Language

04 Aug 2026 in Business use cases

Financial Services vs. Other Sectors: Who’s More Prepared for AI in Identity Verification?

Henry Patishman

Executive VP, Identity Verification solutions

In brief: The financial services sector reports more AI-assisted identity activity than the pooled group of other surveyed sectors. It also records clearer visibility, stronger top-tier verification capability, and better audit evidence.

The pattern points to a sector that has had to formalize how it recognizes machine participation, tests identity evidence, and records the basis for a decision.

Who is more prepared for AI in identity verification? In Regula’s research, the financial services sector has the stronger case — but hardly because it sees less AI-assisted activity. 

In fact, it reports a higher AI Exposure Score than the pooled group of other surveyed sectors, and also claims victory leads in clear visibility, verification capability, and audit evidence.

How do we know this? Why are financial services ahead? What can other industries learn? Read further to find out.

This analysis uses Regula’s 2026 research among 850 fraud and financial-crime decision-makers in seven markets and six industries. Financial Services contributes 192 respondents. 

For every comparison below, those 192 responses are compared with a pooled group of 658 respondents from Banking, Crypto, Gaming and Gambling, Government, and Telecommunications.

Regula's AI Identity Readiness Scorecard

Each value is calculated from raw survey counts, using the same formula for both groups, with rounding applied only after the final calculation.

AI Exposure Score

What the value is based on

The AI Exposure Score gives equal weight to three survey findings: common AI-assisted use, automated or scripted behavior with uncertain attribution, and confirmed AI-assisted or automated attempts.

Financial Services scores 49. After its responses are removed from the source totals, the other surveyed sectors score 44.

AI exposure score: Financial Services - 49, Other Sectors - 44

Why financial services is higher

We think that several factors contribute to the higher score:

  • More identity events are available. New accounts are only one target of many. Recovery, lending, beneficiary changes, card replacement, and profile updates create others.

  • Identity signals can be reused. Stolen personal data, copied documents, prepared facial media, and scripted behavior may be tested in several products or channels.

  • Monitoring is often more developed. Better observation can raise the reported activity score, as machine-like behavior is more often classified as such.

Thus, the safe conclusion to make is that AI-assisted and automated behavior takes up more of the identity workload in financial services than in the other surveyed sectors.

What the response to higher AI exposure should be

What's needed is a classification policy that separates permitted assistance from suspicious or hostile behavior. One broad “AI detected” label gives reviewers too little information and can create unnecessary friction for legitimate customers.

A workable classification model can use five categories:

  • Customer-led activity: the customer completes the event without material software assistance.

  • Permitted assistance: an approved tool helps with accessibility, language, credentials, or another limited task.

  • Delegated activity: software performs a defined action under the customer’s authority.

  • Suspicious automation: behavior looks machine-operated, while the available proof is incomplete.

  • Confirmed abuse: investigation establishes hostile automation or fraudulent control.

The policy should ideally cover the full customer relationship. Enrolment, onboarding, recovery, re-verification, device changes, and account-control requests all need evidence tied to the value of the requested action. A low-risk profile edit and a request that transfers payment authority should not receive the same treatment.

Subscribe

Get posts like this in your inbox with the bi-weekly Regula Blog Digest!

Clear Visibility Score

What the value is based on

The Clear Visibility Score uses only respondents who report that AI-assisted use is common. It divides the clear-visibility group by all common-use respondents, giving a conditional score for organizations where AI participation is already routine.

Financial Services scores 63. The other surveyed sectors score 54 after Financial Services is removed from both parts of the calculation.

Clear visibility score: Financial Services - 63, Other Sectors - 54

Why financial services is higher

We reckon that financial institutions are noticeably better at clearly detecting AI activity for two main reasons.

First, external scrutiny gives a strong reason to retain much technical information. Fraud, compliance, audit, legal, and customer-support staff may all need to explain why an identity event was accepted, rejected, or referred.

Second, many financial institutions run several checks during one identity event. Document authenticity, biometric comparison, liveness, device/session data, sanctions screening, and manual review can create a richer case record when their outputs are connected.

Naturally, a score of 63 does not mean visibility is perfect, but it does show a clear peer advantage.

What other industries can learn from financial services

Clear visibility can be extremely useful as it gives a KYC specialist facts that can support a decision. An “AI suspected” label without supporting evidence creates extra review work and weakens later explanation.

A readable case record should state:

  • whether a live person was present;

  • whether the document and biometrics were captured live;

  • whether document authenticity and biometric checks were completed;

  • whether the source was trusted;

  • which finding caused referral, added verification, or rejection;

  • what the reviewer examined before closing the case.

Terminology also needs discipline. A translation tool, accessibility aid, remote-control session, and scripted fraud attempt should not be placed in one broad AI category. The case type should tell staff what happened, which policy applies, and what proof is still needed.

Verification Capability Score

What the value is based on

The Verification Capability Score pools the responses from five survey questions: on reliable human-presence controls, full biometric liveness checks, established synthetic-content detection, fully reconstructable decisions, and explicit treatment of AI-assisted interaction in identity verification strategy.

Financial Services scores 57; the other surveyed sectors score 48.

Verification capability score: Financial Services - 57, Other Sectors - 58

Why financial services is higher

Another nine-point gap, and another time financial services is above the peer group by a considerable margin. 

