The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/AI & Data/Leading Detection
Leading Detection artwork

The future is continuous verification

Leading Detection · 2026-06-17 · 40 min

0:00--:--

Key moments - from our scoring

Substance score

42 / 100

Five dimensions, 20 points each

Insight Density9 / 20
Originality8 / 20
Guest Caliber11 / 20
Specificity & Evidence6 / 20
Conversational Craft8 / 20

Identity verification has fundamentally transformed in the AI era, shifting from static document checks to continuous, multi-layered verification systems. Shyam, a fraud prevention expert at MITAC specializing in confidential computing and identity verification, explains why organizations can no longer rely on point-in-time identity validation - what worked 10 years ago with government-issued credentials now fails against sophisticated deepfakes, synthetic documents, and manipulation techniques that expert human reviewers cannot detect. The core challenge isn't technology or talent; fraud prevention teams have both. Instead, the bottleneck is organizational and regulatory: product teams can build models in two weeks, but deploying them through financial institutions' governance committees takes months, during which attackers have already evolved their tactics. Shyam discusses how continuous verification, behavioral signals, biometric checks (video, selfies, handwriting), and confidential computing enable data sharing across regulated institutions - but only if organizations restructure themselves to move at the speed of modern fraud attacks.

Key takeaways

  • →Identity verification can no longer rely solely on government-issued credentials or documents, as deepfakes and manipulated credentials now fool even expert human reviewers.
  • →The biggest gap in fraud prevention is the speed difference between agile product teams building solutions and regulated financial institutions that need weeks to months for model governance approvals.
  • →Proactive fraud prevention - identifying suspicious patterns before fraud occurs - distinguishes successful teams from those that only react after events happen.
  • →Organizations have abundant talent and technology to address fraud, but lack the organizational structures and processes to productionize solutions at the pace threats evolve.
  • →Confidential computing and secure data sharing between institutions are critical emerging technologies that can improve fraud detection while respecting regulatory constraints.

In this episode

  1. 1The Evolution of Identity Definition in the AI Era
  2. 2From Point-in-Time to Continuous Verification
  3. 3The Digital Transformation and New Fraud Challenges
  4. 4Deepfakes and the End of "Seeing is Believing"
  5. 5The Gap Between Theory and Production Deployment
  6. 6Organizational and Regulatory Constraints on Speed
  7. 7Data, Insights, and Proactive Fraud Detection
  8. 8Multi-Factor Identity Verification Beyond Documents

Mentioned

mitacLeading Detectioncedulo

Guests

Shyam

Topics in this episode

Identity VerificationBiometric verificationDeepfakes and synthetic mediaVideo verification frameworksEU eIDAS regulatory frameworkConfidential computingMachine learning model governanceDigital fraud detection signalsCard-not-present transactionsInjection attacks

Questions this episode answers

Why can't financial institutions deploy fraud detection models as fast as they're built?

Product teams can develop models in two-week sprints, but financial institutions require model governance committee approval and regulatory compliance review, which typically takes months - by which time fraudsters have already moved to new attack vectors. This creates a chicken-and-egg problem where institutions need performance metrics before approval, but those only exist after the model is complete.

What makes deepfakes and synthetic identity documents effective against current verification systems?

Modern deepfakes and digitally manipulated documents are so sophisticated that expert human reviewers - even those with years of experience - cannot reliably distinguish them from authentic materials. The quality of deception has evolved to the point where seeing is no longer believing, making visual-only verification insufficient.

What is continuous verification and why is it replacing point-in-time identity checks?

Point-in-time verification (checking identity once at onboarding) no longer works because credentials can be forged and user behavior changes. Continuous verification combines ongoing behavioral signals (IP address, transaction patterns), biometric checks (video, selfies, handwriting), and composite data analysis to maintain assurance throughout the customer journey rather than relying on a single identity check.

How does confidential computing address data-sharing challenges in fraud prevention?

Confidential computing enables financial institutions to share data across organizations for better fraud detection while maintaining regulatory compliance and data privacy protections, since technology operates in encrypted environments that comply with GDPR, eIDAS, and other frameworks.

What's the difference between reactive and proactive fraud detection?

Reactive detection analyzes events after they've happened and explains what went wrong; proactive detection uses data signals to predict and prevent fraud before it occurs by identifying suspicious patterns early and triggering controls.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

9 / 20

The episode surfaces a few genuinely useful ideas - continuous verification vs. point-in-time, the regulatory chicken-and-egg problem slowing model deployment, and confidential computing as a data-sharing unlock - but these are surrounded by substantial throat-clearing, repetition, and high-level abstraction that dilutes the useful density per minute.

the problem is my team may be able to spin up that model in two weeks in a sprint. Right. But there is no financial institution that we work with can actually put it into production in a sprint
it is continuous verification as you're interacting with the platform. Which means I am looking at your behavioral sign, ongoing basis, as in how fast do you type?

