By NHI Mgmt Group Editorial TeamDomain: Identity Beyond IAMSource: FingerprintPublished November 24, 2025

TL;DR: Fragmented point solutions leave banks blind to AI-driven fraud, according to Fingerprint, with 41% of fraud attempts in its survey described as AI-driven and financial institutions reporting 54% exposure. The governance lesson is that fraud, identity, and compliance now need shared, real-time signals rather than isolated checks.


At a glance

What this is: This is an analysis of how device intelligence can unify fraud, identity, and compliance signals in banking, with the key finding that siloed controls create blind spots against AI-driven fraud.

Why it matters: It matters because financial institutions increasingly need shared identity and device context to reduce false positives, strengthen KYC and AML controls, and preserve onboarding speed without weakening assurance.

By the numbers:

👉 Read Fingerprint's analysis of device intelligence for banking fraud and compliance


Context

Banking fraud has become a governance problem as much as a detection problem. When fraud, identity, compliance, and cybersecurity teams operate separate tools and separate data views, the organisation ends up with repeated verification, delayed alerts, and weak correlation across sessions. The primary issue is not a lack of controls, but a lack of shared context across the identity lifecycle and customer risk decision points.

Device intelligence sits in the middle of that gap by connecting browser, network, and behavioural signals into a persistent view of a returning user or device. For IAM and identity verification teams, the important question is how to use those signals without turning them into another silo. That intersection between fraud prevention, KYC, and identity governance is where the article is most relevant to NHIMG readers.


Key questions

Q: How should banks use device intelligence without creating another silo?

A: Banks should treat device intelligence as a shared decision layer, not a stand-alone fraud tool. The signals need to feed onboarding, authentication, investigations, and compliance workflows so the same context supports multiple decisions. If the data cannot be reused across teams, it is adding cost without improving trust decisions.

Q: Why do AI-driven fraud attacks bypass traditional KYC controls?

A: Traditional KYC controls are designed to verify a person once, not to prove that the same person is still present later. AI-driven fraud exploits that gap with synthetic identities, face swaps, and adaptive social engineering. The control failure is not identity collection, but the lack of runtime revalidation when risk changes.

Q: What breaks when fraud and identity teams work in silos?

A: When fraud and identity teams work in silos, policy decisions diverge, exceptions are handled inconsistently, and no one owns the full trust lifecycle. That creates both over-blocking and under-blocking. The business then absorbs the cost as manual review, lost conversion, and weak auditability.

Q: Who is accountable when fraud controls block legitimate customers in real time?

A: Accountability should sit with the team that owns the end-to-end decision path, not only the fraud model. If checkout, identity, and risk signals are not orchestrated into one control, then the business is responsible for the conversion loss as well as the fraud loss. Governance needs shared ownership across fraud, product, and security leaders.


Technical breakdown

Why siloed fraud stacks miss cross-session identity patterns

Traditional fraud stacks score individual events, such as a failed login or a suspicious geolocation, but they often fail to connect those events across sessions and teams. That creates a structural blind spot when the same device, browser, or behavioural pattern reappears under different identities. Device intelligence addresses this by building a persistent signal layer from browser, network, and device attributes. The important architectural point is not just detection volume, but continuity of identity context across channels and sessions.

Practical implication: unify device and identity signals into one review path so fraud teams can correlate behaviour before account abuse scales.

How AI-driven fraud changes KYC and AML signal design

AI-assisted fraud can generate synthetic identities, mimic normal interaction patterns, and spread activity across many accounts to avoid threshold-based controls. That breaks compliance designs that depend on isolated KYC checks or periodic reviews. Continuous monitoring becomes essential because the attack is adaptive, not static. For financial institutions, the control challenge is to connect onboarding, session behaviour, and transaction patterns into one risk model that can detect repeated device reuse, coordinated logins, and identity misuse.

Practical implication: extend KYC and AML monitoring beyond onboarding into session-level and cross-session anomaly detection.

Why a shared intelligence layer matters more than another point product

The article points to a common enterprise failure mode in which each team buys a control that answers only its own question. Fraud tools look for abuse, identity teams verify users, and compliance teams produce audit evidence, but none of them independently provide a complete trust decision. Shared intelligence is the architectural response. It does not eliminate specialist controls, but it reduces the cost of false positives and the time spent reconciling conflicting signals. That is especially important where customer friction and regulatory scrutiny pull in opposite directions.

Practical implication: evaluate whether each control contributes reusable identity context or merely adds another isolated alerting layer.


Threat narrative

Attacker objective: The attacker objective is to abuse bank trust decisions at scale while avoiding detection across onboarding, authentication, and transaction monitoring.

  1. Entry begins when fraudsters use AI to create synthetic identities or imitate legitimate user behaviour across onboarding and login flows.
  2. Escalation occurs when the same actor reuses devices, fingerprints, or session patterns to bypass isolated controls and blend into normal activity.
  3. Impact follows when coordinated account takeover, identity misuse, or payment abuse bypasses KYC and compliance checks at scale.