The reason for that is fairly simple: identity verification failures in finance can lead to account takeover, credit loss, payment fraud, regulatory exposure, customer complaints, and expensive remediation. Those consequences give identity verification a clear owner, and, likely, a higher budget.

We must also note that the overall score is based on the sum of five components, so it’s not the case of just one feature being more robust. The five components also depend on one another:

  • Human-presence proof establishes that a person is behind the interaction.

  • Biometric liveness check tests whether the person is real, as opposed to a realistic mask, injection, screen replay, or a deepfake.

  • Synthetic-content detection assesses whether the submitted media may have been generated or altered.

  • Decision reconstruction preserves the checks, reviewer actions, and reasoning behind the result.

  • Explicit AI strategy sets rules for permitted assistance, escalation, accountability, and evidence.

A weakness in one area can reduce the value of the rest. For example, if a live person is indeed present, but the face does not match the document portrait, human-presence proof alone cannot establish that person’s identity. Likewise, a strong face match may also be unreliable when the image came through an untrusted capture source, since replay or injection remains possible.

What other industries can learn from financial services

The main lesson is to treat verification capability as a connected control system rather than a checklist of verification methods. Human-presence checks, liveness checks, synthetic-content detection, decision reconstruction, and AI policy each answer a different question. A strong result in one area cannot compensate for a weak result somewhere else.

Control testing should therefore focus on combinations of evidence, especially when some inputs are genuine and others are hostile. Useful test cases may include:

  • a genuine document paired with generated or injected facial media;

  • a stolen document paired with a convincing live impostor;

  • a clean face comparison taken from an untrusted capture source;

  • permitted software assistance that resembles hostile automation;

  • conflicting results from document, biometric, and behavioral checks.

These tests reveal whether the organization can reach a consistent decision when the evidence does not agree.

Audit Evidence Score

What the value is based on

The Audit Evidence Score includes only organizations that had been required to explain an identity verification decision to a regulator, court, or external auditor. It divides audit-grade evidence responses by the combined group that supplied either audit-grade or limited evidence.

Financial Services scores 75; the other surveyed sectors score 66.

Audit evidence score: Financial Services - 75, Other Sectors - 66

Why financial services is higher

A third and final nine-point gap in favor of financial services — and it fits a sector that is accustomed to regulatory examination, formal retention duties, customer disputes, internal control testing, and legal review.

Naturally, evidence quality is related to technical capability, but the two are not identical. A firm can have capable detection tools and still retain only a brief result code. Another can use fewer checks while maintaining a clear record of source media, test results, policy rules, reviewer actions, and final reasoning.

The higher financial services score suggests that technical evidence is more often treated as part of the verification decision itself. Regular scrutiny may have encouraged firms to build retention and reconstruction into system design.

What other industries can learn from financial services

Audit evidence should be designed way before the first external request. What’s more, an evidence package needs enough detail to recreate the identity event without relying on the memory of the original reviewer.

That package should contain:

  • capture time, source, and channel;

  • document type detection and verification, extracted data, authenticity checks, and chip verification results where available;

  • biometric comparison and liveness detection results;

  • the policy rule behind acceptance, rejection, added verification, or manual review;

  • reviewer actions, comments, and final rationale;

  • the software version and configuration relevant to the decision.

Retention periods should follow legal, regulatory, and business requirements. Access should be restricted, and changes to the case record should be logged. Data exporting deserves equal attention because an external reviewer may need a readable evidence package rather than access to the production system.

The verdict: Financial services faces more AI activity and shows better preparation

What we discovered is that financial services report more AI activity than the survey-wide average. At the same time, our research cannot prove that heavier pressure actually caused the sector’s stronger preparation scores. It remains to be seen whether it’s a matter of correlation or causation.

The clear strengths of the financial services industry can be summed up as clearer visibility, stronger identity controls, and better decision evidence.

Still, financial institutions seem to have spent more time converting higher AI risk into real policy as well as updated verification rules and review procedures.

As for the wider market, this is what it can do to be better prepared for AI-assisted interactions, (legitimate or otherwise):

  • Define permitted machine assistance. Acceptable use cases (e.g., accessibility tools) and abuse (e.g., suspicious automation) require different policies and verification responses.

  • Match high-risk actions with stronger proof. Recovery, re-verification, and device changes may require liveness detection, document-chip checks, or manual review.

  • Build evidence into the decision. Capture source, document findings, biometric results, reviewer actions, and the policy basis should remain available after the case closes.

In summary, much of the success will depend on the ability to identify machine participation, determine what it means, apply the right checks, and retain enough evidence for future audits.

For example, Regula IDV Platform can support identity lifecycle management from onboarding and ongoing re-verification to identity refresh, KYC screening, authentication, profile management, and audit records. It combines configurable workflows, decision rules, user profiles, case management, and activity history with Regula’s document and biometric technologies, giving teams one system for managing identity verification decisions throughout the customer lifecycle.

More insights on the state of ID verification—a few clicks away

The full Regula survey report is publicly available, free, with no strings attached. 

To learn how Regula can help strengthen identity verification against AI-assisted threats, talk to our experts.

Book Your Discovery Call

Let’s talk about making your ID verification faster, smarter, and fully integrated.

On our website, we use cookies to collect technical information. In particular, we process the IP address of your location to personalize the content of the site

Cookie Policy rules