Identity Issues in Banking: Why Identity Fraud Should Be an Audit, Compliance and Fraud-Control Priority
- John C. Blackshire, Jr.

- 1 day ago
- 7 min read
Identity Issues in Banking — September 14 and November 9, 2026
Banks operate on a fundamental assumption:
The person opening or using an account is who they claim to be.
When that assumption fails, many other controls can fail with it.
A fraudster using a stolen or synthetic identity may open an account, obtain credit, move money, take over an existing account, exploit compromised credentials or use the banking system as part of a larger fraud scheme.
Identity risk therefore isn't simply a customer-service problem.
It is a fraud risk, compliance risk, cybersecurity risk, operational risk and Internal Audit issue.
Corporate Compliance Seminars' Identity Issues in Banking is a focused 2-CPE Auditing webinar addressing identity fraud, regulatory red flags, fraud-control programs and identity-validation techniques for banking professionals. The program specifically addresses the federal identity-theft red flags and how banks can improve controls designed to detect and combat identity theft.
Upcoming sessions are:
Monday, September 14, 2026
Monday, November 9, 2026
Identity Is a Control
Banks have traditionally thought about identity primarily in terms of identification:
Who is this customer?
Today's environment requires a broader question:
What evidence gives us reasonable confidence that this individual is actually who they claim to be?
Those aren't necessarily the same question.
A customer can provide:
A name
Address
Social Security number
Date of birth
Government identification
Credit history
and a fraudster may have obtained some or all of that information.
The control objective is therefore not merely collecting identity information.
It is validating identity sufficiently to manage the risk associated with the transaction or relationship.
The 26 Red Flags Give Banks a Starting Point
A major focus of the CCS program is understanding the 26 identity-fraud red flags identified through federal regulatory guidance. The course examines warning signs associated with new and existing accounts, applications, credit reports, customer-provided documents and the early use of newly established credit.
The concept is straightforward:
Identity Information
→ Verification
→ Red Flags
→ Investigation
→ Risk Decision
→ Monitoring
A red flag doesn't automatically establish fraud.
It tells the institution:
Something doesn't fit. Investigate before proceeding.
That distinction is important for auditors.
What Does an Identity Red Flag Look Like?
Identity-related anomalies can appear in numerous places.
For example, information on an application may conflict with information obtained from another source.
Documentation may appear altered or inconsistent.
A credit report may contain unusual information.
An address, telephone number or other identifying information may be associated with suspicious activity.
An existing account may suddenly display activity inconsistent with the customer's historical behavior.
The CCS course specifically separates its discussion into red flags involving new accounts and existing accounts, an important distinction because identity risk doesn't disappear after account opening.
Existing Customers Can Become Identity-Fraud Victims
Banks cannot assume:
“We verified this customer five years ago, so identity is no longer a risk.”
Account takeover demonstrates why.
The legitimate customer exists.
The account is legitimate.
The problem is that the person now attempting to control the account may not be the legitimate customer.
That means banks need controls not only around identity establishment, but around continuing authentication and account behavior.
The audit question becomes:
What would tell the bank that the person currently controlling this account may no longer be the legitimate customer?
That is a detective-control question.
Data Breaches Changed Identity Verification
CCS specifically incorporates lessons from major data breaches into the program and asks how banks should think about identity-validation tools in a post-breach world.
This is important because information that was once considered relatively private may have been compromised.
The old model was essentially:
“Tell me something only you should know.”
The problem is that criminals may now know it too.
That forces financial institutions to consider stronger, layered approaches to identity validation rather than excessive reliance on static personal information.
Identity Fraud Should Be Viewed as a Control System
A bank's identity-fraud program shouldn't depend upon one control.
Think in layers:
Identity Information
→ Identity Verification
→ Authentication
→ Red-Flag Detection
→ Transaction Monitoring
→ Exception Investigation
→ Escalation
→ Loss Prevention
This is defense in depth.
One control may fail.
The next control should have an opportunity to detect the problem.
Preventive and Detective Controls Both Matter
A good identity-fraud control environment requires both.
Preventive controls attempt to stop the fraudster before access or credit is granted.
Examples include identity validation, document verification, authentication and approval controls.
Detective controls attempt to identify suspicious activity that gets through preventive measures.
Examples include behavioral monitoring, transaction alerts, account-change monitoring and exception reporting.
The critical Internal Audit question is:
If our preventive identity controls fail, which detective control should tell us?
If nobody can answer that question, the bank may have a significant control gap.
The Internal Auditor Should Test the Process, Not Just Read the Policy
A bank may have an excellent identity-theft policy.
That doesn't prove the controls operate.
Internal Audit should follow transactions through the process.
For example:
Select new accounts.
Determine what identity information was obtained.
Determine what verification occurred.
Identify whether red flags were generated.
Determine how exceptions were resolved.
Inspect the supporting evidence.
Then ask:
Could the account have been opened if the identity controls were circumvented?
That is testing.
The CCS program specifically identifies Internal Auditors as one of its intended audiences and focuses on helping attendees review their institution's current compliance and identify opportunities to improve it.
