TL;DR: A reported 180% rise in sophisticated multi-step attacks across 2024 to 2025 underscores how identity signals, device intelligence, and behaviour monitoring are converging in enterprise fraud controls, according to SumSub. Fraud governance is no longer separate from identity governance, because the same trust decisions now span user onboarding, transaction monitoring, and real-time risk response.
At a glance
What this is: This is a recognition story about enterprise fraud controls, with Chartis positioning Sumsub as a Category Leader and highlighting the shift toward identity signals, device intelligence, and real-time fraud detection.
Why it matters: It matters because fraud detection is converging with identity governance, so IAM, fraud, compliance, and NHI teams are increasingly making decisions from the same trust signals and response workflows.
By the numbers:
- The share of sophisticated multi-step attacks increased by 180% over 2024-2025, according to SumSub.
Context
Fraud identity controls are no longer limited to onboarding checks or static risk rules. The article frames fraud as a live trust problem, where identity signals, device intelligence, and behavioural monitoring all contribute to one real-time decisioning layer.
That shift matters for identity governance because the same evidence now influences verification, authentication, transaction review, and escalation. When fraud operations and identity governance pull from the same signals, control design has to account for lifecycle, context, and response together rather than as separate programmes.
Key questions
Q: Where do identity trust controls fail in practice?
A: They fail when separate controls validate different parts of the path but do not present a unified signal to the user. A secure message, a valid certificate, and a protected connection can still feel untrustworthy if the recipient cannot tell who is behind it or where it is going.
Q: Why do identity signals matter in fraud prevention models?
A: Identity signals matter because fraud rarely appears as a single event. It shows up across accounts, devices, payment methods, and behavioural changes, so a model that cannot correlate those relationships will miss serial abuse or overreact to legitimate customer variance. Identity context makes decisions more accurate and more defensible.
Q: How should teams decide when to step up fraud controls?
A: Use observed risk change as the trigger, not just the presence of a new session or transaction. Step-up controls work best when they respond to anomalies in device continuity, behavioural sequence, or transaction context, because those changes often reveal that the same actor is progressing through a fraud chain.
Q: What does convergence between fraud and identity governance mean for security teams?
A: It means the same evidence now supports verification, response, and compliance decisions, so separate operating models become inefficient and inconsistent. Teams need shared ownership of trust signals, escalation logic, and review outcomes, otherwise one function can undermine the controls another function depends on.
Technical breakdown
Identity signals as fraud control inputs
Identity-centric fraud controls use multiple evidence sources to decide whether a session, transaction, or account creation attempt is trustworthy. In this model, identity signals are not just onboarding data. They include device reputation, behavioural patterns, and historical risk context that can be scored in real time. The practical value is in combining signals fast enough to make an intervention before fraud completes, rather than after the loss is recorded.
Practical implication: map which trust signals are used at onboarding, during session activity, and at transaction time so gaps are visible.
Device intelligence and behavioural monitoring
Device intelligence links a user or session to the characteristics of the endpoint being used, such as fingerprint consistency, environment anomalies, and reputation history. Behaviour monitoring adds interaction patterns, timing, and sequence anomalies that can expose scripted or coordinated fraud. Together, these controls reduce reliance on single-factor trust decisions and make it harder for attackers to reuse stolen identities across channels.
Practical implication: correlate device and behaviour telemetry with identity records so suspicious continuity, reuse, or drift is detectable.
Real-time fraud decisioning across the user journey
Real-time decisioning means the control does not wait for batch review or post-incident analysis. It evaluates trust continuously across the full user journey, from registration through payment or account activity, and can trigger step-up checks, review, or blocking in line with policy. That architecture matters because sophisticated fraud often succeeds by changing form mid-journey rather than at one obvious entry point.
Practical implication: define the decision points where automated intervention can occur before fraud progresses to irreversible impact.
Threat narrative
Attacker objective: The attacker aims to complete fraud while appearing trustworthy enough to move through identity checks, transaction controls, and response thresholds.
- Entry occurs through onboarding, account creation, or session initiation where identity trust is first established.
- Escalation follows when attackers use device changes, behavioural adaptation, or multi-step social engineering to move past initial controls.
- Impact arrives when fraudulent activity completes inside the same trust chain that should have detected anomaly, reuse, or coordination.
NHI Mgmt Group analysis
Fraud controls are becoming identity governance controls. The article shows that identity signals, device intelligence, and behavioural monitoring are now part of the same trust decision layer. That means fraud programmes are no longer separate from IAM or compliance in practice, even if the org charts still say otherwise. The practitioner implication is that control ownership must be shared across identity, fraud, and risk teams.
