Go back

Defending Bank Onboarding Against Evolving Risk with Mary Ann Miller of Prove

28m 22s

Defending Bank Onboarding Against Evolving Risk with Mary Ann Miller of Prove

The discussion focuses on optimizing digital onboarding, particularly for co-branded card enrollment, which acts as a stress test balancing instant customer access with fraud prevention. A key challenge is the rise of sophisticated, AI-driven fraud, such as polymorphic agentic attacks, which adapt in real-time. This necessitates moving beyond basic data validation to "entity resolution"—ensuring the applicant is the legitimate owner of the presented information. The modern decision architecture for onboarding should start with perimeter security (firewalls) and endpoint bot protection, then incorporate dynamic, in-flow controls like biometrics, device trust, and phone number analysis to distinguish legitimate customers from fraudsters without creating friction. Tokenized identity is highlighted as a future capability that could enable persistent, portable authentication across channels, dramatically improving customer experience. However, its success hinges on solving the initial identity proofing challenge. Ultimately, banks that invest in these advanced, layered controls will be better positioned to scale safely, as effective fraud prevention directly protects revenue and enables faster, more competitive service offerings.

Transcription

3884 Words, 22404 Characters

English
Welcome everyone to the Emerge AI and Financial Services Podcast. Today's guest is Mary Ann Miller, VP of Client Experience and Fraud Advisor at Proof. Proof is a digital identity verification company that uses phone, centric, authentication technology to help enterprises reduce fraud and confirm customer identities across digital channels. Mary Ann joins us on today's show to discuss optimizing the welcome mat of onboarding, balancing the need for instant digital issuance with the rising threat of sophisticated AI-driven fraud. We also explore the future of tokenized identity and how a persistent identity bound process allows for faster, safer and scalable services that work better for both institutions and their clientele. Before we begin, a quick note for our executive listeners. Emerge invites enterprise leaders who are driving meaningful AI initiatives to share what they're learning with a peer audience. If you're moving real projects forward and want to be part of the conversation, you can learn more at go.emerge.com/expert. Hi Nick, it's great to be here today. It's great to be back on the show again. It's great having you back. And last time you were on the podcast with my wonderful colleague Marilee for Share, you described onboarding as a welcome mat for financial institutions and also that leaders need to move fast enough to win the customer, but of course not so fast that they invite fraud or operational fallout. Looking at the space and talking to several executives within the sector, we're kind of seeing that co-bradded card enrollment in particular, maybe serves as a really great example of this and a stress test for this onboarding process. A, because we're seeing a lot more of these partnerships starting to take shape, but also this reveals and shows very quickly whether an onboarding program delivers the measurable CX improvements and the risk reduction that we're all aiming for. So I say today, I think we should focus a little bit less on the why and more on kind of the execution. So whether journey stumbles, how decisions and governance works in practice and how tokenisation, something I'm particularly intrigued by, could change what's possible once identity is established. So with all of that in mind, from your perspective, Marianne, in co-brounded card enrollment, where do onboarding journeys most often break and how are these breakdowns driving both abandonment and fraud risk? Nick, that's a great, I call it the strategic challenge, but it comes to fraud. You're trying to balance, you know, customer experience with fraud and voidance along with, you know, operational cost and expense, so that kind of that triangle of when you're building your controls. And when we think of the card arena, that's really, especially with credit card, a lending opportunity for those institutions that are issuing. And it's often, you know, one of the customers' first products that they get to enjoy when they're, you know, starting their financial journey. But what I also find is, you know, there's a big push to improve that particular onboarding experience to make it more modern, to make it more convenient. I'll give you an example. It's not uncommon for card issuers to want to actually issue a digital version of the card immediately once the customer is approved so that they can begin to use their card immediately at it to their wallet or use it for a card not present transaction. Unfortunately, that's exactly what the fraudsters like to do, too. So we have a balance to achieve whether he has, you know, to have smooth onboarding, but also look at those risk moments that matter. That's what I call them along the journey. And some of those risk moments will matter more to the customer, but others will matter more to the fraudster. So those are the moments when we really want to think about what is our control landscape. What are the signals that we're building in the flow that help us determine safely whether Mary Ann Miller during the onboarding and welcome that experience is validating or presenting her own information in the flow. It's not just where we're beyond the point where we just validate the information. Well, that's certainly important and very important when it comes to synthetics, you know, a synthetic ID. So we want to make sure that that is Mary Ann's correct name and her correct address or correct data birth in the US, which checks social security number and other markets might be different. Now