By NHI Mgmt Group Editorial TeamBased on SumSub: “Sumsub Joins Merchant Risk Council to Advance Fraud Prevention and Digital Trust” (June 8, 2026)

TL;DR: Merchant fraud is increasingly blending identity verification, account takeover, synthetic identity, and payment abuse into one control problem, according to SumSub. That convergence makes lifecycle governance, fraud signals, and customer trust management inseparable for practitioners.


At a glance

What this is: SumSub’s MRC membership announcement frames fraud prevention and identity verification as a single control problem spanning merchants, marketplaces, and digital platforms.

Why it matters: It matters because IAM, fraud, and trust teams increasingly need shared lifecycle, verification, and risk signals to stop abuse without fragmenting customer controls.


Context

Merchant risk here means the set of controls used to prevent abuse across onboarding, payments, seller activity, and account access. The article argues that this space is no longer separable from identity verification because fraud patterns now mix synthetic identities, account takeovers, fake accounts, and payment abuse.

For identity practitioners, the important shift is architectural rather than organisational. If identity proofing, behavioural risk, payment controls, and lifecycle decisions sit in different teams, attackers can move through the gaps between them. The article positions merchant fraud as a convergence problem for IAM, fraud operations, and trust management.


Key questions

Q: What breaks when identity verification, authentication, and fraud controls are managed in separate systems?

A: Separate systems usually create duplicated data, inconsistent decisions, and weak context sharing. That leads to more false confidence, slower responses to fraud, and higher friction for legitimate users. The failure is not only technical. It is operational. Teams lose continuity, so a good onboarding signal may never inform later authentication or payment risk decisions.

Q: When should teams prioritise identity verification over downstream fraud review?

A: Teams should prioritise stronger identity verification when account creation, seller onboarding, or payout access creates immediate loss potential. Downstream fraud review still matters, but it cannot substitute for identity assurance when the platform is exposed to synthetic identities, account takeovers, or rapid abuse of new accounts.

Q: How should security teams measure whether trust controls are actually working?

A: Security teams should measure trust controls through a small set of operational indicators that show scope, compliance, lifecycle performance, and anomaly trends. The key is to pair each metric with an owner and a response threshold so the number drives action rather than reporting theatre. If a metric cannot change a decision, it is not a control indicator.

Q: What should merchants do when verified accounts start behaving like fraud risk?

A: They should move from verification status to behavioural review, then restrict or suspend privileges that create financial exposure. Verified identity does not equal safe behaviour, so the response should focus on limiting payout access, order abuse, and account misuse before the case is closed.


Technical breakdown

Why merchant fraud now depends on identity verification

Merchant and marketplace fraud is no longer limited to payment abuse at checkout. It now includes who is allowed to create accounts, open seller profiles, place orders, or receive payouts, which makes identity verification part of the fraud control plane. When synthetic identities and stolen identities are used together, the issue is not just transaction risk but trust in the person or entity behind the account. The control challenge is joining identity assurance to ongoing risk monitoring rather than treating onboarding as a one-time event.

Practical implication: align identity proofing with fraud rules so account trust can be revisited as behaviour changes.

How lifecycle governance intersects with fraud signals

Lifecycle governance in this context means controlling when an account is created, escalated, restricted, reviewed, or removed as risk changes. That matters because merchant fraud often evolves after initial verification, especially when mule accounts, promo abuse, or seller fraud begin as apparently valid relationships. The technical issue is that a trusted state can decay after onboarding if review triggers are weak or disconnected from fraud telemetry. Identity teams therefore need lifecycle states that can absorb fraud signals without waiting for a manual case closure.

Practical implication: define review and suspension triggers that are driven by fraud evidence, not just initial identity checks.

Why AI-driven fraud changes the trust model

AI-driven fraud increases the speed and variability of abuse, which weakens controls that assume predictable attacker behaviour. In practice, that means fake accounts, synthetic identities, and account takeovers can be generated, tested, and abandoned faster than static policy rules adapt. The article’s broader point is that trust models built around single-point verification do not hold when fraud adapts continuously across the customer lifecycle. The response has to be dynamic scoring, cross-signal correlation, and faster governance decisions.

Practical implication: move from static verification gates to continuous risk scoring across the account lifecycle.


Threat narrative

Attacker objective: The attacker aims to exploit platform trust for financial gain while avoiding detection across onboarding, payments, and account lifecycle controls.

  1. Entry occurs when attackers use fake accounts, stolen identities, or synthetic identities to pass initial trust checks on a merchant or marketplace platform.
  2. Escalation follows when those accounts are used for seller fraud, promo abuse, mule activity, chargebacks, or payment-related abuse under a trusted profile.
  3. Impact is broader than a single transaction loss because fraud erodes user trust, increases operational burden, and weakens the integrity of the digital ecosystem.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Merchant fraud and identity verification now form one governance surface. The article reflects a broader market reality: identity assurance no longer ends at onboarding, because fraud actors exploit the gap between verified identity and trusted behaviour. That collapse matters for merchant risk teams, IAM leads, and fraud operations alike. Practitioners should stop designing controls around a single verification event and instead govern trust as a lifecycle property.