Originality

8 / 20

The regulatory-lag chicken-and-egg framing and the frank admission that even internal legal/compliance teams constrain product builds are mildly contrarian, but the bulk of the episode recycles well-worn industry talking points about deepfakes, the shift to digital, and 'seeing is believing' that circulate widely in fraud/fintech media.

the bad actors don't have any of those constraints. Right. I mean, they don't have organizational structures to report into. They don't have regulatory mechanisms they have to abide by
to get the approval that they need on their side, they need performance metrics from us, which would only be available once we have actually completed the build

Guest Caliber

11 / 20

Shyam is a genuine dual-track practitioner - operational fraud background followed by a product leadership role at an identity-signal vendor - which gives him credible perspective on both sides of the deployment gap, but he is not a recognisable name at scale and the company ('Mitac/Mitech') is never clearly identified or contextualised.

my first role in fraud was actually operational. Right. Um, right now I'm on the product side
I have experts today at MITAC who would look at, and they would not be able to tell whether that's

Specificity & Evidence

6 / 20

The transcript is almost entirely devoid of named institutions, concrete metrics, dollar figures, or measurable outcomes; references are vague ('biggest banks in the US', 'around 16, 17, 18') and no attack-rate data, product performance numbers, or case study details are provided.

specifically I would say around 16, 17, 18, 20, 16, 17, 18, a lot of the traffic started moving digitally
in the EU they have this new, uh, eids, um, you know, regulatory framework that is gone into place

Conversational Craft

8 / 20

The host asks a handful of purposeful bridging questions ('Is it just a data problem?', 'Which is most important, which is lacking?') that do open useful threads, but there is no meaningful pushback, no challenge to vague claims, and several guest tangents are allowed to run without follow-up redirection.

Chicken and egg. Exactly.
So if we're talking about technology, we're talking about people, we're talking about organization, which is most important, which is lacking

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B88%
  • Speaker A12%

Most-used words

fraud30identity25teams24space23data17technology15terms14today13product13team13seeing12regulatory12important11customers11financial11build11

Episode notes

In this episode, Shyam Menon discusses the evolving landscape of identity in the AI era, the challenges of fraud prevention, and how technology and organisational strategies are adapting to new threats. A must-listen for anyone interested in digital trust and security. Key Topics The changing definition of identity in the AI era Challenges of fraud prevention with deepfakes and manipulated videos The importance of continuous verification and behavioural signals Organisational and regulatory hurdles in deploying fraud detection models The role of technology and talent in combating fraud Chapters 00:00 The Evolution of Identity in the AI Era 09:13 Challenges in Fraud Prevention and Identity Verification 18:30 The Role of Technology in Identity Verification 27:34 Proactive vs Reactive Approaches in Fraud Prevention 36:40 Future Trends in Fraud Prevention and Identity Management #Cybersecurity #AI #FraudPrevention #DigitalTrust #Deepfakes

Full transcript

40 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: This is Leading Detection, a cedulo podcast where fraud fighters talk tech. Welcome back to the Leading Detection podcast. And today we're joined by Cheyenne and um, yes, super important topic. We keep bringing it up. It's relevant that we keep talking about this. We're going to be talking about identity and how it's changing in the AI era. Shyam is an expert, shall we say, within fraud prevention, identity verification and confidential AI. So it's going to be a great chat today. Shayam, thank you very much for joining us.

Speaker B: Thank you, Brad, thank you for having me. Lovely, um, to talk to you again.

Speaker A: Yeah, uh, this time we'll be recording and we had great fun having the prep call, so I'm looking forward to this one. So why do we keep talking about identity at the moment when we're talking about fraud prevention? Why is it important to continue to do so?

