Payments Fraud is an Identity Problem, Not a Transaction Problem

Fraud prevention in payments has become a layering exercise. Behavioural analytics, device intelligence, velocity checks and transaction scoring sit one on top of another, and each new layer is added because the last one did not stop the losses.

Paul Twigg, chief technology officer of Digital Commerce Group (DCG)

The contributed piece below argues that all of those layers share a weakness: they watch what a user does once inside the system, while the question of who that user is was answered once, at onboarding, if at all. Its author writes from Canada, where provincial digital identity schemes, a new national standard and an approaching real-time payments rail make the country a useful test of whether identity infrastructure can do what transaction monitoring has not.

Paul Twigg is chief technology officer of Digital Commerce Group (DCG), a Canadian payments company, and has spent his career building and operating payments infrastructure. The article that follows sets out his opinion.

Every year, the payments industry invests billions in fraud detection: smarter AI models, more sophisticated transaction monitoring, seven-layer security frameworks that track device fingerprints, flag velocity anomalies and score behavioural patterns in milliseconds.

And yet fraud keeps coming and the losses keep climbing.

After years spent building and operating payment infrastructure, my view is that we have been fighting this battle at the wrong layer. Most fraud is not a transaction problem. It is an identity problem. We do not know with certainty who is on either end of a digital payment. Everything else we build, the detection tools, the controls and the AI, is compensation for that foundational gap.

Until those that govern the payments industry are willing to confront that reality, we will keep running faster on the same treadmill.

Layering up: the industry’s default playbook

Ask any bank or payment processor how they fight fraud and you will hear a familiar answer: a layered approach. Industry frameworks involve defensive layers from scam detection and customer education at the front end, through to multi-factor authentication, session monitoring, and real-time transaction rule and pattern analysis further in. Financial institutions combine AI-powered behavioural analytics, device intelligence and network analysis, all operating continuously in the background.

These controls are genuinely sophisticated. But notice what they have in common: they all assume the user is already inside the system. They are designed to watch what someone does after they have got in, not to confirm who they actually are before they get there.

Identity verification, where it exists at all, typically happens once at onboarding and is rarely shared or revisited later at the moment of a transaction. Most digital payment flows authenticate via an email address, a phone number, or a username and password pair. These are credentials. They confirm access to a device or an inbox. Not identity.

A fraudster who has stolen your login has, from the system’s perspective, become you. With the prevailing ‘I want my money now’ mentality, the result is a system built to approve access quickly, not to verify identity with enough certainty before money moves.

The scale of the problem, and why it keeps evolving

From my knowledge of the Canadian financial landscape, I see all of this unfolding regularly, and the implications are global.

In 2024, the Canadian Anti-Fraud Centre reported that Canadians lost $643 million to fraud, a nearly 300 per cent increase since 2020. And that figure is almost certainly a significant undercount: the CAFC estimates it represents only 5 to 10 per cent of actual losses, as most victims never report.

The top three most reported fraud types in Canada in 2024 were identity fraud, service fraud and investment fraud, all variations of the same underlying problem: someone successfully impersonated someone else. More than 75 per cent of fraudulent credit applications in Canada involve identity theft, as do 73.5 per cent of fraudulent credit card applications and 89.3 per cent of deposit fraud cases. The pattern is consistent and unambiguous: fraud is an identity problem wearing different costumes.

Canadian businesses face an even higher rate of payment fraud than consumers, 20 per cent against 13 per cent, with impersonation fraud representing a quarter of what businesses experience.

What makes this problem particularly urgent is that fraudsters are not standing still. Deepfake fraud incidents increased tenfold between 2022 and 2023, and in the first quarter of 2025 alone, more than US$200 million was stolen globally through deepfake-enabled scams. Generative AI is now being used by fraudsters to stay ahead of the very detection systems providers are deploying, creating synthetic identities sophisticated enough to pass traditional onboarding checks.

The arms race approach clearly is not working, as fraud losses keep accumulating even as detection investment grows. The industry needs a smarter strategy, and that includes digital identity.

Digital ID in Canada is a live case study

I have seen real progress from my Canadian vantage point, but also real gaps that the payments industry needs to understand and address at a macro level.

The value of a strong digital identity framework became tangible during Covid-19. British Columbia’s digital identity system allowed residents to verify themselves for government services without any in-person interaction, demonstrating what identity infrastructure can enable under pressure. Both BC and Alberta have established provincially issued trusted digital identities, and the federal government has signed agreements allowing residents to use these credentials to access services such as My Service Canada Account.