Lifecycle controls are becoming fraud controls. Fake accounts, mule accounts, seller fraud, and promo abuse all show that the account state itself is now a risk signal. If a platform cannot move an identity from trusted to reviewed to restricted quickly, fraud outpaces governance. The implication is that access decisions, payout permissions, and customer trust states need shared policy logic.

Trust throughout the customer lifecycle is the right named concept here. The article’s core signal is that trust is no longer a front-door problem. It is created, tested, and sometimes lost repeatedly across the full relationship with the merchant or marketplace. Practitioners should therefore design controls that preserve verification value after initial enrollment, not just at the point of sign-up.

AI-driven fraud compresses the response window for identity teams. As fraud becomes more automated, the distance between initial identity acceptance and abusive use keeps shrinking. That makes manual review-only models too slow for modern merchant risk. Practitioners should expect governance to move toward continuous scoring, faster containment, and tighter integration between fraud and identity operations.

The merchant risk category is converging with NHI-style governance patterns. While the subject is customer and seller identity, the governance lesson is similar to NHI programmes: the hardest problem is not creating an identity control, but keeping its trust posture current as conditions change. Teams that already manage lifecycle, entitlement drift, and revocation discipline are better positioned to adapt than teams that still treat fraud as a separate silo.

From our research library:

What this signals

Trust has to be governed as a changing state, not a permanent label. Merchant platforms that continue to treat identity verification as a one-time checkpoint will miss the point of modern fraud control. The more useful operating model is to connect proofing, monitoring, and intervention into one lifecycle so that trust can be reduced as quickly as it was granted.

Fraud and identity teams need a shared decision model. The article signals a practical convergence that many organisations still handle in separate workflows. If identity proofing, account risk scoring, and financial abuse response are not aligned, the platform will keep discovering fraud after the loss has already occurred.


For practitioners

  • Align verification with lifecycle governance Define when an account moves from trusted to monitored to restricted, and tie those states to fraud telemetry rather than initial KYC or onboarding checks alone.
  • Correlate fraud and identity signals Join account creation, login behaviour, payout changes, device signals, and payment outcomes so fake accounts and mule activity are visible in one risk view.
  • Separate customer trust from compliance completion Avoid treating completed verification as a permanent trust outcome, because fraud patterns can emerge after the original identity check has passed.
  • Add fast containment paths for suspicious accounts Create clear escalation steps for promo abuse, seller fraud, stolen identities, and chargeback spikes so teams can limit loss before manual review finishes.

Key takeaways

  • Merchant fraud is increasingly a lifecycle governance problem, not just a payment or onboarding problem.
  • The article points to a convergence of identity verification, account takeover, synthetic identity, and payment abuse.
  • Practitioners should connect identity proofing, fraud telemetry, and containment decisions so trust can change as quickly as risk does.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the technical controls, while GDPR defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsIdentity trust decisions here affect account and payout authorisation across the merchant lifecycle.
Recommendation — Link identity assurance to entitlement decisions so verified accounts can be restricted when fraud risk changes.
CIS Controls v8CIS-5 — Account ManagementThe article centres on account creation, misuse, and lifecycle handling across merchant environments.
Recommendation — Apply account management controls to review, limit, and remove high-risk merchant and marketplace accounts.
NIST SP 800-63SP 800-63A — Enrollment and Identity ProofingThe article’s core subject is identity verification as an input to fraud control.
Recommendation — Use enrollment and proofing outcomes as one input to risk decisions, not as a permanent trust state.
GDPRArt.32 — Security of ProcessingWhere customer identity data is processed, the control challenge includes protecting that data and its use.
Recommendation — Apply security of processing controls to protect identity data used in fraud and trust workflows.

Key terms

  • Merchant Risk: The set of controls used to prevent financial, identity, and abuse-related losses across an online merchant or marketplace environment. It covers onboarding, account behaviour, payments, and payout risk, and it works best when identity, fraud, and trust decisions are governed together.
  • Identity verification: Identity verification is the process of confirming that a user, workload, or agent is the entity it claims to be before access is granted. In AI-heavy environments, that verification must include the requester, the system acting on its behalf, and the sensitivity of the action.
  • Synthetic Identity: A synthetic identity is a software-based actor that can authenticate, request access, and execute actions without being a human user. In practice, this includes AI agents, bots, service accounts, tokens, and other machine identities that need clear ownership, scope, and revocation.
  • Lifecycle Trust Decision: An approval that is valid only for the current stage of an account’s journey, such as onboarding, listing, or payout. The point is to stop treating trust as permanent once admission is granted. In marketplaces, each later stage should be able to challenge or revoke the earlier decision.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org