Speaker B: Yeah, so one of the things that I think has significantly changed over, I would say the last five years, I would say, uh, is basically the definition of what identity actually is. And so that evaluation, that definition has changed over the last five years. And so it has become more and more important to define that in a way that actually makes sense in today's era where you know, in many cases what you see is not actually real. And, and, and, and uh, it, it becomes more and more important, uh, for even individuals and obviously organizations, especially in regulated industries, to understand the people they're engaging with or the identities they're engaging with. Right. And, and identities have transformed itself from, you know, kind of being a person to being agents and you know, uh, uh, machines that are interacting with you. So, so it does become more and more kind of narrow in terms of definition and granular in terms of definition of what an identity is. Previously you could, you know, def. Rely on what you would call, you know, government issued, uh, credentials as being a pretty good measure of who a particular person is. But that's not necessarily the case anymore. Right. And then you have to have a bunch of other factors and dimensions that you have to look at to actually identify whether um, something or someone that you're interacting with is actually who or what they say they are. And so that's the reason why that conversation has become so prevalent. And obviously, as you know, you're in this space, uh, this has become more and more of an issue across multiple industries and it's becoming more and more, um, you know, important to have that conversation on an ongoing basis, which is why podcasts like yours, and you know, there are others that are so Important where you get people from different aspects of that identity journey to talk about what they see and how that definition is being um, evolved and defined. And so um, that's primarily the reason. I mean the pace of change around this has been so fast that if you're not talking about it, you're going to be left behind in terms of how you show up in the space specifically around fraud.

Speaker A: Yeah, you've been in the fraud and identity space for a little bit of time now. Would you have anticipated m, 10 years ago that you'd be questioning identity and what that means?

Speaker B: Absolutely not. I remember my first role in fraud was actually operational. Right. Um, right now I'm on the product side but, but my initial entry into fraud was on the operational side which basically meant I was responsible for our customers not being defrauded. Right. On a day to day basis. So, so our teams were responsible for monitoring uh, uh, and um, you know, obviously I, I'm, I'm worked in the financial services space mostly. And so it was about, hey, let's uh, make sure there are no losses in terms of money and, and, and, and uh, that was the primary uh, you know, responsibility our teams had. And at the, at the time, this is going back 10, 11 years now would be the thing you hang your hat on was identity, right? Once a person had given you the credentials around their identity, you are perfectly comfortable saying hey, we're fine with this person, right? And we don't have to worry about this person because we have already verified their identity and it was a point of time verification, right? And you're, you're like, so if Matt Brady is coming to our uh, platform or something, as soon as you come on, we know, okay, it's Matt Brady, this is his passport, ID, whatever. We're good to go, right? And then every time Matt Brady comes on, we don't have to worry about Matt Brady because we already checked. That's not at all the case today. Right. Because first of all, the credentials that you present themselves may not be real, even though they appear real. And by the measure of what we used to look at 10 years ago, almost every fake identity we see would pass today. Because the quality of deception, if you want to use that word, has evolved to an extent where even expert humans in our teams, previously we used to have expert agents who would look at identity documents. They would be able to make an assessment whether this was an authentic document or not. I have experts today at MITAC who would look at, and they would not be able to tell whether that's and so identity in itself is not sufficient anymore. It's necessary, but it's not sufficient to actually prevent a fraudster from doing damage to whatever journey that you are trying to secure. Right. And so yeah, I would have never imagined what the uh, and specifically the speed is. What's uh, know, I mean if, if you are a really forward thinking person, I'm sure you could have predicted right. In the future you would have. But this pace with which it has happened is what's caught most teams, both operational teams and product teams by surprise. And so, and most of the teams that are doing well in this space are teams that are the most agile and have aligned their structure both uh, from a, um, a product build perspective and also from an organizational perspective to actually align with that pace and be able to support what customers need in kind of this evolving fraud space.

Speaker A: Yeah, so, and before we kind of touch on AI, was it coming beforehand, this kind of push to a digital world? Was it always going to be on the horizon that identity would be questioned? Did you see it come in?

Speaker B: Yeah, so that's actually true because as we move. So initially when I started a majority of traffic that my teams used to see were like point of sale m kind of transactions. Right. If you're just looking at transaction security, which was basically somebody going into a, you know, outlet of some kind of retail outlet or something and presenting a card in the point of sale and you're just making a judgment about whether that transaction is valid or not in the background. Right. And then over time, and specifically I would say around 16, 17, 18, 20, 16, 17, 18, a lot of the traffic started moving digitally so it became more of a card not present. It's a digital transaction so the value you placed on certain other signals became more important. Right. So for example, uh, where is that transaction initiated from? What is the IP address? You know, what is the risk associated with the IP service provider? You know, so there were other signals that you could look at in addition to the identity itself that you were looking at to begin with. And so it was basically adding another dimension to verifying whether a particular event was genuine, uh, and authentic. Um, but what has happened is not just the, you know, migration of much of this activity to a digital sphere. It's more after that has happened, which already puts a certain layer of uh, you know, what, what you would call opaqueness to, to what is happening. The idea that identity itself could be manipulated. Right. Became even more of a, you know, uh, additional layer of what do you call, confusion that you had to like, maneuver through. So did we see this moving? Yes, obviously that, you know, even in, you know, mid 2010s, traffic was moving digital. And you knew there was. But like I said earlier, just the pace with which things have changed. Uh, right. It's not just a, I think most teams, most fraud prevention teams had this belief when, uh, things were moving digital that the structures they had in place were sufficient to support that transition. But what we are realizing in the last four or five years is that it's not right. Like, you have to have a completely different thinking around how you verify something, how you validate something, how you authenticate something. And so, uh, um, the transition itself is not surprising. But like I said, the different aspects that have changed, plus the pace is what has caught people by surprise.

