
The Future of Banking
How banks can protect their businesses and customers from online fraud







Whether it’s an established retail banking name, an investment giant, or a brand-new neobank, the banking sector faces a severe challenge from online fraud. But while the danger is clear, organizations across different verticals are realizing the security benefits of AI-powered IDV and biometrics.
It’s clear that banks must contend with significant danger, easily eclipsing the threat faced by other industries. Indeed, Veriff’s analysis of our internal data shows an overall fraud rate of 5.5% in financial services, compared with a global average of about 4% across all industries.
It isn’t surprising that fraudsters have trained their sights on the sector, given the high volume and value of financial transactions that banks deal with every day. Against this backdrop, banks need robust defenses to protect their bottom line.
Such security isn’t a ‘nice-to-have’: it’s essential to meet customer demands. In fact, our data shows that more than four-fifths (82%) of consumers say it’s important that financial services providers have protections like IDV technology in place.
And the challenges don’t stop there. Banks also face an increasingly complex regulatory environment that impacts the fight against fraud, ranging from the EU’s GDPR to the US Bank Secrecy Act. They need the right defenses to meet consumer demands, protect their business, and stay on the right side of the law.
In this report, we collate and analyze our in-depth research into fraud in the banking space. The key resources in focus are our Identity Fraud Report 2026, which offers extensive analysis of our global customer data throughout 2025; our Fraud Industry Pulse Survey, which covers the views of key fraud decision-makers; and the Fraud Index 2024, based on interviews with consumers.
Introduction

Ira Bondar-Mucci
Fraud Platform Lead, Veriff
Our research highlights key lessons for banks as they seek to navigate the growing threat from fraudsters. Crucially, AI-powered IDV and biometrics can provide a significant advantage, helping banks ensure that both customers and employees are who they say they are.
The value of Veriff’s capabilities lies in answering three key questions:
1
Is your customer/employee real?
Through a photo of their government-issue ID and a simple selfie, we can tell immediately if something is wrong with an image or video. We can detect liveness and realness without asking users to move unnaturally or follow complex instructions - in other words, we can ensure they really exist and that they are who they claim to be.
2
Is this customer/employee of value to you or a potential cost?
We can determine at the onboarding stage if the person is a potential customer of value - or if they simply cannot be trusted. With our cross-linking capabilities, we take huge amounts of data and search for patterns, helping us identify potential fraudsters who target certain industries. Of course, if they’re a legitimate customer, the process is smooth and safe, building security - and your company’s reputation.
3
Is the answer to those questions still the same on an ongoing basis?
Can you ensure that users of your platform are who they say they are every time they engage with your platform? Reauthentication of customers and employees is absolutely critical. With biometric authentication, users are promptly and securely authenticated across all stage of their user journey. We know they are who they say they are because we can quickly check the information already on file.
Let’s turn to the current state of play in online fraud for banks and outline the best ways to build defenses against an ever-evolving threat.
PART 2
Key takeaways
PART 3
The fraud threat for banking
Banks face a growing threat from fraud
Fraud remains a consistent and persistent threat, no matter the industry. Our Identity Fraud Report 2026 found that the overall net fraud rate across our customer base stood at more than 4% in 2025, meaning that one in every 25 verification attempts we encountered was someone pretending to be someone else.
But for the financial services sector - including banks - the problem is even worse.
This figure is concerning enough in isolation. What’s worse, it represents a growing trend, marking a big increase on the figure recorded in 2024.
This is perhaps unsurprising. Fraudsters will naturally target sectors with high-value transactions, and banking is at the top of the list. But imagine the potential financial consequences if we hadn’t caught these attacks.
5.5%
Net fraud for financial services in 2025

A growing problem for fraud professionals
The expanding danger was also reflected in our US Fraud Industry Pulse Survey 2025. This surveyed fraud decision-makers at businesses in the US with more than 100 employees or revenues over $100 million, including banks.
Given the size of the organizations involved, the financial consequences of a successful attack are obvious. And the fraud experts painted a worrying picture.
Importantly, this is a global problem. Our research also found similar results among UK (72.5%) and Brazilian (70%) decision-makers.
72%
Decision-makers who saw an increase in online fraud in the previous 12 months

