Connect with us

Hi, what are you looking for?

AIO

What is continuous identity assurance?

What is continuous identity assurance?

It is the practice of maintaining confidence in who is using a digital application after the initial login. Unlike point-in-time authentication, it considers whether the person interacting with the application remains the authorised user as the session continues.

The question “What is continuous identity assurance?” becomes clearer when access and later activity are treated as different moments. Authentication helps establish whether the correct credentials or factors were presented at a particular time. Identity assurance during the session helps an organisation assess whether later activity should still be trusted as belonging to the same person. It does not make login security unnecessary.

Identity checks serve different purposes

Digital identity is not established through one control alone. Different checks support different stages of the customer journey:

  • Identity verification helps establish that a person is who they claim to be, often during onboarding or account recovery.
  • Authentication checks whether the person attempting to access an account can present the required credentials or factors.
  • Session-level identity assurance adds context after access has been granted.
  • Transaction controls help an organisation decide whether a particular action should proceed, require another check or be reviewed.

These controls are related, but they are not interchangeable. A successful login confirms that the required checks were passed at that point. It does not, by itself, answer every identity question that may arise later in the session.

Why the action matters as much as the access

The risk within an application is not constant. Viewing an account balance is different from adding a beneficiary, changing payout details or approving a high-value payment. Updating an email address is different from reading a notification.

This is why identity assurance can be applied according to the significance of the action. An organisation may decide that ordinary activity can continue under its existing controls, while selected higher-risk actions require greater confidence in who is present.

The aim is not to treat every click as suspicious. It is to identify the moments where a change in control, destination or value creates a stronger need for identity context.

What can support identity assurance during a session?

Organisations can draw on more than one type of signal. Depending on the application and its risk model, these may include device information, behavioural patterns, transaction risk, session context and biometric presence.

An identity signal can help answer a narrow question: does the application still have reason to believe that the authorised person is present? The signal does not make the business decision on its own. It becomes one input into the organisation’s existing session, fraud and authentication policies.

That distinction matters. The application must still determine what happens when confidence changes. It may continue the session, request another form of authentication, pause a sensitive action, refer the event for review or take another response defined by the organisation.

What continuous identity assurance does not prove

Confirming identity is not the same as confirming intent.

A recognised user may still have been deceived into making a payment. They may be acting under pressure, or their device may be affected by malicious or remote-access software. A facial identity signal does not identify malware and cannot determine whether a person’s decision is informed or voluntary.

Continuous identity assurance should therefore be treated as one layer within a broader control environment. It can add identity context, but it does not replace multi-factor authentication, device security, transaction monitoring, behavioural analytics, customer education or human review.

What responsible implementation requires

Before adding another identity signal, an organisation should define the problem it expects that signal to address. It should also establish:

  • Which actions justify additional identity assurance
  • What information the technology captures, stores or transmits
  • How the application responds when the authorised person cannot be identified
  • What alternative is available when facial recognition cannot be used
  • How consent, transparency, retention and access will be handled
  • How the control will work alongside existing authentication and fraud systems

These decisions are as important as the technology. They determine whether identity assurance supports the customer journey or simply introduces another isolated control.

Where Continuous Facial Recognition with Liveness fits

Continuous Facial Recognition with Liveness is one way to add an identity signal during an active digital session. It is designed to work alongside an application’s existing authentication and session-management infrastructure, while the organisation retains control over how the signal is used and what response should follow.

Datanamix has introduced the technology to South Africa. The solution is powered by the YEO Continuous Facial Recognition SDK and is positioned as an additional identity-assurance layer, not a replacement for the authentication and fraud controls an organisation already uses.

The practical starting point is to identify the actions where knowing who is present would materially improve a decision. Contact Datanamix to discuss where Continuous Facial Recognition with Liveness may fit within your existing digital journey.

You May Also Like

Datanamix News

How to improve right-party contact rates in debt collection in South Africa  Right-party contact is one of the most important performance indicators in debt...

Datanamix News

How to find updated debtor contact details in South Africa  One of the biggest operational challenges facing South African debt collectors today is outdated debtor...

Datanamix News

How can businesses prevent commercial fraud in South Africa?  Commercial fraud is no longer a distant risk. Commercial fraud is a daily reality for...

Datanamix News

Is manual verification slowing your digital retail business down?  Manual verification is one of the biggest hidden risks in digital retail today. As digital...

Datanamix News

How do you verify a Trust in South Africa?    Verifying a Trust in South Africa is one of the most misunderstood and risk-heavy parts of...

Datanamix News

How do you verify a business and its directors in South Africa?  Verifying a business in South Africa is no longer just about confirming registration details. It...

Datanamix News

Datanamix brings Continuous Facial Recognition with Liveness to South Africa through YEO Messaging Digital fraud is evolving. As organisations continue to expand digital onboarding,...

Datanamix News

The Digital Compliance Gap in Debt Review: Why Identity Assurance Matters More Than Ever  The debt review industry in South Africa has embraced digital...

News Watch

Ghana’s National Identification Authority (NIA) says it plans to expand use cases of the national ID – the Ghana Card – in order to drive financial...

Datanamix News

How can you assess business credit risk without paying for a full credit report every time?  Every lender, supplier, insurer, and credit provider faces...

Copyright © 2026 - Datanamix
Disclaimer: The information in this BLOG is provided for general informational purposes only and is the opinion of the author only. No information contained in this blog should be construed as legal advice from Datanamix or the individual author, nor is it intended to be a substitute for legal counsel on any subject matter. No reader of this blog should act or refrain from acting on the basis of any information included in, or accessible through, this blog without seeking the appropriate legal or other professional advice on the particular facts and circumstances at issue.