we want to make sure that we do what I call entity resolution, that that information belongs to Mary Ann, but also at the same time, we really need to know if Mary Ann is presenting your own information. Absolutely. Absolutely. Just kind of touching it a little bit further on this other kind of specific steps that create avoidable drop off in your experience. If so, why would that be the case? Yeah. So, you know, often when I go through an experience and, you know, here at Proof and we look at experiences, I look at what I call the Figma charts and the number of steps that a customer needs to take. How many screens do I need to answer questions before I actually have some kind of answer of whether I've been approved for this product. So that can be cumbersome, sometimes that involves receiving a one time password to my phone. Sometimes that will require me to fill in information over and over. I do see a lot of financial institutions, especially on the card side, moving to more what I call intelligent pre-fill, where the information is safely pre-filled. In other words, there's fraud and security algorithms in the background working to understand whether this pre-fill experience is accurate. And that really helps the customer then attest to their own information and then continue to move on in the flow. So we're not looking at numbers and numbers of minutes. We're looking to really optimize that time limit around approval. Absolutely. I mean, it's use cases like this, I think, for the laymen out there and laymen such as myself. I think use cases like this really kind of bring to life, although it being somewhat like Monday and brings to life, I think the promise of some of this AI future of things just being a little bit more seamless or sometimes a lot more seamless and ensuring those tedious tasks that we did previously are kind of eradicated. And again, this touches on to many different spaces that one day in the future we may all be in a very smooth environment and society where we're not having to deal with admin with our banks. I think Nick, you brought up a really good topic around AI and we know that AI is tremendously helpful in our everyday lives. It comes to products. We also know that the broadsters are using AI in their everyday lives. Recently, we've been talking, I've talked to financial institution actually who issues cards. And they had their first, this is a big word. So I'll use it all amorphic, adjunic attack with AI. Okay. So for your audience, that's an attack where the actual AI agent is actually, you know, we call agents for good and agents for bad. This particular agent adjusts and learns in the flow if their attack is not successful. So that's what we're seeing. So when we really look at those risk moments that we talked about earlier, it's important to keep that in mind that the AI threats that are out there when you're building your control stack because that's very, very important. I recently got some information. I found this pretty interesting in the financial services here in the US. We have these accounts that are called funnel accounts and these are accounts that were opened up originally for various reasons and have lots of fraudsters depositing lots and lots of money, many, many fraudsters into one account. And between January of 2025 and October of 2025, the banks have seen a 46% increase in noticing and reporting these funnel accounts. So that really just shows what I call the attack rate on, on any kind of welcome environment that's going up. So we're really looking at this very closely and I really, you know, when I talk to audiences, I get often asked, you know, where do I start? You know, I have so many things to do in fraud. I have my welcome mat to protect. I have my transaction to protect. I have my post-transaction environment, my operational environment. And while that can be a complex, you know, and question to answer, really if you focus on that welcome mat, that will help you for all of those backend processes. That's really where I think identity and authentication is really key to your whole safety and soundness to your whole environment. And I think we'll touch a little bit on identity, a little bit further into the conversation. I think given, you know, you're discussing the increasing sophistication of these threats and the changing modes, faces, modalities, etc., polymorphic, agentic, AI attacks, in the face of all of this tumult and change, what would you say a modern kind of decision architecture or framework for onboarding looks like? Or at least how should leaders design these processes, you know, from auto-approved or step-up referral paths without creating this kind of very inconsistent customer experience? Yeah, that's a great question. So when you think about let's use credit card and instant issuance as an example, you want to start, the first thing you want to look at is your perimeter. So we often know that any kind of organization, especially if you're online, you'll have what's called a web application firewall. I want to make sure that generally your organization has a good firewall in place because that will keep out some of the attacks. We know that on a daily basis, we have nation states or just really good fraudsters that want to come in with their bots. But-- Yeah, that's true. But what we know, we also have come to find out, you know, through, you know, the cyber and fraud lens, is that the firewall is not enough. And we have what I call-- I finally call them web application firewall leaks. And this is, then, a fraudster is keen enough, and smart enough to get through the firewall. And what they do is they hit endpoints. And they hit endpoints, but log in. They hit endpoints, a password reset. And they hit endpoints at application. So what we want to do is make sure that you have adequate endpoint bot protection. That is really important in this process. So if we start to look at