Test the Red-Flag Escalation Process
A bank can have sophisticated red-flag technology and still have a weak control environment.
Suppose the system generates 5,000 alerts.
What happens next?
Auditors should determine:
Who receives the alerts?
How are they prioritized?
What requires investigation?
How quickly must investigation occur?
Who can close an alert?
What evidence supports closure?
Who reviews overrides?
Are recurring patterns analyzed?
An alert nobody investigates is not an effective detective control.
Don't Ignore the Human Element
Technology is essential, but fraudsters understand human behavior.
They exploit urgency.
Authority.
Fear.
Trust.
Confusion.
Customer-service pressure.
A fraudster may intentionally create a situation where the employee feels pressure to bypass normal procedures:
“I need access immediately.”
“I'm traveling.”
“I lost my phone.”
“I've been a customer for twenty years.”
“Your other employee always does this for me.”
The identity-control system needs to work precisely when someone pressures an employee not to follow it.
Identity Fraud and Cybersecurity Are Converging
Banks increasingly operate in a digital environment.
That means identity management and cybersecurity cannot be treated as completely separate subjects.
Consider:
Stolen Credentials
→ Account Access
→ Account Takeover
→ Unauthorized Transactions
Or:
Compromised Personal Data
→ Identity Impersonation
→ New Account
→ Credit
→ Fraud Loss
Identity is often the bridge between cyber compromise and financial fraud.
That makes identity management relevant to Internal Audit, IT Audit, cybersecurity, fraud and compliance teams simultaneously.
Artificial Intelligence Raises the Stakes
AI can strengthen identity-fraud detection.
It can potentially help institutions identify unusual patterns, compare large amounts of information and prioritize suspicious activity.
But AI also strengthens the fraudster.
Generative technologies can facilitate more convincing impersonation, fraudulent documents and social-engineering attempts.
The control question remains the same:
What evidence are we relying upon to establish that this individual is legitimate?
Banks should avoid confusing better-looking evidence with better evidence.
Identity Fraud Belongs in the Fraud Risk Assessment
A bank's fraud risk assessment should explicitly consider identity.
Ask:
How could someone establish a fraudulent identity?
How could someone take over an existing customer's identity?
Which products are most exposed?
Which channels are most vulnerable?
What controls prevent the fraud?
What controls detect it?
What losses have occurred?
Which controls have failed?
Are fraud patterns changing?
This connects identity management to the bank's broader enterprise fraud-control program.
CCS specifically positions the course around developing and implementing fraud controls to combat identity theft and reduce future losses.
Internal Audit Should Look for Control Gaps Between Departments
Identity management frequently crosses organizational boundaries.
Customer onboarding may collect information.
Compliance may establish requirements.
IT manages authentication technology.
Cybersecurity monitors threats.
Fraud investigates suspicious behavior.
Operations processes transactions.
Internal Audit evaluates the system.
That creates a classic enterprise-control risk:
Everyone owns part of the process, but does anyone understand the whole process?
Internal Audit is particularly well positioned to evaluate the identity-control framework end to end.
A Practical Audit Model
Internal Auditors can approach identity risk using a straightforward model:
1. Identify the identity-fraud scenario
How could the fraud occur?
2. Identify the preventive control
What should stop it?
3. Identify the detective control
What should identify it if prevention fails?
4. Determine the control owner
Who is responsible?
5. Identify the evidence
What proves the control operated?
6. Test operating effectiveness
Did it actually work?
7. Evaluate exceptions
What happened when a red flag occurred?
8. Determine residual risk
What exposure remains after considering the controls?
This converts identity fraud from a vague cybersecurity concern into an auditable control system.
Two Opportunities to Attend in 2026
Corporate Compliance Seminars' Identity Issues in Banking is a Basic-level, Group Internet-Based program providing 2 CPE credits in Auditing. It requires no prerequisites or advance preparation and is scheduled from 10:00 a.m. to noon Central Time.
Monday, September 14, 2026
The September session provides banking auditors, compliance professionals and fraud specialists an opportunity to evaluate identity-related risks and controls before year-end.
Monday, November 9, 2026
The November program is particularly well timed for organizations developing their 2027 fraud risk assessments, compliance plans and Internal Audit programs.
The program is designed particularly for banking compliance professionals, Internal Auditors and fraud-prevention personnel.
The Bottom Line: Identity Is the First Control
Many banking controls assume that the person initiating the transaction is legitimate.
If that assumption is wrong, everything downstream becomes vulnerable.
The control model should therefore be:
Establish Identity
→ Validate Identity
→ Authenticate
→ Identify Red Flags
→ Investigate Exceptions
→ Monitor Account Activity
→ Escalate Suspicious Behavior
→ Improve Controls
Internal Audit should then ask the question that matters:
What evidence demonstrates that this system actually works?
That is why identity issues should be treated as much more than an onboarding or compliance problem.
Identity is a fundamental banking control.
Corporate Compliance Seminars' Identity Issues in Banking on September 14 and November 9, 2026 provides two focused CPE hours for professionals responsible for evaluating and strengthening that control environment.
Comments