Identity Verification & Fraud Prevention Glossary

Practitioner-oriented definitions for 237 terms covering identity verification, KYC/AML, biometrics, liveness detection, fraud prevention, and compliance.

1:1 Verification

Biometric verification that compares a captured biometric sample against a single enrolled template to confirm the claimed identity.

1:N Identification

Biometric identification that searches a captured biometric sample against a database of enrolled templates to determine identity.

2FA (Two-Factor Authentication)

A subset of multi-factor authentication that requires exactly two different authentication factors to verify a user's identity.

3-D Secure (3DS)

A card-payment authentication protocol that lets an issuer assess a card-not-present transaction and, when risk warrants it, challenge the cardholder before authorization. Modern versions support risk-based, low-friction flows as well as step-up authentication.

AAL (Authenticator Assurance Level)

NIST categories (1-3) describing the strength of authentication, from single-factor to hardware-bound multi-factor.

ABAC (Attribute-Based Access Control)

Access control using attributes (user, resource, action, environment) evaluated against policies to make dynamic authorization decisions.

AML (Anti-Money Laundering)

Laws, regulations, and procedures designed to prevent criminals from disguising illegally obtained funds as legitimate income.

API Security

Practices and technologies protecting APIs from unauthorized access, abuse, and data exposure, including authentication, rate limiting, and input validation.

Access Certification

Periodic reviews — typically quarterly or annual — where managers formally confirm whether each team member still requires their existing system access, a core IGA control.

Account Takeover (ATO)

A form of fraud where criminals gain unauthorized access to user accounts, typically through stolen credentials, social engineering, or session hijacking.

Active Liveness

A liveness detection approach requiring explicit user participation — blinking, turning the head, reading a displayed prompt — to confirm a live person is present. More resistant to basic photo attacks but creates more friction than passive approaches.

Adaptive Authentication

Authentication that adjusts security requirements based on real-time risk assessment of user behavior, device, and context.

Address Verification

Confirming that a provided address is real and corresponds to the claimed identity, using postal records, utility data, or credit bureau information — a standard layer in KYC flows.

Address Verification Service (AVS)

A card-not-present fraud control that compares the numeric parts of a billing address supplied during checkout with the address held by the card issuer and returns a match result for use in the merchant's risk decision.

Affiliate Fraud

Manipulation of an affiliate program to obtain commissions that were not legitimately earned, including fake leads, cookie stuffing, attribution hijacking, automated traffic, and transactions designed to be cancelled or refunded.

Age Assurance

A category of identity verification technology designed to confirm whether a user meets a minimum age threshold, without necessarily verifying full identity. Age assurance methods range from self-declaration and credit card checks to document verification and biometric facial age estimation. The UK Online Safety Act and similar legislation globally have accelerated demand for robust, privacy-preserving age assurance solutions.

Why it matters: Regulatory pressure across the UK, EU, Australia, and US states is mandating robust age verification for online platforms serving minors. Buyers need to understand the tradeoffs between assurance strength, friction, and privacy across different age assurance methods.

Angler Phishing

A social-media impersonation attack in which a criminal poses as a brand's support account and approaches customers who have publicly asked for help, then redirects them to disclose credentials, payment information, or recovery codes.

Anonymization

Irreversibly altering data so that individuals can no longer be identified — directly or indirectly — removing it from the scope of data-protection regulations such as GDPR.

Anti-Money Laundering Directive (AMLD)

A series of EU directives — from 1AMLD (1991) to 6AMLD (2021) — progressively raising AML/CFT standards across member states, expanding scope to crypto assets, beneficial ownership registers, and cross-border supervision.

Anti-Spoofing

Techniques used to detect and reject fraudulent biometric samples — printed photos, silicone masks, replay videos — before they can deceive a biometric authentication system.

Application Fraud

Fraud committed while applying for a new account, credit product, insurance policy, benefit, or service using fabricated, manipulated, stolen, or materially misrepresented information.

Attack Surface

The total set of entry points — APIs, user interfaces, network ports, third-party integrations — through which an attacker could attempt to gain unauthorized access.

Australian Transaction Reports and Analysis Centre (AUSTRAC)

Australia's financial intelligence agency and primary AML/CTF regulator, responsible for collecting transaction reports, detecting financial crime, and taking enforcement action against non-compliant entities.

Authentication

The process of establishing that a person, device, workload, or service presenting an identifier is entitled to act as that identity, using one or more credentials or factors at a required level of assurance.

Authentication Context

The set of conditions surrounding an authentication event — device type, location, network, and time — used to evaluate risk and determine the appropriate verification step-up.

Authorized Push Payment Fraud (APP Fraud)

A scam where victims are manipulated — often via impersonation of banks, government agencies, or romantic partners — into voluntarily authorizing payments to fraudster-controlled accounts.

BSA (Bank Secrecy Act)

US legislation requiring financial institutions to assist government agencies in detecting and preventing money laundering through reporting and recordkeeping.

Behavioral Biometrics

Analysis of unique patterns in user behavior (typing rhythm, mouse movements, touch gestures) to verify identity and detect fraud.

Biometric Enrollment

The initial capture and storage of a user's biometric reference template — face, fingerprint, iris — against which future authentication attempts are compared.

