Recently online bank Revolut announced a trial of “payment by face” in retailer stores which is interesting.
The UK GOV login and ID verification system is also using face scanning for company directors and the self employed. It all sounds good, until criminals start using coercive control over fraud victims, blackmail, physical threats and much more. How does the face scan cope with things like flu-like illness where the shape of the face may vary, weight loss/gain, or men growing various types of elaborate facial hair, or shaving it all off?
For insurers it might be worth looking at ingesting some facial recognitions data into the claims process, especially in higher value claims. But the privacy issues and potential regulatory problems could cause legal action further down the line if things go wrong, even in a handful of cases.
Herr are some insights from Smartsearch;
Phil Cotter, CEO SmartSearch, says: “Fraud is becoming more emotionally sophisticated and more personalised, designed to exploit the layer of trust that verifies who someone is and who they are acting for. Impersonation scams, much like romance and investment scams, work through weak or inconsistent checks within the heart of regulated activities, and an individual can end up funding or facilitating illicit activity through a regulated entity like a bank without knowing who sits on the other side of the screen, with little means of recovering their money. With many firms now liable for criminal prosecution when they fail to prevent fraud, this gap is a legal exposure as much as a reputational and financial one, and a signal that the verification infrastructure the regulated economy relies on is falling behind the scale and pace of modern fraud.
Breaches like these show why fintechs are such an attractive target, they hold identity documents and transaction histories that few other companies collect in one place, which is exactly what a criminal needs to impersonate a customer elsewhere. Stolen identity data is usually only the opening move, because someone armed with a victim’s name alongside their recent transactions and rough balance can pose as their bank or trusted association convincingly enough to catch out even careful people, with fallout that runs for months or years after the incident is publicly resolved. If a compromised business handles cryptocurrency or emerging asset classes, funds could also be laundered through a fraudulently opened and verified account at pace and across borders, with limited means of tracking where they travel.
Fintechs also carry the same anti-money laundering obligations as established banks without the compliance function those banks have spent twenty years building, which leaves them further exposed. An attacker operating from a genuine government address is betting that nobody on the receiving end will stop to question who is really asking, so compliance and data access controls need to work even when the person making an approach is, or appears to be, someone important, and that discipline has to extend to every partner a fintech shares customer data with.
Whoever a criminal claims to be, the money they take has to be received somewhere, and that account sits within a regulated firm. Verification is the last control acting before a victim’s funds move, and it only closes the loop if it continues across the life of a relationship, so a firm knows who is operating an account today rather than who it checked when a customer first came on board. Paying by face raises the stakes further, because a biometric matched against data captured at onboarding will faithfully confirm whoever passed that first check, including a criminal who opened the account with stolen details.
The technology to do this already exists, and providers can complete a full identity and AML check in under two seconds for individuals, and cross-reference multiple global databases to generate a comprehensive business check in under two minutes, with AI flagging unusual patterns of activity in real time before they escalate. Fintechs don’t have the decades of customer relationship equity larger institutions can draw on when something goes wrong, so getting this right is the difference between stopping a criminal and absorbing lasting reputational damage.”

Be the first to comment