Speaker A: Yeah, I mean, through evolution, through our lives, seeing is believing, right? That's what we've, that's what we've been told. That's what we, we see every day. But is that gone, is seeing believing? Um, no longer.

Speaker B: I mean, if, if you look at, I mean any, I mean, it's not even a fraud issue. Like, for example, in politics, right? You'll see videos, like, you know, you'll see videos of, you know, political candidates have, you know, creating videos with their opponent that is not real, right? I, I, I, I, Somebody uh, sent me a video of a election in India where, you know, a candidate had created this video of their opponent which was totally fake, but it took off like wildfire on social media. And, and, and, and, and if you saw the video, you would believe the video because like you said, you are conditioned as children to believe what you see, right? Like, that's where you, you know, like all of us. So that's what I mean by what I said earlier about you literally have to rethink the way that you validate, authenticate, uh, something now, right? And so some of the qualities of deep fakes we see, whether it be documents, digitally manipulated documents, or just deep fake videos, selfies, and you know, sometimes you'll ask for video clips for authorization, et cetera, they are so good that there is absolutely no way for anybody to really just rely on the seeing is believing. Now there is an aspect of that, of course, that's never going to go away because you have to look at something. But if you just rely on that, which is kind of what you're trained to do, you are setting yourself up for a lot of damage, especially in the financial, uh, space, because that is not enough. Um, you have to have other layers of authentication and validation that has, have to be built in, in the journey that allows you to not just rely on seeing is believing, but there is this composite picture that you can, you need to create which you know, kind of raises the assurance level you have in terms of whatever journey you're trying to support.

Speaker A: Yeah, this is where machines come in. This is where we, we start leveraging technology because the best fraud investigator in the world, if they had only their eyes and then they would fail.

Speaker B: And we see that operationally, I mean like, and this is not a, uh, you know, what I'm talking about is not necessarily hypothetical. We see it on a day to day basis where agents and really, really good agents with years and years of experience looking at something and making a judgment about yes, this is authentic, but we know it's not authentic. Uh, you know, we may have created it or whatever. Right. And so absolutely, uh, I don't think somebody relying on. So one of the things that we do, at least in my role today at mitac, is we try to provide our customer base with that additional signal set that would allow their operational teams to supplement the seeing is believing caveat. Right? Say okay, I see this, but now let me look at all these other signals that are part of, you know, this particular event and uh, let's see what they are telling us and whether that matches what I'm seeing. Right. And it's that comparison that you know, raises a level of assurance for that particular, um, event or that particular journey. So that's where the space is evolving to. And good organizations who work in the, you know, fraud prevention space are those who are able to provide their customers the richness of that additional signal set that they need, uh, to go with what they're saying to make a decision. Those are the ones that are going to succeed. And that's what we are trying to do at mitac. Right? We are trying to make sure that our signals are actually that additional layer of assurance that a particular operational team would need at a financial services institution. So, so, so that's, that, that's basically where we are at.

Speaker A: So, so as an industry as well, we're kind of handing over to, when we say machines, we say machine learning and having that support and supplement those experts have been in the domain for, for many years and seen more than most. But where's the gap? You specialize in products, where's that gap between what can be done in theory in demos versus what is actually being put out there, uh, in the real world in production? And um, what is Working. Yeah.