Biometric Template

A digital representation of a person's unique biometric characteristics, stored for comparison during verification or identification.

Bug Bounty

Programs offering financial rewards to external security researchers who responsibly disclose vulnerabilities, providing continuous adversarial testing at lower cost than full-time red teams.

Business Email Compromise (BEC)

A sophisticated social engineering attack where criminals compromise or convincingly impersonate executive email accounts to authorize fraudulent wire transfers, redirect payroll, or steal sensitive data — typically targeting finance and HR teams.

Bust-Out Fraud

A scheme where fraudsters build good credit standing with financial institutions before maxing out all available credit and disappearing.

CCPA (California Consumer Privacy Act)

California law providing consumers with rights regarding their personal information, including the right to know, delete, and opt-out of sale.

CDD (Customer Due Diligence)

The process of gathering sufficient information about customers to assess risk and verify their identity, including understanding the nature of customer relationships.

CEO Fraud

A business email compromise scenario in which an attacker impersonates a senior executive and pressures an employee or business partner to transfer money, change payment instructions, purchase assets, or disclose sensitive information.

CFPB Section 1033

A rule issued by the US Consumer Financial Protection Bureau under Section 1033 of the Dodd-Frank Act that grants consumers the right to access their personal financial data held by financial institutions and to share it with authorised third parties. The rule establishes data portability standards for US open banking, requiring financial institutions to provide machine-readable data access through secure APIs.

Why it matters: Section 1033 will require financial institutions to support open banking data sharing, creating new identity and consent verification requirements. Identity orchestration vendors and account aggregators are directly impacted by the compliance timeline.

CFT (Countering the Financing of Terrorism)

Financial regulations and procedures designed to identify and prevent the flow of funds to terrorist organizations.

CIAM (Customer Identity and Access Management)

Identity management focused on external customers, handling registration, authentication, consent, and profile management at consumer scale.

CPAU (Cost Per Approved User)

The total cost to successfully onboard one legitimate, approved user, including verification costs, fraud losses, and operational expenses.

CTR (Currency Transaction Report)

A report required for cash transactions over $10,000 in the United States, designed to detect potential money laundering.

Call Center Fraud

Fraud that exploits customer-support or contact-center processes to take over accounts, reset credentials, redirect payments, obtain sensitive information, or persuade agents to override established controls.

Card Fraud

Unauthorized or deceptive use of payment-card credentials or card-processing rules for financial gain. It includes lost or stolen card use, counterfeit cards, card-not-present fraud, card testing, and some forms of first-party misuse.

Card Testing

Attacks where fraudsters validate stolen card numbers by making small, low-visibility transactions before using confirmed valid cards for larger purchases or resale.

Card Verification Value (CVV)

A security code printed on, or cryptographically generated for, a payment card and used as evidence that the payer possesses card details beyond the primary account number. It is also called CVC or CSC.

Card-Not-Present Fraud (CNP Fraud)

Payment-card fraud in a transaction where the merchant cannot physically inspect the card, such as web, app, mail, or telephone orders. Controls commonly combine 3-D Secure, CVV, AVS, device, identity, and behavioral signals.

Chargeback

A payment reversal initiated by a cardholder through their issuing bank, used to dispute unauthorized or fraudulent transactions. Excessive chargeback rates result in merchant penalties or processor termination.

Check Fraud

The theft, alteration, counterfeiting, duplication, or deceptive deposit of paper or electronic checks to obtain funds without authorization. Common patterns include check washing, forged endorsements, counterfeit checks, and duplicate presentment.

Common Reporting Standard (CRS)

An OECD standard for the automatic exchange of financial account information between participating tax authorities, designed to combat offshore tax evasion by enabling cross-border account data sharing.

Consent Management

Systems and processes for collecting, recording, and managing user consent for data processing activities.

Consent Management Platform (CMP)

Software that collects, records, and manages user consent for data processing and marketing activities across websites and apps, typically surfaced as a cookie-consent or privacy-preference UI.

Continuous Authentication

Ongoing verification of user identity throughout an active session using passive behavioral signals — typing cadence, mouse dynamics, touch patterns — rather than only at login.

Continuous Monitoring

Ongoing surveillance of customer risk profiles, transactions, and watchlist status throughout the business relationship.

Conversion Rate

The percentage of users who successfully complete an identity verification flow without abandoning or failing.

Correspondent Banking

A relationship in which one bank (the correspondent) provides banking services — account management, payments, FX — on behalf of another bank (the respondent), enabling cross-border transactions. Nested correspondent networks represent a high ML/TF risk and a major AML compliance challenge.

Credential Rotation

The practice of periodically replacing credentials — passwords, API keys, certificates — to limit the window of exposure if those credentials are compromised.

Credential Sharing

Multiple users accessing a system with the same credentials, eroding individual accountability and creating significant insider-threat and audit compliance risks.

Credential Stuffing

Automated attacks using stolen username/password pairs from data breaches to gain unauthorized access to accounts across multiple services.

Credit Header Data

Non-financial identity information from credit bureaus (name, address, SSN) used to verify identity without accessing credit history.

Cross-Border Data Transfer

Moving personal data across country or jurisdiction borders, subject to adequacy decisions, standard contractual clauses, or binding corporate rules under GDPR and equivalent frameworks.

