Really. So anyone can physically break into an archiving unit, steal someone's BC, change some details and use it get benefits/fraud? And the victim wouldn't even get a hint? Sounds very dangerous!
I have my details saved in a centralised database, which notifies me via an SMS anytime my credentials are used.
I acknowledge the BM issue elsewhere in this thread. But please realise that unless you live in a cave your BM are already public. I can take you out for a coffee and steal your finger prints.
The point is that for KYC/payments BM are much more secure than the alternative you would use - signatures/xerox which are even easier to steal since you just need a pen and a paper.