By NHI Mgmt Group Editorial TeamBased on Strivacity: “Why financial services needs a new way to measure customer identity” (October 8, 2025)

TL;DR: Financial services firms still measure CIAM with uptime, API calls, and latency even though the business impact shows up in fraud losses, onboarding abandonment, support costs, and compliance pressure, according to Strivacity. The governance gap is that customer identity is often tracked as a technical service instead of a financial control.


At a glance

What this is: This is a Strivacity analysis arguing that financial services teams measure customer identity with technical KPIs instead of business outcomes tied to fraud, cost, growth, and compliance.

Why it matters: That matters because IAM leaders need CIAM reporting that boards, CFOs, and regulators can act on, not just service health metrics that fail to show business impact.

By the numbers:

  • $40 billion in projected U.S. fraud losses by 2027 are part of the cost of weak customer identity outcomes, according to Strivacity.
  • 60–68% of digital account openings are abandoned, according to Strivacity.
  • 20–50% of help desk calls are tied to password resets, each costing about $70, according to Strivacity.

Context

Customer identity metrics in financial services are supposed to show whether identity controls support revenue, risk reduction, and operational efficiency. In practice, many programmes still report technical service health and leave business impact to separate dashboards, which makes CIAM hard to govern as a financial control.

That gap matters because account opening, fraud prevention, customer support, and compliance all depend on identity decisions. When those outcomes are not measured together, identity leaders cannot prove value to the board or prioritise work against the business losses that matter most.


Key questions

Q: How should financial services teams measure CIAM success beyond uptime?

A: Measure customer identity against business outcomes that matter to the board, such as fraud losses, onboarding completion, help desk cost, and compliance burden. Keep operational metrics, but treat them as inputs. The governance question is whether identity controls change revenue, risk, and cost in ways executives can see and fund.

Q: Why do technical CIAM metrics fail to satisfy board reporting?

A: Because uptime and latency describe platform health, not enterprise impact. Boards need to know whether customer identity is reducing fraud, improving conversion, lowering support demand, or avoiding compliance cost. If a metric cannot be translated into one of those outcomes, it is incomplete for governance purposes.

Q: What breaks when customer identity is tracked only as an IT service?

A: Identity leaders lose the ability to prove value, and executives underestimate how much CIAM affects the bottom line. That creates a funding problem and a prioritisation problem at the same time. The result is often underinvestment in controls that could materially change fraud, cost, or growth outcomes.

Q: How do customer identity metrics differ from general IAM reporting?

A: Customer identity metrics should show commercial and operational impact, not only access reliability. For financial services, that means linking authentication and onboarding performance to revenue protection, customer completion, support load, and compliance pressure. IAM reporting that stops at service health misses the governance signal.


Technical breakdown

Why technical CIAM KPIs fail financial services governance

Metrics such as uptime, API calls, and latency describe service performance, not business effect. In CIAM, the control question is whether identity reduces fraud, abandonment, support cost, and compliance exposure. A technical dashboard can show that the login stack is healthy while the organisation still loses money through failed onboarding or excessive reset volume. That is why outcome-based measurement is not a reporting preference. It is the only way to connect customer identity to executive decisions about growth and risk.

Practical implication: replace pure service KPIs with outcome metrics tied to fraud, abandonment, support load, and revenue.

How customer identity links to fraud, cost, and growth

Customer identity sits upstream of several business outcomes at once. Stronger onboarding and authentication can reduce fraud exposure, lower help desk volume, and improve completion rates, while poor identity flows push customers out before account opening finishes. The article’s point is not that every metric must be financial in isolation, but that the metric set must explain a financial effect. That gives identity leaders a line from control decisions to business performance that technical metrics alone cannot provide.

Practical implication: map each CIAM control to one financial outcome so the board can see cause and effect.

Why business-outcome reporting changes board conversations

Boards do not fund identity because it is elegant infrastructure. They fund it when they can see reduced loss, lower operating cost, better customer conversion, or less compliance friction. A business-outcome model changes the conversation from whether CIAM is available to whether it is producing measurable value. That shift also improves prioritisation, because teams can compare identity initiatives by impact rather than by engineering visibility alone.

Practical implication: present CIAM as a business control with measurable returns, not as a platform uptime report.


NHI Mgmt Group analysis

Customer identity metrics have been over-indexed on service health for too long: uptime, latency, and API counts are operational signals, but they are not governance signals. In financial services, the real question is whether CIAM changes fraud exposure, onboarding conversion, support demand, and compliance cost. When those outcomes are not on the same scorecard, identity gets treated as plumbing instead of a control domain.

