What it means
A customer asks support to change account ownership or export sensitive data, but the usual identity check fails because the customer has lost their phone. Customer identity verification exception rate measures the share of eligible verification attempts that need an approved alternative, escalation or rejection because the standard path did not establish identity.
Define the event first, since one person can attempt verification several times, and specify attempt-based or case-based counting. NIST's digital identity guidance describes proofing exceptions and errors, including ways to support applicants who lack the usual evidence, while the UK Information Commissioner's Office advises verifying requester identity and the destination for information in access requests.
These are distinct contexts, not a single global identity policy. Define the standard path, since login, multifactor challenge and account records may provide different assurance for different actions, and risk-match the action, because viewing a public help article does not need the same proof as changing a payout account.
Check the source, as an email address or caller ID alone does not prove the person controls the customer account, and check the destination, since a requester may pass identity proof but ask for data to be sent to an unverified new address. Preserve accessibility, because people may lack a particular phone, document or device and an approved alternate route can protect access without weakening controls.
Review delegated access too, as an employee can be authorised by a company even if they are not the account owner, so confirm that role. Record the reason, since a lost authenticator, mismatched name, expired document, suspected impersonation and system outage are different exceptions, and set the outcome so that alternative verified, unresolved, denied and referred for investigation are reported separately.
Do not share sensitive data during the check, because verification is a gate, not an excuse to reveal account facts to help a caller pass, and avoid overcollection by asking for evidence proportionate to the action and retaining it under the privacy policy. Record timestamps so that the initial attempt, alternative evidence, final decision and any account action are distinct.
Track attempts, as repeated guessing can be an abuse signal but legitimate customers may also struggle with a broken flow, and separate false rejects, since a high exception rate might reveal accessibility or data-quality problems rather than widespread fraud. Check automated matches, because similar names, transliteration and outdated records can generate legitimate exceptions, and handle outages without inventing alternate controls ad hoc if the standard identity provider is down.
Use human review, with an approved escalation path and a traceable reviewer, for high-risk exceptions, and audit override use, since a privileged staff override without rationale can hide unauthorised changes. Show open cases, as a case stuck waiting for evidence is not a successful verification, report by action because billing changes, privacy requests and basic account support may have different exception rates, and keep the denominator honest, since excluding difficult cases makes the rate appear artificially low.
Pair it with outcome quality, because a low exception rate can mean a smooth process or weak checks, so review sampled decisions, and protect staff by handling a disputed identity neutrally rather than with accusations based on one mismatch. An exception should not disappear when an agent ultimately completes the task, because the rate tracks the difficult path while the outcome tracks whether access was correctly granted or withheld, so use the measure to improve safe, accessible verification without granting access from an unverified claim.
In practice
Real-world examples.
Example
Of 200 high-risk support verifications, 12 need an approved alternate route, a 6% exception rate. The team lists the reasons, such as lost phones and expired documents. Eight of the twelve are verified through the alternative and the account change goes ahead.
Example
A customer has lost an authenticator but passes the documented recovery process, so the case remains an exception with a valid final outcome. The agent records the evidence and the reviewer. The exception is counted even though access was correctly restored.
Example
A caller knows an email address but cannot satisfy the required check, so no private export is sent. The agent explains the approved ways to verify and does not disclose any account detail. The case is logged as denied or unresolved, not as a success.
Formula
Calculation
Exception rate = eligible verification cases routed outside the standard approved path / all eligible verification cases attempted x 100. Report verified, unresolved and denied outcomes separately.
Worked example. A fictional support team handles 200 high-risk verification cases in a month, and 12 are routed outside the standard path.
- Exception rate = 12 / 200 x 100 = 6%.
- Of the 12 exceptions, 8 are verified through an approved alternative, 3 are denied and 1 is still unresolved, so 8 + 3 + 1 = 12.
- The report shows the 6% together with these outcomes and the reasons, such as lost authenticators or expired documents.Case study
Seen in the real world.
This entirely fictional case follows Meadow Support. A customer could not use an old phone number to pass verification for an account change. The agent followed the approved recovery route, withheld account details until verification and recorded the alternate evidence and decision. The case is not authority to change any real account.
Meadow later reviewed its exception reasons and found that many came from customers with outdated phone numbers. It added a safe prompt to update contact details and a clearer recovery page. The exception rate fell, and sampled decisions were reviewed to confirm that the checks had not become weaker.
Watch out
Common mistakes.
- Treating caller ID or a familiar email address as sufficient identity proof.
- Inventing an undocumented override when the normal challenge fails.
- Calling a legitimate accessibility exception evidence of fraud.
Questions
People also ask.
Does an exception mean the person is fraudulent?
No. It means the standard route was not enough or did not work.
Can there be an alternative path?
Yes, if it is approved for the action risk and properly recorded.
Should the destination also be checked?
Yes. Identity proof alone does not authorize disclosure to an arbitrary new address.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%Related
