Glossary

A

Account takeover (ATO)

An Account takeover (ATO) occurs when a fraudster gains unauthorized access to a legitimate user's account. ATO can be accomplished through methods like phishing, social engineering, or exploiting data breaches. The fraudster, after taking control of the account, can make unauthorized transactions, steal sensitive personal information, or engage in fraudulent activities.

Age verification

Age verification uses data from identity document validation in conjunction with biometric data to confirm a customer's age. This helps businesses ensure customer safety and regulatory compliance when offering age-sensitive products or services online.

AI-driven fraud detection

AI-driven fraud detection leverages artificial intelligence (AI) and machine learning to identify and prevent fraudulent activity in real-time. AI-powered fraud detection systems analyze large volumes of data, looking for anomalous patterns or unusual behaviors that might be otherwise missed by traditional, rule-based methods. Mitek's AI-powered tools for fraud detection help organizations to proactively detect and stop threats.

Anti-Money Laundering (AML)

Anti-Money Laundering (AML) practices include laws, regulations, and procedures applicable to the detection, prevention and reporting of activities that involve money laundering. AML practices that are implemented by financial institutions and other regulated entities are designed to prevent illicit funds from entering the financial system and becoming commingled with and indistinguishable from legitimate funds. This protects financial institutions from being a party to criminal activity and ensures compliance with federal regulations.

Anti-Money Laundering vs KYC

Anti-Money Laundering (AML) and Know Your Customer (KYC) are interconnected regulations, but are discrete processes. AML refers to the broad set of laws, regulations, and procedures that are designed to detect, prevent, and report on activities that potentially involve money laundering. KYC is an essential component of AML.

Application fraud

Application fraud occurs when an individual deliberately provides false, stolen, or misleading information in an application for a financial services product, such as loans, credit cards, or bank accounts. Fraudsters may use stolen or synthetic identity documents to commit application fraud with a wide range of goals, from gaining unauthorized access to credit to facilitating money laundering, leading to significant financial losses, regulatory issues, and/or reputational damage for businesses.

Authentication

Authentication processes are used to verify the identity of a user or entity attempting to gain access to systems or services, such as online banking or social media accounts, or a personal or corporate email account. Common methods of authentication include passwords, biometrics (including facial recognition or fingerprint), multi-factor authentication (MFA), passive liveness detection, and behavioral analytics that determine the consistency of the login attempt with previous logins.

Authorization

Authorization, broadly, is the process of granting appropriate access to a verified user. In contrast to authentication, which confirms a user's identity, authorization defines what that user is permitted to do. This might include viewing certain types of data, executing transactions, or accessing specific structures. Authorization is governed by policies and roles that define permissions related to resources. They might follow a user's role within an organization or specific account identity.

B

Bad actor

A bad actor is an individual or entity (such as a nation-state) that engages in fraudulent or otherwise malicious activity with the goal of harming others, exploiting systems, or gaining unauthorized access to sensitive information related to individuals or organizations. Bad actors employ various tactics such as identity theft, phishing, malware, social engineering, and other deceptive practices to obtain access to systems and achieve their goals.

Bank account fraud

Bank account fraud involves unauthorized access to or use of a customer's bank account. This type of fraud typically includes activities such as unauthorized withdrawals, fraudulent fund transfers, or unauthorized account openings using stolen or falsified identity information. Fraudsters often gain access through phishing, social engineering, or compromised login credentials.

Bank Secrecy Act (BSA)

The Bank Secrecy Act (BSA) is a U.S. federal law. The BSA requires financial institutions to proactively participate in the detection and prevention of money laundering. Under BSA regulations, banks and financial institutions are required to maintain detailed transaction records as well as to report suspicious activities and/or transactions — for example, large cash transactions and suspicious financial activities like patterns of regular, unexplained cash transactions — to the appropriate regulatory and legal authorities.

Behavioral biometrics

Behavioral biometrics is an advanced approach to identity verification and fraud prevention. It analyzes unique user behavior, like the user's typing patterns, mouse movement, navigation menu flow, and their touchscreen interactions for natural and consistent behavior. By continuously monitoring these traits passively, organizations can add an additional layer of authentication in real time without adding friction, thus providing a more seamless, secure user experience while still effectively enhancing their ability to detect fraud.

Biometric authentication

Biometric authentication is a secure method of identity verification that analyzes a user’s unique biological or physical characteristics, such as their fingerprint, facial geometry, iris patterns, or voiceprint. Unlike password- or token-based methods, biometric authentication offers stronger protection and a more seamless user experience by leveraging individual traits that are extremely difficult for a fraudster to replicate.

