By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: Ping IdentityPublished September 22, 2025

TL;DR: Identity fraud protection is becoming a board-level priority as technology change expands attack surface and executives look to decentralized identity for stronger trust controls, according to Ping Identity. The issue is no longer authentication alone but how identity governance and fraud prevention hold up across increasingly complex digital journeys.


At a glance

What this is: This is a Ping Identity survey report about how AI and identity fraud are reshaping digital trust priorities, with decentralized identity positioned as a response to rising fraud pressure.

Why it matters: It matters because IAM, identity verification, and fraud teams need a governance model that can distinguish legitimate users, services, and automation as identity journeys become more complex.

👉 Read Ping Identity's survey report on AI, identity fraud, and decentralized identity


Context

Identity fraud protection is no longer just a customer experience concern. As AI-enabled fraud techniques evolve, identity programmes need stronger controls that can validate trust across onboarding, authentication, and account recovery without creating brittle user journeys.

Ping Identity frames decentralized identity as a way to reduce fraud pressure in digital experiences. For IAM and identity verification teams, the real question is how far current controls can distinguish real users from manipulated or synthetic interactions when identity signals become harder to trust.


Key questions

Q: How should security teams reduce identity fraud without blocking legitimate users?

A: Use layered decisioning instead of single-step checks. Combine document verification, behavioural signals, device intelligence, and recovery risk scoring so trust is assessed across the full journey. The goal is not to stop every suspicious event at the first gate, but to make fraud expensive enough that repeated abuse no longer scales.

Q: Why does decentralized identity matter for fraud prevention in financial services?

A: It matters because wallet-based, out-of-band approval reduces dependence on reusable personal and payment data that attackers exploit in browser and API-driven fraud. When verification is bound to the holder, device, and local approval step, attackers face a higher bar than simply stealing stored identity data.

Q: What do teams get wrong about identity-based fraud detection?

A: Teams often assume identity verification at onboarding is the main trust decision. In practice, the trust posture has to be reassessed during the session or transaction because fraud can emerge after the first check passes. The mistake is treating identity as a gate instead of a continuously scored signal that changes with context.

Q: Should organisations adopt decentralized identity for every use case?

A: No. Decentralized identity is useful where selective disclosure, portability, or reduced data sharing creates real value. It is not automatically the best fit for every process, especially where revocation, issuer trust, or operational readiness is immature. Start with the use cases that benefit most from reduced exposure.


Technical breakdown

Why identity fraud and digital trust now overlap

Identity fraud has expanded beyond stolen passwords and account takeover. Modern fraud combines manipulated identity attributes, synthetic signals, and social engineering across digital journeys, which means the control problem is not limited to login. The challenge is establishing trust at each identity decision point, including proofing, step-up checks, session validation, and recovery. Decentralized identity is often discussed here because it can reduce repeated disclosure of sensitive attributes, but the core issue remains governance: how much assurance is enough for a given transaction and identity risk.

Practical implication: map trust requirements by journey stage, not just by authentication method.

Where AI changes the identity fraud equation

AI makes fraud more scalable because it lowers the cost of producing believable text, images, and behavioural patterns. That matters for identity teams because fraud detection signals can be imitated, weak identity proofing can be exploited at scale, and recovery processes become attractive targets. The security issue is not that AI creates a new identity category by itself, but that it amplifies existing weaknesses in verification, friction management, and exception handling. Identity programmes that rely on static rules will struggle when attack patterns change faster than policy updates.

Practical implication: treat AI-driven fraud as a test of identity process resilience, not just detection tooling.

How decentralized identity changes the control model

Decentralized identity shifts some trust assertions away from central repositories and toward verifiable claims that can be presented when needed. In practice, that can reduce unnecessary data exposure and improve selective disclosure, but it does not remove the need for issuer trust, wallet security, revocation handling, or policy decisions about which claims matter. For IAM architects, the key issue is that decentralized identity changes where trust is checked, not whether trust is required. Governance still needs to define acceptable issuers, revocation paths, and assurance thresholds.

Practical implication: evaluate decentralized identity as a trust distribution model, not a fraud cure.



