TL;DR: 40% of global businesses reported fraud victims, while sophisticated fraud rose 180% year over year to 28% of detected attacks, underscoring why firms are being pushed to demonstrate KYC, AML and fraud controls more visibly, according to SumSub. Public recognition may shape trust, but it does not replace governance, evidence, or continuous assurance.
At a glance
What this is: SumSub is using public badges to turn compliance and fraud-prevention performance into visible proof for selected businesses, while linking the initiative to rising fraud pressure and AML/CFT expectations.
Why it matters: For compliance, IAM and fraud teams, the signal is that external proof is becoming part of trust-building, but the underlying controls still need to stand up to regulatory review and operational scrutiny.
By the numbers:
- 40% of global businesses reported being victims of fraud, according to SumSub 2025 Fraud Exposure Survey.
- The share of sophisticated fraud increased by 180% over 2024-2025, reaching 28% of all detected attacks, according to SumSub 2025 Fraud Exposure Survey.
Context
Public recognition programmes for compliance are different from certification, because they turn assessed controls into a market-facing signal rather than a regulatory attestation. In this case, the primary governance issue is not whether fraud controls exist, but how organisations evidence them in a way that is legible to customers, partners, and peers.
The article sits at the intersection of fraud prevention, KYC, AML/CFT, and trust signalling. That matters for practitioners because visibility can improve market confidence, but it can also blur the line between demonstrated practice and durable assurance if the underlying assessment method is not understood.
The article also reflects a broader shift in identity and fraud programmes: organisations are being judged not only on whether they reduce risk, but on whether they can prove it publicly without overstating what the proof actually means.
Key questions
Q: How should compliance teams treat public trust badges in fraud programmes?
A: As supplementary assurance, not as evidence of lasting control effectiveness. A badge can help customers or partners understand that a review occurred, but it does not replace current testing, monitoring, or governance over the underlying KYC, AML, and fraud processes. Teams should verify scope, date, and evidence quality before relying on it.
Q: Why do fraud and AML badges fail as proof of ongoing security?
A: Because they are usually point-in-time signals. Fraud tactics, onboarding risk, and detection quality change over time, so a badge can age out quickly if there is no re-assessment or withdrawal logic. Without continuous assurance, the signal may outlast the control environment it was meant to represent.
Q: What are the signs that a public compliance claim is overstating reality?
A: Look for vague scope, missing assessment dates, unclear control criteria, and language that implies future protection rather than current recognition. If the claim cannot be tied to specific controls, evidence, and review cadence, it is marketing language, not governance evidence.
Q: What should organisations do if a trust badge no longer reflects current controls?
A: They should retire or refresh it immediately, then revalidate the controls behind it. Keeping an outdated badge visible creates reputational risk and can mislead partners into assuming stronger fraud or compliance posture than actually exists.
Technical breakdown
Public badges as compliance signalling
A public badge programme is a signalling layer, not a control layer. It converts an assessment outcome into a reputation marker that can be consumed by buyers, partners, and end users. The security value depends on the assessment scope, the evidence quality, and whether the badge reflects current state or only point-in-time review. In fraud and compliance contexts, that distinction matters because control performance drifts as processes, fraud patterns, and third-party dependencies change. Without that context, a badge can be read as stronger assurance than it really provides.
Practical implication: treat public badges as supplementary assurance and verify the underlying assessment criteria before relying on them in supplier or trust decisions.
Why fraud and AML controls are being externalised
Fraud programmes increasingly sit alongside AML/CFT, KYC, and broader trust governance because attackers exploit process gaps, not just technical weaknesses. When firms expose controls to public scrutiny, they are effectively claiming that onboarding, monitoring, investigation, and escalation are mature enough to withstand evaluation. The article’s emphasis on AI-enabled fraud also matters: machine-assisted scams can scale faster than manual review processes, so governance has to account for speed, adaptability, and evidence retention. That makes fraud control a lifecycle issue, not a single checkbox.
Practical implication: align fraud controls with lifecycle evidence, especially for onboarding, monitoring, and case escalation, so public claims match operational reality.
Trust claims need revocation logic
Any public trust signal needs a way to age out, because control performance is not static. A badge based on a past assessment can become misleading if fraud patterns change, a vendor relationship shifts, or internal controls degrade. In governance terms, the problem is not just acquisition of proof but retention of validity. That is why public trust mechanisms should be treated like governed credentials: issued under defined conditions, reviewed against current evidence, and withdrawn when the facts change.
Practical implication: define expiry, re-assessment, and withdrawal rules for any externally visible trust signal so it cannot outlive the controls behind it.
Threat narrative
Attacker objective: The attacker aims to monetise fraudulent access while degrading confidence in the organisation’s controls and reputation.
- Entry begins when fraudsters exploit weak or inconsistent KYC, AML, or onboarding controls to reach customers or business systems.
- Escalation follows as AI-assisted tactics increase the scale and sophistication of fraud, making attacks harder to distinguish from legitimate activity.
- Impact lands in stolen assets, compromised customer profiles, data exposure, operational disruption, and loss of trust.