Speaker B: So the easiest answer to that is speed. So, uh, let me clarify that a little bit. Theoretically, there are a lot of things you can do, right? Uh, the problem is all of us, for better or worse, operate under a strict kind of structure, whether that's organizational or regulatory. Right? Organizational from an internal perspective, if you're a product team, regulatory as a, uh, industry. Right. So for example, if my team decides, hey, we are seeing this attack pattern, whatever that may be, and we know how to address that attack pattern by building this X model, right. And, and deploying it into production, the problem is my team may be able to spin up that model in two weeks in a sprint. Right. But there is no financial institution that we work with can actually put it into production in a, uh, sprint because that, it needs to go through the internal regulatory requirements of the model governance committee, the model who will. And, and that process in most large institutions, whether that be here in the US or in the UK or eu, that is at least even in the fastest cases or at least. Right. So by the time you have deployed that model, that attack vector no longer exists because the uh, fraudsters moved on to some other way of around the system. Right. And that's the biggest challenge from both a product perspective and operational perspective between what is possible in theory and what you can put into production. And one of the things that I was mentioning earlier about rethinking, uh, kind of how we approach this relates to this gap. And this is a significant gap by the way, because I've had conversations with, um, the biggest banks here in the US people who lead fraud organizations there. And one of the things that they ask us to do is give them advance notice of what we may be building so that they can start the process on their end of actually getting the approvals necessary so that when we are ready some way they will be ready. By the way, that's not possible partly because that synchronicity is not actually 100% possible because to get the approval that they need on their side, they, they need performance metrics from us, which would only be available once we have actually completed the build, if you know what I mean. Right. And so.

Speaker A: Chicken and egg. Exactly.

Speaker B: It's almost like a chicken and egg scenario. Right. And so, uh, that is a huge gap. And part of the problem for that is you can have a product team that's incredibly agile, incredibly smart, incredibly proactive and forward thinking, but what they can theoretically accomplish doesn't get translated into production at the same pace. And um, remember, the bad actors don't have any of those constraints. Right. I mean, they don't have organizational structures to report into. They don't have regulatory mechanisms they have to abide by. So they operate kind of in a freewheeling way, whereas we are still stuck in the old organizational structure, the regulatory structure, the process, etc. Etc. And basically, uh, kind of go from there. So.

Speaker A: Yeah, so if we're talking about technology, we're talking about people, we're talking about organization, which is most important, which is lacking, um, because technology appears to be strong. Right?

Speaker B: Yeah.

Speaker A: Do we have the talent for the, to the problem or is it just organizational?

Speaker B: Oh, no shortage of talent. I mean, the, plenty of very, very smart people working on these problems. Right. I know, like, and, you know, I've worked in multiple institutions now in my career. Yeah, everywhere. You have really, really smart people. For me personally, that's one of the joys of the work I do because I get to interact with so many people who are so bright and thinking about these things and much, uh, smarter than I am. And so it's intellectually really stimulating. But that capability, what I'm saying is we are not harnessing it in the way that we should be harnessing it in terms of, uh, what do you call what we should be doing to kind of address the pace and speed with which things are happening, like I mentioned earlier, right. And so there is no shortage of talent, man. I mean, there's talent everywhere, but it's about, are we in a position to actually harness that talent? Um, and, and, and you, uh, know, apply what that talent produces in a effective, timely way, uh, operationally productionize it in a timely way so that what is being produced by that talent is actually putting a whole, you know, wall against some of these, you know, challenges, uh, we see in the fraud space. So, yeah, I, I, I don't, I don't have any concerns around talent. We have had, like, just from a, even from a recruiting perspective, right. I mean, we, we have a number of people. Like, we have never had an issue able to find people. That's never been an issue. The issue has always been about, okay, we have all these people, they come up with all these great ideas. Now it's up to you as leadership to go figure out how to leverage what they have produced so that you bring maximum value to your customer base.

Speaker A: So we've got the people. Would you say the technology is there? Is it still evolving?

Speaker B: Yes, it is evolving. Uh, confidential computing is one of the aspects that one of the challenges, if you want to talk about purely kind of a, from a technology perspective has been specifically in regulated industries like financial services, data sharing.

Speaker A: Right.

Speaker B: Uh, so because your technology is only as good as the data you have. So the. And by the way, much of what you see today in the space is, uh, you know, uh, not limited to a single financial institution or a type of industry. It's actually across the board. Right. And so if you're able to share some of the data between institutions, between organizations, that, that is incredibly beneficial in terms of just fraud prevention. But the challenge is, because we operate in a kind of a regulated space and, you know, some of that data is protected under, you know, whatever regulatory, uh, framework you want to talk about, depending on what geography you're in, that has always been a challenge. Uh, which is why some of this evolving technology and confidential computing, et cetera, makes it a little bit more easier to convince people that, hey, we can use your data to give you additional, you know, signals that, you know, as I was talking about earlier, and why that is actually valuable to you. So the technology is evolving, is there, Is the technology being leveraged better on the bad actor side? Probably, but I think that's got more to do with what I was mentioning earlier about, you know, they don't have to go through regulatory frameworks and things like that, so they could pick up anything and do whatever they want to with that. On our side, you know, there are limitations. And you know, even internally when we build something, our legal and compliance folks have a say about whether that's actually something we should be doing, shouldn't be doing. Um, and so, so, so, yeah, I mean, technology is there, but, but, you know, both organizationally and, um, and regulatory, uh, framework wise, we do have some challenges in kind of leveraging that.