In August 2025, Canada published a national digital identity standard, CAN/DGSI 103-0:2025, which provides a comprehensive code of practice for building trustworthy digital identity systems, aligned with international frameworks including Europe’s eIDAS and FATF. Canada and the EU also formalised a memorandum of understanding in December 2025 to collaborate on digital credentials and trust services, representing a meaningful step toward cross-border interoperability.

But the gap between a published standard and a functioning ecosystem is significant. DIACC‘s current recommendations to the federal government still include funding an interoperable, reusable digital credentials system for federal services, which means it does not yet exist at scale. Identity governance in Canada remains fragmented across provinces, federal departments, banks and hundreds of third-party solutions, making true pan-Canadian consistency a policy challenge as much as a technical one. And extending any of this into private-sector financial transactions, where it would matter most for fraud, remains largely undone.

There is also a trust dimension that cannot be ignored. Any digital ID framework requires Canadians to believe their data will be handled securely and used only as intended. That trust has not yet been fully earned. Building it will take consistent and transparent execution, not just announcements.

Why identity infrastructure changes everything

A strong, interoperable digital identity framework structurally changes the narrative. If payment senders and receivers are bound more directly to a verified identity credential, impersonation fraud, account takeover fraud and synthetic identity fraud become much harder to execute. The fraudster’s core advantage, the ability to convincingly be someone they are not, is significantly reduced. Canada is already starting to test parts of this model through efforts such as Interac‘s KONEK.

This represents a fundamental shift in how fraud prevention works: from transaction monitoring, which detects anomalies after the fact, to identity infrastructure, which confirms who is present before the transaction occurs. It does not replace existing fraud controls. It makes them dramatically sharper, because detection tools work better when baseline identity is verified and known.

New international standards for digital identity, such as mobile documents (mDocs), work by converting existing government-issued IDs into secure digital credentials stored on a device using strong encryption. These tools are not theoretical. They exist today and are being deployed in markets outside Canada.

Real-time rails, which are about to launch in Canada and already exist elsewhere, turn the speed of settlement into an increased fraud risk, because transactions become effectively irreversible faster. Identity verification at the point of initiation becomes more critical, not less, in a real-time environment. Having a real-time rail without a parallel investment in identity infrastructure means launching a faster, harder-to-reverse version of the same vulnerable system.

Four things the industry can do today

The payments industry should move with the urgency this problem demands. Here are four concrete actions that can accelerate progress today.

First, treat identity as a transaction-level signal, not a one-time onboarding check. Banks and payment processors should invest now in binding verified identity to payment initiation, not just to account creation. Tokenised, cryptographic identity credentials can be checked at the moment of a transaction, dramatically reducing the window of exposure.

Second, integrate with digital identity frameworks where they already exist. Turning again to what I know with a Canadian example: BC and Alberta have working, trusted digital identity systems. Fintechs and payment service providers operating in those provinces can begin integrating today to build the private-sector use case. That will demonstrate the value of expanded identity infrastructure and create momentum for national adoption. The same applies at an international level.

Third, build identity-first architectures from the ground up. Fintechs and payment service providers entering the market have a structural advantage over legacy institutions: they are not inheriting layers of technical debt and compliance systems designed for a credential-based world. Building identity verification into the core architecture, rather than bolting it on later, is both more secure and more economical over time.

Fourth, advocate for private-sector inclusion in national and international digital ID frameworks. The current trajectory of Canada’s digital identity work is primarily focused on government services. The payments industry needs to engage actively with DIACC, Payments Canada and federal policymakers to ensure that financial transactions are a first-class use case in the pan-Canadian trust framework, not an afterthought addressed in a future phase. Early tools such as Interac’s KONEK also show that parts of this model are already beginning to emerge in the market, even if they are not yet broad or widely connected. The same coordination is needed at a global scale as international transactions grow.

For too long, the payments industry has treated fraud as an inevitability to manage rather than a problem to solve at the root. We have become expert at chasing anomalies through a system whose front door was never properly secured.

Reliable digital identity is that front door. The technology exists. The standards are being written. Canada has the early building blocks in place. What is needed now is the will from financial institutions, fintechs, regulators and governments to move from pilots and frameworks to production-grade implementation across the payments ecosystem.

The fraudsters are not waiting. Neither should we.

The post Payments Fraud is an Identity Problem, Not a Transaction Problem appeared first on The Fintech Times.

Read More

Leave a Reply

Your email address will not be published. Required fields are marked *