Cross-Border Identity Verification

The challenge of reliably verifying identities across jurisdictions with differing document standards, data sources, and regulatory requirements — a key pain point for global onboarding.

Crypto Investment Scam

Investment fraud that uses cryptocurrency as the supposed asset, payment rail, or withdrawal mechanism. Criminals may display fabricated profits on a controlled platform and demand additional fees before blocking access to the funds.

Customer Risk Rating

A risk classification assigned to each customer based on factors including geography, transaction behavior, business type, PEP status, and product usage — the rating drives the level of due diligence applied and monitoring frequency.

DID (Decentralized Identifier)

A new type of identifier that enables verifiable, decentralized digital identity, controlled by the identity owner rather than a central registry.

DPIA (Data Protection Impact Assessment)

A process to identify and minimize privacy risks of a project, required under GDPR for high-risk processing activities.

Data Breach

An incident where sensitive, protected, or confidential data is accessed, copied, or stolen by an unauthorized party.

Data Localization

Regulatory requirements mandating that data about a country's residents be stored and processed within that country's borders, complicating global identity platform architectures.

Data Minimization

The principle of collecting only the minimum personal data necessary for a specific purpose, reducing privacy risks.

Data Retention Policy

Rules governing how long different categories of personal data are retained before they must be deleted or anonymized, balancing compliance, legal hold, and minimization obligations.

Data Subject Rights

Rights granted to individuals under privacy laws including access, rectification, erasure, portability, and objection to processing.

Database Verification

Checking provided identity information against authoritative databases (credit bureaus, government records) to confirm data accuracy.

De-Risking

The practice of financial institutions exiting entire customer segments, geographies, or product lines deemed too high-risk rather than implementing proportionate controls — a significant unintended consequence of aggressive AML enforcement.

Decentralized Identity

An identity model where individuals control their own identity data using cryptographic proofs, rather than relying on centralized authorities.

Deepfake

AI-generated synthetic media that convincingly depicts someone saying or doing something they never did, increasingly used in fraud and identity attacks.

Device Fingerprinting

Technology that identifies unique device attributes (browser settings, hardware, IP) to recognize returning devices and detect suspicious activity.

Device Identifier (Device ID)

A hardware-, operating-system-, browser-, or application-derived value used to recognize a device across sessions. Fraud systems combine identifiers with other signals because individual values may be reset, shared, or spoofed.

Device Takeover (DTO)

Unauthorized control of a victim's phone or computer, often through remote-access software, malware, credential theft, or social engineering. Control of the device can expose sessions, authentication codes, banking apps, and stored credentials.

Document Verification

The process of validating identity documents (passports, driver's licenses) by checking security features, data consistency, and authenticity.

EDD (Enhanced Due Diligence)

Additional scrutiny applied to higher-risk customers, involving deeper investigation into source of funds, business activities, and beneficial ownership.

EU Digital Identity Wallet (EUDIW)

A mobile application framework mandated by eIDAS 2.0, enabling EU citizens to store government-verified identity attributes and credentials, share them selectively across borders, and use them for both public and private sector services.

Email Intelligence

Analysis of email addresses including domain age, breach history, and account associations to assess identity risk.

Encryption

The process of converting data into a coded format that can only be read by authorized parties with the decryption key.

Entitlement Management

The process of defining, granting, reviewing, and revoking the specific permissions users hold, ensuring access remains aligned with job function and least-privilege principles.

FAR (False Accept Rate)

The probability that a biometric system incorrectly accepts an unauthorized person, matching them against an enrolled template.

FIDO2 (Fast Identity Online 2)

An authentication standard enabling passwordless login using public key cryptography, supported by major browsers and platforms.

FRR (False Reject Rate)

The probability that a biometric system incorrectly rejects a legitimate user who should have been matched.

Facial Recognition

Biometric technology that identifies or verifies a person by analyzing facial features from images or video, comparing against stored facial templates.

FedRAMP (Federal Risk and Authorization Management Program)

The Federal Risk and Authorization Management Program — a US government framework that standardises the security assessment, authorisation, and continuous monitoring of cloud service providers (CSPs) used by federal agencies. FedRAMP authorisation signals a cloud product has met rigorous NIST-based security controls, and is often required for identity and fraud vendors selling into US government contracts.

Why it matters: Identity vendors pursuing US federal contracts must obtain FedRAMP authorisation. Buyers evaluating vendors for government use cases should treat FedRAMP status as a minimum security baseline requirement.

Financial Action Task Force (FATF)

The global intergovernmental body that sets international standards for combating money laundering, terrorist financing, and proliferation financing. FATF recommendations form the basis of AML/CFT regulation in over 200 jurisdictions.

Financial Crimes Enforcement Network (FinCEN)

The US Treasury bureau responsible for safeguarding the financial system from illicit use, administering the Bank Secrecy Act, collecting financial intelligence from SARs and CTRs, and issuing AML/KYC guidance.

