By NHI Mgmt Group Editorial TeamBased on SumSub: “Sumsub Rewards Companies with Risk Intolerant Badge to Celebrate Digital Trust while Sharing Best Practices” (June 8, 2026)

TL;DR: 40% of global businesses reported fraud victims, while sophisticated fraud rose 180% year over year to 28% of detected attacks, underscoring why firms are being pushed to demonstrate KYC, AML and fraud controls more visibly, according to SumSub. Public recognition may shape trust, but it does not replace governance, evidence, or continuous assurance.


At a glance

What this is: SumSub is using public badges to turn compliance and fraud-prevention performance into visible proof for selected businesses, while linking the initiative to rising fraud pressure and AML/CFT expectations.

Why it matters: For compliance, IAM and fraud teams, the signal is that external proof is becoming part of trust-building, but the underlying controls still need to stand up to regulatory review and operational scrutiny.

By the numbers:

  • 40% of global businesses reported being victims of fraud, according to SumSub 2025 Fraud Exposure Survey.
  • The share of sophisticated fraud increased by 180% over 2024-2025, reaching 28% of all detected attacks, according to SumSub 2025 Fraud Exposure Survey.

Context

Public recognition programmes for compliance are different from certification, because they turn assessed controls into a market-facing signal rather than a regulatory attestation. In this case, the primary governance issue is not whether fraud controls exist, but how organisations evidence them in a way that is legible to customers, partners, and peers.

The article sits at the intersection of fraud prevention, KYC, AML/CFT, and trust signalling. That matters for practitioners because visibility can improve market confidence, but it can also blur the line between demonstrated practice and durable assurance if the underlying assessment method is not understood.

The article also reflects a broader shift in identity and fraud programmes: organisations are being judged not only on whether they reduce risk, but on whether they can prove it publicly without overstating what the proof actually means.


Key questions

Q: How should compliance teams treat public trust badges in fraud programmes?

A: As supplementary assurance, not as evidence of lasting control effectiveness. A badge can help customers or partners understand that a review occurred, but it does not replace current testing, monitoring, or governance over the underlying KYC, AML, and fraud processes. Teams should verify scope, date, and evidence quality before relying on it.

Q: Why do fraud and AML badges fail as proof of ongoing security?

A: Because they are usually point-in-time signals. Fraud tactics, onboarding risk, and detection quality change over time, so a badge can age out quickly if there is no re-assessment or withdrawal logic. Without continuous assurance, the signal may outlast the control environment it was meant to represent.

Q: What are the signs that a public compliance claim is overstating reality?

A: Look for vague scope, missing assessment dates, unclear control criteria, and language that implies future protection rather than current recognition. If the claim cannot be tied to specific controls, evidence, and review cadence, it is marketing language, not governance evidence.

Q: What should organisations do if a trust badge no longer reflects current controls?

A: They should retire or refresh it immediately, then revalidate the controls behind it. Keeping an outdated badge visible creates reputational risk and can mislead partners into assuming stronger fraud or compliance posture than actually exists.


Technical breakdown

Public badges as compliance signalling

A public badge programme is a signalling layer, not a control layer. It converts an assessment outcome into a reputation marker that can be consumed by buyers, partners, and end users. The security value depends on the assessment scope, the evidence quality, and whether the badge reflects current state or only point-in-time review. In fraud and compliance contexts, that distinction matters because control performance drifts as processes, fraud patterns, and third-party dependencies change. Without that context, a badge can be read as stronger assurance than it really provides.

Practical implication: treat public badges as supplementary assurance and verify the underlying assessment criteria before relying on them in supplier or trust decisions.

Why fraud and AML controls are being externalised

Fraud programmes increasingly sit alongside AML/CFT, KYC, and broader trust governance because attackers exploit process gaps, not just technical weaknesses. When firms expose controls to public scrutiny, they are effectively claiming that onboarding, monitoring, investigation, and escalation are mature enough to withstand evaluation. The article’s emphasis on AI-enabled fraud also matters: machine-assisted scams can scale faster than manual review processes, so governance has to account for speed, adaptability, and evidence retention. That makes fraud control a lifecycle issue, not a single checkbox.

Practical implication: align fraud controls with lifecycle evidence, especially for onboarding, monitoring, and case escalation, so public claims match operational reality.

Trust claims need revocation logic

Any public trust signal needs a way to age out, because control performance is not static. A badge based on a past assessment can become misleading if fraud patterns change, a vendor relationship shifts, or internal controls degrade. In governance terms, the problem is not just acquisition of proof but retention of validity. That is why public trust mechanisms should be treated like governed credentials: issued under defined conditions, reviewed against current evidence, and withdrawn when the facts change.

Practical implication: define expiry, re-assessment, and withdrawal rules for any externally visible trust signal so it cannot outlive the controls behind it.


Threat narrative

Attacker objective: The attacker aims to monetise fraudulent access while degrading confidence in the organisation’s controls and reputation.