Breaches seen in the wild
- Secrets in Docker Hub images (RWTH Aachen study): A 2023 RWTH Aachen study found secrets in 8.5% of container images, and 275,269 internet hosts still using the leaked private keys.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Public trust badges create a new governance layer, not a new control. The article is really about converting internal compliance evidence into external credibility, which is a different discipline from passing an audit or meeting a threshold. That matters because reputation signals travel faster than the controls that support them. Practitioners should treat badge claims as a governed artefact, not as a substitute for control assurance.
Fraud visibility is becoming part of identity governance. KYC, AML, and fraud prevention are no longer isolated compliance functions when customers, partners, and market observers can see the outcome. The more visible the claim, the more important it becomes to maintain evidence quality, assessment currency, and scoping discipline. The implication is that governance teams need a stronger model for what can be safely disclosed.
Risk-intolerant badges expose the gap between point-in-time review and continuous assurance. The article celebrates selected organisations, but the underlying threat environment continues to change quickly, especially with AI-assisted fraud. A badge can indicate maturity at one moment, yet fraud operations evolve continuously. Practitioners should assume any external proof expires unless refreshed against current operational evidence.
Trust signalling will increasingly influence control priorities. Organisations are being judged not only on whether they reduce fraud, but on whether they can demonstrate that capability in a form the market understands. That creates pressure to package compliance evidence more cleanly, but it also increases the cost of overclaiming. The practical conclusion is simple: if a trust signal cannot be defended with current evidence, it should not be visible.
Public recognition will not resolve weak fraud governance. The article shows that symbolic recognition can coexist with real exposure, which means the market can reward transparency without fixing root causes. For identity and fraud teams, that means the harder work remains control design, evidence retention, and review discipline. Public proof only matters when the underlying governance can withstand challenge.
What this signals
Public proof will increasingly sit beside private control design. Organisations should expect external trust signals to become part of procurement, partnership, and customer due diligence, but only if the evidence behind them can be audited. That raises the bar for control documentation and review discipline across fraud and compliance programmes.
Risk-intolerant badges may help the market compare commitment, but they do not standardise assurance. The key programme question is whether your organisation can defend the scope, freshness, and withdrawal rules behind any visible trust claim. If not, the badge becomes a branding layer detached from operational reality.
For practitioners
- Define badge scope and evidence boundaries Document exactly which controls, populations, and time windows are covered before any external trust signal is displayed.
- Review KYC, AML, and fraud evidence currency Check whether the latest assessment still reflects current onboarding, monitoring, and escalation practices, especially where AI-enabled fraud has changed the threat profile.
- Set expiry and withdrawal rules for public trust claims Require re-assessment, expiration, and removal criteria so a recognition badge cannot continue after control conditions change.
- Separate marketing language from assurance language Ensure externally visible claims describe recognition at a point in time, not a guarantee of future performance or regulatory compliance.
Key takeaways
- Risk-intolerant badges turn fraud and compliance performance into a visible trust signal, but they are not a substitute for evidence-backed governance.
- The article links the initiative to significant fraud pressure, including rising sophisticated attacks and broad victimisation among businesses.
- Practitioners should define scope, refresh cadence, and withdrawal rules before allowing any public trust claim to represent current control effectiveness.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST SP 800-63 set the technical controls, while GDPR defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Public trust claims depend on the governance of who and what is authorised in fraud-sensitive systems. |
| GV.OV-01 — Organisational Context and Risk Oversight | The article centres on how organisations evidence and oversee trust posture publicly. | |
| Recommendation — Review authorisation scope for fraud and compliance workflows before any external trust claim is made. Assign oversight for external trust signals to the same governance process used for risk disclosures. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Fraud and compliance evidence is only credible when access and review scope stay constrained. |
| Recommendation — Limit access to fraud evidence, assessment records, and trust-badge approvals to named roles. | ||
| NIST SP 800-63 | SP 800-63C — Federation | The article’s trust signalling touches externally consumable identity proof and assurance. |
| Recommendation — Align public identity claims with federation and assurance expectations before exposing them to partners. | ||
| GDPR | Art.32 — Security of Processing | The article references customer data exposure and compliance claims that affect processing security. |
| Recommendation — Treat public assurance claims as part of the broader duty to secure personal data processing. | ||
Key terms
- Consumer Trust Signal: An observable cue that shapes how people judge whether a digital service is safe enough to use. In identity and fraud programmes, trust signals include login prompts, recovery flows, privacy messaging, and visible security features that help users understand protection is active.
- Continuous Assurance: A control model that checks identity and security conditions continuously instead of only during scheduled audits. It improves readiness in dynamic environments, but it requires clear thresholds, exception handling, and human accountability so automation does not outpace governance.
- AML/CFT: AML/CFT refers to anti-money laundering and countering the financing of terrorism controls used to detect, prevent, and report suspicious financial activity. In identity and fraud governance, these controls often overlap with onboarding, monitoring, and escalation workflows that must stay current as attack methods change.
- Fraud Exposure: Fraud exposure is the degree to which an organisation is vulnerable to fraud attempts, successful attacks, or repeat abuse across its customer and operational workflows. It reflects both attack frequency and the quality of controls in place to detect, prevent, and respond to identity-driven fraud.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org