NHI Mgmt Group analysis

Fragmented fraud governance is now a trust failure, not just an efficiency problem. When fraud, identity, and compliance teams rely on separate telemetry, they create inconsistent risk decisions for the same customer journey. That inconsistency is exactly what adaptive fraud exploits because the attacker only needs one disconnected control path to succeed. For practitioners, the governance test is whether one decision fabric can support KYC, AML, and fraud review together.

Device intelligence creates a persistent trust layer, but only if identity teams own its use model. The value is not in collecting more signals for their own sake. The value is in turning device and behavioural context into a reusable identity decision input across onboarding, authentication, and investigation workflows. That makes the device signal part of identity governance rather than a separate fraud silo, which is the right framing for financial services.

Cross-session correlation is the named capability banks need to sharpen now. The article describes the operational gap clearly: isolated checks cannot see repeated device reuse, linked sessions, or coordinated fraud rings. Cross-session correlation is the control concept that closes that gap by preserving context over time. For security leaders, the practical conclusion is that a point-in-time review model is no longer sufficient for high-volume digital banking.

AML and KYC controls are being stress-tested by AI, not replaced by it. AI-driven fraud does not remove the need for compliance evidence, but it does invalidate assumptions that periodic checks and static risk scoring are enough. The field needs monitoring that is continuous, auditable, and shared across teams. Practitioners should treat this as a redesign of evidence flow, not a tuning exercise.

What this signals

Cross-session identity correlation is becoming a core control requirement for financial services. The pattern here is broader than fraud tooling. Banks need a repeatable way to connect onboarding, session behaviour, and case evidence so that trust decisions survive across channels and over time. Where identity data already exists, device intelligence should enrich it rather than duplicate it.

The governance signal is that customer experience and control strength no longer have to sit in opposition. Organisations that can reuse context across fraud, compliance, and IAM reduce friction without weakening evidence quality. The practical benchmark is whether a team can explain why a customer is trusted using shared data instead of a stack of unrelated alerts.


For practitioners

  • Unify fraud and identity review queues Route onboarding, authentication, and case-management events into a shared queue so fraud analysts and identity teams review the same device and session context before escalating.
  • Add cross-session correlation to KYC workflows Preserve device and behavioural continuity across sessions so repeated fingerprints, geolocation shifts, and account reuse are visible during KYC and AML monitoring.
  • Measure false-positive reduction by context reuse Track whether the same device intelligence signal can resolve multiple investigations, rather than generating isolated alerts that each team must re-interpret.
  • Map device signals to compliance evidence Document which device, browser, and behavioural indicators support audit trails for suspicious activity decisions, then align them with existing control evidence requirements.

Key takeaways

  • Fragmented fraud, identity, and compliance tooling leaves banks unable to see the full trust picture across the customer journey.
  • Fingerprint's survey data shows AI-driven fraud is already material, which makes static, one-off verification controls increasingly brittle.
  • The right response is shared context, not more isolated checks, so that KYC, AML, and fraud decisions can reuse the same evidence.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST SP 800-63 set the technical controls, while GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4Shared trust decisions depend on controlled access and consistent identity context.
NIST SP 800-53 Rev 5AU-2The article stresses audit-ready, continuous monitoring across fraud and compliance workflows.
NIST SP 800-63SP 800-63BThe identity-verification angle aligns with authenticators and session assurance.
GDPRArt.32Device intelligence used in identity verification and fraud detection must protect personal data.

Use AU-2 to define which device and behavioural events become audit evidence for suspicious activity.


Key terms

  • Device Intelligence: Device intelligence is the practice of interpreting signals from a device to assess whether a session or transaction is likely legitimate. It goes beyond fingerprinting by combining device context with behavioural, identity, and payment evidence to support a risk decision.
  • Cross-Session Correlation: Cross-session correlation is the practice of linking events across accounts, devices, infrastructure, and time to reveal coordinated behaviour. It is the difference between seeing one clean session and seeing an abuse campaign that only becomes visible when many clean sessions are analyzed together.
  • Unified Asset Intelligence Layer: A near real-time view of an organisation’s assets, suppliers, and externally visible exposures. It combines internal inventory with telemetry from outside the environment so teams can identify which weaknesses are reachable, which are being targeted, and where defensive effort will reduce operational risk fastest.
  • Synthetic Identity: A synthetic identity is a software-based actor that can authenticate, request access, and execute actions without being a human user. In practice, this includes AI agents, bots, service accounts, tokens, and other machine identities that need clear ownership, scope, and revocation.

What's in the full article

Fingerprint's full article covers the operational detail this post intentionally leaves for the source:

  • How device intelligence evaluates hundreds of browser, network, and device signals in practice
  • Examples of how banks can use shared intelligence to cut false positives without weakening customer verification
  • The specific ways device continuity supports fraud, compliance, and identity workflows across sessions
  • Why AI-driven fraud changes the balance between friction, onboarding speed, and auditability

👉 The full Fingerprint article covers the signal model, fraud scenarios, and compliance use cases in more detail.

Deepen your knowledge

NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, IAM, secrets management, and workload identity. It helps practitioners connect identity controls to the broader security and risk decisions their programmes depend on.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 15, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org