top of page
Search

Identity Issues in Banking: Why Identity Fraud Should Be an Audit, Compliance and Fraud-Control Priority

Identity Issues in Banking — September 14 and November 9, 2026


Banks operate on a fundamental assumption:

The person opening or using an account is who they claim to be.

When that assumption fails, many other controls can fail with it.


A fraudster using a stolen or synthetic identity may open an account, obtain credit, move money, take over an existing account, exploit compromised credentials or use the banking system as part of a larger fraud scheme.


Identity risk therefore isn't simply a customer-service problem.


It is a fraud risk, compliance risk, cybersecurity risk, operational risk and Internal Audit issue.


Corporate Compliance Seminars' Identity Issues in Banking is a focused 2-CPE Auditing webinar addressing identity fraud, regulatory red flags, fraud-control programs and identity-validation techniques for banking professionals. The program specifically addresses the federal identity-theft red flags and how banks can improve controls designed to detect and combat identity theft.


Upcoming sessions are:

  • Monday, September 14, 2026

  • Monday, November 9, 2026



Identity Is a Control

Banks have traditionally thought about identity primarily in terms of identification:

Who is this customer?

Today's environment requires a broader question:

What evidence gives us reasonable confidence that this individual is actually who they claim to be?

Those aren't necessarily the same question.


A customer can provide:

  • A name

  • Address

  • Social Security number

  • Date of birth

  • Government identification

  • Credit history

and a fraudster may have obtained some or all of that information.


The control objective is therefore not merely collecting identity information.

It is validating identity sufficiently to manage the risk associated with the transaction or relationship.


The 26 Red Flags Give Banks a Starting Point

A major focus of the CCS program is understanding the 26 identity-fraud red flags identified through federal regulatory guidance. The course examines warning signs associated with new and existing accounts, applications, credit reports, customer-provided documents and the early use of newly established credit.


The concept is straightforward:


Identity Information

Verification

Red Flags

Investigation

Risk Decision

Monitoring


A red flag doesn't automatically establish fraud.


It tells the institution:

Something doesn't fit. Investigate before proceeding.

That distinction is important for auditors.


What Does an Identity Red Flag Look Like?

Identity-related anomalies can appear in numerous places.


For example, information on an application may conflict with information obtained from another source.


Documentation may appear altered or inconsistent.


A credit report may contain unusual information.


An address, telephone number or other identifying information may be associated with suspicious activity.


An existing account may suddenly display activity inconsistent with the customer's historical behavior.


The CCS course specifically separates its discussion into red flags involving new accounts and existing accounts, an important distinction because identity risk doesn't disappear after account opening.


Existing Customers Can Become Identity-Fraud Victims


Banks cannot assume:

“We verified this customer five years ago, so identity is no longer a risk.”

Account takeover demonstrates why.


The legitimate customer exists.


The account is legitimate.


The problem is that the person now attempting to control the account may not be the legitimate customer.


That means banks need controls not only around identity establishment, but around continuing authentication and account behavior.


The audit question becomes:

What would tell the bank that the person currently controlling this account may no longer be the legitimate customer?

That is a detective-control question.


Data Breaches Changed Identity Verification

CCS specifically incorporates lessons from major data breaches into the program and asks how banks should think about identity-validation tools in a post-breach world.


This is important because information that was once considered relatively private may have been compromised.


The old model was essentially:

“Tell me something only you should know.”

The problem is that criminals may now know it too.


That forces financial institutions to consider stronger, layered approaches to identity validation rather than excessive reliance on static personal information.


Identity Fraud Should Be Viewed as a Control System

A bank's identity-fraud program shouldn't depend upon one control.


Think in layers:


Identity Information

Identity Verification

Authentication

Red-Flag Detection

Transaction Monitoring

Exception Investigation

Escalation

Loss Prevention


This is defense in depth.


One control may fail.


The next control should have an opportunity to detect the problem.


Preventive and Detective Controls Both Matter

A good identity-fraud control environment requires both.


Preventive controls attempt to stop the fraudster before access or credit is granted.


Examples include identity validation, document verification, authentication and approval controls.


Detective controls attempt to identify suspicious activity that gets through preventive measures.


Examples include behavioral monitoring, transaction alerts, account-change monitoring and exception reporting.


The critical Internal Audit question is:

If our preventive identity controls fail, which detective control should tell us?

If nobody can answer that question, the bank may have a significant control gap.


The Internal Auditor Should Test the Process, Not Just Read the Policy

A bank may have an excellent identity-theft policy.


That doesn't prove the controls operate.


Internal Audit should follow transactions through the process.


For example:

  • Select new accounts.

  • Determine what identity information was obtained.

  • Determine what verification occurred.

  • Identify whether red flags were generated.

  • Determine how exceptions were resolved.

  • Inspect the supporting evidence.


Then ask:

Could the account have been opened if the identity controls were circumvented?

That is testing.


The CCS program specifically identifies Internal Auditors as one of its intended audiences and focuses on helping attendees review their institution's current compliance and identify opportunities to improve it.


Test the Red-Flag Escalation Process

A bank can have sophisticated red-flag technology and still have a weak control environment.


Suppose the system generates 5,000 alerts.