Identity outcome measurement is now a board-level governance problem: the article shows that fraud losses, abandonment, and reset costs are already large enough to justify a different measurement model. That is a financial governance issue, not a reporting preference. Practitioners should expect more scrutiny on whether identity programmes can express value in the language of loss reduction, revenue protection, and operating efficiency.

CIAM needs a business control model, not a technical dashboard: the industry still fragments fraud, customer experience, and support metrics into separate views, which hides the cumulative effect of identity decisions. Business outcome metrics is the right named concept here because it captures the missing layer between identity operations and enterprise value. The practical implication is that CIAM owners must be able to defend spend with outcome evidence, not infrastructure telemetry.

The organisations that win here will connect identity decisions to economic outcomes: account opening conversion, support deflection, fraud containment, and compliance pressure should be tracked as a single governance story. That does not mean every metric becomes financial accounting, but it does mean identity leaders need one narrative that executives can use in budgeting and risk review. Practitioners should reframe CIAM measurement around decision quality, not dashboard volume.

From our research library:

What this signals

Business outcome metrics: CIAM in financial services is moving from a technical service view to a control view that executives can budget against. That shift matters because identity now touches fraud, onboarding, support, and compliance in the same business process, so the scorecard has to reflect the combined effect rather than isolated system health.

Boards will keep asking identity teams for evidence that translates into money saved, revenue protected, or friction removed. Programmes that cannot connect their controls to those outcomes will struggle to justify investment, even when the underlying technology is working as designed.


For practitioners

  • Define a CIAM outcome scorecard Tie customer identity metrics to fraud loss, onboarding completion, support cost, and compliance burden instead of tracking uptime alone.
  • Separate service health from business impact Keep API latency and availability in operations reporting, but add a second layer that shows what those service levels change in customer and financial outcomes.
  • Quantify onboarding abandonment by identity step Break digital account opening into discrete identity stages so you can see where customers drop out and which control changes improve completion.
  • Translate password reset volume into cost Use help desk ticket volume, average reset cost, and authentication friction to show how customer identity design affects operating expense.

Key takeaways

  • Customer identity should be measured as a business control in financial services, not just as a platform with uptime and latency targets.
  • The article links weak outcome reporting to major costs, including fraud losses, abandonment, and password reset support demand.
  • Practitioners need a CIAM scorecard that connects identity decisions to fraud, growth, operating expense, and compliance outcomes.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-63 set the technical controls, while GDPR defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OV-01 — Oversight of Cybersecurity StrategyCIAM metrics here are a governance and oversight problem, not only a technical service issue.
ID.RA-01 — Asset Vulnerabilities Are Identified and DocumentedThe article shows organisations are not documenting the business risk of customer identity well enough.
PR.AA-05 — Access Permissions, Entitlements and AuthorizationsAuthentication and authorisation choices drive the customer outcomes discussed in the article.
Recommendation — Align CIAM reporting to governance outcomes so executives can oversee fraud, conversion, and support impacts. Document how identity controls affect fraud, abandonment, and service cost as part of risk assessment. Treat access and authorisation decisions as controls that should be evaluated against business outcomes.
NIST SP 800-63SP 800-63C — FederationCustomer identity metrics in financial services often depend on federated journeys and login outcomes.
Recommendation — Measure federated customer journeys by completion and risk outcomes, not just authentication uptime.
GDPRArt.5(2) — AccountabilityFinancial services identity reporting often supports accountability for personal data processing and customer access.
Recommendation — Keep identity metrics auditable so accountability for customer data processing is demonstrable.

Key terms

  • Business Outcome-Based Measurement: Business outcome-based measurement evaluates IT by the operational and financial value it creates, not just by cost or activity volume. It links technology decisions to productivity, resilience, uptime, and risk reduction. This approach helps leaders justify investment in controls that prevent disruption and enable growth.
  • Customer Identity And Access Management: Customer Identity and Access Management is the discipline of governing how external users sign in, recover access, and move through digital services. It combines authentication, profile management, and lifecycle control so organisations can deliver secure, low-friction experiences at scale.
  • Onboarding Abandonment: Onboarding abandonment is the point at which legitimate users stop a registration flow before completing it. In identity programmes, it is a governance signal as much as a conversion metric because excessive friction can push organisations toward weaker verification decisions.
  • Identity Control Effectiveness: The extent to which an identity control produces the intended operational or business result. For customer identity programmes, effectiveness means the control can be tied to lower fraud, lower support demand, better completion rates, or other measurable outcomes.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org