Speaker A: So is fraud identity, is it just a data problem? Effectively? Is it more complex than that?

Speaker B: Well, it's a little bit more complex than that because it's not just data. Right. Raw data doesn't tell you anything. It's just data. It's just sitting there. It's your ability to draw insights from that data that defines how successful you are in this space. Right. Uh, and the additional layer to that is how proactively you can draw those insights. Right. Anybody can look at something after it has happened and say what happened and what we should have done. The challenge is the ability to draw proactive insights from data and tell your customers, hey, wait a minute, this thing is not looking good. Something is going to happen here in a minute. So you might want to take a second look at it. That's the difference between product teams that succeed in this space and those who don't. Right. I have never met a fraud team that can't look at an event and tell you why something happened and what should I be done? Right. Every fraud team on the planet can do that. The good teams, whether they are operational or product, are teams that can look at a set of data signals and say, proactively, we don't like the direction this is going, so maybe we want to build XYZ controls now so that the event that we think is going to happen won't happen. Right. And so it's that reactive versus proactive, that difference that defines a good product, a good product team and a good operational team. Right. And so I don't think it's just a data issue. It's more about extracting insights from the data in a manner that's proactive and valuable before a adverse event happens.

Speaker A: Because I mean, hindsight's 2020 vision, right? Or always has been, always, always will be. But as we kind of dive deeper into identity, because say if I went to uh, an E Commerce site and said, prove it's you, I'll put uh, my passport in, it said, that's not enough. Um, what else have you got? Like how deep can we go with technology to identify someone is who they are?

Speaker B: So documents alone is absolutely not where you need to be. Right. That's 10 years ago. That's 12 years ago. Right. So now we have different. And you know, in the EU they have this new, uh, eids, um, you know, regulatory framework that is gone into place and you know, you have to be compliant by that. And one of the components of that is, uh, video verification is one of the ways. So generally the regulatory framework is behind always to what's actually happening. Right. Because the politicians and regulators generally are uh, reactive. Always.

Speaker A: Mhm.

Speaker B: Like, oh, something happened. So now I need to put a regulation in to make sure that doesn't happen again. So, you know, so this video framework, et cetera, is somewhat reactive because if you look at it in the way that we see at mitac, we see issues around injection attacks and things like that that easily kind of bypass all these video verifications. But from a regulatory framework, what we can do is kind of that which is basically, uh, you combine identity with a biometric verification, whatever you want to. It could be video, it could be a selfie, whatever. Yeah. You also have handwriting verification stuff, et cetera. Um, um. And so, um, you know, those kinds of things. But the speed That I was mentioning earlier, in terms of the changes that are happening, even those additional layers that you're introducing are already falling behind in terms of what we are seeing, which is like injection attacks and deepfakes that actually bypass even your biometric checks. So the best way that I know today is continuous verification. What that means is if Matt Brady is coming on to my platform, it's not just Matt Brady's identity documents, it's not just Matt Brady's biometrics, whatever they may be. It is continuous verification as you're interacting with the platform. Which means I am looking at your behavioral sign, ongoing basis, as in how fast do you type? Is this different from how he, how we know Matt Brady types? How, how does his mouse movements, you know, um, appear, the tracker, uh, all of these things. So, so it's almost an ongoing process. Previously, identity and fraud was about point of time verification and then say, okay, we're good, now we know he's on the platform, fine. No, that, that, that's no longer sufficient. What you need is throughout the journey, you are continuously verifying, authenticating that person. Uh, so that any anomaly, right, that appears in behavior from where you normally log in. It's simple things. I mean, I know these things have existed for a while, but, uh, they are much more valuable today in putting together that holistic picture of the person on the screen. Right. And so, um, I would say that is basically kind of the approach that most teams that I know are taking, both from a product design perspective and I think one of the primary or, uh, at least for my team at mitech, in terms of product design, we look at the primary kind of goal we have is how can we consolidate everything we can legally gather into one single holistic picture on an ongoing basis. Not a point of time, but on an ongoing basis. Right. And so, uh, that's the approach. But like I said, even from a regulatory perspective, we are kind of behind the curve in terms of what we are seeing in the market. So, you know, would this be, would this approach be sufficient two years from now? I don't know, probably not. But as of today, that's the best approach we have and that's what we are guided by generally.

