Banks have traditionally concentrated identity verification at account opening. Yet many of the moments most attractive to fraudsters happen later – when a customer recovers an account, activates a new device, changes sensitive information or initiates a higher-risk payment. The decision for banks is no longer whether to verify identity, but how to increase assurance at the right moment without making every digital interaction harder.
The pressure is growing. UK Finance reported that criminals stole £1.28 billion through payment fraud in 2025, according to its Annual Fraud Report 2026. In its flagship intelligence report, Fraudscape 2026, Cifas recorded more than 78,000 account takeover cases that year, up 6% on 2024. Mandatory reimbursement requirements for authorized give payment firms a further financial incentive to prevent fraud before money moves. Banks therefore need to move from one-time verification at onboarding to risk-based identity assurance throughout the customer lifecycle.
Onboarding is no longer the only identity checkpoint
Digital journeys contain multiple points where a bank may need renewed confidence that the person behind the screen is the legitimate customer. Weak checks can expose account recovery, device registration, profile changes and payment flows. Universal checks create a different problem: genuine customers face unnecessary delay, abandonment rises and trust in the digital experience can fall. The better model is adaptive – assurance increases when risk, behaviour or context justifies it.
Banks shouldn’t have to choose between stronger identity assurance and a frictionless digital experience. The opportunity we see with Temenos is to make step-up verification available exactly when the customer journey requires it, from onboarding to account recovery or any other high-risk action, while maintaining a consistent customer experience”.
Jari-Pekka Sova
Chief Commercial Officer, Candour
Identity verification must become part of the journey
Temenos Exchange Provider Candour tested this approach by embedding identity verification into a Temenos digital banking journey. After validating the development workflow with a simple mobile application, the team created an end-to-end experience that captured an identity document and customer selfie, connected the front-end journey to server-side verification and returned the result within the banking experience.
Stronger assurance should follow risk, not every customer
The proof of concept showed that high-assurance identity verification can sit inside a digital banking journey rather than operate as a separate process. The same capability can support onboarding, account recovery, new-device activation, sensitive profile changes or higher-risk transactions. The trigger and level of assurance may differ, but the principle is consistent: verification should respond to the risk of the moment.
The work also demonstrated that step-up verification can be incorporated into an existing digital experiences using shared development resources and integration capabilities. That matters because a control is more valuable when it works with the customer journey, operational processes and risk decisions already in place. A proof of concept is not the same as a production deployment, but it can validate the journey, integration pattern and customer experience before wider implementation.
Start with the moments where trust matters most
Banks can begin by mapping the journeys where a compromised identity would create the greatest customer or financial harm. They should then define the signals that justify additional assurance – such as a new device, unusual behavior, a sensitive profile change or a high-risk transaction – and match the verification step to that context. Finally, identity checks should be designed and tested as part of the end-to-end journey, with clear measures for completion, abandonment, fraud prevention and operational handling.
Doing nothing leaves banks with an uncomfortable choice between controls that are too weak at critical moments and controls that create friction everywhere. A risk-based model offers a more proportionate alternative: stronger assurance where it is needed, with simpler journeys where it is not.
Identity assurance should no longer be treated as a gate customers pass through once. Used selectively across the lifecycle, it can help banks reduce fraud exposure, support stronger financial crime controls and protect trust without burdening every customer interaction. The next step is to identify the moments that need more confidence and make verification a natural part of those journeys.
Request a demo of the Candour IDV proof of concept to see how risk-based identity verification can support digital banking journeys.