Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM What should organisations balance when they expand fraud…
Identity Beyond IAM

What should organisations balance when they expand fraud prevention beyond KYC?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 6, 2026 Domain: Identity Beyond IAM

Organisations need to balance regulatory compliance, fraud risk, and customer friction at the same time. Tight controls can reduce abuse, but overly rigid flows may drive abandonment and degrade the experience for legitimate users. Effective programmes use risk-based decisioning so higher-risk activity gets more scrutiny while low-risk journeys remain efficient. That balance is essential in regulated environments where both trust and usability matter.

Balancing Compliance, Fraud Signal, and Customer Friction

When fraud prevention expands beyond KYC, the real challenge is no longer just proving who a customer is. Organisations also need to decide how much additional signal they want to collect, how aggressively they want to challenge activity, and how much friction the business can tolerate before legitimate users start to abandon the journey. That balance becomes especially important where fraud controls sit alongside regulated onboarding, account recovery, payments, or access decisions. The European identity framework in eIDAS 2.0 — EU Digital Identity Framework is a useful reference point because it shows how identity assurance and usability can be treated as linked design concerns rather than separate afterthoughts.

Fraud teams often get this wrong by treating stronger control as automatically better control. In practice, the organisation has to preserve enough trust in the journey for genuine users to complete it, while still making abuse expensive enough to matter.

How Fraud Controls Extend Beyond Identity Verification

Once organisations move beyond KYC, fraud prevention usually becomes a layered decisioning problem. KYC answers whether a person or entity appears valid at the point of onboarding. Wider fraud controls ask whether the session, device, behaviour, payment instrument, account recovery request, or transaction pattern looks consistent with expected use. That broader view is important because many attacks do not start with a broken identity check. They start with a legitimate identity being misused later, or with an otherwise valid account being manipulated through social engineering, synthetic identities, credential abuse, or high-velocity automation.

In practice, teams usually combine several signals rather than relying on one control. Common examples include:

  • behavioural signals that identify unusual interaction patterns
  • device and session reputation that highlights abnormal access context
  • transaction screening that looks for velocity, value, and destination anomalies
  • step-up checks that increase scrutiny only when risk rises
  • manual review for ambiguous cases where automation would be too blunt

The key operational question is not whether a control can block more abuse in isolation. It is whether the full decision chain reduces loss without creating so much friction that legitimate customers fail, disengage, or route around the control. FATF guidance on AML and KYC expectations remains relevant here because it illustrates the broader regulatory pattern: stronger assurance is often expected where risk is higher, but proportionality still matters in how controls are applied. The useful design pattern is risk-based escalation, not blanket hardening.

Where this guidance breaks down is in environments with very low tolerance for false negatives or where an attacker can easily adapt faster than the decision model can be tuned.

Where the Trade-Offs Shift in Regulated and High-Risk Journeys

Tighter fraud controls often increase operational overhead, so organisations have to balance stronger abuse resistance against higher review load and more user drop-off.

That trade-off changes materially across different journeys. In onboarding, heavy friction may be acceptable for high-risk products but damaging for consumer conversion. In account recovery, the same level of friction may be justified because recovery paths are a prime target for takeover. In payments or withdrawals, the cost of false negatives may outweigh the cost of additional checks. The right answer therefore depends on where the control sits in the lifecycle, what loss it is intended to prevent, and how recoverable the user experience is if the system blocks a legitimate action.

For teams building this capability, the main failure mode is over-generalising one fraud policy across every channel and risk tier. That usually produces one of two bad outcomes: either the programme is too permissive to stop meaningful abuse, or it is so rigid that customer operations absorb the damage through complaints, manual overrides, and support escalations. The better approach is to define where friction is acceptable, where it must be minimal, and which events justify step-up review. That is also where evidence matters most. If the control cannot show why a journey was challenged, it becomes difficult to defend the decision to regulators, investigators, or customer support.

In practice, many organisations discover the weakness only after they have scaled the control into a live journey and seen either fraud adaptation or legitimate-user abandonment become visible at the same time.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the technical controls, while EU AI Act define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-01 — Identity Management, Authentication, and Access ControlBalances assurance and access decisions across fraud-sensitive journeys.
DE.CM-01 — Monitoring for Anomalies and EventsFraud prevention beyond KYC depends on detecting abnormal account and session behaviour.
Recommendation — Apply PR.AA-01 to raise assurance only where fraud risk justifies extra friction. Use DE.CM-01 to detect anomalous activity that should trigger step-up review.
CIS Controls v86.3 — Access Control ManagementSupports risk-based restriction of sensitive actions and recovery paths.
Recommendation — Use 6.3 to tighten approval paths for high-risk account actions.
NIST SP 800-63IAL2 — Identity Assurance Level 2Identity proofing strength must be proportional to the onboarding risk.
Recommendation — Map onboarding friction to IAL2 where higher assurance is operationally justified.
EU AI ActArticle 9 — Risk Management SystemFraud decisioning can use automated scoring that needs governance and oversight.
Recommendation — Govern automated fraud scoring under Article 9 with documented risk controls and review.

Practitioner Guidance

What to prioritise: Start by separating the journeys that can tolerate friction from the ones that cannot. Account recovery, high-value transactions, and change-of-payee actions usually deserve much stronger scrutiny than routine low-risk interactions.

Decision rule: If the control increases abandonment more than it reduces abuse in a specific journey, narrow it to step-up handling rather than applying it as a default gate. If the risk is concentrated, target the friction where the loss opportunity is concentrated.

What to verify: Confirm that the programme can explain challenged decisions in terms of observable risk signals, not just a black-box score. Teams should be able to show why a case was escalated and who approved exceptions.

What practitioners underestimate: The biggest governance mistake is treating fraud prevention as a single-line control problem. Once the programme spans onboarding, account lifecycle, and transaction monitoring, it becomes a product, operations, and risk coordination issue as much as a security one.

Practitioner takeaway: The best fraud programme beyond KYC is not the one with the harshest checks, but the one that applies stronger scrutiny only where the business can justify the friction and the loss exposure truly warrants it.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 6, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org