Identity-centric fraud models only work when trust is evaluated continuously. Static onboarding rules are too narrow for multi-step fraud that changes shape during the session. A programme that treats verification as a one-time gate will miss the moment when legitimate-seeming activity becomes malicious. The implication is that decisioning architecture, not just detection content, is now a core governance issue.
Fraud identity controls now create an identity blast radius. Once the same signals drive onboarding, step-up, monitoring, and investigation, poor data quality or weak correlation logic affects every downstream decision. That expands the blast radius from a single false positive to a programme-wide trust failure. Practitioners need to govern signal lineage and decision thresholds as first-class control surfaces.
Chartis recognition matters because it reflects category convergence, not just vendor positioning. The market is increasingly rewarding platforms that can connect identity verification to fraud detection and compliance workflows. For practitioners, that signals a shift away from isolated point controls toward integrated trust architectures. The practical conclusion is that programme design should be evaluated on signal reuse, response speed, and governance coherence.
Multi-step fraud is exposing the limits of point-in-time assurance. The reported 180% increase in sophisticated attacks shows that fraud now behaves like a chained process, not a one-off event. Controls that only certify identity at the start of a journey do not address how attackers persist through later stages. The implication is that assurance has to follow the journey, not just the login.
From our research library:
- Nearly 60% of companies reported that fraud losses were still increasing in 2025.
What this signals
Identity-centric fraud controls are now a governance pattern, not a niche detection tactic. Once identity signals and device intelligence drive real-time decisions, fraud operations and IAM start sharing the same evidence base. That forces practitioners to treat signal lineage, decision thresholds, and escalation paths as programme controls rather than implementation details.
The real shift is from static assurance to journey-based assurance. Multi-step fraud is designed to survive the first check and adapt after it. Teams should expect future controls to be evaluated on how well they preserve trust decisions across the full lifecycle, not just at the point of enrolment.
For practitioners
- Map trust decisions across the full user journey Document where onboarding, session monitoring, payment review, and case management each consume the same identity signals so governance gaps are visible.
- Separate signal quality from decision ownership Assign clear owners for identity data quality, device telemetry, behavioural indicators, and fraud decision thresholds so one weak input does not distort every downstream action.
- Test for multi-step attack progression Exercise scenarios where the same actor changes device, behaviour, or channel mid-journey to see whether controls still correlate the activity as one risk path.
- Review step-up and blocking thresholds Validate that escalation rules are tied to observed risk changes, not just login events or static policy triggers, so response can occur before fraud completes.
- Align fraud and IAM governance Create a shared operating model for fraud, compliance, and identity teams so verification, monitoring, and investigation use the same lifecycle logic.
Key takeaways
- Fraud controls now sit inside the identity governance problem because the same signals increasingly support onboarding, monitoring, and response.
- The reported 180% rise in sophisticated multi-step attacks shows why point-in-time verification is no longer enough on its own.
- Practitioners should govern identity signals, decision thresholds, and escalation paths as one trust architecture rather than separate fraud and IAM processes.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP API Security Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP API Security Top 10 | API2 — Broken Authentication | Fraud identity controls hinge on reliable authentication and trust decisions across user journeys. |
| Recommendation — Review authentication paths for weak trust decisions that let fraud progress after initial verification. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Identity-driven fraud governance depends on correct authorisation and trust evaluation at each decision point. |
| Recommendation — Align trust decisions with PR.AA-05 so access and transaction responses reflect current risk. | ||
| CIS Controls v8 | CIS-5 — Account Management | Fraud identity control relies on managing account lifecycle, reuse, and abnormal change patterns. |
| Recommendation — Apply CIS-5 to govern account creation, change, and review paths that fraud can abuse. | ||
Key terms
- Identity-Centric Fraud Governance: An operating model that treats fraud detection, identity proofing, and access decisions as one connected control problem. It uses identity evidence, device context, and behavioural signals to decide whether a person or account should be trusted at each stage of a journey.
- Device Intelligence: Device intelligence is the practice of interpreting signals from a device to assess whether a session or transaction is likely legitimate. It goes beyond fingerprinting by combining device context with behavioural, identity, and payment evidence to support a risk decision.
- Behavioural Monitoring: Behavioural monitoring is the practice of watching for abnormal identity or workflow patterns after authentication succeeds. In source-code security it can reveal bulk downloads, unusual commit timing, or approval bypasses that suggest insider misuse or account compromise.
- Real-Time Fraud Decisioning: Real-time fraud decisioning is the practice of evaluating a payment or account action before it completes, using identity, behavioural, and transaction signals. In fast-moving P2P systems, it is the difference between preventing abuse and only documenting it after funds have moved.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org