Join our Newsletter — 33% off our NHI Course
Home› FAQ› Authentication, Authorisation & Trust› Why do TPR and FPR matter more than…
Authentication, Authorisation & Trust

Why do TPR and FPR matter more than overall accuracy in KYC?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 11, 2026 Domain: Authentication, Authorisation & Trust

They show the fraud-friction trade-off at the chosen threshold. Accuracy can rise while the system still misses attacks or rejects too many real customers, so banks should judge performance where the workflow will actually operate, not on a single summary number.

Why threshold metrics tell the real KYC story

TPR and FPR are threshold metrics, so they describe how the model behaves where the onboarding or review workflow will actually run. In KYC, that matters because banks do not deploy a model in the abstract, they deploy a decision rule that either escalates a customer, clears them, or sends work to manual review.

Overall accuracy hides that operating point. A model can look “good” if most applicants are legitimate, yet still miss a meaningful share of fraud or create a flood of false alerts that slows onboarding. TPR and FPR expose the operational consequences of the chosen threshold, which is what the business actually feels.

That is why KYC performance should be read as a trade-off, not a single score. A higher threshold may reduce false positives but also let more bad actors through; a lower threshold may catch more risk but reject or delay more real customers. The useful question is not whether the model is accurate in the abstract, but whether its error mix matches the bank’s risk appetite and review capacity.

How TPR and FPR shape fraud, friction, and review load

TPR, the true positive rate, shows how often the system catches the cases you care about, such as suspicious applicants, forged documents, or other risky onboarding profiles. FPR, the false positive rate, shows how often it wrongly flags legitimate customers. Together, they describe whether the control is tuned for security, customer experience, or a point in between.

This is especially important in KYC because the costs of the two errors are different. Missed fraud can create downstream AML exposure, while false positives create onboarding friction, longer cycle times, and unnecessary analyst effort. A model with slightly lower accuracy can still be better if it produces a more workable balance of detection and disruption.

KYC teams should therefore judge the metric pair against the process they support, not against a generic benchmark. If the threshold is set for automated pre-screening, the acceptable FPR may be lower than if the output only feeds a human reviewer. If the threshold is set for high-risk customer intake, the organisation may tolerate more false positives to protect against missed bad actors.

Why accuracy can improve while KYC quality gets worse

Accuracy is dominated by the majority class, so it can rise even when the model becomes less useful for risk decisions. In KYC, that is a common failure mode because genuine customers usually outnumber suspicious ones. A model that simply predicts “legitimate” most of the time can score well on accuracy while doing very little to separate real risk from normal activity.

That makes accuracy a weak summary measure for thresholded screening. It does not tell you whether the model is catching the right cases, how many legitimate customers it is disrupting, or what happens when the threshold changes. TPR and FPR preserve that operational detail, which is why they are better suited to KYC decisioning and model governance.

For practitioners, the practical test is whether the metric reflects the workflow outcome they need. If the review queue, customer abandonment rate, or fraud escape rate changes materially when the threshold moves, then accuracy is not the right headline number. The model should be evaluated at the operating point where it will be used, with TPR and FPR as the primary lens.

Risk and Threat Considerations

When KYC is tuned on accuracy alone, the organisation can end up with a control that looks strong on paper but is weak against actual fraud. The risk is either under-detection, which leaves account-opening abuse and synthetic identity activity less visible, or over-blocking, which overloads analysts and creates a backlog that weakens the control in practice.

Failure mechanism: A skewed class distribution or poorly chosen threshold lets the model optimise the majority outcome while masking high-impact misses or excessive false alerts. Attackers benefit when the screening rule is calibrated to score well overall but not to the specific cases that matter operationally.

Impact: Missed fraud increases financial-crime exposure and remediation cost, while high false positives create customer friction, manual-review bottlenecks, and inconsistent onboarding outcomes. Over time, both conditions can reduce trust in the KYC process itself.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and NIST SP 800-63 set the technical controls, while GDPR defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-8 — Identification and Authentication (Non-Organizational Users)KYC verifies external customer identity before access is granted.
Recommendation — Use IA-8 to require stronger identity proofing where customer onboarding risk is high.
NIST SP 800-63Digital Identity GuidelinesKYC decisions align to assurance and fraud-friction trade-offs in identity proofing.
Recommendation — Apply assurance guidance to choose an onboarding threshold that matches risk.
GDPRA.5.1 — Not applicableKYC can process personal data and biometric evidence during identity checks.
Recommendation — No framework mapping selected.

Practitioner Guidance

What to prioritise: Set the threshold from the business consequence of each error, not from the highest accuracy point. In KYC, that usually means deciding first how much fraud escape you can tolerate, then checking whether the resulting false positive load is operationally sustainable.

What to verify: Measure TPR and FPR on a validation set that reflects the live customer mix and the actual decision threshold used in production. If the KYC workflow routes borderline cases to analysts, verify metrics at that exact route, not just on a retrospective test score.

Practitioner takeaway: In KYC, the best model is the one whose errors you can explain and absorb at the operating threshold, because that is where fraud control and customer friction become real.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org