Use layered controls that separate identity authenticity from session authenticity, then tune each control to the risk level of the transaction. Source-backed proofing, device integrity checks, and low-friction liveness signals work better together than a single document-based gate. The goal is not maximum friction. It is enough assurance to stop synthetic identity abuse without driving legitimate users away.
Why This Matters for Security Teams
Fraud controls often fail when teams treat identity proofing, session trust, and transaction risk as the same problem. That leads to brittle step-up verification, avoidable abandonment, and false confidence in a single gate. Current guidance suggests separating the question of “who is this?” from “is this session trustworthy right now?” and then applying stronger checks only where the risk justifies it. The control objective is better fraud resistance, not blanket scrutiny.
This is especially important in account opening, high-value transfers, payout changes, and account recovery, where synthetic identities and takeover activity can look legitimate until the last step. Mapping the decision flow to NIST SP 800-53 Rev 5 Security and Privacy Controls helps teams anchor verification to risk, auditability, and access enforcement rather than to a single vendor process. In practice, many security teams encounter fraud only after excessive challenge rates have already pushed legitimate users into support queues and workarounds.
How It Works in Practice
Effective fraud reduction usually starts with layered signals rather than one hard checkpoint. Identity proofing can establish whether a person is likely real, while device posture, behavioral consistency, and session signals determine whether the current interaction should be trusted. For lower-risk actions, passive signals may be enough. For money movement, credential resets, or profile changes, the system should add stronger verification only when the risk score or policy threshold says so.
A practical design typically includes:
- Document and data-source verification for onboarding or recovery, with clear fallback paths when sources are unavailable.
- Device integrity checks to reduce replay, emulator, and automation abuse.
- Liveness or challenge-response signals that are difficult to automate at scale.
- Transaction-level risk scoring that can raise assurance requirements only for higher-risk actions.
- Logging and review workflows so investigators can see which signals drove a decision.
Where teams need a broader fraud and trust lens, the identity assurance baseline in NIST SP 800-63-3 Digital Identity Guidelines remains useful for separating identity proofing from authentication strength, while CISA Zero Trust Maturity Model is helpful for thinking about continuous trust instead of one-time trust. The main operational point is that friction should be proportional to the consequence of failure, not uniform across every user path. These controls tend to break down when legacy onboarding flows, thin device telemetry, and manual exception handling all coexist because policy decisions become inconsistent and easy to bypass.
Common Variations and Edge Cases
Tighter verification often increases abandonment and support overhead, requiring organisations to balance fraud loss reduction against conversion, accessibility, and operational cost. There is no universal standard for this yet, because the right balance depends on transaction type, user population, and regulatory exposure. For example, a consumer fintech app, a healthcare portal, and a business payments platform will rarely accept the same friction profile.
One common edge case is legitimate users with poor device quality, travel patterns, or limited documentation. Another is high-risk but low-frequency activity, such as account recovery after a long dormancy period, where the signal set is weak but the potential loss is high. In these cases, best practice is evolving toward graduated assurance: start with low-friction signals, then step up only if the risk model or anomaly score justifies it. Teams should also avoid over-relying on any single control, because document checks can be spoofed, biometrics can fail in real-world conditions, and device fingerprints can be unstable.
Where fraud controls touch automated decisioning, transparency matters. Policy owners should be able to explain why a user was challenged, what evidence was used, and how appeals or manual review work. That is especially important when security, compliance, and customer experience teams share the same workflow.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATLAS and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-01 | Risk-based identity proofing supports stronger access decisions for higher-risk transactions. |
| NIST SP 800-63 | IAL/AAL | Separates identity proofing from authentication strength, which is central to reducing friction. |
| NIST AI RMF | GOVERN | Fraud scoring and step-up logic need accountable, explainable governance. |
| MITRE ATLAS | AML.T0021 | Automated abuse and evasion patterns are relevant to fraud controls and liveness checks. |
| OWASP Agentic AI Top 10 | Prompt Injection | If AI supports verification or review, it can be manipulated into unsafe decisions. |
Tune proofing and authentication to the required assurance level instead of applying one fixed gate.
Related resources from NHI Mgmt Group
- How should security teams reduce phishing risk in MFA without creating more user friction?
- How can organisations reduce fraud without creating excessive user friction?
- How should iGaming teams use predictive fraud scoring without creating excessive customer friction?
- How should security teams govern access requests without creating excessive approval friction?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 14, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org