This section is The content in this section is supplied by GlobeNewswire for the purposes of distributing press releases on behalf of its clients. Postmedia has not reviewed the content. by GlobeNewswire Article content
RESTON, Va., Sept. 09, 2026 (GLOBE NEWSWIRE) — 82% of organizations have been asked to document or explain an identity-related decision to a regulator, court, or external auditor, according to a
global study by Regula of 850 fraud prevention and financial crime decision-makers. Among that group, 32% could provide only limited or indirect evidence, making it harder to defend decisions, investigate fraud, resolve disputes, and demonstrate compliance.
Sign In or Create an Account
or View more offersArticle content
Story continues below
This advertisement has not loaded yet, but your article continues below.
Article content
Among organizations that had already been asked to explain an identity-related decision, nearly one-third could provide only limited or indirect evidence
Article contentWe apologize, but this video has failed to load.Try refreshing your browser, or
tap here to see other videos from our team.Article contentArticle content
Of the organizations that had been asked to explain a decision, 68% could produce clear, audit-grade evidence, such as logs, provenance data, or a decision trace. The other 32% had only limited or indirect evidence, including partial logs, vendor reports, or manual records. The difference matters when a business must demonstrate not only what outcome its system produced, but why.
Article content
Visibility is not the same as full traceability
Article content
The same study found that only 50% of organizations can fully reconstruct an identity verification decision across all contributing systems, signals, and decision logic. Another 42% can identify the main systems and signals involved but cannot fully reconstruct how the final outcome was reached. A further 7% report only limited visibility, while 1% say reconstruction is not possible in practice.
Article content
These findings point to two distinct capabilities. Decision traceability helps teams understand what happened. Audit-grade evidence helps them prove it to someone else. As AI-assisted fraud increases the speed and complexity of identity interactions, organizations are adding more checks, data sources, and automated rules to their workflows – making both capabilities more important and potentially more difficult to achieve.
Article content
Story continues below
This advertisement has not loaded yet, but your article continues below.
Article content
A complete identity decision trace should show:
Article content
- What identity evidence was presented.
- Which checks were performed.
- What signals and risk indicators were generated.
- Which rules or thresholds were applied.
- Whether manual intervention occurred.
- How these inputs produced the final outcome.
Article content
“The challenge of building reliable audit trails is partly architectural. Many identity verification systems were designed to answer an immediate operational question: should this user pass, fail, or be sent for manual review? They were not necessarily built to preserve the full chain of evidence and decision logic behind that outcome. Auditability can be added later, but it can be like installing new wiring after a building is finished – much harder than designing for it from the start,” says Henry Patishman, Executive Vice President of Identity Verification Solutions at Regula.
Article content
Making identity decisions traceable by design
Article content
One way to address the problem is to make traceability part of the identity architecture rather than reconstructing it across disconnected systems after the fact.

