A useful identity strategy distinguishes between routine activity and actions with greater consequences. What Is Risk-Based Identity Assurance? It is an approach that matches the level of identity confidence required to the risk and consequence of a digital action.
The question ‘What Is Risk-Based Identity Assurance?’ becomes practical when an authenticated journey includes many different actions. Reading information, changing contact details and approving a large payment should not automatically be treated as if they present the same risk.
Risk-based identity assurance begins with the action
The organisation first identifies what a user can do inside the application. It then considers the financial, privacy, operational and recovery consequences if an action is completed by someone other than the authorised user.
Context determines the appropriate response
A payment amount, a new beneficiary, an unfamiliar device or a change to payout details may affect how an organisation treats an action. The response can also depend on the controls already present and the organisation’s tolerance for risk and customer disruption.
A simple risk-based process
A practical assessment can follow four steps:
- Identify the action the user wants to complete.
- Assess what could happen if the wrong person completes it.
- Review the authentication, device, transaction and approval controls already applied.
- Choose an appropriate response, including a clear alternative for legitimate users who cannot be verified.
Identity assurance and authentication are related
Authentication can establish who enters an application and may also protect selected actions. Identity assurance asks whether the organisation has enough confidence in the user’s identity at the point where a particular decision is made. The two work together rather than competing for the same role.
Where Continuous Facial Recognition with Liveness fits
Continuous Facial Recognition with Liveness is one way to extend identity assurance into an active session. Datanamix provides the technology in South Africa, powered by the YEO Continuous Facial Recognition SDK. It is designed to complement existing authentication and fraud controls.
The approved Datanamix article provides further context on Continuous Facial Recognition with Liveness and fraud prevention.
The technology does not decide whether an action is safe
Confirming that the authorised person is present does not establish that a payment is legitimate, detect malware or show whether the user is acting under pressure. Those risks still require the organisation’s wider security, transaction and fraud-management processes.
The objective is proportionate assurance
Risk-based identity assurance is most useful when it improves a defined decision. It should help the organisation protect consequential actions while avoiding unnecessary interruption during routine activity.
Contact Datanamix to explore how risk-based identity assurance could support your digital customer journeys.