Biometric matching

Biometric matching is the process of comparing a user's biometric data, like their fingerprint, facial geometry, or voiceprint, against a stored reference to confirm identity. This comparison can be one-to-one (as secondary validation to verify a claimed identity), or one-to-many (for example, to search for a match across a database before authorizing or denying access based on the biometric information alone). Biometric matching is a foundational capability for biometric authentication systems. It enables fast, accurate, and more secure user verification. 

Biometrics

Biometrics refers to the use of measurable physical or behavioral traits, including fingerprints, facial geometry, iris patterns, voiceprints, and individual user behavior, for the purposes of identity verification and controlling access, for example, to digital accounts or physical locations. By analyzing these unique user characteristics, biometric systems provide a powerful foundation for secure and user-friendly authentication.

Bust out fraud

Bust out fraud is a form of financial fraud orchestrated over a longer timeline. An individual establishes a strong credit profile, often over months or even years, with the intention of eventually maxing out the lines of credit extended to that profile and not repaying them. Frequently, bust out fraud involves stolen or synthetic identities and is designed to evade early detection.

C

Call center fraud

Call center fraud occurs when criminals exploit customer service channels to gain unauthorized access to financial accounts or sensitive data. Using techniques that include social engineering, caller ID spoofing, and/or stolen personally identifying information, the fraudsters put on a convincing act and manipulate call center agents into bypassing the security protocols that protect customer accounts. This type of fraud typically targets human vulnerabilities and agents' desire to help, rather than a financial institution's technical defenses.

Card-Not-Present (CNP) fraud

Card-Not-Present (CNP) fraud refers to unauthorized transactions made without the physical presence of a payment card, which is typical of online/in-app purchases or purchases made by phone. Fraudsters use stolen payment card details to complete these remote payments, with no need to steal or clone a physical card to complete the verification required by face-to-face transactions. The scale of online commerce and speed expected for online payment processing means that CNP fraud remains one of the most prevalent threats in digital commerce.

Credit card fraud

Credit Card Fraud is the unauthorized use of credit card details to illegally access funds or purchase goods or services. Fraudsters obtain credit card info in many ways, including physical theft, the use of skimming devices, data breaches of banks or retailers, phishing attacks, or account takeovers. Credit card fraud results in immediate financial losses for financial institutions and can also cause lasting reputational damage if a bank has a constant history of not detecting and blocking fraudulent activity on its customers' accounts. 

Credit invisible

Credit invisible describes individuals who lack sufficient credit history with the major credit bureaus due to having few or no payment accounts (like credit cards, a mortgage, or an auto loan). This "thin file" makes these customers effectively invisible due to traditional lending systems not having the data they would otherwise use to rate their risk. While that means they do not have a negative credit history, it still typically restricts their ability to obtain loans, credit cards, or similar financial services.

Customer Due Diligence (CDD)

Customer Due Diligence (CDD) is a regulatory requirement for financial institutions. CDD mandates that these institutions verify customer identities, understand the nature and purpose of the customer's relationship with the financial institution, and evaluate any risk factors present that could indicate involvement in fraud or other financial crimes.

Customer Identification Program (CIP)

A Customer Identification Program (CIP) is a core regulatory requirement for financial institutions. It requires these institutions to properly verify the identity of individuals and entities before establishing financial relationships with them. CIP is a foundational element of Know Your Customer (KYC) and Anti-Money Laundering (AML) compliance, and helps financial institutions prevent identity fraud, reduce their exposure to illicit activity, and safeguard the entire financial system.

D

Data encryption

Data encryption is the technique used to transform readable data into an encoded format through the use of cryptographic encryption algorithms, ensuring that only authorized parties with a decryption key can access or interpret it. Data encryption is widely used to protect sensitive information in transit (for example, during a payment transaction) and at rest (for example, where account information is stored), making it a critical control for safeguarding customer data and maintaining regulatory compliance.

Data privacy

Data privacy refers to the policies, practices, and regulatory frameworks that have been put in place to protect individuals’ personal information from unauthorized access, disclosure, or misuse. Implementation of strong data privacy measures is a legal and ethical imperative, and is necessary for maintaining customer trust, meeting compliance obligations, and reducing the overall risk of identity theft and fraud.