A devastating financial impact
It’s clear that fraud poses a major financial threat, but what does this mean in real terms? Unfortunately, there is clear evidence of significant financial damage: we found that the vast majority of businesses have seen their revenues fall due to fraudsters.
Almost a third (32%) reported a 3-5% reduction - for a business with revenue of $1 million, that could mean a loss of $50k per year, just to fraudsters. Most banks fall into this category.
Strikingly, a combined 13.5% of respondents have suffered reductions ranging from 10% to more than 20%, devastating numbers for any business. That’s even worse than last year’s survey, when just 1% of respondents cited a hit of more than 9%.
75.5%
Businesses that saw a negative impact on revenue due to fraud

Hitting consumers in the pocket
This has financial consequences not just for banks, but for their customers, with all the reputational and business damage that entails. Our Fraud Index - which interviewed 1,000 consumers across the US and UK - found that almost half of respondents had experienced such activity in the previous year, including in their interactions with banks.
And it’s hitting them in their pockets, with a third of US consumers suffering at least some financial loss and a quarter in the UK. Among US respondents, 1% reported losing more than $1,000. Consider the implications if 1% of consumers in the world’s largest economy are losing $1,000+ to fraud online every year - it could represent upwards of $3.5bn lost to fraud.
48%
Respondents who encountered fraudulent or suspicious activity in the last 12 months.

Banking is at the very heart of our daily financial lives, so the consequences for the sector are stark.

Ira BondAr-Mucci, Fraud Platform Lead, Veriff

Types of fraud that impact banking
The picture gets worse when we drill down into some of the sub-verticals that make up financial services. Traditional banks were among the worst hit sectors, at about double the global average when it comes to net fraud rates, our Identity Fraud Report 2026 found.
What types of fraud are hitting the banking sector? Let’s break it down further.
Please use desktop of tablet version to view these graphs
Notably, we found that both neobanks and traditional banks were highly susceptible to impersonation fraud.
Impersonation fraud
In this form of identity fraud, a person pretends to be someone else in order to fraudulently access or apply for a digital account or service. It is a particular problem for both neobanks and traditional banks.
However, the data shows that the banking sector faces a diverse threat, hit by a range of scams. This also includes document fraud.
Document
fraud
When a document’s data is physically altered or a counterfeit document is fabricated from scratch.
The diverse danger was also reflected in our pulse survey of fraud industry decision-makers, including key players across the banking sector. They highlighted four key dangers:
Malware (46%)
Impersonation Fraud (44%)
Authorized Fraud (41%)
Document Fraud (38%)
Customer demands
It’s obviously important to protect your bank against such dangers. What’s more, it’s a key demand for customers across sectors, including banking.
And that’s a global demand, with 79.5% of Brazilian fraud professionals and 71% of their UK counterparts reporting the same trend.
The message is clear: if banks and other businesses fail to protect their customers from online fraud, they stand to lose them.
71.5%
Decision-makers in the Pulse Survey who say their customers are now more demanding of robust fraud prevention capabilities.

77.44%
Consumers who expect companies to reimburse them for money lost to fraud.

Again, this is a problem for consumers everywhere. In fact, almost 80% of Latin American respondents encountered fraudulent or suspicious activity in the year to March 2024, according to our survey of consumers in three of the region’s most important economies (Brazil, Colombia and Mexico).
The message is clear: consumers expect banks, like other businesses, to protect their money from fraudsters. If they fail, they don’t just face financial consequences, but damage to their reputation.

Ira BondAr-Mucci, Fraud Platform Lead, Veriff

The impact of AI: A threat and an opportunity
All of this is taking place against a rapidly evolving technological background, notably when it comes to the evolution of AI.
On the one hand, this technology poses new dangers: the Identity Fraud Report, for example, found that digitally presented media was 300% likelier to be entirely AI-generated or altered in 2025 compared to 2024.
This adds a new dimension to the fraud threat for banks. And decision-makers see the danger, according to our Pulse Survey:
300%
Digitally presented media was 300% more likely to be either entirely AI-generated or otherwise altered in 2025 compared to 2024.

60.5%
Fraud decision-makers who have recorded an increase in AI use in fraud attacks.

