By Paul Twigg, Chief Technology Officer, Digital Commerce Group (DCG)

Every year, the payments industry invests billions in fraud detection. Smarter AI models, more sophisticated transaction monitoring, seven-layer security frameworks that track device fingerprints, flag velocity anomalies, and score behavioral patterns in milliseconds.

And yet, fraud keeps coming and the losses keep climbing.

Advertisement

300 × 250

After years spent building and operating payment infrastructure, my view is that we’ve been fighting this battle at the wrong layer. Most fraud is not a transaction problem. It is an identity problem. We don’t know with certainty who is on either end of a digital payment. Everything else we build from the detection tools, the controls, and the AI is compensation for that foundational gap.

Until those that govern the payments industry are willing to confront that reality, we will keep running faster on the same treadmill.

Layering Up: The Industry’s Default Playbook

Ask any bank or payment processor how they fight fraud and you’ll hear a familiar answer: a layered approach. Industry frameworks involve defensive layers from scam detection and customer education at the front end, through to multi-factor authentication, session monitoring, and real-time transaction rule and pattern analysis further in. Financial institutions combine AI-powered behavioral analytics, device intelligence, and network analysis, all operating continuously in the background.

These controls are genuinely sophisticated. But notice what they have in common: they all assume the user is already inside the system. They are designed to watch what someone does after they’ve gotten in, not to confirm who they actually are before they get there.

Identity verification, where it exists at all, typically happens once at onboarding and is rarely shared or revisited later at the moment of a transaction. Most digital payment flows authenticate via an email address, a phone number, or a username and password pair. These are credentials. They confirm access to a device or an inbox. Not identity.

A fraudster who has stolen your login has, from the system’s perspective, become you. With the prevailing “I want my money now” mentality, the result is a system built to approve access quickly, not to verify identity with enough certainty before money moves.

The Scale of the Problem and Why It Keeps Evolving

From my knowledge of the Canadian financial landscape, I see all of this unfolding regularly and the implications are global:

In 2024, the Canadian Anti-Fraud Centre reported that Canadians lost $643 million to fraud — a nearly 300% increase since 2020. And that figure is almost certainly a significant undercount: the CAFC estimates, it represents only 5 to 10% of actual losses as most victims never report.

The top three most reported fraud types in Canada in 2024  were identity fraud, service fraud, and investment fraud—all variations of the same underlying problem: someone successfully impersonated someone else. More than 75% of fraudulent credit applications in Canada involve identity theft, as do 73.5% of fraudulent credit card applications and 89.3% of deposit fraud cases. The pattern is consistent and unambiguous: fraud is an identity problem wearing different costumes.

Canadian businesses face an even higher rate of payment fraud than consumers — 20% versus 13%, with impersonation fraud representing a quarter of what businesses experience.

What makes this problem particularly urgent is that fraudsters are not standing still. Deepfake fraud incidents increased tenfold between 2022 and 2023, and in the first quarter of 2025 alone, over $200 million USD was stolen globally through deepfake-enabled scams. Generative AI is now being used by fraudsters to stay ahead of the very detection systems providers are deploying, creating synthetic identities sophisticated enough to pass traditional onboarding checks.

The arms race approach clearly isn’t working as fraud losses keep accumulating even as detection investment grows. The industry needs a smarter strategy—that includes digital identity.

Digital ID in Canada Is a Live Case Study

I’ve seen real progress from my Canadian vantage point, but also real gaps that the payments industry needs to understand and address at a macro level.

The value of a strong digital identity framework became tangible during COVID-19. British Columbia’s digital identity system allowed residents to verify themselves for government services without any in-person interaction, demonstrating what identity infrastructure can enable under pressure. Both BC and Alberta have established provincially issued trusted digital identities, and the federal government has signed agreements allowing residents to use these credentials to access services like My Service Canada Account.

Newsletter

Get the week's best tech coverage.

Free. Read by thousands of HR, tech, and business leaders.

In August 2025, Canada published a national digital identity standard (CAN/DGSI 103-0:2025), which provides a comprehensive code of practice for building trustworthy digital identity systems, aligned with international frameworks including Europe’s eIDAS and FATF. Canada and the EU also formalized a memorandum of understanding in December 2025 to collaborate on digital credentials and trust services, representing a meaningful step toward cross-border interoperability.