Decentralized Identity (DID)

Decentralized Identity (DID) refers to a digital identity model that allows individuals to manage and control their own personal data, without reliance on a centralized authority. DID technology frameworks shift ownership of identity to the user, giving them more control over their digital identity. DID enhances overall privacy, reduces the risk of identity fraud, and offers a secure, user-centric approach to authentication.

Deepfake

Deepfake refers to AI-generated or digitally manipulated media, including videos, images, or audio, that has been designed to realistically mimic the appearance, behavior, and/or voice of a real person. While the creation of your own digital twin can serve legitimate purposes, deepfake media presents many risks for identity fraud, impersonation, misinformation, and social engineering attacks.

Demand Deposit Account (DDA) fraud

Demand Deposit Account (DDA) fraud involves the exploitation of checking or savings accounts (demand deposit accounts) by fraudsters, who make unauthorized withdrawals or other fraudulent transactions, or open accounts using false or stolen identities. Common tactics seen with DDA fraud include check fraud, electronic funds transfer (EFT) scams, and account takeovers. DDA fraud can result in significant monetary losses and operational risk for financial institutions.

Device fingerprinting

Device fingerprinting is a technique that is used to identify and track unique devices, like smartphones, computers, or tablets, based on a combination of their hardware and software attributes. This device fingerprint includes aspects like mobile carrier, browser type, operating system, screen resolution, and more.

Digital identity

Digital identity refers to the collection of verified digital attributes, credentials, and behaviors that constitute an individual's identity online. It enables secure, trusted access to digital services, including banking, e-commerce, social platforms, and government portals, by serving as the foundation for authentication, authorization, and identity-based decisioning processes online.

Digital identity verification

Digital identity verification is the process of confirming that an individual’s claimed identity matches their true identity. This verification is typically conducted online using a layered system that verifies official ID documents, biometrics like facial geometry, behavioral data, and other verification signals. Digital identity verification ensures that only legitimate users are able to gain access to services or accounts, and is a foundational component of secure onboarding, fraud prevention, and regulatory compliance.

Document liveness

Document liveness is a real-time security check during digital identity verification. It is used to confirm that the identification document presented is authentic and that the genuine document is being displayed by the user, not a photo, scanned document, or deepfake. This stops fraudsters from bypassing identity checks by using fake, manipulated, or previously captured images of documents. For added security, Mitek’s document liveness detection layers seamlessly with our mobile identity suite, ensuring that every document presented is present and valid.

Document template attack

A document template attackis the use of authentic-looking document templates, like drivers' licenses, passports, utility bills, or pay stubs, to create convincing forgeries to use for fraudulent identity verification purposes. Often sold on the dark web, these blank or partially completed templates are customizable with stolen or fabricated target information and photos. They are surprisingly sophisticated, and many have replicated security features along with the formatting and design elements of legitimate documents.

Document verification

Document verification is the process of confirming the authenticity of identity documents, including passports, driver’s licenses, or national ID cards, that are submitted during online identity verification. Verification ensures that the documents presented are valid and are free from tampering or forgery. Robust document verification processes are a core element of secure onboarding and compliance workflows for banks, financial institutions, and other organizations with fiscal or age-related compliance requirements.

E

eKYC (Electronic Know Your Customer)

Electronic Know Your Customer (eKYC) is the digital equivalent of traditional KYC processes. eKYC processes are used by financial institutions to verify customer identities remotely and in real time. By leveraging biometrics, digital document verification, AI-driven risk analysis, and other technologies, eKYC improves the customer experience by streamlining onboarding with seamless verification checks, while strengthening an institution's compliance and preventing fraud.

F

False negative

A false negative occurs when fraud detection or identity verification systems fail to identify a fraud attempt and incorrectly classify it as legitimate, allowing it to pass the security check. For example, in identity verification, a false negative would happen if an application submitted with a stolen identity and/or forged documents was approved, or in fraud detection, it would occur if an unauthorized transaction was not flagged and was approved. False negatives can result in direct financial losses, regulatory issues, and reputational damage.

False positive

A False positive refers to a legitimate transaction or user activity that is mistakenly flagged as fraudulent. Security or fraud detection systems that report excessive false positives can disrupt the customer experience, delay important transactions, and strain operational resources because of the amount of manual effort required to resolve them and reauthorize the flagged activities. While false positives will occur with every risk management system, their reduction is a key goal for internal fraud teams as well as CX leaders.