The AI advantage
However, while AI is undoubtedly a growing threat, it also provides clear benefits. Indeed, most fraud decision-makers have deployed the technology to strengthen their defenses, the Pulse Survey found:
It’s a similar story around the world, according to our global survey. In the UK, 60% of decision-makers utilize AI/ML in fraud prevention, with a further 25% planning to do so in the next year. In Brazil, 69.5% are using the technology, while 16.5% plan to do so in the coming 12 months.
64%
US-based decision-makers using AI/machine learning in fraud prevention, with a further 20% planning to do so in the next 12 months.

IDV and biometrics
This is part of a crucial trend in the fraud detection space: a growing acceptance for AI-powered IDV and biometrics technology. Consumers are keen to embrace this capability:
61.74%
Respondents to the Fraud Index who are comfortable using IDs and selfies to confirm their identities online.

62.44%
Consumers who are comfortable using facial biometrics to access accounts with online businesses. And when asked what means of logging into an online service they think is the most secure, biometric options (facial, fingerprint, and voice) made up more than a third of responses.

Finance-specific demands
Such robust technology is even more important for financial services sectors, including banking. Our Fraud Index found that consumers have particularly high demands that the right security measures are in place when signing up to a new financial service provider:
74.5%
Decision-makers who have seen AI stop at least some attacks.
83%
Decision-makers who have adopted at least some version of IDV software and biometrics into their risk-based/step-up authentication systems.
81%
Fraud experts who plan to boost their dependence on IDV and biometrics.
And the trend is also clear among fraud professionals, who see the benefits of AI-powered IDV and biometrics across the board:
82.62%
Consumers who say it is important that financial services providers have in place security measures like showing an ID and taking a selfie.

This is a clear recognition of the advantages banking fraud teams are seeing from AI-powered security, and their expectations for future benefits.

Ira BondAr-Mucci, Fraud Platform Lead, Veriff

PART 4
The compliance picture
Banks must comply with a range of regulations across the globe. Here we highlight some of the key legal architectures they must keep front of mind in the fight against fraud.
dora
Bank Secrecy Act
Regulation (EU) 2022/2554, known as the Digital Operational Resilience Act (DORA), is a comprehensive legislative framework developed by the European Union. It outlines new regulatory measures to ensure that the financial sector’s ICT infrastructure remains resilient against cyber threats, operational failures, and other ICT disruptions.
DORA applies to a wide range of institutions, including banks. By establishing standardized rules across Member States, DORA eliminates regulatory fragmentation and provides a uniform approach to managing ICT risk.
It has a range of implications for banks and the wider financial services industry, including extended reporting obligations; ongoing monitoring; closer scrutiny of vendors; and alignment of internal processes with technical standards.
The US Bank Secrecy Act was initially passed in 1970 to combat money laundering and other financial crimes, surfacing at a time when organized crime was flourishing. It has evolved alongside financial crime, with such amendments as the USA Patriot Act, which reinforced the BSA as a landmark statute combating money laundering and terrorism financing.
The BSA and its regulations have created an enormous impact on banks and the wider financial sector. They have greatly enhanced the accountability and transparency of regulated entities and therefore strengthened public trust in the financial sector.
It may be difficult for banks to effectively navigate the multitude of legislative pieces without investing in technology, personnel, and training programs. However, as BSA compliance is imperative to the sound functioning of the financial system, the BSA’s rigorous requirements are the cornerstone of safeguarding regulators’ and users’ trust and ensuring the security of the processes of financial organizations, including banks.
The EU’s General Data Protection Regulation aims to protect data, a vital consideration for banks. The principles involved also apply to the UK (a huge player in financial services) even after Brexit, with the country implementing its UK Data Protection Act 2018, which mirrors the principles of GDPR while addressing specific UK needs.

Lawfulness, fairness and transparency when it comes to processing data
For financial services organizations like banks, this has particular implications in know your customer (KYC) and anti-money laundering (AML) obligations.

Purpose limitation
Data should be collected for specific, legitimate purposes, and not processed further in a way incompatible with those purposes without clear consent.

Data minimization and accuracy
Collect only necessary data and keep it accurate to avoid unnecessary risks.

Storage limitation
Implement appropriate retention periods and promptly delete outdated data.