First-Party Fraud

Fraud committed by the account holder themselves, using their real identity to obtain credit, goods, or services with no intention of repayment or return. Unlike third-party fraud — where a criminal impersonates a victim — first-party fraud is perpetrated by individuals who are genuinely who they claim to be. Common forms include: bust-out fraud (building credit lines then deliberately defaulting), friendly chargebacks (disputing legitimate purchases after receiving goods), and false income or asset declarations on loan applications. Because the identity itself is real and verified, first-party fraud does not trigger standard identity verification alerts. Detection depends on behavioral and transactional signals, cross-institution data sharing, and historical account patterns rather than document verification anomalies. The synthetic identity fraud variant occupies a grey zone: a real Social Security number paired with fabricated identity elements blurs attribution between first- and third-party fraud.

Why it matters: First-party fraud is structurally harder to detect than third-party fraud because the perpetrator is a legitimate account holder with genuine access — their behavior mimics real usage until the moment of default or dispute. Traditional fraud models trained on third-party patterns (stolen credentials, account takeover) perform poorly here because there is no identity mismatch to flag. Detection requires a different signal set: account history, application velocity, cross-institution consortium data, and behavioral analytics over time. Since document verification confirms the identity is genuine, the detection burden shifts to transactional behavior, application inconsistencies, and shared industry intelligence. This distinction is critical for practitioners evaluating identity verification vendors: a strong document verification capability does not reduce first-party fraud risk — that requires behavioral analytics and data consortium access.

Foreign Account Tax Compliance Act (FATCA)

US legislation requiring foreign financial institutions to identify and report accounts held by US persons to the IRS, or face a 30% withholding tax — effectively exporting US tax compliance requirements globally.

Fraud Consortium

Shared intelligence networks where financial institutions pool anonymized fraud signals and known bad-actor data to improve collective detection — particularly effective against synthetic identity and mule networks.

Fraud Farm

An organized operation that uses groups of people, devices, accounts, automation, or combinations of them to perform abusive actions at scale, such as fake sign-ups, account farming, promotion abuse, or transaction laundering.

Fraud Fusion Center

An operating model that brings fraud, cybersecurity, identity, anti-money-laundering, threat-intelligence, and investigation teams together to share signals, coordinate cases, and respond to threats that cross traditional organizational boundaries.

Fraud Rate

The percentage of transactions or accounts that are determined to be fraudulent, typically measured in basis points.

Fraud Scoring

Machine learning or rules-based models that assign a real-time risk score to a transaction, account, or identity event — the score determines whether to approve, decline, or escalate for review.

Friendly Fraud

When legitimate customers dispute valid transactions, often claiming non-receipt or unauthorized purchase despite having made the purchase.

GDPR (General Data Protection Regulation)

European Union regulation governing personal data protection and privacy, requiring lawful basis for processing and granting individuals rights over their data.

Gait Analysis

Biometric identification based on a person's unique walking pattern — stride, pace, posture — captured via video or motion sensors and used for passive or continuous authentication.

Hardware Security Key

A physical device — typically USB or NFC — that stores cryptographic keys and performs authentication operations on-device, providing strong phishing-resistant MFA.

Holder Binding

A cryptographic mechanism that ties a verifiable credential to its legitimate holder — typically through a DID or key pair — preventing the credential from being transferred or misused by a different individual.

IAL (Identity Assurance Level)

NIST categories (1-3) describing the degree of confidence in identity proofing, from self-assertion to in-person proofing.

IAM (Identity and Access Management)

A framework of policies and technologies ensuring the right individuals access the right resources at the right times for the right reasons.

IP Geolocation

The estimation of a network connection's geographic location from its IP address and related routing data. It is a risk signal rather than proof of a person's location because VPNs, proxies, carrier routing, and shared networks can distort it.

ISO 27001

International standard for information security management systems (ISMS), providing a framework for managing security risks.

ISO/IEC 29115

The international standard defining a framework for entity authentication assurance, specifying four assurance levels aligned with authentication context and risk — a global complement to NIST SP 800-63's assurance level model.

ISO/IEC 30107

The international standard series for biometric presentation attack detection (PAD), defining terminology, testing methodology, and performance reporting requirements. Certification to ISO 30107-3 is required by regulators including the UK DIATF and EU eIDAS 2.0.

IdP (Identity Provider)

A system that creates, maintains, and manages identity information and provides authentication services to relying applications.

Identity Federation

Linking a user's identity across multiple identity management systems, enabling SSO across organizational boundaries.

Identity Governance and Administration (IGA)

A framework combining identity lifecycle management with access governance — provisioning, role management, access certification, and audit — to enforce who has access to what and why.

Identity Orchestration

The coordination of multiple identity verification services and data sources in a unified workflow to make risk-based decisions.

Identity Proofing

The process of collecting and verifying information about a person to establish they are who they claim to be during initial enrollment.

Identity Proofing Orchestration

The coordination and sequencing of multiple identity verification steps — document check, liveness, database lookup — into an adaptive workflow that optimizes for both pass rate and fraud prevention.

Impersonation Scam

A scam in which a criminal pretends to be a trusted person or organization—such as a bank, government agency, employer, supplier, or relative—to induce a victim to disclose information, grant access, or send money.

Injection Attack

A technique where fraudsters bypass camera capture to inject pre-recorded or synthetic media directly into a verification session.

Insider Threat

The risk posed by current or former employees, contractors, or partners who misuse legitimate access to cause harm — whether maliciously or through negligence.