Family or Familiar fraud

Family or Familiar fraud occurs when someone uses the identity and/or financial accounts of their relative, partner, or friend or acquaintance, typically without that person's consent. This type of fraud leverages the access and personal trust the fraudster has due to their proximity to the victim, which makes it easier for them to bypass security controls. This type of fraud is also often harder to detect. It also sometimes occurs in conjunction with other crimes like elder abuse.

First-party fraud

First-party fraud occurs when an individual deliberately misrepresents their identity, financial status, or intent to repay, to gain access to credit or services, such as applying for a loan or credit card without any intention of fulfilling their repayment obligations. In contrast to third-party fraud, where the fraudster uses the identity of another person or uses a synthetic identity, the perpetrator of first-party fraud is the account holder themselves.

Fraud detection

Fraud detection processes monitor and analyze customer data, transaction activity and other user behavior to identify suspicious or potentially unauthorized activity. By leveraging AI, machine learning, and advanced analytics, modern fraud detection systems proactively detect and prevent fraud and mitigate institutional losses. Mitek’s AI-powered fraud prevention solutions give organizations the ability to spot and stop threats in real time.

Fraud prevention

Fraud prevention refers to proactive strategies and technologies that are used to stop fraudulent activity before it happens. Fraud prevention techniques include identity verification, document verification, biometric authentication, and transaction monitoring, all of which are capable of detecting anomalies in real time. Mitek’s AI-driven solutions strengthen these fraud prevention defenses, proactively stopping threats to prevent financial losses and preserve customer trust.

Fraud rings

Fraud rings are organized networks of individuals that work together to execute fraud schemes at scale. These groups often share stolen identity documents and/or compromised data and engage in criminal tactics to systematically target businesses and consumers. These groups can have global reach, and the breadth and depth of their organized network allows them to amplify the impact and complexity of their fraudulent activity.

Friendly fraud

Friendly fraud occurs when a legitimate customer subsequently initiates a chargeback for a transaction they knowingly authorized, claiming the purchase was unauthorized, undelivered, or otherwise unsatisfactory. The practice has been widely publicized on social media platforms. This type of dispute results in revenue loss, increased operational costs, and added risk for merchants as well as financial institutions. Tr

Fullz

Fullz is a term used to describe a complete set of stolen personal data, including name, address, Social Security number, birthdate, and financial account details, that can be used to commit identity fraud. Fullz are often sold on the dark web. With this data, fraudsters have all of the basic information required to attempt to open new accounts or take over existing accounts, apply for credit, or conduct unauthorized transactions.

G

General Data Protection Regulation (GDPR)

General Data Protection Regulation (GDPR) is a law in the European Union that focuses on safeguarding privacy and personal data for EU citizens. GDPR regulations require businesses that serve customers in the EU, regardless of the business' location, to implement strict data handling, consent, and transparency practices for processing the personally identifiable information of EU residents. Non-compliance can result in significant financial penalties, as well as reputational damage.

Global watchlist

Global watchlist refers to a compiled list of individuals and entities that have been identified as high-risk, due to their suspected involvement in activities like terrorism, money laundering, violating government sanctions, or other financial crimes. These lists are used by financial institutions as part of their compliance, screening, and due diligence processes to improve regulatory compliance and minimize their reputational risk.

I

Identity-as-a-Service (IDaaS)

Identity-as-a-Service (IDaaS) refers to cloud-based, plug-and-play solutions that enable businesses to manage and verify user identities. IDaaS platforms will typically incorporate document verification, biometric authentication, access control, and identity proofing capabilities, delivering all of the capabilities of on-premises identity solutions.

Identity fraud

Identity fraud occurs when a fraudster obtains stolen personal information, like a name, Social Security number, driver's license number, date of birth, address, and/or bank account details, and uses them to impersonate someone and carry out financial fraud. Unlike identity theft, which involves the unauthorized acquisition of this type of personal data, the definition of identity fraud is focused on the deliberate act of misuse of that data for deception and monetary gain.

Identity fraud detection and prevention software

Identity fraud detection and prevention software includes a full suite of AI-powered tools that create layered defenses using biometrics, behavioral analytics, and document verification to stop identity fraud activity. Together, these solutions assess risk profiles, detect and flag anomalies, and confirm user authenticity, all without adding unnecessary friction to the customer experience. Mitek’s advanced identity fraud prevention platform empowers organizations to detect and neutralize threats in real time, maintaining compliance and security.