Integrity and confidentiality
Secure data processing, protecting against unauthorized access and breaches.
California and other US data privacy laws
Recently, data protection in the US took an interesting turn. In 2018, the California Consumer Privacy Act (CCPA) was signed into law. It became effective on January 1, 2020, and it was the first comprehensive data privacy law in the United States.
It gives consumers much more control over their personal information than any of the previous privacy laws. The CCPA protects consumers on another level, setting an example for other states. Suddenly, consumers could ask about what personal data is being collected about them, receive information about data disclosures, say “no” to the sale of their personal data, or even request that their personal information be deleted, regardless of the industry of the business.
Though California remains by far the most stringent of the state data protection laws, there are several state-level data protection and privacy laws granting similarly broad protection to consumers in other states as well.
The CCPA may have set the precedent, but Virginia, Colorado, and Utah soon followed, and now more and more states are enacting their own privacy laws. For banks, understanding and complying with these laws is crucial not only to avoid significant legal penalties, but also to build and strengthen relationships with clients.
With the American Privacy Rights Act (APRA) on the horizon, only time will tell whether someday there will also be a “United States General Data Protection Regulation”.
PART 5
How banking businesses use Veriff
Veriff helps protect banks across different sectors, from traditional banks to neobanks. Let’s look at some key examples, analyzing how they use Veriff’s solutions - and the benefits they’ve seen.
Supporting a neobank from conception to launch in under a year
The next challenge was to get to market quickly. And, thanks to developments in tech, embracing artificial intelligence (AI), and being an agile business run by experienced tech people, we were able to build out our proposition and our app in less than one year.

LHV is the newest bank in the UK’s highly competitive retail banking landscape. Originally entering the UK market in 2018 by opening as a branch of subsidiary company LHV Group, a rapidly growing financial group and capital provider based in Estonia, LHV Bank was formally established in 2021 and fully licensed by 2023, becoming the first new bank in the UK in four years.
With a focus on customer centricity, helping customers save, and being a digital-first, app-based bank, LHV has already positioned itself to stand out from the crowd in the UK’s retail banking market.
Kris Brewster, LHV’s Director of Retail Banking, explained: “The retail banking marketplace is highly competitive, but by focusing on providing better value for customers we saw an opportunity to provide a genuine challenge to the challenger banks. We fundamentally do that through offering better interest rates - by providing far better rates for customers on both our current accounts and savings products than they can get elsewhere - and we are able to pay sustainably better interest rates to our customers because of the tech we use and the app-based infrastructure we have built, which is far more streamlined and cost-effective than other banks out there.
“Financial crime is one of the main threats to our business,” Brewster said. “It has always been a problem but the tech developments of the last few years, especially in the realm of AI, make this the number one issue facing all financial institutions.
"We took the approach that if we wanted to protect ourselves and, more importantly, our customers, then we needed to work with best-in-class partners who are specialists in what they do. Veriff is very much in that class and we have been delighted with the work they have done to make our onboarding flows really secure.”
A new bank is always going to be a target for fraudsters, who perhaps assume that being a disruptor in the space with a hard deadline for launch points to a lack of operational experience and ill-prepared fraud prevention systems and teams.
But as many fraudsters have discovered already, LHV was more than ready for the challenge. By opting to work with best-in-class partners like Veriff, LHV can strike the required balance between an optimum level of fraud prevention and a seamless user experience that delights genuine customers.
How Veriff helped
Delivering an elevated and optimized experience for customers
During the due diligence process, we were able to get a sense of how Veriff ingests data and plays it back to its customers without speaking to anybody at the company. That impressed us a lot. We also liked the fact that Veriff’s API docs were public. So, when it came to making a choice, we knew exactly who we wanted.


Founded by David Jarvis and Allen Rohner, Griffin is an API-first UK bank and full-stack banking-as-a-service (BaaS) platform. Griffin was set up to help companies embed financial services into their own products. By managing complex infrastructure and compliance requirements, Griffin lets their customers focus on what matters most - creating world-class products and experiences for their own users.
“We were looking for an alternative solution and spoke to several industry contacts,” Stephens added. “Veriff came highly recommended because of its superior user experience, pass rates, guidance, and customer support, which ultimately steered us toward selecting the company.”
When a new company enters an industry, it often tests its products and services with a select group of customers. This is what Griffin is doing after receiving authorization (with restrictions) from the Prudential Regulation Authority (PRA) to operate as a bank in the UK from March 2023.
Griffin quickly found that its existing identity verification (IDV) provider could not meet its needs. “We were integrated with another IDV solution, but the customer experience and the way we could ingest that product and share data with the underlying provider just wasn’t proficient,” says Ed Stephens, Product Manager at Griffin.
How Veriff helped
The implementation that followed focused on integrating Veriff’s software into Griffin’s onboarding process. Griffin had to make sure that Veriff worked as a standalone check within a sequence of checks. A lot of testing also went into determining whether the technology could work independently and as part of a comprehensive solution.
With Veriff now installed, Griffin can carry out due diligence on direct customers quickly and effectively. It can verify people’s identities and move them seamlessly through the process of onboarding. Most importantly, Griffin now has a solution that can scale with the business - because Veriff’s software is fully automated it can handle large volumes of checks without manual input.

