Re-Authentication Is the New Know Your Customer (KYC)

A headshot photo of Deji Amund
Deji Amund

August 7, 2026

Re-Authentication Is the New Know Your Customer (KYC)

Most fraud conversations start and end at onboarding, right after the various checks have returned as verified. However, every account sitting in a bank or fintech's book today was verified under yesterday's controls. And in the modern era, new threats emerge by the minute.

Most troublingly, many accounts were onboarded two, three, even five years ago, when thresholds were looser, liveness models were weaker, and GenAI-assisted documents and deepfakes barely existed. These accounts were real, legitimate customers at the time. But "verified once" is not the same as "safe forever." Account takeover, not fraudulent onboarding, is quickly becoming the more dangerous side of KYC.

The Onboarding-Only Model Has a Blind Spot

Incode data shows a marked increase in document and selfie fraud attempts, with most sessions involving the use of advanced AI.

Every one of those numbers describes fraud at the point of entry, but they also imply something risk teams don't talk about enough: if attackers are this much better at defeating verification today than they were two years ago, then every account that passed a weaker check two years ago is a live question mark.

An account isn't just a one-time pass/fail event. It is a standing credential that fraudsters can target long after onboarding through credential stuffing, SIM swaps, session hijacking, or increasingly, synthetic re-verification designed to survive a lighter-touch step-up check. The same forces driving up onboarding fraud (including cheap GenAI tooling, high-value single verification moments, and regulatory pressure without infrastructure parity) apply with equal force to account takeover.

Why Continuous Trust Matters More Now

Continuous trust is more relevant today than ever before, largely due to three converging trends:

  1. GenAI has collapsed the cost of producing convincing fraud artifacts
  2. More services are treating one identity check as sufficient proof of who someone is, indefinitely
  3. Regulators are tightening KYC/AML requirements faster than identity infrastructure can keep up

That combination doesn't just make new account openings riskier. It makes previously onboarded accounts a growing liability. Why? Because the defenses that verified them were calibrated for a threat environment that no longer exists.

An institution doesn't need a high failure rate on old accounts to have a large absolute exposure; it just needs a large book of accounts that were never re-checked against current-generation defenses.

From "Verify Once" To "Re-Verify Continuously"

The core approach for new onboarding is multi-signal, adaptive defense: correlating biometrics, device integrity, and behavior instead of relying on any single check. That same logic should extend backward into the existing customer base:

  1. Segment existing accounts by timing and control strength. Accounts opened before stronger liveness, deepfake, or device-integrity checks were in place deserve a second look.
  2. Treat behavioral signals as ongoing risk inputs. Retry patterns, device changes, and session anomalies are as relevant six months after onboarding as they are on day one.
  3. Prioritize by exposure, not just by fraud rate. An account with a working set of credentials tied to payments, credit, or benefits access is a higher-value target for takeover than the raw fraud rate might suggest.
  4. Build re-authentication into the customer lifecycle, not just into incident response. Waiting for a takeover to trigger a review means the damage is already done.

The Bottom Line

The reality we all face is that the front door isn't the only door anymore. Every account onboarded under yesterday's controls carries exposures under today's threat model. Institutions that only look forward, strengthening new onboarding while leaving the existing accounts untouched, are defending only a small portion of risk.

Ready to see what continuous trust looks like with Incode? Request a demo today.

A headshot photo of Deji Amund
Deji Amund
Deji Amund, Africa Growth & Strategic Partnerships Lead at Incode, drives the expansion of identity verification and digital trust solutions across the African continent. With a focus on building high-value ecosystems, he bridges Incode's cutting-edge technology with the region's most critical market opportunities, from data and source-of-truth partnerships to regulatory and government engagements.‍
Linkedin
Chapters