Identity fraud detection in banking

Identity fraud detection in banking involves the use of advanced technology within financial institutions to identify identity impersonation attempts or the use of synthetic identities. These systems rely on document and biometric verification, behavioral analytics, database checks, and fraud pattern recognition to keep customer accounts secure, block the creation of fraudulent accounts, and protect the overall banking infrastructure. Mitek’s AI-powered solutions help banks detect threats early and respond proactively.

Identity fraud management

Identity fraud management refers to the use of strategic processes, technologies, and governance frameworks to detect and mitigate identity-related fraud. These processes include continuous monitoring, robust incident response protocols, post-incident root-cause analysis, and adaptive controls that often leverage AI and machine learning so that they can evolve with emerging threats, ensuring long-term resilience against fraud attempts and ongoing regulatory compliance.

Identity proofing

Identity proofing is the process of collecting, verifying, and validating personal information in order to confirm that an individual is who they claim to be. Identity proofing is a foundational element of digital identity verification and is necessary for meeting KYC and AML compliance standards. Common methods of identity proofing include document authentication, biometric validation, and cross-checks against reputable industry databases to ensure accuracy.

Identity theft

Identity theft is the act of stealing someone’s personal information, like their Social Security number or driver's license number, banking login credentials, or other account details, with the intent to use this information to commit fraud. This stolen data is often used to execute identity fraud by opening new fraudulent accounts, conducting unauthorized transactions on the victim's existing accounts, or fabricating synthetic identities, posing significant financial risks to individuals and institutions.

Identity verification

Identity verification is a process used to confirm that a person’s presented identity, for example, via identification documents, voice or facial biometrics, or other data, is an accurate reflection of their real-world identity. Identity verification is needed for secure onboarding, fraud prevention, and regulatory compliance. Verification typically involves document validation, biometric authentication, and liveness detection to ensure users are who they claim to be. 

Identity verification software

Identity verification software provides automated verification of individuals by utilizing technologies like document scanning, biometrics, facial recognition, database cross-checks, and AI. These tools streamline user onboarding while improving fraud detection and reducing compliance risks. These tools provide layered protection against identity fraud. They are used to secure new customer onboarding as well as other transactions, and to ensure regulatory compliance.

Injection attack

An Injection attack, in the identity verification context, is a sophisticated fraud technique where fraudsters feed pre-recorded images or video content into digital verification systems in an attempt to spoof or bypass liveness detection and biometric checks. These attacks are commonly linked to deepfakes or replay attacks. Liveness detection can catch these injection attacks by analyzing the video to determine if the content is truly live.

K

Know Your Customer (KYC)

Know Your Customer (KYC) is a regulatory process that requires businesses to verify the identities of their customers before doing business with them. KYC processes include collecting and validating information such as IDs, biometric information, and addresses, and confirming that the customers aren't on sanctions lists or potentially involved in illegal activities.

Use case/ examples of Know Your Customer (KYC)

Account opening: Verifying a customer's identity and their source of funds before establishing a new banking relationship. 

Knowledge-Based Authentication (KBA)

Knowledge-Based Authentication (KBA) is an identity verification method that relies on the user answering personal security questions based on information that only they should know. This sometimes includes information the customer has provided, like the name of their first pet, or information from databases, like selecting a street the customer once lived on or a car the customer once owned. KBA has declined in usage due to vulnerabilities, including public data leaks and the ease of social engineering to obtain this information.

KYC compliance

KYC compliance refers to adhering to the Know Your Customer (KYC) regulations. These regulations require businesses, especially financial institutions, to verify the identities of their customers before doing business with them. The KYC compliance process involves confirming personal information, verifying identity documents, assessing risks associated with customers, and ongoing transaction monitoring - plus reporting anything suspicious to authorities.

L

Liveness detection

Liveness detection refers to advanced biometric technology designed to confirm that a real, living person is present at the time of identity verification - not a photo, deepfaked or replayed video, or someone using prosthetics. Liveness detection helps prevent spoofing attacks where fraudsters use physical props or digital media to bypass biometric checks. It can be active, requiring the user to participate in the process, or passive, as a background process that checks elements like shadows, textures, and more, even without the user's knowledge.

Location-based authentication

Location-based authentication verifies a user's identity based on a login's geographic location or its proximity to that user's known, trusted devices and/or typical login locations. It enhances security by using geolocation data from devices or IP addresses to validate user identity and detect unauthorized access attempts. It can be layered with other processes like biometric authentication, multi-factor authentication (MFA), and passive liveness detection for added security.

