fidentity logo

Digital fraud at Swiss banks: identity verification beyond onboarding

Fraud prevention in the customer lifecycle

On April 9, 2026, FINMA published its guidance on digital fraud risks at Swiss banks. It identifies areas for action in risk management, the detection of new fraud patterns, and the handling of online account openings and unauthorized account access. This article focuses on one aspect: how reliably verified identity data can contribute to fraud prevention beyond the onboarding process.

Portrait von Thorsten Hau, CEO und Gründer von fidentity
Thorsten Hau
12.8.2026

Secure onboarding is the foundation — but digital fraud can occur later

At the end of 2025, FINMA surveyed 19 Swiss banks about their approach to digital fraud risks. The Guidance 02/2026 provides no clear indication that fraudulent activity occurs more frequently during online account openings than through other channels. What is striking, however, is the increase in reports to the Money Laundering Reporting Office Switzerland (MROS) related to accounts opened online.

Different fraud patterns lie behind this trend. In some cases, the account opening itself is carried out with fraudulent intent. In others, individuals are deceived into opening an account and then handing control over to criminal third parties. There are also account takeovers, where criminals gain access to an existing account — for example through phishing.

In many of these cases, the account may have been opened using valid identity documents and in full compliance with applicable due diligence requirements. The identification process worked as intended. The actual fraud only begins afterward.

FINMA therefore points out that the risks associated with digital account opening and unauthorized account access should not be viewed in isolation. Both belong within a comprehensive strategy for preventing digital fraud risks.

Reliable identification remains the foundation. Before a bank opens a client relationship, it needs to know who it is dealing with — at the branch as well as in the digital channel. FINMA Circular 2016/7 on video and online identification sets out the requirements that must be met. Clear standards and independently audited processes ensure that digital onboarding can be carried out securely, compliantly, and traceably.

This creates more than a completed compliance step. The verified and documented identity forms a reliable data foundation. It establishes which person the client relationship has been assigned to — and can remain relevant for subsequent security and compliance processes.

Fraud prevention in the customer lifecycle

Compliant onboarding creates a reliable identity foundation. It does not, however, prevent third parties from later gaining control of an account. Authentication, fraud monitoring, and re-identification serve different purposes and complement each other in fraud prevention. At sensitive points in the customer lifecycle, a renewed identity check can provide additional security.

Questions about integration into your processes?

Contact us

Good identity data retains its value

FINMA's guidance does not create a regulatory obligation to reuse identity data after onboarding. The cases described do show, however, why a reliably verified identity can remain valuable later on.

For certain transactions, knowing that someone has successfully logged in is not always enough. What can matter is whether the person actually acting is the one who was originally identified.

Typical situations include:

  • Account access recovery: someone who has lost access to their device or credentials needs to be authenticated through an alternative process.
  • Changes to key account data: for example, a phone number or email address used to send security codes or notifications.

These are precisely the moments that can be attractive to attackers — because if misused, they can bypass or undermine existing security mechanisms. In such cases, verifying the existing access may not be sufficient. What matters again is the identity of the person acting.

Re-identification is not authentication

Authentication, fraud monitoring, and re-identification serve different purposes:

  • Authentication verifies whether someone has the required credentials.
  • Fraud monitoring assesses transactions and behavioral patterns for anomalies.
  • Re-identification answers the question of whether the person acting matches the person who was originally identified. The individual is verified again and the result is linked to the existing client identity.

Re-identification therefore replaces neither strong authentication nor effective monitoring. It complements these measures where renewed certainty about identity is required.

A building block for digital fraud prevention

fidentity helps banks create good, traceable identity data during digital onboarding. With the flexible modules of IDENT, identity can also be verified again at a later stage and linked to an existing client relationship. Processes can be integrated into existing workflows on a risk-based basis.

This means identification does not resolve every challenge in digital fraud prevention. It does, however, provide an important building block: a reliable foundation that banks can draw on when credentials and behavioral signals alone do not provide sufficient certainty.

Re-identification can also serve as an additional “step-up” for low-level risk signals—in other words, as a targeted additional identity check. The comparison is performed automatically against previously collected biometric data, making the process quick and easy for customers and cost-efficient for the bank. This allows re-identification to be used with a low threshold.

«Good identity data is not just the result of a secure onboarding process. It creates a reliable foundation that banks can draw on whenever clarity about who is acting is needed.»

Thorsten Hau, CEO fidentity

This article is part of our series on digital fraud prevention. Upcoming articles will explore individual fraud patterns in greater detail and show how identity verification can be integrated into digital customer processes.

fidentity is certified according to ETSI TS 119 461 and operates an information security management system certified to ISO/IEC 27001. Our identification solutions comply with the requirements of FINMA Circular 2016/7 and the relevant provisions of ZertES and eIDAS.

View current certificates and compliance documentation
Share article:

Get in touch.

Portrait René Greiss, Head of Sales and Business Development
René Greiss
Head of Sales and Business Development
Interested in learning more about IDENT, SIGN, and ONBOARD? Get in touch now. I’m happy to assist you.
Contact me
Read more news