A digital solution with the human touch

Crown Agents Bank is a UK-regulated bank that has existed for around 190 years and has just opened its first European office in a bid to expand globally. Among other services, Crown Agents Bank provides a pensions payroll offering, in particular international pension payroll.
As an ancillary service, Crown Agents Bank provides proof-of-life solutions. Historically, this has entailed pension funds sending out manual forms.
Pensioners would then be asked to complete the forms, sign them, gain third-party attestation from a notary of sorts and then post the forms back to either Crown Agents Bank or the fund directly.
This worked as a solution for many years, but Crown Agents Bank recognized that there’s now technology in place that can better serve those pension funds and give them a higher level of assurance. This way of working benefits pensioners, too, providing alternatives to manual processes that involved filling out forms, gaining attestation and then worrying about the postage.
Prior to partnering with Veriff, Crown Agents Bank was seeing less than satisfactory data in terms of user experience on the member side. It was seeing high abandonment rates, members having to complete the process several times and high numbers of calls coming into call centers as a result.
Crown Agents Bank then trialed two providers, including Veriff, within a proof of concept. An A/B test was conducted, which led to the selection of Veriff.
Crown Agents Bank’s original success metric was 20% digital uptake. This was very much surpassed to an 80-90% uptake rate, which the company describes as “phenomenal”.
Crown Agents Bank made a conscious decision not to go down the app route. Its hypothesis was that the commitment of downloading an app and the technical document that was needed to complete the journey this way wouldn’t best serve the demographic they were working with, so they decided against it.
Another factor was that in a previous proof of concept, it was discovered that members were often relying on help from family members and/or carers. As such, they were experiencing a large number of declines.
Crown Agents Bank worked with Veriff to change the technology using customization, which has resulted in what the company describes as a frictionless solution.
Another plus was the fact that Veriff allowed Crown Agents Bank to embrace technology combined with a human touch - its preference was always a solution that wasn’t all about tech.
How Veriff helped
PART 6
What the future holds
How Veriff can help you fight the AI threat
Technology to identify manipulated images

Biometric analysis of photographs and videos

The ability to identify patterns across verifications and customers

Examination of key device attributes

Veriff’s software development kits are secure and robust by nature because we can control their interactions, making it difficult for fraudsters to digitally inject media into the stream. In effect, we build a hard wrapper around our system, ensuring that content that’s captured or uploaded is valid. We also offer a multi-dimensional approach to tackling these problems:
Veriff’s platform is built on sophisticated models that constantly evolve, providing a multi-layered approach that combines threat-mitigation tools. We treat the absence of data as a risk factor itself and provide a robust and comprehensive check of identity documents.

Ira BondAr-Mucci, Fraud Platform Lead, Veriff

The fraud prevention ecosystem
Veriff is building the infrastructure for trust online. We are doing this by helping digital organizations to do the following three things:
Fight ever-more sophisticated fraud
Achieve growth on a global scale
To do these three things, businesses must ask three key questions of their customers:
Is this person real at the moment of signing up for an account?
Is this person trusted - are they a potential fraud risk or are they a high-value customer?
Is this still the same real and trusted person logging in throughout the lifetime of that account?