M

Mail theft

Mail theft involves stealing physical mail to obtain items like credit cards or checks that can be used directly for financial fraud, or documents that contain sensitive personal information or financial details that can be used for identity theft and other malicious purposes.

Mobile device fingerprinting

Mobile device fingerprinting creates a unique profile for mobile devices based on attributes such as the device model, operating system, settings, installed applications, geolocation, and IP addresses, as well as other characteristics. Organizations can monitor whether a login from a device is consistent with a user's usual preferred devices, or when one device is being used for multiple fraudulent accounts or fraud attempts.

Money laundering

Money laundering is the illegal process of disguising proceeds from criminal activities in a way that makes them appear to have been legally obtained. In a money laundering scheme, criminals typically perform multiple financial transactions or transfers to obfuscate the original source of the funds, making it difficult for authorities to track and possible to spend without raising suspicion.

Money mule

A money mule is an individual who transfers or moves illicitly obtained money on behalf of others, typically criminals. Some money mules are unaware that they are involved in illicit activity, and may have been recruited via romance scams or fake job postings. Other money mules knowingly operate as a part of organized fraud rings. Money mules facilitate money laundering; their transactions help fraudsters and organized crime disguise the original source of illegal funds.

Multi-Factor Authentication (MFA)

Multi-Factor Authentication (MFA) is a security protocol requiring two or more independent verification methods to confirm a user's identity. Typically, the MFA process includes something the user knows (password), something the user has (their smartphone on which they can receive or generate a code), and/or something the user is (fingerprint or facial recognition). It can include passive liveness detection for added security.

N

New account fraud

New account fraud occurs when fraudsters use stolen or fabricated/synthetic identities to open new accounts, like credit cards, bank accounts, or loans. Criminals exploit these accounts in many ways; they might take the proceeds of loans or run up the balance of a credit card without any intention of paying, or use new bank accounts for money laundering activities.

O

One-Time Password (OTP)

A One-Time Password (OTP) is a temporary, dynamically generated numeric or alphanumeric code valid for authenticating a single transaction or login session. OTPs enhance security by reducing the risks associated with password sharing and credential theft.

Use case/ examples of One-Time Password (OTP)

Login verification: Requiring the use of a code from an authenticator app to verify a user's identity when there is a login attempt from a new device or location. 

Optical Character Recognition (OCR)

Optical Character Recognition (OCR) software is used to turn scanned images of printed or handwritten text into digital form. OCR technology is commonly used for quick and seamless extraction of information from identity documents, significantly speeding up digital onboarding and verification processes. For example, OCR can be used to scan the name, address, number, and expiration date from an image of a customer's driver's license, saving them time entering this information.

P

P2P fraud

P2P (Peer-to-Peer) fraud refers to scams and fraudulent activities involving peer-to-peer payment platforms like Zelle, Venmo, or CashApp. These scams are commonly related to online marketplaces where sellers post listings — sometimes at almost-too-good-to-be-true prices — with no intention of ever shipping the item, as well as phishing scams.

Use case/ examples of P2P fraud

Marketplace protection: Preventing fake seller scams on peer-to-peer marketplace platforms by verifying user identities before enabling payment receipt. 

Passive authentication

Passive authentication is a method of verifying user identities unobtrusively by analyzing how a user naturally uses their device or app, the device's characteristics, or the user's biometrics, without requiring active input from the user. It provides frictionless, continuous identity validation throughout user interactions. It can include biometric authentication, multi-factor authentication (MFA), and passive liveness detection for added security.

Passive liveness detection

Passive liveness detection refers to the use of biometric technology that automatically confirms a user's presence without requiring them to take deliberate actions, such as blinking or moving. It uses AI to analyze the user's presented biometric data for any discrepancies,  protecting against spoofing attacks without disrupting the user experience.

PEPs and sanctions

PEPs and sanctions refer to the screening processes used to identify Politically Exposed Persons (PEPs) and other individuals and entities that are subject to government sanctions. PEPs are individuals who hold or have held prominent positions (for example, senior government officials, executives of state-owned enterprises, and high-ranking military officials) as well as their family and close associates; they may present elevated money laundering risks.

Phishing

Phishing is a form of cybercrime where attackers use channels like email, text messages, or websites to pretend to be an entity the target trusts. Phishing messages often use tactics to create urgency, for example, suggesting a user's account will be locked or may have been compromised. The goal is to deceive individuals into revealing personal, sensitive, or financial information, such as their passwords or credit card numbers.

