In-House Identity Teams Faced More KYA Security Incidents
Companies managing verification internally face higher incident rates than those using outsourced or hybrid models.
Updated on Oct. 1, 2026 in Remote Work

Live Poll
Do you feel that automated identity verification processes often prevent you from completing your online activities?
A PYMNTS Intelligence study of 350 risk management leaders found that 53% of in-house identity teams reported incidents or losses related to Know Your Agent (KYA) verification. These internal teams face significant operational friction as they navigate rising bot traffic and manual review processes.
Why it matters
Businesses are struggling to balance rigorous verification with the need for low-friction user experiences, as over 60% of internal programs report missed opportunities due to user abandonment. Enterprises are now reevaluating their reliance on manual staff reviews to mitigate security gaps while maintaining growth.
In-house identity teams reported KYA incidents at a rate of 53%, compared to 28.8% for hybrid programs and 24.1% for externally managed models. Furthermore, 52.3% of organizations reported an increase in bot traffic over the prior year, with 89.5% identifying such traffic as a major operational challenge.
The players
PYMNTS Intelligence
A research and data analysis firm providing insights on digital commerce and identity verification metrics.
The details
Companies currently rely on three models for identity verification: internal, external, and hybrid. Internal teams are heavily dependent on manual staff reviews, a process utilized by 86.4% of in-house groups, which contributes to higher vulnerability and user friction. Hybrid models specifically struggle with credential stuffing and account takeover attempts, reporting a 73.1% exposure rate to these threats.
Timeline
The PYMNTS Intelligence report was published in October 2026.
Market Landscape
The findings underscore a widening security gap in how firms manage digital identity amidst a sustained rise in bot-driven fraud. This data marks a departure from traditional reliance on manual internal reviews, suggesting a broader industry shift toward automated, layered identity controls.
Operators managing identity verification should benchmark their incident rates against the 28.8% average found in hybrid models to determine if their current mix of manual and automated review is sufficient. Companies facing high user abandonment should audit their sign-up processes to identify if friction from verification steps is causing revenue loss.
The takeaway
Internal verification teams are currently the most vulnerable to KYA incidents due to high reliance on manual processing and exposure to rising bot traffic. To improve resilience, leadership should evaluate the potential for hybrid automation to reduce staff-dependent friction points while maintaining security layers.
Further reading
For more on managing digital operations and security, see our Remote Work section.
Source note: This article includes information reported by PYMNTS.
Live Poll
Do you feel that automated identity verification processes often prevent you from completing your online activities?