the life cycle of your application, if your customer, of your prospect, is really to look at to make sure you've answered the question, is this a human? That's applying or is it a machine? And keeping out the machines does two things. It prevents mass application fraud. It also keeps the door open and not clogged for really true human customers. So make sure that that's protected. The next thing you want to look at is how you're capturing the required information from the customer. So that, as we talked about earlier, it can come two different ways. One is the customer fills out partial information, like a phone number, and maybe the last four digits of their social security number or another identification number. And then that information is safely pre-filled after it's filtered through fraud filters. Into an application where it can be attested and approved by the customer or a customer can fill out their information and hit enter. In both cases, there's going to be dynamically in the background, a lot of controls going in place. You're looking at in-depth things like biometrics. You're looking at in-depth things like the phone. Is the phone number have tenure? Does this phone number have a risky line type? Does this phone number have just been swapped? There's lots of what I call attributes behind the scenes that really, you know, is this phone owned by the person's information that's been attested to or filled out in the flow? Is this phone trustworthy? Especially if it's coming through, you know, and I'll say, maybe say, device. It's coming through a mobile app experience or enter experience. You want to just check a number of things along around the actual device and the actual movement of the keyboard. You want to make sure that there's not any cyber concerns in that flow as well. And then more importantly too, is you want to make sure, as we briefly touched on earlier, that the information that's being provided, the information that's being or approved, is accurate. If Marianne just moved, you want to make sure that if she needs to edit or update her address or she's providing the right address, that information's required. Eventually, all the, and then there'll be some kind of credit risk evaluation that'll take place, whether that's a soft poll or a hard poll depending on the product. Those kinds of credit tracks will then take place. That starts to create what I call the origination flow. That creates the approval flow. Then we used to, you know, origination. And the old days was more about, are you credit or the answering that question? Right. These days, it's more very, very, very much a more in-depth flow and requires a lot of more evaluation in that flow. Absolutely. Yeah, I can't even imagine the level of sophistication that must go into all of the efforts to ensure this type of security. Just kind of shifting our focus a little bit slightly. From your perspective, and again, given the broad experience that you've had, or should I say, focused experience that you've had, how should banks begin to kind of quantify ROI and govern risk? There's many, many different things that we need to be considering at the same time. How should they be quantifying ROI and balancing that with the risk governance in this kind of increasingly AI-driven onboarding era, especially when third-party data is involved and tokenization also increasingly becoming part of the flow. And next, that's really a good question. When you look at tokenization and you look at the, we know, I call it what goes wrong when you don't get identity, right? If you aren't as accurate and don't have the highest assurance levels that you can, but this is actually marrying and that you actually is applying for your product, then cost to the organization can be high. In fact, I've talked to some credit card executives, and sometimes their fraud reduction efforts is the biggest revenue generator in the organization as opposed to some marketing efforts. So if you're not really paying close attention to those fraud controls, it can cost you the bottom line later because you're working at cleaning up the mess or you're taking actual hard losses from those credit losses that you're ready on. So while it might not be as I say, we knew it was worthy to book a thousand good accounts rather than 10,000 bad accounts where you think they're good and then later have to clean them up. It's really, really important to look at that safety and sound is to make sure that you're onboarding true customers, the right customers because I really believe that that's the key to a successful business. Absolutely, absolutely. I think just speaking to, you know, I mentioned at the end of the question, a bit on third party data coming into the mix as well as tokenization becoming part of the flow. And I wanted to just touch in a little bit on tokenization. I don't know, we're running a little bit short for time, but looking ahead, you know, what is kind of, what is the idea of being able to enable a persistent identity across devices and channels and this tokenized identity bound payment process? What is this kind of enabling for the future of the space, would you say? Oh, I don't think Nick, there's ever a time when I'm not filling out my identity information or having to blog in again that I don't think I can't wait for tokenization. Sit there and go, oh please, oh please, let's get this going. But carefully, just like I think about recently, I had a conversation about past keys. And what past keys are great, but there's low adoption from customers because of the fact that it's hard to actually go through the identity process to register and to actually go through the process of of recovery. That's really no difference than establishing your identity before you go onto a blockchain crypto rail or establishing. I think about tokenization in the same way. Once we tokenize our identity and if we have portable tokenization