NHI Mgmt Group analysis

AI-driven identity fraud is now a governance problem, not only a detection problem. As fraud techniques become easier to generate and harder to distinguish from legitimate activity, identity programmes need assurance models that extend beyond login. The practical takeaway is that proofing, recovery, and exception handling now sit inside the fraud perimeter.

Decentralized identity reduces disclosure risk, but it does not remove trust decisions. Verifiable claims can limit unnecessary data exposure, yet every deployment still depends on issuer trust, revocation, wallet security, and policy enforcement. Practitioners should treat the model as a control redesign, not a shortcut around identity governance.

Identity journeys are the new fraud surface. Attackers increasingly target the points where organisations verify, recover, or re-establish identity, because those are the places where exceptions are easier to exploit. Teams need to review the full journey, not just the primary authentication event.

Fraud resilience will depend on aligning identity assurance with transaction risk. A single fixed level of verification does not match the way modern digital services operate. The stronger pattern is risk-based identity governance that can raise or lower assurance requirements based on context, value, and sensitivity.

What this signals

Identity fraud programmes will increasingly need to sit inside broader IAM governance rather than operate as a separate fraud layer. The practical shift is toward assurance decisions that are tied to context, recovery risk, and transaction sensitivity, with stronger alignment between identity operations and customer trust outcomes.

For identity architects, the next step is to decide where decentralised claims help and where they simply relocate complexity. The governance question is not whether a trust claim is portable, but whether the organisation can verify issuer quality, manage revocation, and keep recovery flows from becoming the easiest attack path.


For practitioners

  • Map fraud exposure across the full identity journey Review proofing, registration, login, recovery, and escalation paths as one control plane. Identify where attackers can exploit weak checks, manual exceptions, or inconsistent assurance levels.
  • Reassess where decentralized identity actually reduces risk Use decentralized identity where selective disclosure and verifiable claims lower unnecessary data sharing, but only after defining issuer trust, revocation handling, and recovery fallback.
  • Align assurance to transaction risk Set identity verification thresholds by transaction sensitivity, account value, and fraud impact so low-risk actions do not create excessive friction and high-risk actions receive stronger checks.

Key takeaways

  • AI is making identity fraud easier to scale, which pushes identity teams to govern the full user journey rather than only authentication.
  • Decentralized identity can reduce unnecessary exposure, but issuer trust, revocation, and recovery governance remain mandatory.
  • The strongest fraud programmes tie identity assurance to transaction risk instead of applying one uniform control model everywhere.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-63 set the technical controls, while ISO/IEC 27001:2022 and GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-1Identity fraud protection depends on verifying identities before access is granted.
NIST SP 800-63SP 800-63BThe article is about identity assurance and authentication confidence.
ISO/IEC 27001:2022A.5.15Access control governance is central to fraud-resistant identity journeys.
GDPRArt.32Decentralized identity can reduce data exposure in identity verification flows.

Map proofing and authentication decisions to PR.AC-1 and require risk-based assurance for sensitive journeys.


Key terms

  • Decentralized Identity: A model where users control portable credentials and present them to applications for verification. Instead of one organisation holding all identity data, trust is distributed across issuers, wallets, and relying parties, which changes how access decisions, recovery, and account linking must be governed.
  • Identity proofing: The process of verifying that a person is who they claim to be before granting or restoring access. In higher-risk recovery paths, proofing can include stronger evidence checks such as government ID validation or liveness-based facial verification so the assurance level matches the sensitivity of the request.
  • Risk assurance: Risk assurance is the evidence that a control is actually constraining identity exposure, not just existing on paper. In practice, it includes segregation of duties, access validation, and audit-ready proof that privileged and non-human access is being governed consistently.

What's in the full report

Ping Identity's full survey report covers the operational detail this post intentionally leaves for the source:

  • Survey findings on executive priorities and how respondents are weighing decentralized identity against other trust controls.
  • The report's broader consumer and digital experience context, including how identity strategy affects user trust.
  • Additional survey framing on the next major digital threat and why fraud protection is becoming more central to identity programmes.

👉 Ping Identity's full report provides the survey framing and market context behind the fraud protection shift.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on July 28, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org