Digital banking must answer three related questions: Who is this person, can they prove they control the account today, and what are they allowed to do? Digital identity connects those questions without treating them as the same control.
Identity proofing establishes the person
During enrollment, a bank gathers and verifies evidence that a person is who they claim to be. Depending on the product and risk, that may involve identity documents, trusted records, contact information, device signals or a live check.
Proofing is risk-based. More sensitive products or higher-risk circumstances may require stronger evidence, while privacy and data-minimization principles limit information that is not reasonably needed.
Authentication checks a returning user
After enrollment, authentication tests whether the person attempting access controls an approved credential. Passwords, passkeys, security tokens, biometrics and one-time codes are examples, each with different strengths and failure modes.
Multi-factor authentication combines different types of evidence. It can make account takeover harder, but recovery procedures also need strong controls because attackers may target password resets or replacement devices.
Authorization controls what happens next
Successful authentication does not automatically permit every action. Authorization determines whether that user may view information, add a payee, transfer money, change a profile or perform an administrative task.
Banks may require step-up authentication for higher-risk actions, apply transaction limits or use separate approval roles for business accounts.
Federation can carry identity across systems
In a federated arrangement, one trusted system makes an identity or authentication assertion that another system accepts under agreed rules. This can reduce repeated enrollment and support connections among banks, applications and service providers.
Federation shifts rather than removes risk. Participants need clear standards for trust, consent, data sharing, security, revocation and responsibility when something goes wrong.
Digital identity is a continuing control
Identity risk changes after onboarding. Devices change, credentials are compromised, customer behavior evolves and synthetic or manipulated evidence can become more convincing.
Banks therefore combine enrollment controls with monitoring, customer alerts, secure recovery, fraud investigation and periodic review. The goal is appropriate confidence—not a claim that identity can be proven with perfect certainty.
Read the primary material
Banking Explained prioritizes regulators, official publications and first-party announcements.
