Continuous trust essential for African fintech

(Left to right) Sumsub CEO Andrew Sever and Hannes Bezuidenhout, VP for sales Africa (Image source: Sumsub).
(Left to right) Sumsub CEO Andrew Sever and Hannes Bezuidenhout, VP for sales Africa (Image source: Sumsub).

African fintech platforms risk severe cybercrime losses by treating digital identity verification as a one-off onboarding step rather than a continuous process.

The warning comes from global identity verification provider Sumsub during an interview with ITWeb Africa at the firm’s Africa Team Meet Up in Cape Town.

More than 60% of digital fraud across the continent occurs after a user has successfully onboarded and initiated transactions, revealing a massive architectural vulnerability in traditional financial security systems, according to Andrew Sever, co-founder and CEO of Sumsub.

He said: “Traditional verification stops at the digital front door instead of following the user journey consistently.

“Controlling every subsequent user step — including suspicious behaviour and device intelligence — is essential. Using a one-time event to onboard users is no longer enough; security must be continuous.”

Historically, fintechs across Africa have relied on static government databases, such as South Africa's Department of Home Affairs or Nigeria's national identity registries, to cross-check credentials during sign-up.

However, relying strictly on database verification at entry leaves systems vulnerable to AI-enabled synthetic identity fraud, said Hannes Bezuidenhout, vice-president for sales in Africa at Sumsub. 

In these attacks, cybercriminals pair valid registry text data with AI-generated biometric faces to pass initial checks undetected, subsequently executing rapid credential testing across multiple institutions.

To counter post-onboarding threats, Sumsub advocates moving from static rules to continuous behavioural monitoring. 

This strategy uses passive evaluation — tracking device intelligence, location shifts, and behavioural anomalies throughout active transactions — to route suspicious activity into targeted biometric challenges without creating friction for legitimate users.

Beyond direct financial losses, failing to upgrade from static verification threatens long-term market survival.

“There is significant reputational damage at stake, not just direct fraud losses,” said Bezuidenhout. “Whether fraud losses mount immediately or not, institutions will ultimately be forced to put continuous security measures in place.”

Share

Read more
ITWeb proudly displays the “FAIR” stamp of the Press Council of South Africa, indicating our commitment to adhere to the Code of Ethics for Print and online media which prescribes that our reportage is truthful, accurate and fair. Should you wish to lodge a complaint about our news coverage, please lodge a complaint on the Press Council’s website, www.presscouncil.org.za or email the complaint to enquiries@ombudsman.org.za. Contact the Press Council on 011 484 3612.
Copyright @ 1996 - 2026 ITWeb Limited. All rights reserved.