PII (personally identifiable information)

Personally identifiable information (PII) is any data that can be used to identify or contact a specific individual, whether on its own or when combined with other information. PII includes identifiers like full name, social security number, driver's license number, passport number, and a person's biometric data, along with information like date of birth, address, phone number, email address, and account numbers.

Privacy by design

Privacy by design is an approach in technology and systems development that builds privacy and data protection measures into systems and processes from the outset, rather than trying to add privacy protection later. This helps to ensure personal data is protected throughout its lifecycle. Common privacy by design techniques include building systems that only collect and securely store the data they need, and giving users transparency and control over their information and how it is used.

Privacy policy

A privacy policy is a legal statement that outlines how an organization collects, uses, protects, and manages users' personal information. It includes information like what information a company collects, how they use it, who they share it with, and what rights the user has over their own data. Privacy policies are essential for legal and regulatory compliance, as well as transparency.

Proof of Identity (POI)

Proof of Identity (POI) refers to documents or data provided to verify an individual's identity. These include government-issued IDs like passports, driver's licenses, or national ID cards. POI is an essential component of secure and compliant identity verification and onboarding.

Use case/ examples for Proof of Identity (POI)

Account opening: Verifying customer identity through the use of government-issued documents like passports or driver's licenses during a financial institution's onboarding.

R

Regulatory compliance

Regulatory compliance refers to the process of adhering to all laws and regulations that apply to an organization's industry and operations. In the financial and identity verification space, this includes multiple frameworks that cover everything from identity verification and data protection to money laundering and fraud reporting. These include [link each or spell out] AML, KYC, GDPR, CCPA, and other data protection or financial crime prevention regulations.

Risk-based authentication

Risk-based authentication (RBA) is a dynamic authentication method that automatically adjusts the security measures that are used based on the risk level associated with each login attempt or transaction. It considers factors like user behavior, device type, geolocation, and transaction value to determine if additional verification is needed, so a user can easily log in to their account on their usual device from home, but extra verification would be deployed if that same user's account was being used to transfer a large sum of money from a new device.

Romance scam

A romance scam is a type of fraud where a criminal creates a fake online identity and uses it to engage in romantic relationships with their victims, with the ultimate goal of manipulating them into sending money or granting access to personal information that can be used to compromise their accounts. These scammers might initiate a conversation on a dating app, social media site, or other messaging app. The elderly are common victims, but targets of romance scams can be of all ages.

S

Selfie authentication

Selfie authentication is a biometric identity verification method that matches a selfie submitted by a user in real-time with a previously verified image. Selfie authentication is sometimes used for high-risk, sensitive transactions or account recovery. It may also utilize liveness detection to ensure the user is physically present and prevent a spoofing attack.

Use case/ examples for selfie authentication

New user onboarding: Onboarding a new user of a banking or fintech app by comparing their selfie with an ID photo.

Selfie ID verification

Selfie ID verification compares a live selfie taken by a user against the photo on the identity document they have presented, and uses facial recognition technology to confirm the two match. This process ensures the person presenting the document is the legitimate owner and helps to prevent identity fraud during the digital onboarding process. Selfie ID Verification can be paired with liveness detection to ensure that the selfie was captured in real-time, and is not a static image, deepfake, or other type of spoofing attempt.

Social engineering

Social engineering is a technique used by fraudsters to deceive others into divulging confidential information and/or performing an act that compromises or circumvents security measures. Social engineering techniques exploit human psychology rather than technical vulnerabilities. They often involve the use of urgency, fear, or authority to convince users to bypass security protocols. 

Spoofing attack

A spoofing attack is a fraud technique that can take many forms, but all involve impersonation. Email spoofing forges a sender's address to make it look like a message is from a trusted source. Caller ID spoofing is used to show a legitimate number on a phone's display, rather than the number from which the call really originates. Website spoofing, often used as part of a phishing scam, creates a copy of a legitimate site to harvest user credentials. Biometric spoofing attempts to fool a facial recognition or fingerprint matching algorithm using photos, masks, or prosthetics.

Step up authentication

Step up authentication is a dynamic approach to verification requirements, where multiple factors can, in real-time, trigger a "step up" to require two-factor authentication (2FA), re-entering a password, or another heightened verification requirement. Instead of applying the same authentication process to all interactions, step-up authentication instead is triggered based on factors like transaction value, whether a new device is used, if multiple settings are being changed, or other sensitive behavior.

