions and their audit trail
  • Document or registry checks where the flow claims to confirm a company
  • Failed, expired, and reused verification tokens
  • PDPA-relevant collection of identity data before consent is recorded

What you receive

  • Map of verification steps versus what the live flow actually enforces
  • Sample of bypasses, failures, and staff overrides
  • Note on identity data held without a recorded purpose
  • Prioritised control list for operations

Ask the Subang desk to scope this walk