Internal Fraud

Fraud committed by an employee, contractor, officer, or other insider who abuses legitimate access, authority, information, or a position of trust for personal benefit or to benefit an accomplice.

Investment Fraud

A deceptive scheme that solicits money for a false, misrepresented, unregistered, or manipulated investment opportunity. Warning patterns include guaranteed returns, fabricated platforms, pressure to act quickly, and barriers to withdrawal.

Invoice Fraud

A payment-redirection scheme using a fabricated or altered invoice, or a genuine invoice paired with fraudulently changed bank details. It frequently overlaps with supplier impersonation and business email compromise.

Iris Recognition

Biometric identification using the complex, stable pattern of the colored iris, offering extremely high accuracy and low false-accept rates suitable for high-security access control.

JWT (JSON Web Token)

A compact, URL-safe token format used for securely transmitting claims between parties. Commonly used for stateless authentication in APIs.

Just-In-Time Access (JIT Access)

A PAM strategy that grants elevated privileges only for the specific duration they are needed, then automatically revokes them, eliminating persistent privileged accounts.

KYB (Know Your Business)

The process of verifying business entities, including ownership structure, beneficial owners, and regulatory standing before establishing a business relationship.

KYC (Know Your Customer)

The process financial institutions and other regulated entities use to verify customer identity, assess risk, and ensure compliance with anti-money laundering regulations.

KYC Refresh

The periodic re-verification of existing customer identity data and risk profiles to confirm accuracy and regulatory compliance — typically triggered on a schedule (annual, triennial) or by risk events such as adverse media hits or large transactions.

Knowledge-Based Authentication (KBA)

Authentication using questions whose answers only the legitimate user should know — mother's maiden name, childhood street, first car — increasingly considered weak due to data-breach exposure.

Least Privilege

A security principle that grants users only the minimum permissions necessary to perform their job functions, reducing the attack surface.

Liveness Detection

Technology that determines whether a biometric sample comes from a live person present at the point of capture, rather than a photo, video, or mask.

Loyalty Abuse

Misuse of a rewards or loyalty program to obtain points, status, discounts, or redemptions contrary to program rules. It becomes loyalty fraud when it involves stolen accounts, fabricated activity, payment fraud, or organized resale.

MFA (Multi-Factor Authentication)

A security process that requires users to verify their identity using two or more authentication factors: something they know (password), something they have (phone/token), or something they are (biometric).

MRZ (Machine Readable Zone)

The two or three lines of machine-readable text at the bottom of identity documents containing encoded personal and document information.

Magic Link

A single-use authentication URL sent to a verified email address that logs the user in when clicked, eliminating password entry without requiring a separate app.

Malicious Domain

An internet domain registered, compromised, or repurposed to support phishing, impersonation, malware delivery, command-and-control, fraudulent storefronts, or other harmful activity.

Manual Review

Human review of identity verification cases that cannot be automatically approved or rejected, adding cost and latency.

Merchandise Mule

A person who receives goods acquired through fraud and forwards, resells, or delivers them for a criminal network. Recruitment often uses fake jobs or parcel-reshipping offers, and the participant may be knowing or unwitting.

Money Laundering

The process of disguising the criminal origin, ownership, movement, or destination of funds so they appear legitimate. It is commonly described through placement, layering, and integration, although real schemes do not always follow those stages neatly.

Money Mule

A person — often recruited unknowingly through romance scams, job ads, or social media — who receives and transfers illegally obtained money on behalf of criminals, providing a layer of separation from the original fraud.

Mule Account

Bank accounts used by criminals to receive and transfer illicitly obtained money, often belonging to unwitting accomplices recruited through scams.

Multimodal Biometrics

Identity systems that combine two or more biometric modalities — face and fingerprint, voice and iris — to achieve higher accuracy and resilience against spoofing than any single modality alone.

NFC Chip Verification

Reading and validating cryptographic data stored in the NFC chip of electronic identity documents to confirm document authenticity.

NIST 800-63

US federal guidelines for digital identity covering identity proofing, authentication, and federation at different assurance levels.

NIST SP 800-53

A comprehensive US federal catalog of security and privacy controls for information systems and organizations, used to assess, authorize, and continuously monitor the security of federal systems — and widely adopted as a baseline by regulated enterprises.

Non-Card Payment Fraud

Fraud conducted over account-to-account or other payment rails outside card networks, including ACH, wire, instant-payment, wallet, and peer-to-peer transfers. It may be unauthorized or induced through an authorized-payment scam.

Non-Human Identity (NHI)

Digital identities assigned to machines, services, applications, bots, and automated workloads rather than to human users. NHIs include service accounts, API keys, OAuth tokens, certificates, and secrets used by software to authenticate and authorise actions. As identity attack surfaces expand, managing and securing NHIs has become a critical discipline alongside traditional human IAM.

Why it matters: The majority of credentials in enterprise environments now belong to non-human entities. Compromised NHIs — such as leaked API keys or service account tokens — are a primary attack vector, making NHI governance essential for fraud and security teams.

OAuth (Open Authorization)

An open standard authorization protocol that allows third-party applications to access user data without exposing passwords. Commonly used for 'Login with Google/Facebook' flows.