where we can port that token, the identity process is the key to success. It really is because you can authenticate your tokenized bad actors all day long. You want to make sure that you really have the identity back to the highest insurance levels. I think those organizations who invest in and partner with companies that can really help that answer that question around identity which becomes more challenging every day are the ones that will be the most successful. Absolutely. I think your reference to past keys and the low rate of adoption signals to me or is a great metaphor to me. A lot of the broader problems in the space just in terms of adoption is low and one could argue it's perhaps CX that's a little bit of the problem. It's not clearly communicated and I feel like a lot of these tools have yet to find their perfectly encapsulated communication for their reason for being value, etc. Really interesting to see how CX, the whole customer experience touches on so many different things. You also mentioned the onboarding process that welcome mat can inform so much more of your, whether it's your AI build out or how you're approaching governance, etc. Really interesting stuff. With that being said, I mean, I'd like to just perhaps touch one step, not deeper, but just a little bit more on the idea of tokenization. Again, I would say thinking through the ears of our audience or listening through the ears of our audience, I'd love to ask how should leaders think about tokenization as a customer experience capability and not just a security feature? Because I think we hear about tokenization and it's obviously going to do many things to the world of digital security. But if we take it towards the customer side of the experience, what does that unlock for leaders in the space? Yeah, I think it's a really interesting question and I think part of it I'd like to back into is what services are being tokenized? Are we tokenizing financial services, are we tokenizing the card experience, e-commerce, are we tokenizing healthcare? There's so many arenas where tokenizing and portable tokenization can benefit from. So I feel like, yes, while security and safety is part of that definitely a primary reason for it, I think that customer experience is what will win. We will see customers now, given that, we will always have the broad challenge around tokenization as well. That will be there as well. But I think once a customer is tokenized and that identity is bound to that token, we will see a big dramatic change in the customer experience. Absolutely. And yeah, again, to something I said earlier, perhaps that future state of everything running smoothly will be enabled by technology such as this. One final question, this one purely out of my own curiosity, but I will say I'm also thinking of the audience here. In the next, let's say, 12 to 24 months from what you're seeing right now, what decision would separate a bank or banks that scale from those that store? That's a good question. I think what I've noticed in this, I think, is that more and more, and I've been talking to the industry, is things that we've been talking about in the industry, especially in the US, like speeding up payments or instant issuance of a debit card or higher up or limits or faster onboarding, all of these things that we talk about. When I talk to those individual financial institutions, the reason they can't move forward is because of lack of investment and all those controls that we talk about. And so I think that it's possible that the fraud conversation is starting to be a conversation at the table when the business leaders are talking to the executive management now that if we had these controls, then I could support the business to provide the customer or the consumer what we need. There are financial institutions offering faster payments. Safely, there are financial institutions offering higher up or limits safely. So those were the, just a couple examples, there's a whole list of different data of enableable types, but those financial institutions that figure out that equation and that what I call control stack to be able to enable these types of activities are going to be the ones that customers will gravitate towards. Absolutely. Well, Marianna, I'd love to carry this on for, for at least a few more hours, but for lack of that, I just want to say thank you for kind of walking us through a bit of this fluctuating space at the moment. And I really appreciate your time. And we'd love to have you back again sometime. Perhaps talk about tokenization and let's see what else comes our way that may send some ripples through the industry. Thank you, Nekko. Be great to join your audience again and you and look forward to it. Closing out today's episode, three themes stand out for banking executives, CROs and CSOs from our conversation with Marianna. First, we need to focus on protecting the welcome mat of onboarding by ensuring that identity, resolution, balances and modern, seamless customer experience with the prevention of sophisticated fraud. Second, it's critical to defend against evolving AI threats like holomorphic agentic attacks by implementing endpoint bot protection to distinguish between true human applicants and machines. And lastly, leaders should view robust fraud controls as primary revenue generators that provide the necessary safety and soundness to scale high value services like faster payments and higher credit limits. Position your brown alongside the Fortune 500 leaders defining the enterprise AI roadmap. For the opportunity to showcase your solution to the executives currently funding and scale in global initiatives, partner with the merge to reach the decision makers holding the strategic mandate. Secure your partnership at go.emerge.com/partner. That's g o dot em e r j dot com slash P a r T N E r. On behalf of the team at emerge, we'll see you on the next episode. you

