us

216.73.217.78

Back
Blogs

What is identity intelligence, and Why does more data create more false positives?

What is identity intelligence, and Why does more data create more false positives?
Madiha Khatoon MAY 11, 2026 9 minutes read

Identity intelligence combines six kinds of identity signals into one risk score. If those signals are not tied to one verified person, adding more data sources only creates more AML false positives. 

Identity intelligence combines six kinds of signals into one risk score for a customer, then updates that score as new signals arrive. The six signals are the document someone presents, their face, the device they use, how they behave during a session, what watchlists say about them, and what government registries confirm. 

That is the definition most of the market uses, and it is also why compliance teams buy an identity intelligence platform and then watch their alert queue grow rather than shrink. 

The assumption underneath it is that intelligence improves as you connect more sources: add device data, add adverse media, add behavioural analytics, and the picture should get clearer. 

But, in reality, it usually gets noisier, because each new source generates its own matches against a customer record that was never firmly tied to one person. What separates useful identity intelligence from expensive noise is whether every signal is tied to one verified person before any of it is scored. 

 

What is identity intelligence?

Identity intelligence is the layer that turns identity data into a risk decision that you can explain to teams and auditors. The irony is that most teams already have that data, but they lack the conclusion that’s drawn from it and the ability to show someone how they reached that conclusion.

The three things it has to do

  1. It needs to tie every signal to one verified person: The platform matches each incoming signal against an identity that was proven at onboarding, then decides whether that signal belongs to the same human being or to somebody different. Device data, watchlist hits, and behavioural alerts all attach to a single customer profile, so the system holds one view of that person rather than several partial ones.
  2. It should update as new signals arrive: Risk is recalculated whenever something material changes, such as a new sanctions entry, an unfamiliar device, or a change of address. The score reflects where the customer stands now, and the platform re-checks the existing base continuously instead of waiting for a scheduled review.
  3. It should show the reasoning behind every score: Each result breaks down into the individual fields that produced it and the weight each field carried. Compliance teams can trace any decision back through its inputs, which is what allows them to explain it to an auditor or a regulator later. 

How is identity intelligence different from identity verification?

Identity verification asks whether someone is who they claim to be, once. Identity intelligence asks how much risk that person carries and whether that risk is changing. Verification comes first, and identity intelligence is only as reliable as the verification sitting underneath it. 

Dimension Identity verification Identity intelligence
What it asks Is this person who they claim to be How much risk does this person carry
Signals used Document and face Document, face, device, behaviour, watchlists, registries
When it runs Once, at onboarding Continuously, for as long as the customer stays
What it returns Pass or fail A risk score plus the fields behind it
How it fails A genuine customer gets rejected Alerts go up while detection stays flat
What it proves to an auditor That you checked Why you decided

Why the difference matters to regulators

FATF Recommendation 10 requires ongoing due diligence and scrutiny of transactions throughout the business relationship, not a single check at the door. A verification record shows that you checked someone, whereas an intelligence record shows that you formed a view of their risk and kept it current. 

The same expectation runs through the EU’s Anti-Money Laundering Regulation 2024/1624, which applies from 10 July 2027 and sets one common set of customer due diligence rules across every member state. A firm whose identity programme stops at onboarding will be able to produce records of checks, and very little else. 

What is a digital identity graph?  

A digital identity graph is the data structure that makes that tying-together possible. Every identifier connected to a customer becomes a point in the graph, including email addresses, phone numbers, device fingerprints, IP ranges, document numbers, and stored face templates. Every confirmed or suspected link between two identifiers becomes a line joining them. 

How the graph is put together

A graph records connections, which an ordinary customer table does not. A customer table can tell you that one account used a particular device. A graph can tell you that the same device fingerprint sits behind dozens of accounts opened within the same few weeks, which turns a routine login into evidence of a coordinated group.

Why matching one face against many records matters

The same idea applies to faces. A one-to-one check confirms that the person in front of the camera matches the photo in their document. A one-to-many check analyses whether that same face already sits in your customer base under a different name.

One person running several accounts under different names passes the one-to-one check every single time, because each document really does match the face presenting it. Only a one-to-many check catches the reuse of that document. 

Digital identity graph showing document, face, device, behavioural, watchlist and registry signals resolving to one verified identity.Why does more identity data mean more AML false positives?

More data creates more false positives whenever the new signals are matched against a name instead of against a person. A name is a weak identifier. Different spellings, accent marks, reversed first and last names, and common surnames all produce matches that look plausible and describe somebody else entirely. Each list you add multiplies those matches rather than settling them.

Why adjusting the match score never fixes it

Fuzzy matching, which scores how closely two names resemble each other, has no setting that works. If you set the threshold high and you miss the sanctioned person whose name reached your system through a different alphabet. If you set it low and your analysts spend the week clearing customers who happen to share a surname with someone on a list. Teams move that threshold back and forth for years without improving either outcome, because the threshold was never the thing that was the problem.