OCR (Optical Character Recognition)

Technology that converts images of text (from documents) into machine-readable text for automated data extraction.

OFAC (Office of Foreign Assets Control)

A US Treasury department that administers and enforces economic sanctions against targeted countries, entities, and individuals.

OIDC (OpenID Connect)

An identity layer built on top of OAuth 2.0 that enables clients to verify user identity based on authentication performed by an authorization server.

OTP (One-Time Password)

A password that is valid for only one login session or transaction. OTPs are typically delivered via SMS, email, or authenticator apps.

Out-of-Band Authentication (OOBA)

Authentication where the second factor is delivered through a channel independent of the primary login — SMS, phone call, or push notification — reducing the impact of man-in-the-middle attacks.

PAD (Presentation Attack Detection)

Mechanisms designed to detect and prevent attacks where fraudsters present fake biometric samples like printed photos, silicone masks, or deepfakes.

PAI (Presentation Attack Instrument)

Any object, image, or recording used to attempt to deceive a biometric system, including photos, videos, masks, and synthetic media.

PAM (Privileged Access Management)

Security solutions managing and monitoring access to critical systems by privileged users like system administrators.

PCI DSS (Payment Card Industry Data Security Standard)

Security standards for organizations handling credit card data, covering network security, access control, and monitoring.

PEP (Politically Exposed Person)

Individuals who hold prominent public positions and may pose higher money laundering risks due to their potential access to public funds or influence.

PII (Personally Identifiable Information)

Any information that can be used to identify a specific individual, such as name, SSN, address, or biometric data.

PSD2 (Second Payment Services Directive)

The European Union's second Payment Services Directive, which established requirements for payment-service access, open banking, consumer protection, and strong customer authentication across the European Economic Area.

Palm Vein Recognition

Biometric identification using the unique pattern of veins beneath the palm surface, captured via near-infrared light. Difficult to spoof as the vein pattern is internal and requires blood flow to detect.

Passive Liveness

A liveness detection approach that analyzes a biometric sample without requiring any specific user action, using AI to detect spoofing artifacts — texture inconsistencies, lighting anomalies, depth cues — invisibly during capture.

Passkey

A FIDO2-based credential that replaces passwords with cryptographic key pairs, enabling passwordless authentication across devices using biometrics or device PINs.

Passwordless Authentication

An authentication method that verifies user identity without requiring a traditional password, using methods like biometrics, magic links, passkeys, or hardware tokens.

Payment Fraud

Unauthorized, manipulated, or deceptively induced movement of money through card, bank-transfer, wallet, check, or other payment rails. The term covers both transactions initiated without consent and payments a victim was tricked into authorizing.

Penetration Testing

Authorized simulated attacks against a system — conducted by ethical hackers — to identify exploitable vulnerabilities before malicious actors can discover and leverage them.

Permission Boundary

A policy construct that caps the maximum permissions an identity can be granted, regardless of what other policies might otherwise allow — a guardrail against privilege escalation.

Perpetual KYC (pKYC)

An AML/KYC model replacing periodic batch re-verification (annual, triennial KYC refresh) with continuous, event-triggered updates to customer risk profiles — reacting to changes in behavior, adverse media, or beneficial ownership in real time.

Pharming

Redirection of users from an intended website to a fraudulent destination by manipulating DNS resolution, local host settings, routers, or other traffic-routing components, often without requiring the victim to click a deceptive link.

Phishing

Social engineering attacks that use fraudulent communications (emails, texts, websites) to trick victims into revealing sensitive information or credentials.

Phone Intelligence

Data about phone numbers including carrier, type (mobile/landline/VoIP), SIM swap history, and account tenure used for risk assessment.

Pig Butchering

A long-con fraud in which criminals build genuine-seeming romantic or professional relationships over weeks or months before introducing victims to a fraudulent cryptocurrency investment platform and draining their funds. The name reflects the practice of 'fattening' the victim before slaughter.

Privacy Impact Assessment (PIA)

A systematic process for evaluating the privacy risks of a project or system change before deployment, similar to a DPIA but not always legally mandated.

Privacy by Design

An approach embedding privacy protections into system design from the start, rather than adding them as an afterthought.

Promotion Abuse (Promo Abuse)

Intentional circumvention of a promotion's eligibility or usage rules to obtain discounts, credits, referrals, or bonuses, often through multiple accounts, synthetic attributes, automation, collusion, or resale.

Proof Key for Code Exchange (PKCE)

A security extension to the OAuth 2.0 authorization code flow (RFC 7636) that prevents authorization code interception attacks by requiring a dynamically generated code verifier — essential for mobile and single-page applications.

Pseudonymization

Replacing directly identifying information with an artificial identifier (pseudonym), so the data can only be re-linked to an individual using separately held additional information — reducing privacy risk while retaining analytical utility.

RBAC (Role-Based Access Control)

Access control method where permissions are assigned to roles, and users are assigned to roles rather than receiving individual permissions.

REAL ID

A US federal standard established by the REAL ID Act of 2005 that sets minimum security requirements for state-issued driver's licences and ID cards. REAL ID-compliant documents are required for accessing federal facilities and domestic air travel. Compliance requires states to verify identity documents and share data with a nationwide database, making it a core component of US domestic identity assurance.

