Connect with us

Hi, what are you looking for?

AIO

How to identify higher-risk actions in a digital journey

How to identify higher-risk actions in a digital journey begins with consequence. An action deserves closer attention when it can move value, redirect a payment, change account control, expose sensitive information or produce an outcome that is difficult to reverse.

Understanding how to identify higher-risk actions in a digital journey also requires separating access from activity. Authentication establishes trust when the user enters an application. The level of risk can change later as the user moves from viewing information to changing settings, approving access or directing value somewhere new.

Begin with the outcome of the action

Industry labels are useful, but they are not the best starting point for assessing in-app risk. The same underlying action may appear in several types of application.

Changing a payout account can affect an insurance claim, a medical-aid refund, a property booking or the earnings of a platform worker. Adding an administrator can affect a business application, hospitality account or public-service portal.

Focusing on the outcome makes it easier to identify similar risks across different digital journeys.

Group actions into five practical categories

Actions that move value

These actions release money, credit, loyalty value, refunds or other transferable benefits.

Examples include approving a payment, redeeming loyalty points, drawing down credit or using a stored payment method for a high-value purchase.

Actions that redirect value

These actions change where money or another benefit will be sent.

Examples include replacing payout details, changing a refund account, linking an external wallet or adding a new payment destination.

Actions that change control

These actions affect who can access, administer or recover the account.

Examples include granting another user access, activating an electronic SIM on a new device, changing registered contact details or authorising another administrator.

Actions that expose sensitive information

These actions reveal or export personal, financial, health, customer or operational information.

The risk depends on the sensitivity of the information, the user’s permissions and the consequence of disclosure.

Actions that are difficult to reverse

Some changes create consequences that cannot be corrected easily. A payment may be released, a benefit redirected, a new user granted access or sensitive information exported before the organisation or customer notices.

The harder the outcome is to reverse, the stronger the case for confirming that the authorised person remains behind the interaction.

Compare low-risk and higher-risk moments

The same application can contain very different levels of risk.

A customer may check a booking and later change the account receiving a refund. A medical-aid member may read a statement and later replace the bank details used for reimbursements. A retailer’s customer may view an order and later redeem a large balance of loyalty points.

This comparison helps teams avoid adding unnecessary friction to routine activity while still identifying the actions that deserve greater identity confidence.

Review the controls already in place

Identity assurance should not be assessed in isolation. Organisations may already use passwords, one-time PINs, recognised devices, biometric checks, access permissions, transaction monitoring and fraud investigation.

Each control answers a different question. Authentication helps decide whether access should be granted. Permissions define what the account can do. Transaction monitoring assesses the action. Device controls provide information about the environment.

Additional identity assurance contributes another piece of context: whether the authorised person remains present as the session continues.

Decide where renewed identity confidence adds value

For each higher-risk action, teams can ask:

  • What financial, privacy or access consequence could follow?
  • Which identity checks took place earlier in the journey?
  • How much time or activity may separate login from this action?
  • Which existing controls assess the device, behaviour and transaction?
  • Would greater confidence in the user’s identity improve the decision?
  • What should happen if that confidence cannot be maintained?

The final question is operational as well as technical. The organisation needs a clear response that fits its customer journey, policies and existing fraud controls.

Keep the limits of identity assurance clear

Identity assurance cannot determine whether the authorised user is making a wise decision or acting under manipulation. It does not detect malware, judge a payment destination or replace the investigation of unusual activity.

Its purpose is to strengthen confidence in who is interacting with the application. That signal should be considered alongside other security and fraud information rather than treated as a complete decision on its own.

Extending identity assurance beyond login

Datanamix provides Continuous Facial Recognition with Liveness as part of its identity and verification technology portfolio.

The solution is designed to strengthen existing authentication by extending identity assurance throughout an active digital session. This allows organisations to consider additional identity confidence around selected higher-risk actions while retaining their existing access, device, transaction and fraud controls.

Book a demo with Datanamix to explore the higher-risk moments within your digital journeys.

You May Also Like

Datanamix News

Is manual verification slowing your digital retail business down?  Manual verification is one of the biggest hidden risks in digital retail today. As digital...

Datanamix News

How can businesses prevent commercial fraud in South Africa?  Commercial fraud is no longer a distant risk. Commercial fraud is a daily reality for...

Datanamix News

The Digital Compliance Gap in Debt Review: Why Identity Assurance Matters More Than Ever  The debt review industry in South Africa has embraced digital...

Datanamix News

Datanamix brings Continuous Facial Recognition with Liveness to South Africa through YEO Messaging Digital fraud is evolving. As organisations continue to expand digital onboarding,...

Datanamix News

How can you assess business credit risk without paying for a full credit report every time?  Every lender, supplier, insurer, and credit provider faces...

Datanamix News

‘I’m advocating to change the Rica Act for biometric recognition to be included at time of registration. I propose facial recognition because that works...

Datanamix News

How can digital retailers verify customer identity online in South Africa?    Digital retail in South Africa has grown rapidly, jumping from R37.4 billion in 2018...

News Watch

Ghana’s National Identification Authority (NIA) says it plans to expand use cases of the national ID – the Ghana Card – in order to drive financial...

Datanamix News

How do you verify a business and its directors in South Africa?  Verifying a business in South Africa is no longer just about confirming registration details. It...

Datanamix News

Unauthorised Access Is A Growing Concern For CISOs: Is Identity Verification Enough? For many organisations, identity verification has long been considered the first line...

Copyright © 2026 - Datanamix
Disclaimer: The information in this BLOG is provided for general informational purposes only and is the opinion of the author only. No information contained in this blog should be construed as legal advice from Datanamix or the individual author, nor is it intended to be a substitute for legal counsel on any subject matter. No reader of this blog should act or refrain from acting on the basis of any information included in, or accessible through, this blog without seeking the appropriate legal or other professional advice on the particular facts and circumstances at issue.