Speaker A: Okay, so to finish up, I'm going to put you on the spot, um, a little bit. So how do we push back against the riding costs of fighting fraud? Because we need more data, uh, we need better technology, we need ongoing protection, not just point of time. So how do we balance that with cost?

Speaker B: So this is a question. Product teams have to answer all the time. Because when you go to leadership, executive leadership, and say I want to build this, first question they would ask is, okay, how much is it going to cost you to build this? Right. And say, and why is this a good business case? The very simple answer to that is the cost of not doing anything is just significantly higher. Because the entire, if you think about it, we literally do most of the things we do on a day to day basis in almost all space of our ah, life digitally. Right? I mean, I mean I can't remember the last time I went into a bank. Can you think of the last time you went into a bank?

Speaker A: No.

Speaker B: I mean like even things like healthcare sent to you through your app, your test results come through your app. So you are operating in this opaque kind of digital world where knowing who is on the other end is becoming critical across the board. So everything that you do on a day to day basis is based on that implicit trust you have of, you know, who's behind on the other side of that interaction, whatever that interaction may be. And I'm not even speaking, like I said specifically of financial services, right? Because financial services, you can put, you know, dollars and cents and say, okay, this is, but you know, if it's your doctor you're interacting with, there is an implicit level of trust that, that you have or a therapist, uh, behavioral health has moved online big time. Right. You may be divulging things to the person on the other end that you've never seen that are incredibly private. So the underlying currency there is that trust. So if you don't build mechanisms that can validate that trust or assure or solidify that trust, the entire infrastructure breaks down. So the cost of not doing anything is significantly higher. Beyond even dollars and cents. There is a dollars and cents cost to it, which is significant. But what I'm saying is even beyond that you have an issue with uh, so generally people will build things when you can attach dollars and cents to it, which is why fraud prevention and the trust layer is so important in financial services because that's really quantify. But what is being built underneath in terms of identity and validating identity has applications well beyond just what a bank may need for you to make a transfer. Right. And so one of the ways that I try to convey value things that we build is obviously leadership teams want to know the numbers. So we'll do our research around that and optimize where we can and make sure that we are uh, building something that is uh, uh, profitable, et cetera. But beyond that is to show the actual application of what we are building to be beyond just that use case. Right. Because if you think about it, none of what identity teams do or fraud teams do is specifically just about that use case. The technology underlying is the foundation of just the infrastructure of trust that we are operating under. All of us. It doesn't matter what geography you are in on the planet you are moving towards. Either you are already operating almost exclusively digitally or you're going that direction. So in all aspects of your life and so you know, schooling, you know, all, all these things. Right? Like, I mean if you think about it, all the key elements of what you consider important in your human experience, whether that's your money, whether that's your employment, whether it's, that's your health, whether that's your education, almost all of that is sitting behind this trust in the person on the other end that you think you know and you, you believe is the person you think they are. So whatever, uh, things we build in this space has applications beyond those dollars and sense. So the way that we convey, you know, at least on our side is you know, looking uh, at that in a little bit more of a bigger picture way. But obviously you know we are a for profit business so you know uh, the, the actual calculations around value are important and generally we won't build something which you know, doesn't actually show actual financial value for us as a business. But, but, but the, the underlying technology and the applications of it go well beyond just fraud prevention in the financial services. Yeah, um, so that's the way I look at it.

Speaker A: We could, we could dive into this for, for quite some time. But that's, that's all we've got time for today. Sharon, what, what's coming up? What's, what's next?

Speaker B: Uh, yeah, so on, on, on, on, on our side, uh, we, we are, our teams are basically building out this, a next generation kind of uh, platform on our side which, which basically consolidates some of the things that I mentioned here, which is kind of continuous verification, um, breaking down kind of data silos, proactively extracting insights. So, so that's a direction that, that we are focused on. At my tech and I believe probably most forward looking uh, organization in this space would be focused on. But you know, I hear uh, from customers all the time, every day almost, um, I meet other practitioners, um, and there is a number of other things that are happening that will potentially be helpful as we kind of tackle this new AI era fraud. Confidential computing is one of those you know, kind of foundational things that, that kind of move the goalpost for us a little bit in terms of, uh, of where we want to go. But exciting times to be in the space, really. You know, there is not a single boring day. Uh, you know, you, you come into work thinking you've seen everything and then something new comes up. You're like, oh my goodness, how, how does this come about? Right. And so, so it keeps, you know, people in the space interested. Me certainly, I enjoy it very much. And so, yeah, so looking forward to what the next couple of years are going to be like. Um, uh, it's exciting and nerve wracking at the same time because obviously we are responsible for, uh, making sure our customers are protected in the way that they need to be. So staying ahead of the curve is what I think about all the time. And sometimes, uh, you succeed, sometimes you don't. But, but it's been, um, yeah, it's an exciting time for us overall with, with all the changes that are happening. So, you know, interacting with people like you, you know, I obviously follow you quite a bit. And so I know you were at Money 2020. And so, yeah, you know, those kinds of events and kind of what you gather from other practitioners in the area of your mind about things you may not have thought of, you know, so all of that is exciting. And you know, our teams are focused on kind of bringing all of that knowledge in house and see what we can do with it to help our customers.

