Join our Newsletter — 33% off our NHI Course
Home FAQ Authentication, Authorisation & Trust How should banks use identity verification to reduce…
Authentication, Authorisation & Trust

How should banks use identity verification to reduce AI-driven fraud without adding too much customer friction?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 24, 2026 Domain: Authentication, Authorisation & Trust

Banks should combine multiple identity signals instead of relying on a single credential or one-time password. The goal is to raise the cost of impersonation while keeping legitimate customers moving quickly through onboarding and servicing. In practice, that means using passive verification, device-linked signals, and risk-based checks so fraud controls strengthen the front door without turning routine banking into a manual review queue.

How banks balance stronger identity checks with less customer friction

Banks get the best results when identity verification is treated as a layered decision, not a single gate. The first step is to distinguish low-risk interactions from high-risk ones, then apply the lightest control that still resists impersonation. That usually means passive signals, device history, behavioral consistency, and selective step-up checks rather than forcing every customer through the same heavy verification flow.

That approach matters because AI-assisted fraud often succeeds by making bad requests look ordinary. If a bank uses only one factor or one reusable secret, an attacker only needs to defeat one control. If the bank combines signals that are harder to fake together, it can challenge suspicious activity without slowing every legitimate customer in the queue.

Which verification signals reduce fraud without creating drag?

The strongest pattern is to combine signals that come from different layers of the relationship. A device fingerprint, prior session pattern, account tenure, transaction context, and behavioral consistency are each imperfect on their own, but together they create a much better fraud decision than a one-time password alone. Banks should prefer signals that can be evaluated quietly in the background before asking the customer to do anything extra.

Where a step-up is needed, the control should match the risk. A routine balance check should not trigger the same friction as a first-time payee change or a high-value transfer. This is where risk-based authentication works best: it keeps the happy path fast and reserves stronger verification for moments when the observed context changes sharply.

For onboarding, banks should use progressive proofing rather than front-loading every check. The customer should be able to move through low-risk steps quickly, with additional verification introduced only when the application, device, or transaction profile signals more uncertainty. That preserves conversion while still making synthetic identity and impersonation harder to scale.

What design choices make identity verification effective against AI-driven fraud?

The main design choice is to make verification hard to script, not just hard to guess. AI-generated social engineering can imitate tone, timing, and surface detail, so banks need controls that rely on context, possession, and continuity, not just answers that can be harvested or inferred. Device binding, secure session continuity, and transaction-specific checks are more resilient than knowledge-based questions or reusable OTP flows.

Banks also need to separate identity proofing from ongoing authentication. A strong initial check does not remove the need to monitor for later anomalies, especially when a legitimate customer’s account is being used in an unusual way. In practice, the best programs treat verification as continuous risk evaluation across onboarding, login, payee changes, and servicing actions.

The operational test is simple: if a control adds friction but does not meaningfully improve fraud resistance, it is the wrong control. If it improves detection only by sending too many good customers into manual review, it will usually be abandoned by the business. The useful controls are the ones that shift more cases into automated approval for trusted users while concentrating analyst attention on the small number of high-risk outliers.

What failure modes should banks watch most closely?

The biggest failure mode is overconfidence in a single high-friction control. Attackers do not need to beat every layer if one weak factor remains reusable, replayable, or easy to social-engineer. Another common failure is building rules that are too static, so the bank keeps challenging the same customers even after their behavior has become routine, which increases abandonment without reducing fraud in a meaningful way.

There is also a data-quality problem. If device signals are noisy, if identity signals are not linked well across channels, or if risk models are not tuned to the bank’s own customer mix, the result is either excessive friction or false confidence. Banks need to monitor both fraud loss and customer drop-off together, because a control that stops fraud but breaks servicing can still be a bad outcome.

Identity verification is also only as strong as the recovery path. If an attacker can hijack a reset flow, manipulate a contact channel, or exploit weak support processes, the front-door controls will not matter enough. That is why the verification model has to cover both the primary customer journey and the exception paths used when something goes wrong.

Risk and Threat Considerations

AI-driven fraud increases the scale and believability of impersonation, so the main risk is not just a stolen credential, but a convincing request that can slip through a brittle verification flow. Banks are most exposed when one control is treated as proof of identity, especially if that control can be replayed, phished, or socially engineered.

Failure mechanism: Attackers combine synthetic text, stolen profile data, and account recovery abuse to defeat a single factor or to trigger a weak step-up only after they have already reached a high-value action.

Impact: The result can be account takeover, unauthorized payments, fraudulent onboarding, or support-channel compromise, followed by losses and heavier manual review for legitimate customers.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, OWASP ASVS and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-63Digital Identity GuidelinesBanks need assurance levels and phishing-resistant auth for customer verification.
Recommendation — Apply assurance-based identity checks and use phishing-resistant authenticators where step-up is needed.
OWASP ASVSV6 — AuthenticationThe question centers on stronger authentication without excessive user friction.
V8 — AuthorizationFraud controls must gate high-risk actions like payee changes and transfers.
Recommendation — Require authentication flows that balance assurance, usability, and step-up triggers. Enforce action-level authorization checks for high-risk banking operations.
NIST CSF 2.0PR.AA-05 — Identity Management, Authentication, and Access ControlLayered identity verification and step-up checks align with access control protection.
GV.RM-01 — Risk Management StrategyThe question is about balancing fraud reduction against customer friction.
Recommendation — Implement risk-based identity verification and step-up access control for sensitive actions. Define fraud and friction thresholds that guide when to challenge customers.

Practitioner Guidance

What to prioritize: Put the strongest friction reduction effort into trusted returning customers and low-risk interactions, then reserve stronger challenges for first-time devices, anomalous session behavior, high-value actions, and recovery events.

What to verify: Check that each added signal actually improves fraud precision, not just challenge rates. If a control increases abandonment or manual review without improving detection, it is degrading the customer journey rather than protecting it.

Practitioner takeaway: The goal is not maximum verification at every step, but the smallest set of signals that makes impersonation expensive while leaving ordinary banking interactions close to invisible.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 24, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org