But the gap between a published standard and a functioning ecosystem is significant. DIACC’s current recommendations to the federal government still include funding an interoperable, reusable digital credentials system for federal services, which means it does not yet exist at scale. Identity governance in Canada remains fragmented across provinces, federal departments, banks and hundreds of third party solutions, making true pan-Canadian consistency a policy challenge as much as a technical one. And extending any of this into private-sector financial transactions, where it would matter most for fraud, remains largely undone.

There is also a trust dimension that cannot be ignored. Any digital ID framework requires Canadians to believe their data will be handled securely and used only as intended. That trust has not yet been fully earned. Building it will take consistent and transparent execution, not just announcements.

Why Identity Infrastructure Changes Everything

A strong, interoperable digital identity framework structurally changes the narrative. If payment senders and receivers are bound more directly to a verified identity credential, impersonation fraud, account takeover fraud, and synthetic identity fraud become much harder to execute. The fraudster’s core advantage—the ability to convincingly be someone they are not— is significantly reduced. Canada is already starting to test parts of this model through efforts like Interac’s KONEK. This represents a fundamental shift in how fraud prevention works: from transaction monitoring, which detects anomalies after the fact, to identity infrastructure, which confirms who is present before the transaction occurs. It doesn’t replace existing fraud controls. It makes them dramatically sharper because detection tools work better when baseline identity is verified and known.

New international standards for digital identity such as mobile documents (mDocs), work by converting existing government-issued IDs into secure digital credentials stored on a device using military-grade encryption. These tools are not theoretical. They exist today and are being deployed in non-Canadian markets.

Real-time rails (which is about to deploy in Canada and already exists elsewhere) turn the speed of settlement into an increased fraud risk because transactions become effectively irreversible faster. Identity verification at the point of initiation becomes more critical, not less, in a real-time environment. Having RTR without a parallel investment in identity infrastructure means launching a faster, harder-to-reverse version of the same vulnerable system.

Four Things the Industry Can Do Today

The payments industry should move with the urgency this problem demands. Here are four concrete actions that can accelerate progress today:

  1. Treat identity as a transaction-level signal, not a one-time onboarding check. Banks and payment processors should invest now in binding verified identity to payment initiation — not just to account creation. Tokenized, cryptographic identity credentials can be checked at the moment of a transaction, dramatically reducing the window of exposure.
  2. Integrate with digital identity frameworks where they already exist. Turning again to what I know with a Canadian example: BC and Alberta have working, trusted digital identity systems. Fintechs and PSPs operating in those provinces can begin integrating today to build the private-sector use case. That will demonstrate the value of expanded identity infrastructure and create momentum for national adoption. The same application applies at an international level.
  3. Build identity-first architectures from the ground up. Fintechs and PSPs entering the market have a structural advantage over legacy institutions: they are not inheriting layers of technical debt and compliance systems designed for a credential-based world. Building identity verification into the core architecture, rather than bolting it on later, is both more secure and more economical over time.
  4. Advocate for private-sector inclusion in national and international digital ID frameworks. The current trajectory of Canada’s digital identity work is primarily government services-focused. The payments industry needs to engage actively with DIACC, Payments Canada, and federal policymakers to ensure that financial transactions are a first-class use case in the pan-Canadian trust framework—not an afterthought addressed in a future phase. Early tools such as Interac’s KONEK also show that parts of this model are already beginning to emerge in the market, even if they are not yet broad or widely connected. The same coordination is also needed at a global scale as international transactions grow.

It’s Time to Outsmart the Criminals

For too long, the payments industry has treated fraud as an inevitability to manage rather than a problem to solve at the root. We’ve become expert at chasing anomalies through a system whose front door was never properly secured.

Reliable digital identity is that front door. The technology exists. The standards are being written. Canada has the early building blocks in place. What’s needed now is the will from financial institutions, fintechs, regulators, and governments to move from pilots and frameworks to production-grade implementation across the payments ecosystem.

The fraudsters are not waiting. Neither should we.