Identity-verification provider Sumsub has launched Workforce Verification, a product designed to insert document checks, biometric liveness and screening into enterprise identity and HR workflows.

The product’s most interesting feature is not recruitment screening. It is the attempt to re-establish human identity at high-risk moments after onboarding, such as password resets, suspicious logins, MFA re-enrolment and privilege escalation.

That addresses a familiar weakness in enterprise identity and access management. An IAM system can validate that the correct password, token or device credential was presented, but that does not always prove that the authorised person is the one presenting it. Deepfake-enabled social engineering, stolen credentials and compromised help-desk processes can exploit that gap.

Garbage In, Garbage Faster: Why Agentic AI Exposes Your Organisational Debt
If Agentic AI follows your documented processes, what happens when those processes don’t reflect reality? Most organisations assume AI will figure things out. Business Architect Laura Van Weegen argues the opposite: AI doesn’t create new problems — it removes your ability to ignore the ones that have existed forever and a day. Undocumented workflows, undefined decision ownership, and human workarounds masking broken systems all get amplified at machine speed. You’ll learn: • Why “garbage in, garbage faster” is the real Agentic AI risk • The critical difference between feeding AI data versus information • How process debt compounds the same way technical debt does • Why exception handling is the new decision design priority • What one conversation reveals more than most AI readiness assessments • How to build explainability in from day one Key topics: Agentic AI readiness • Information architecture • Process debt • Data vs information • Contextual blindness • Decision ownership • Explainability vs traceability • Semantic infrastructure • Exception handling • Organisational accountability • Workflow documentation • AI governance Essential viewing for CISOs, CIOs, CFOs, and Chief Legal Officers evaluating Agentic AI deployment — before the human safety net disappears.

Sumsub says its approach creates an initial identity baseline and then triggers step-up checks when another system flags risk. The company also claims the service is designed to resist deepfake attacks. Those performance assertions are vendor claims and should be evaluated independently by buyers.

The broader trend is important for financial services because identity assurance is moving from a one-time onboarding exercise toward a lifecycle problem. Banks already understand this on the customer side through KYC, transaction monitoring and step-up authentication. The same principle is increasingly relevant to employees, contractors and privileged administrators who can reach high-value systems.

Sumsub Chief Product Officer Andrew Novoselsky describes the problem as the difference between possession and identity: a valid credential shows that someone has the credential, not necessarily that the legitimate employee is still behind it.

For CISOs, the control question is how frequently to re-verify and what should trigger it. Continuous biometric checks would be intrusive and operationally heavy. Risk-triggered re-verification offers a more targeted model: ask for stronger proof only when a password reset, new device, unusual login or privilege change raises the stakes.

The product also illustrates why deepfake defence is becoming an identity architecture issue rather than a standalone detection problem. Detecting synthetic media is useful, but the enterprise outcome that matters is whether access is granted, blocked or escalated. The next generation of identity controls will increasingly be judged by how well they connect detection to that decision.


Garbage In, Garbage Faster: Why Agentic AI Exposes Your Organisational Debt
If Agentic AI follows your documented processes, what happens when those processes don’t reflect reality? Most organisations assume AI will figure things out. Business Architect Laura Van Weegen argues the opposite: AI doesn’t create new problems — it removes your ability to ignore the ones that have existed forever and a day. Undocumented workflows, undefined decision ownership, and human workarounds masking broken systems all get amplified at machine speed. You’ll learn: • Why “garbage in, garbage faster” is the real Agentic AI risk • The critical difference between feeding AI data versus information • How process debt compounds the same way technical debt does • Why exception handling is the new decision design priority • What one conversation reveals more than most AI readiness assessments • How to build explainability in from day one Key topics: Agentic AI readiness • Information architecture • Process debt • Data vs information • Contextual blindness • Decision ownership • Explainability vs traceability • Semantic infrastructure • Exception handling • Organisational accountability • Workflow documentation • AI governance Essential viewing for CISOs, CIOs, CFOs, and Chief Legal Officers evaluating Agentic AI deployment — before the human safety net disappears.
Share this post
The link has been copied!