  1. Entry begins when fraudsters exploit weak or inconsistent KYC, AML, or onboarding controls to reach customers or business systems.
  2. Escalation follows as AI-assisted tactics increase the scale and sophistication of fraud, making attacks harder to distinguish from legitimate activity.
  3. Impact lands in stolen assets, compromised customer profiles, data exposure, operational disruption, and loss of trust.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Public trust badges create a new governance layer, not a new control. The article is really about converting internal compliance evidence into external credibility, which is a different discipline from passing an audit or meeting a threshold. That matters because reputation signals travel faster than the controls that support them. Practitioners should treat badge claims as a governed artefact, not as a substitute for control assurance.

Fraud visibility is becoming part of identity governance. KYC, AML, and fraud prevention are no longer isolated compliance functions when customers, partners, and market observers can see the outcome. The more visible the claim, the more important it becomes to maintain evidence quality, assessment currency, and scoping discipline. The implication is that governance teams need a stronger model for what can be safely disclosed.

Risk-intolerant badges expose the gap between point-in-time review and continuous assurance. The article celebrates selected organisations, but the underlying threat environment continues to change quickly, especially with AI-assisted fraud. A badge can indicate maturity at one moment, yet fraud operations evolve continuously. Practitioners should assume any external proof expires unless refreshed against current operational evidence.

Trust signalling will increasingly influence control priorities. Organisations are being judged not only on whether they reduce fraud, but on whether they can demonstrate that capability in a form the market understands. That creates pressure to package compliance evidence more cleanly, but it also increases the cost of overclaiming. The practical conclusion is simple: if a trust signal cannot be defended with current evidence, it should not be visible.

Public recognition will not resolve weak fraud governance. The article shows that symbolic recognition can coexist with real exposure, which means the market can reward transparency without fixing root causes. For identity and fraud teams, that means the harder work remains control design, evidence retention, and review discipline. Public proof only matters when the underlying governance can withstand challenge.

What this signals

Public proof will increasingly sit beside private control design. Organisations should expect external trust signals to become part of procurement, partnership, and customer due diligence, but only if the evidence behind them can be audited. That raises the bar for control documentation and review discipline across fraud and compliance programmes.

Risk-intolerant badges may help the market compare commitment, but they do not standardise assurance. The key programme question is whether your organisation can defend the scope, freshness, and withdrawal rules behind any visible trust claim. If not, the badge becomes a branding layer detached from operational reality.


For practitioners

  • Define badge scope and evidence boundaries Document exactly which controls, populations, and time windows are covered before any external trust signal is displayed.
  • Review KYC, AML, and fraud evidence currency Check whether the latest assessment still reflects current onboarding, monitoring, and escalation practices, especially where AI-enabled fraud has changed the threat profile.
  • Set expiry and withdrawal rules for public trust claims Require re-assessment, expiration, and removal criteria so a recognition badge cannot continue after control conditions change.
  • Separate marketing language from assurance language Ensure externally visible claims describe recognition at a point in time, not a guarantee of future performance or regulatory compliance.

Key takeaways

  • Risk-intolerant badges turn fraud and compliance performance into a visible trust signal, but they are not a substitute for evidence-backed governance.
  • The article links the initiative to significant fraud pressure, including rising sophisticated attacks and broad victimisation among businesses.
  • Practitioners should define scope, refresh cadence, and withdrawal rules before allowing any public trust claim to represent current control effectiveness.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST SP 800-63 set the technical controls, while GDPR defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsPublic trust claims depend on the governance of who and what is authorised in fraud-sensitive systems.
GV.OV-01 — Organisational Context and Risk OversightThe article centres on how organisations evidence and oversee trust posture publicly.
Recommendation — Review authorisation scope for fraud and compliance workflows before any external trust claim is made. Assign oversight for external trust signals to the same governance process used for risk disclosures.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeFraud and compliance evidence is only credible when access and review scope stay constrained.
Recommendation — Limit access to fraud evidence, assessment records, and trust-badge approvals to named roles.
NIST SP 800-63SP 800-63C — FederationThe article’s trust signalling touches externally consumable identity proof and assurance.
Recommendation — Align public identity claims with federation and assurance expectations before exposing them to partners.
GDPRArt.32 — Security of ProcessingThe article references customer data exposure and compliance claims that affect processing security.
Recommendation — Treat public assurance claims as part of the broader duty to secure personal data processing.

Key terms

  • Consumer Trust Signal: An observable cue that shapes how people judge whether a digital service is safe enough to use. In identity and fraud programmes, trust signals include login prompts, recovery flows, privacy messaging, and visible security features that help users understand protection is active.
  • Continuous Assurance: A control model that checks identity and security conditions continuously instead of only during scheduled audits. It improves readiness in dynamic environments, but it requires clear thresholds, exception handling, and human accountability so automation does not outpace governance.
  • AML/CFT: AML/CFT refers to anti-money laundering and countering the financing of terrorism controls used to detect, prevent, and report suspicious financial activity. In identity and fraud governance, these controls often overlap with onboarding, monitoring, and escalation workflows that must stay current as attack methods change.
  • Fraud Exposure: Fraud exposure is the degree to which an organisation is vulnerable to fraud attempts, successful attacks, or repeat abuse across its customer and operational workflows. It reflects both attack frequency and the quality of controls in place to detect, prevent, and respond to identity-driven fraud.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org