Synthetic identity

A synthetic identity is a fabricated identity that combines real and fictitious personal information, forming a new digital persona that does not correspond to any real person. For example, a fraudster might combine a Social Security number (commonly from a child, elderly person, or deceased person) with a fake name, address, and date of birth. They often pass basic identity checks, and because no real person is being compromised, synthetic identities can exist for long periods of time, building credit history, before being used for large-scale fraud. 

Synthetic identity fraud

Synthetic identity fraud occurs when a criminal uses a synthetic identity (link) to open accounts, obtain credit, or access services. This fast-growing threat is difficult to detect, as they often pass initial verification checks and can build months or years of legitimate credit history before a fraudster maxes out their credit lines and vanishes. With no "real" victim to report the fraud early on, the fraud often goes undetected and can result in significant synthetic identity fraud losses for lenders.

T

Thin file

A thin file refers to an individual with little to no credit or financial history on record. Thin files make it difficult for traditional verification and scoring systems to assess a person's risk profile. Typical thin file users are young adults, recent immigrants, people who use cash for most transactions, and those who were previously unbanked. Instead of conventional credit checks, which have little information on thin file users, institutions must seek novel methods and alternative data sources to serve these populations while still managing risk.

Third-party fraud

Third-party fraud occurs when a criminal uses stolen or fabricated identity information to impersonate a real person during a transaction or application. Unlike first-party fraud, third-party fraud victimizes an innocent person whose identity has been compromised. Fraudsters may use the victim's identity to open accounts, apply for loans, or make unauthorized purchases.

Tokenization

Tokenization is a data security technique that replaces sensitive data (such as payment card numbers) with a unique and randomly generated identifier (a token). Tokens retain the format and structure of the original data, but have no exploitable value without access to the secure token vault, which makes it possible to map the tokens back to their original values. Tokenization is widely used in industries that involve sensitive data, including payment processing and healthcare.

Tokens

Tokens are digital representations of sensitive data, used for security and encryption. Tokens can be used to replace sensitive information, like payment card numbers, with equivalents that have no exploitable value if they are intercepted. They are also used to generate one-time passwords (OTPs) or cryptographic codes to verify a login or transaction. They help institutions reduce the risk of information being misused, even if communication channels are compromised. 

Transaction authentication

Transaction authentication is the process of verifying and authorizing individual financial transactions to confirm that they were initiated by the legitimate account holder. Transaction Authentication is a verification layer that prevents fraudulent transactions and account takeovers by using multi-factor authentication (MFA), biometric verification, one-time passwords (OTPs), and, in some institutions, risk-based authentication that adjusts these requirements based on the characteristics of the transaction. 

Two-Factor Authentication (2FA)

Two-Factor Authentication (2FA) is a security method that requires users to verify themselves in two different ways before accessing their account or completing a transaction. Common 2FA  combinations include something you know (like a PIN or password), something you have (a mobile device or a security token), and/or something you are (biometric data like a fingerprint or selfie). 2FA significantly enhances account security even when one factor, like a password, has been compromised. 

U

Unbanked

The unbanked refers to individuals who do not have access to traditional banking services or accounts, like checking or savings accounts. They may have encountered barriers to banking if they do not possess identity documents or may have little to no credit history. These unbanked populations often are reliant on alternative financial sources like payday loans and check-cashing businesses, which generally are more costly and less secure than mainstream institutions.

User authentication

User authentication is the process of verifying the identity of a user attempting to gain access to digital systems, platforms, or sensitive information. User authentication methods include passwords, personal identification numbers (PINs), biometrics (fingerprint, facial recognition, or voice), one-time passwords (OTPs), or multi-factor authentication (MFA) and other tools to ensure secure access and prevent unauthorized use. Some organizations implement two-factor authentication (2FA) or multi-factor authentication (MFA) that combines these methods to verify user identity.

V

Velocity check

A velocity check is a fraud detection technique that monitors both the frequency and the speed of activity on an account, device, or person's identity, looking for suspicious patterns (especially suspiciously high activity). For example, velocity checks will flag abnormal behaviors like multiple login attempts within sections, repeated password reset requests, multiple rapid-fire outbound money transfers, or numerous account applications from the same IP address or device.

Z

Zelle fraud

Zelle fraud refers specifically to financial scams or unauthorized transactions conducted through the popular peer-to-peer digital payment service Zelle. Zelle payment transfers are designed to be instantaneous and are also difficult to reverse, making the platform an attractive target for fraud.