Podcast Summary

Key Points:

  1. Onboarding is a critical "welcome mat" for financial institutions, requiring a balance between fast, seamless customer experience and robust fraud prevention.
  2. Sophisticated, AI-driven fraud (e.g., polymorphic agentic attacks) is increasing, making advanced controls like entity resolution, biometrics, and endpoint bot protection essential during identity verification.
  3. Tokenized identity holds future promise for secure, portable customer authentication across services, but its success depends on solving the initial identity proofing and customer experience challenges.
  4. Quantifying ROI in fraud prevention is crucial, as effective controls can be a major revenue protector, outweighing the cost of acquiring accounts that later become fraudulent.
  5. Leaders must design onboarding with intelligent, dynamic controls (e.g., safe pre-fill, risk-based step-ups) to reduce abandonment without compromising security, viewing tokenization as a CX enabler, not just a security feature.

Summary:

The discussion focuses on optimizing digital onboarding, particularly for co-branded card enrollment, which acts as a stress test balancing instant customer access with fraud prevention. A key challenge is the rise of sophisticated, AI-driven fraud, such as polymorphic agentic attacks, which adapt in real-time. This necessitates moving beyond basic data validation to "entity resolution"—ensuring the applicant is the legitimate owner of the presented information.

The modern decision architecture for onboarding should start with perimeter security (firewalls) and endpoint bot protection, then incorporate dynamic, in-flow controls like biometrics, device trust, and phone number analysis to distinguish legitimate customers from fraudsters without creating friction. Tokenized identity is highlighted as a future capability that could enable persistent, portable authentication across channels, dramatically improving customer experience. However, its success hinges on solving the initial identity proofing challenge.

Ultimately, banks that invest in these advanced, layered controls will be better positioned to scale safely, as effective fraud prevention directly protects revenue and enables faster, more competitive service offerings.

FAQs

The key challenge is optimizing the customer experience for speed and convenience while implementing robust fraud controls to prevent sophisticated AI-driven attacks, without causing operational issues or customer abandonment.

Institutions can use intelligent pre-fill with fraud algorithms to reduce steps, implement endpoint bot protection to filter out automated attacks, and focus on verifying that the applicant is the legitimate owner of the presented information.

Risk moments are specific points in the onboarding flow where fraud is most likely to occur, such as during identity verification or instant digital issuance. These require tailored controls to distinguish legitimate customers from fraudsters.

Fraudsters use AI to launch sophisticated attacks, such as polymorphic agentic attacks where AI agents learn and adapt in real-time if an initial attempt fails, increasing the threat to digital onboarding systems.

Tokenized identity enables a persistent, portable identity across devices and channels, which can dramatically improve customer experience by reducing repetitive logins and forms, while maintaining high security when identity is properly verified and bound to the token.

It's crucial to confirm that the person presenting the information (like name, address, or SSN) is its legitimate owner, not just that the data is accurate. This helps prevent synthetic identity fraud and ensures the applicant is who they claim to be.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.