Why it matters: REAL ID compliance affects identity verification workflows for any US-facing service that accepts driver's licences as proof of identity, influencing document verification requirements and acceptable ID types.

Ransomware

Malicious software that encrypts a victim's data and demands payment for the decryption key, increasingly targeting identity infrastructure and backup systems to maximize leverage.

Refund Fraud

Abuse of a merchant's return or refund process to obtain money or replacement goods without a legitimate entitlement, including false non-delivery claims, empty-box returns, receipt manipulation, and returns of substituted merchandise.

Regulatory Technology (RegTech)

Technology solutions — AI, automation, data analytics — that help financial institutions comply with regulatory requirements more efficiently, reducing manual effort in KYC, AML monitoring, and reporting.

Remote Access Scam

A social-engineering scam in which a criminal persuades a victim to install or activate remote-control software, then uses the access to steal credentials, manipulate banking sessions, move money, or conceal fraudulent activity.

Reseller Abuse

Acquisition of scarce, discounted, restricted, or promotional goods at scale for unauthorized resale, using automation, multiple identities, coordinated accounts, or policy circumvention in ways that harm legitimate customers or the merchant.

Risk Appetite

The level and type of risk an organization is willing to accept in pursuit of its strategic objectives, formally documented in a risk appetite statement — a key input to KYC/AML program design, fraud threshold calibration, and identity assurance level selection.

Risk Engine

A system that analyzes multiple signals and applies rules or machine learning to calculate risk scores for identity and fraud decisions.

Risk-Based Authentication

Authentication that evaluates transaction risk using signals like device, location, and behavior to determine required verification level.

Romance Scam

Fraud in which criminals cultivate fake romantic relationships — typically via dating apps or social media — to build emotional dependency before requesting money, gift cards, or cryptocurrency from the victim.

SAML (Security Assertion Markup Language)

An XML-based standard for exchanging authentication and authorization data between identity providers and service providers, commonly used in enterprise SSO.

SAR (Suspicious Activity Report)

A report filed by financial institutions when they detect known or suspected violations of law or suspicious transactions.

SDD (Simplified Due Diligence)

Reduced due diligence measures applied to lower-risk customers when certain conditions are met under regulatory frameworks.

SDN List (Specially Designated Nationals)

A list maintained by OFAC of individuals and entities whose assets are blocked and with whom US persons are prohibited from dealing.

SIM Swap

A type of fraud where criminals convince a carrier to transfer a victim's phone number to a new SIM card, enabling account takeover.

SOC 2 (Service Organization Control 2)

An auditing procedure ensuring service providers securely manage data to protect customer interests and privacy.

SSI (Self-Sovereign Identity)

A model where individuals fully own and control their digital identities without relying on any central authority to store and manage identity data.

SSO (Single Sign-On)

An authentication scheme that allows users to log in with a single set of credentials to access multiple independent applications or systems.

Sarbanes-Oxley Act (SOX)

US legislation requiring public companies to implement and attest to internal controls over financial reporting. SOX Section 404 has direct identity implications — requiring strong access controls, privileged access management, and audit trails.

Security Information and Event Management (SIEM)

A platform aggregating log data from across an organization's infrastructure, correlating events to detect threats in real time and maintain the audit trail required for compliance.

Security Orchestration, Automation and Response (SOAR)

Technology enabling security teams to collect data from disparate sources, automate repetitive threat-response actions, and coordinate playbooks — reducing mean time to respond.

Security Posture

The overall cybersecurity strength of an organization as measured by its controls, processes, and technology — effectively, how well prepared it is to prevent, detect, and recover from attacks.

Selective Disclosure

The ability to share only specific attributes from a credential — proving age without revealing exact birthdate, or confirming employment without disclosing salary — while cryptographically proving the withheld data is also valid.

Selfie Verification

A verification step where users submit a real-time selfie that is compared against their identity document photo using facial recognition, combined with liveness detection to confirm presence.

Separation of Duties (SoD)

A control requiring that critical processes — such as payment initiation and authorization — be split across two or more people, preventing any single actor from committing and concealing fraud.

Session Management

The process of securely handling user sessions including creation, validation, timeout, and termination to prevent unauthorized access.

Smishing

Phishing attacks conducted via SMS text messages, often impersonating banks, delivery services, or government agencies.

Social Engineering

Manipulation of people into revealing information, changing controls, granting access, or taking an action that benefits an attacker. It exploits trust, authority, urgency, fear, curiosity, or familiarity rather than relying only on a technical vulnerability.

Spear Phishing

A targeted phishing attack tailored to a particular person, role, or organization using contextual information to make the message and requested action appear credible.

Step-Up Authentication

Requiring additional authentication factors when users attempt high-risk actions, even if already authenticated.

Strong Customer Authentication (SCA)

A European payments requirement for authentication using at least two independent elements from knowledge, possession, and inherence categories, with transaction-specific dynamic linking where applicable. Exemptions and out-of-scope cases are subject to defined conditions.

Supervisory Technology (SupTech)

Technology adopted by financial regulators and supervisory authorities — AI, NLP, data analytics — to enhance the efficiency and effectiveness of regulatory supervision, including automated reporting analysis and risk-based examination scheduling.