The customer identity solution built to answer the key questions facing businesses
Human thought behind the machine learning
Preparing you for the rise of deepfakes
Veriff uses machine learning to detect patterns or anomalies that identify fraud, including those created with deepfakes. This could involve detecting inconsistencies in facial features, skin texture, or lighting conditions. But even with advanced AI, some deepfakes might be sophisticated enough to fool automated systems. Having trained professionals in our human-in-the-loop review helps us to provide an extra layer of security.
By combining these techniques with ongoing research and development, we aim to stay one step ahead of emerging fraud techniques and safeguard our systems and users against potential threats.
Veriff is uniquely placed because we have the ability to provide positive answers to the challenges facing global businesses
Our IDV solution verifies users at the point of sign-up to your systems, confirming they are genuine. Our cross-linking and risk scores create a powerful network effect from across our customer base that enables you to determine whether a customer is to be trusted. And our Biometric Authentication solution enables you to ensure the returning user is still the genuine owner of the account throughout that account’s lifespan.
We have been seeing deepfakes for a couple of years already in our customers’ sessions. With the recent generative AI boom, we can see more and more of these kinds of sessions coming in, where the images have been generated with AI. We take a multi-layered approach to combating deepfakes and AI-generated media.
One key strategy is implementing face liveness checks to validate the authenticity of human presence. This involves using algorithms to detect subtle facial movements and responses, ensuring that the individual interacting with our systems is indeed real.
In addition, we employ a variety of checks to validate the legitimacy of documents. This includes leveraging machine learning algorithms to analyze document features and detect anomalies or signs of manipulation, as well as our proprietary document specimen database populated by document experts.
How we do it ⬇️
Our core Document and Identity Verification solution uses advanced AI and is supported by fraud mitigation tools. We deploy machine learning-powered checks, advanced fraud network mitigation strategies, and a team of in-house counter-fraud experts to help protect organizations.
Meanwhile, our Fraud Protect solution helps to identify patterns and deliver actionable insight built on industry expertise, enabling users to approve greater numbers of genuine users and eliminate more fraud. Its elements are:
Which searches for signs of physical or digital data or structural manipulation.
This prevents individuals suspected of fraud from attempting to access your business.
Offers biometric analysis of the user’s selfie image for signs of physical or digital manipulation.
Which collects and analyzes multiple signals from the user’s device and network to identify potential risk.
CrossLinks and RiskScore techniques are something we utilize across our portfolio to build a comprehensive picture of fraud-related danger, including the risks from deepfakes (see below for more detail).
Analyzing the biometric characteristics from a submitted selfie image to ensure that the subject is real and physically present during the verification, as well as checking for signs of manipulation.






DocCheck:
FaceBlock:
FaceCheck:
DeviceCheck:
CrossLinks and RiskScore:
FaceCheck Liveness:

Similarly, our CrossLinks approach - where we are crosslinking multiple pieces of information to derive new insights and fraudulent patterns that are not detectable when analyzing a single session in isolation - means we can group together verifications with similar data points, helping us to identify fraudsters who might use multiple fake identities on different occasions across our network.
This capability has deepened and expanded. We have long been capable of identifying a document that shows up on multiple occasions with the same customer, or the same biometrics, IP address, or device characteristics.
With Industry CrossLinks, we can look cross-customer, within the same industry vertical - for example, looking to see if the same fraudster has been working across our financial services customers - and the fact we work globally means we can spot evolving trends that a customer working on their own would never be aware of. All of this can happen without any personally identifiable information being shared across customers.
This is effective because fraudsters will always try to reuse their tools and tactics across multiple organizations. Even as they turn to machine learning, AI, and deepfakes, they will reuse credentials, templates, and faces. Our Industry CrossLinks capability stops them in their tracks.
CrossLinks in action:
Learn more
We have plenty of resources available for you to learn more about fraud, and how to protect your business.
Visit our dedicated Fraud Education Center here

Learn more about the threat of AI and deepfakes here

Discover the cost of fraud with our interactive RoI calculator here

Explore our fraud-prevention solutions here


Veriff is the preferred identity verification and authentication partner for the world’s biggest and best digital companies, including pioneers in fintech, crypto, gaming, and the mobility sectors. We provide advanced technology, deep insights, and expertise from our foundation in digital-first Estonia and honed in leading the digital identity revolution. The partner of choice for businesses who need to rapidly and effortlessly verify online users from anywhere in the world, Veriff delivers the broadest possible identity document coverage.
By supporting government-issued IDs from more than 230 issuing countries and territories and with our intelligent decision engine, which analyzes thousands of technological and behavioral variables, Veriff enables trust from the first hello.









Speak to one of our fraud experts today to discover how we can create customizable fraud protection for your business.