We’ve spent years treating this as a matching problem when in reality it’s a context problem. There’s no perfect fuzzy-match score between 50 and 100. The real shift is from screening names to making better, more informed decisions in context.”

Umair Hameed, Regional VP of Sales, MENA at Shufti, speaking on a Shufti AML roundtable. Watch Shufti’s webinars

What should an identity intelligence platform include?

Five things separate a working identity intelligence platform from a set of checks wired together. Weigh any option against all five, because a gap in one weakens the rest.

  1. One verified identity to attach everything to: Every later signal needs to hang off an identity that was properly proven once, not off a customer reference number.
  2. A shared data layer: Document checks, face checks, screening, and monitoring all have to be written into the same customer profile, because separate systems cannot produce a single view of risk.
  3. Continuous re-screening: Ongoing monitoring should recheck existing customers as lists change, rather than waiting for the next scheduled review.
  4. Scoring you can adjust and explain: Compliance teams need to set their own weights and thresholds and to see which fields drove each result.
  5. Evidence an analyst can open: Every score needs to unfold into the evidence beneath it, because nobody can approve a decision they cannot inspect.

Where does AI help, and where does it not?

AI suits sorting and ranking a large alert queue. It does not suit being the final answer, and that boundary is where most implementations go wrong.

What AI models do well

Models handle volume and correlation far better than fixed rules. They pick up combinations of weak signals that no analyst would connect by hand, and they adjust as attack patterns change, which a rulebook cannot do until somebody rewrites it. The clearest win is automatic dismissal of alerts that probably describe a different person, because that work never had any value to begin with.

Where responsibility stays with people

Regulators ask why a decision was made, and a model output nobody can explain is not an answer. Accountability stays with the person reviewing the case, backed by a written policy, an audit trail, and reasoning a human can read. AI should shrink the queue and put the important cases at the top, and the judgement on those cases should still belong to your analyst.

How Shufti approaches identity intelligence

Shufti’s AML screening attaches every hit to an identity already verified by document and face. Date of birth, nationality, document number, and entity type captured during onboarding feed straight into the match score, so a hit that contradicts the verified record is dropped automatically instead of queuing up for somebody to dismiss by hand. The engine weighs who the customer is rather than how their name is spelt, and the field-level score behind each decision stays visible for audit.

That screening covers 4,000+ watchlists and 2.6M PEPs across 215+ jurisdictions, refreshed every 15 minutes, so a newly listed customer surfaces within minutes rather than at the next scheduled review.

See how screening tied to a verified identity handles your own false-positive queue on live data, then book a 20-minute demo.

Frequently Asked Questions

Q: What is identity intelligence in simple terms?

Identity intelligence is the layer that turns identity data into a risk decision you can explain. It combines document, face, device, behavioural, watchlist, and registry signals, ties them to one verified person, and updates that view as new signals arrive.

Q: Is identity intelligence the same as identity verification?

No. Verification confirms that someone is who they claim to be at a single moment and returns a pass or fail. Identity intelligence carries on after that, scoring how much risk the verified person carries and revising the score whenever the underlying signals change.

Q: How does identity intelligence reduce AML false positives?

It attaches each screening hit to a verified person rather than to a name. Details such as date of birth, nationality, and document number can rule a match out on their own, so alerts that describe somebody else are dropped before an analyst ever sees them.

Q: What is a digital identity graph used for?

A digital identity graph links every identifier tied to a person, including devices, emails, phone numbers, and stored face templates, and records the connections between them. It exposes infrastructure shared across accounts, which is how coordinated fraud groups and duplicate identities become visible.

Disclaimer: The views and opinions expressed on this webpage or weblink are those of the author only, and are not necessarily the views or opinions of Shufti Pro Limited. The material and information on this weblink is solely for general information purposes. You should not rely upon the material or information on the website as a basis for making any business or legal decision.

While we endeavor to keep the information up-to-date and/or correct, we make no representations or warranties of any kind, express or implied, or for any purpose about the completeness, accuracy, reliability, suitability, or availability of the contents or information herein. Any reliance on its content is thus entirely at your own risk.

For the avoidance of doubt, Shufti Pro Limited will not be liable for any false, inaccurate, inappropriate, or incomplete information presented herein, and all liabilities with respect to actions taken, or not taken, based on the contents or information herein, or for any loss sustained by you as a consequence are hereby expressly disclaimed by us.

Join the
Shufti Sphere Newsletter

Get the latest trends, insights, and expert opinions on KYC, AML, fraud prevention, and more, straight to your inbox.

    Pitch a piece and get a verified byline in the Media room.

    Partnership Inquiries?
    Email us at [email protected]

    iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
    Copyright © 2026 Shufti. All rights reserved.