What happens next?


Auditors should determine:

  • Who receives the alerts?

  • How are they prioritized?

  • What requires investigation?

  • How quickly must investigation occur?

  • Who can close an alert?

  • What evidence supports closure?

  • Who reviews overrides?

  • Are recurring patterns analyzed?


An alert nobody investigates is not an effective detective control.


Don't Ignore the Human Element

Technology is essential, but fraudsters understand human behavior.


They exploit urgency.


Authority.


Fear.


Trust.


Confusion.


Customer-service pressure.


A fraudster may intentionally create a situation where the employee feels pressure to bypass normal procedures:

“I need access immediately.”
“I'm traveling.”
“I lost my phone.”
“I've been a customer for twenty years.”
“Your other employee always does this for me.”

The identity-control system needs to work precisely when someone pressures an employee not to follow it.


Identity Fraud and Cybersecurity Are Converging

Banks increasingly operate in a digital environment.


That means identity management and cybersecurity cannot be treated as completely separate subjects.


Consider:


Stolen Credentials

Account Access

Account Takeover

Unauthorized Transactions

Or:

Compromised Personal Data

Identity Impersonation

New Account

Credit

Fraud Loss


Identity is often the bridge between cyber compromise and financial fraud.


That makes identity management relevant to Internal Audit, IT Audit, cybersecurity, fraud and compliance teams simultaneously.


Artificial Intelligence Raises the Stakes

AI can strengthen identity-fraud detection.


It can potentially help institutions identify unusual patterns, compare large amounts of information and prioritize suspicious activity.


But AI also strengthens the fraudster.


Generative technologies can facilitate more convincing impersonation, fraudulent documents and social-engineering attempts.


The control question remains the same:

What evidence are we relying upon to establish that this individual is legitimate?

Banks should avoid confusing better-looking evidence with better evidence.


Identity Fraud Belongs in the Fraud Risk Assessment

A bank's fraud risk assessment should explicitly consider identity.


Ask:

How could someone establish a fraudulent identity?
How could someone take over an existing customer's identity?
Which products are most exposed?
Which channels are most vulnerable?
What controls prevent the fraud?
What controls detect it?
What losses have occurred?
Which controls have failed?
Are fraud patterns changing?

This connects identity management to the bank's broader enterprise fraud-control program.


CCS specifically positions the course around developing and implementing fraud controls to combat identity theft and reduce future losses.


Internal Audit Should Look for Control Gaps Between Departments

Identity management frequently crosses organizational boundaries.


Customer onboarding may collect information.


Compliance may establish requirements.


IT manages authentication technology.


Cybersecurity monitors threats.


Fraud investigates suspicious behavior.


Operations processes transactions.


Internal Audit evaluates the system.


That creates a classic enterprise-control risk:

Everyone owns part of the process, but does anyone understand the whole process?

Internal Audit is particularly well positioned to evaluate the identity-control framework end to end.


A Practical Audit Model

Internal Auditors can approach identity risk using a straightforward model:


1. Identify the identity-fraud scenario

How could the fraud occur?

2. Identify the preventive control

What should stop it?

3. Identify the detective control

What should identify it if prevention fails?

4. Determine the control owner

Who is responsible?

5. Identify the evidence

What proves the control operated?

6. Test operating effectiveness

Did it actually work?

7. Evaluate exceptions

What happened when a red flag occurred?

8. Determine residual risk

What exposure remains after considering the controls?


This converts identity fraud from a vague cybersecurity concern into an auditable control system.


Two Opportunities to Attend in 2026

Corporate Compliance Seminars' Identity Issues in Banking is a Basic-level, Group Internet-Based program providing 2 CPE credits in Auditing. It requires no prerequisites or advance preparation and is scheduled from 10:00 a.m. to noon Central Time.


Monday, September 14, 2026

The September session provides banking auditors, compliance professionals and fraud specialists an opportunity to evaluate identity-related risks and controls before year-end.


Monday, November 9, 2026

The November program is particularly well timed for organizations developing their 2027 fraud risk assessments, compliance plans and Internal Audit programs.


The program is designed particularly for banking compliance professionals, Internal Auditors and fraud-prevention personnel.


The Bottom Line: Identity Is the First Control

Many banking controls assume that the person initiating the transaction is legitimate.


If that assumption is wrong, everything downstream becomes vulnerable.


The control model should therefore be:


Establish Identity

Validate Identity

Authenticate

Identify Red Flags

Investigate Exceptions

Monitor Account Activity

Escalate Suspicious Behavior

Improve Controls


Internal Audit should then ask the question that matters:

What evidence demonstrates that this system actually works?

That is why identity issues should be treated as much more than an onboarding or compliance problem.


Identity is a fundamental banking control.


Corporate Compliance Seminars' Identity Issues in Banking on September 14 and November 9, 2026 provides two focused CPE hours for professionals responsible for evaluating and strengthening that control environment.


 
 
 

Recent Posts

See All
What the CIA Taught Me About Audit Tradecraft

I learned the real meaning of tradecraft while designing a training-tracking system for new intelligence officers at the Central Intelligence Agency. The system had to track more than completed course

 
 
 

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page