Aug 10 2026
Security

How Digital Identity Verification Helps Banks Fight Fraud

As artificial intelligence and deepfakes complicate the fraud landscape, financial services firms need a continuous approach to identity verification to protect customers.

Banks and financial services institutions (FSIs) are heavily regulated for good reason. Banks’ average daily transaction volume can range from tens of millions to hundreds of billions or even trillions of dollars daily depending on the size of the company. To protect their customers and their own business, banks must ensure that the person requesting a transaction is who they claim to be. 

That’s where digital identity verification comes in. It’s a process used in modern banking to confirm that a customer is who they say they are. Banks and financial services institutions could use digital identity verification when customers are opening accounts, submitting loan applications, conducting payments and high-risk transactions, or requesting password resets. 

However, the prevalence of AI-powered deepfakes and other fraud threats, such as synthetic identities and social engineering attacks, mean that banks need sophisticated digital identity verification tools in place to prevent fraud and protect customers.

Click the banner below to learn more about managing identity and access in today's threat landscape. 

 

In 2024, an employee at a financial firm in Hong Kong was tricked into wiring $25 million to fraudsters after attending a multiperson videoconference in which all of the other participants were fake. The criminals used deepfake technology to impersonate the employee’s colleagues. 

“At its core, digital identity verification is the process of confirming a person’s real-world identity through digital means, often by matching a government-issued ID document with a biometric selfie. However, in a world of deepfakes, proving you are you is getting harder, and verifiable credentials will become the standard for secure identity,” says Gareth Davies, Auth0 chief product officer at Okta.

DISCOVER: This is the key step beyond authentication in identity and access management. 

The Growing Complexity of Today’s Fraud Landscape 

Historically, fraud attempts involved using stolen passwords to access an account. Stopping this type of fraud relied on blocking unauthorized access. Today, however, fraud attempts have become much more sophisticated, says Davies. 

“Some of the most devastating financial losses occur during all-green sessions, where the legitimate accountholder initiates a transaction using correct credentials,” he explains. “Through highly sophisticated social engineering and ‘authorized fraud’ schemes, victims are manipulated into authorizing transactions themselves.” 

Generative artificial intelligence and large language models have made it easier both technically and financially for anyone to execute highly sophisticated attacks at unprecedented velocity. According to Davies, AI allows bad actors to automate phishing, credential stuffing and bot attacks at a massive scale that can overwhelm legacy security systems. 

What Is Digital Identity Verification, and How Can Banks Support It? 

Digital identity verification offers a way to extend the trust models in traditional identity and access management to verification, Davies explains. It’s built in a way that’s tamper proof, privacy preserving and instantly verifiable anywhere. Digital identity verification is “a digital, cryptographically secure way to prove something about yourself,” he says. 

According to Davies, financial services institutions rely heavily on digital identity verification for critical operations throughout the customer lifecycle: 

  • Financial institutions are legally mandated to verify customer identities during account openings under Know Your Customer and Anti-Money Laundering regulations. This includes verifying customer details against government databases to ensure compliance. 
  • Digital verification is integrated with mobile and web portals, allowing customers to verify their identity and open accounts remotely in minutes. 
  • When a customer initiates a high-value or unusual action (such as wire transfers, loan applications or password resets), institutions trigger step-up verification. This prevents account takeover and unauthorized transactions before funds can leave the institution. 
  • As banks deploy autonomous AI agents to process loans or interact with customer accounts, digital identity verification is used to bind those actions to a “human in the loop” and authorize the AI agent as a secure proxy. This ensures clear, compliant audit trails and maintains the principle of least privilege in automated banking environments. 

A major difference between traditional identity tools and digital identity verification is the picture provided. Traditional tools provide a one-time snapshot, which isn’t enough in a world of AI impersonation and digital-first interactions.

Davies explains that transitioning from outdated static snapshots to continuous, secure digital identity verification requires that organizations build an integrated identity security fabric. 

“This requires a modern stack of interconnected technologies working in real time. First, to verify an identity remotely, the front-end interface must ingest and validate real-world physical credentials. Since onboarding is just a single point in time, organizations need technologies that monitor ongoing risk dynamically; processes such as liveness detection (to defeat deepfakes), behavioral biometrics and device fingerprinting are crucial here,” Davies adds. “Financial institutions also need adaptive multifactor authentication, which automatically steps up or steps down friction based on these real-time risk signals. And perhaps most important, instead of using siloed, disconnected platforms, organizations need to have a unified data layer that aggregates identity signals across the organization.” 

Best Practices for Managing Digital Identity Verification 

As banks look to adopt modern digital identity verification tools, Davies recommends they build a unified identity data directory. Synthetic identities and multi-channel fraud often bypass traditional, siloed security gates because individual systems don’t share information. Without a unified identity data directory, systems such as onboarding, transaction processing and customer support can become weak points in an organization’s environment. 

He also suggests mapping verification to the risk level to balance security with a seamless customer experience. 

GET THE DETAILS: Accelerate growth with cloud platforms in finance.

“Oververifying users during low-risk interactions introduces unnecessary friction and increases customer abandonment, which directly impacts the bank’s bottom line. Conversely, underverifying during high-risk moments leaves the organization vulnerable,” says Davies. 

Bank security teams also need to change their approach from static snapshots to continuous verification. Davies points out that traditional identity verification has been treated as a one-time checkbox completed during onboarding. However, a customer verified at onboarding can still have their account hijacked hours later or fall victim to an active social engineering scam. 

“Make sure to implement passive, continuous verification tools,” he advises. 

The Future of Digital Identity Verification for Financial Services 

Modern identity frameworks such as verifiable digital credentials (VDCs) and passkeys are shifting to cryptographic standards that give ownership back to the user. As part of this evolution, Davies expects that establishing “proof of human” will become essential. 

“When a service provider interacts with a third-party AI agent (for example, Claude or any other agent acting on behalf of a customer), the provider needs to trust that the agent it’s working with is both legitimate and cryptographically tied to a unique, verified human,” he says. “Otherwise, organizations risk severe attacks from malicious agents or humans using automated agents to bypass traditional fraud and abuse protections.” 

READ MORE: Platform engineering may be the missing link in banking AI success.

According to Davies, one of the greatest security risks for financial institutions is the overcollection of personal data, which makes them prime targets for data breaches. 

“Today, banks must adopt a zero-trust architecture and strictly enforce data minimization, collecting only what is legally required and storing it with strong encryption,” he says. 

Going forward, expect the industry to transition to VDCs built on open standards. “These cryptographically signed, tamper-proof credentials are held directly in the customer’s digital wallet and minimize risk for financial institutions,” Davies says.

ArtistGNDphotography/Getty Images
Close

New Research from CDW Explores AI and Cybersecurity

Learn how AI is helping IT teams manage risk and improve resilience.