Speaker A: Amazing. Well, it's been an absolute pleasure diving into it. It's a unique space to work in. Right. You've got a, you got to have a protective security guard Persona, the kind of detective, crime fighter, uh, and then you need to be the curious technology geek as well. So it's all those three pillars kind of coming in together.

Speaker B: Advisor, counselor.

Speaker A: Yeah, Psychologists, behavioralists. Yeah, exactly.

Speaker B: And sometimes you have to convince customers about, hey, it's okay for you to have a little bit of fraud because that helps you. And you know, those kinds of, you know, there is quite a bit of educational component to it. Right. Because we see more than generally our customers because customers are siloed in what they see in their, in their space. Right. And in their traffic. But we see across, you know, multiple customers. And so, you know, we are able to bring a perspective that they may not have internally. So, so, and what I've noticed in the last couple of years is the, uh, ask for that kind of insight has actually increased. Right. And they want you to come and tell them hey, what are you seeing overall? Right. What is it that we are not seeing, but you are, so that we can start thinking about, hey, what should we be doing to. And that goes back to what we were talking about, about data sharing and, you know, things like that. It's a great time to be in this space. The fraud teams were not very visible. Right. Generally, the fraud and risk teams today in most institutions have a voice that's loud enough that you know what their opinion and their insight, you know, form kind of one pillar of all the decision frameworks that are built within that organization. Yeah.

Speaker A: And fraud is all the time. It's not going anywhere. So, uh, we'll always, We'll a job. Yeah.

Speaker B: So that's what I always mention to my team. Right. Like, it keeps us employed. It's always a good thing. And so obviously not saying that, you know, we need to see an increase in fraud activity, but, you know, I don't think there is, uh, uh, going to be any kind of letdown in terms of the dynamics we are seeing in this space.

Speaker A: Shyam, um, it's been an absolute pleasure. Thank you for joining us. Where can people keep up with you and the work that you're doing? Yeah.

Speaker B: So you, you can follow me on LinkedIn. I also have a, uh, website, shawmanon.com, i write very regularly. Some of the things that I've talked about here are on there. And obviously, you know, you can follow my tech on, uh, LinkedIn as well. A lot of exciting things happening from our team. So, uh, you know, a lot of talent people on, on our team that are doing some amazing work. And so all these, all those three channels would be good spaces to keep an eye on what is happening with my tech and, uh, me personally as well.

Speaker A: Amazing. Well, uh, absolute pleasure. I'm sure. We'll do this again, uh, in the future and we'll speak soon to the listeners. Until next time. Ciao for now.

Speaker B: Thank you, Matt.

Speaker A: Want to hear more about fighting fraud with tech? Subscribe to Leading Detection wherever you get your podcasts.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Five Seconds to Fraud: Detecting AI Deepfakes Before They Strike with Ben ColmanCyber Sentries: AI Insight to Cloud Security · on Identity Verification87 / 100
  • Is encryption enough to protect our data?Technology Now · on Confidential computing81 / 100
  • PayPal Ads’ Big Retail Media Bet: Why Shoppable Ads Could Finally Work (And The Future of Commerce in an AI World)Retail Media Breakfast Club · on Identity Verification80 / 100
  • Why Conventional Cybersecurity Won’t Protect AI? | Interview with Hugo HuangSecure & Simple · on Confidential computing72 / 100
  • Fintech Power 50 webinar: Regtech at scale - control, cost and accountabilityThe Fintech & Payments Power 50 · on Identity Verification68 / 100
  • The Future and AI with Joe Carbonara of Zoomba Group and Dan Hartlein of Antunes: Part 2Foodservice for Thought · on Deepfakes and synthetic media66 / 100

More from Leading Detection

All episodes →
  • The human side of fraud
  • Fighting fraud in the Agentic Era
  • Is Identity Verification now redundant?
  • Uncovering CX Fraud
  • Fraud Prevention has to be AI-driven
Explore the best B2B AI & Data podcasts →
All Leading Detection episodes →