Supply Chain Attack

A cyberattack that targets less-secure elements in an organization's supply chain — software vendors, build pipelines, third-party libraries — to compromise the ultimate target indirectly.

Synthetic Identity Fraud

Fraud where criminals combine real and fake information to create new identities that don't correspond to any real person, used to open accounts and build credit.

System for Cross-domain Identity Management (SCIM)

An open standard protocol (RFC 7644) for automating the exchange of user identity information between identity domains and IT systems, dramatically simplifying provisioning and de-provisioning at scale.

TLS (Transport Layer Security)

A cryptographic protocol that provides secure communication over a computer network, encrypting data in transit.

TOTP (Time-based One-Time Password)

A time-based algorithm that generates one-time passwords that change every 30 seconds, commonly used in authenticator apps like Google Authenticator.

Telephone-Oriented Attack Delivery (TOAD)

An attack pattern that uses telephone contact to move a victim into a later compromise step, such as installing remote-access software, visiting a malicious site, disclosing credentials, or authorizing a payment.

Template Aging

The gradual degradation of biometric matching accuracy over time as a person's physical characteristics naturally change — facial hair, weight, aging — requiring periodic template updates.

Third-Party Fraud

Fraud committed by someone other than the genuine customer using stolen, purchased, fabricated, or otherwise misappropriated identity, account, or payment information without the legitimate owner's authorization.

Threat Intelligence

Evidence-based knowledge about current or emerging threats — actor TTPs, indicators of compromise, vulnerabilities — that enables organizations to make proactive, informed security decisions.

Transaction Fraud

Fraud involving the initiation, alteration, interception, or repudiation of a financial transaction. Detection typically combines account history, identity, device, behavioral, beneficiary, and payment-rail signals.

Transaction Monitoring

Real-time or batch analysis of financial transactions to detect suspicious patterns indicative of money laundering or fraud.

Travel Rule

A FATF requirement (and its crypto extension under FATF Rec. 16) mandating that originating financial institutions pass customer identification information alongside wire transfers above a threshold — now extended to virtual asset service providers.

Triangulation Fraud

An e-commerce fraud scheme where a criminal lists products at attractive prices, collects payment from a legitimate buyer, then purchases the item from a real retailer using a stolen payment card — making the criminal difficult to detect.

Trust Framework

A published set of rules, policies, and technical specifications governing how identity systems interoperate — defining liability allocation, assurance levels, credential issuance standards, and how trust is established between issuers, holders, and verifiers.

Trusted Contact Person (TCP)

A person designated by a financial-services customer whom an institution may contact when it reasonably suspects financial exploitation, diminished capacity, or difficulty reaching the customer. Designation does not ordinarily grant authority over the account.

UBO (Ultimate Beneficial Owner)

The natural person(s) who ultimately own or control a legal entity, typically those with 25% or more ownership or significant control.

Velocity Check

A fraud detection control that monitors the frequency of actions — logins, transactions, applications — within a defined time window to flag anomalous patterns before they escalate.

Verifiable Credential

A tamper-evident credential with cryptographic proof of who issued it, enabling secure digital identity verification without contacting the issuer.

Vishing

Voice phishing attacks conducted over phone calls, where fraudsters impersonate legitimate organizations to extract sensitive information.

Voice Biometrics

Authentication using the unique acoustic characteristics of a person's voice — pitch, cadence, accent, pronunciation — for phone or voice-assistant channels, vulnerable to audio deepfake attacks.

Watchlist Screening

Checking individuals or entities against sanctions lists, PEP databases, and adverse media to assess regulatory and reputational risk.

WebAuthn (Web Authentication)

A W3C web standard that defines an API for creating strong, public key-based credentials for web authentication.

ZTNA (Zero Trust Network Access)

A security framework providing secure remote access to applications based on defined access control policies, without exposing the corporate network.

Zero Trust

Security model that requires strict identity verification for every person and device trying to access resources, regardless of network location.

Zero-Knowledge Proof (ZKP)

A cryptographic protocol allowing one party to prove to another that a statement is true — such as 'I am over 18' or 'I hold a valid credential' — without revealing any underlying data, enabling privacy-preserving identity verification.

eIDAS (Electronic Identification, Authentication and Trust Services)

EU regulation establishing a framework for electronic identification and trust services, enabling cross-border recognition of eIDs.

eIDAS 2.0

Updated EU regulation mandating European Digital Identity Wallets for all EU citizens, with enhanced privacy and cross-sector use cases.

iBeta PAD (Presentation Attack Detection)

A Presentation Attack Detection (PAD) conformance testing standard administered by iBeta Quality Assurance. Vendors submit liveness detection and anti-spoofing technology for standardised testing against a library of physical and digital presentation attacks (e.g. printed photos, video replays, 3D masks). Level 1 and Level 2 certifications indicate the proportion of attacks successfully detected.

Why it matters: iBeta PAD certification is the de-facto industry benchmark for liveness detection quality. Buyers evaluating biometric identity verification vendors should treat Level 2 certification as the minimum bar for high-assurance use cases.

mDL (Mobile Driver's License)

A digital version of a driver's license stored on a mobile device, following ISO 18013-5 standards for secure identity verification.