# Ping says mobile driver’s licenses can narrow false positives

By MarketScale Newsroom · Published 2026-09-22 · Updated 2026-09-23 · Software & Technology on MarketScale
Canonical: https://www.marketscale.com/industries/software-and-technology/ping-says-mobile-driver-s-licenses-cut-false-positives-better-than-document-scans

> One bank’s blanket ID re-checks stopped fraud but wore on tellers and customers. Ping’s Diana Gouard argues for verifying once, then carrying trust forward.

## Key points

- A bank that re-verified every visitor's document on every branch visit stopped fraud but pushed failure handling onto tellers; the fix now underway is enrolling a face once and using a tablet glance after that.
- Identity proofing should happen once, with an email or facial biometric bound to that event carrying trust through the account lifecycle until trust is dissolved.

A bank was watching people walk into its branches, open accounts and move money on behalf of someone else. Its answer was to put every visitor through document verification, every time they came in. Diana Gouard, product lead for Neo at Ping Identity, describes the case on Mitek's Fraud in Focus podcast as the clearest example she knows of a fraud program that worked and still cost the business.

Speaking with host Becky Keithley of Mitek in a recent episode of the show, Gouard said customers and partners largely accepted the policy. The fraud stopped. The bank could point to a figure it had saved.

## The cost lands on the teller, not the fraud line

Document authentication brings failure handling with it. When a real fraud is caught, or when one ID type simply does not read well, the teller at the window is the person who has to manage the outcome in front of a customer, Gouard said. Keithley added that tellers are not document experts and are not agents accustomed to examining IDs.

That is the cost a fraud dashboard does not show. The operations lead sees slower branches, the branch employee absorbs the awkward conversation, and the customer decides whether to come back. Gouard said the bank still runs the policy today and Ping is working with it to enroll customers' faces so a glance at a tablet replaces a fresh round of identity proofing on each visit.

## A single bad account reset can stop a company

Gouard's argument starts with how companies count. She said she often sees companies looking at false positives and fraud strictly as a P&L item rather than as preservation of the business, and she compares that to governments that do not fund flood or fire prevention until the disaster has already happened.

She points to one large manufacturer where a bad actor performed an account reset through a help desk that had no identity verification in place. It was a workforce case, and it halted business processes for months.

> You can look at a false positive as just a number, or you can also look at it as, honestly, preventing them is the lifeline and the infrastructure to keep your business safe and humming. — Diana Gouard, Product Lead, Neo, Ping Identity

Ping Identity and Deloitte said in a joint press release that help desks could become the top target for social engineering as multifactor authentication, single sign-on and perimeter controls harden, with attackers using AI-generated voice deepfakes and urgency to get agents to reset credentials or disable MFA. The same release said 17% of consumers trust the organizations managing their identity data and 75% of people globally are more concerned about data security than five years ago. The report comes from Gouard's own employer, so it reads as a vendor describing a problem it sells a fix for rather than outside confirmation of the scale.

## Prove identity once, then carry the trust

Gouard's alternative treats verification as the gate into the user lifecycle rather than a recurring toll. Do the proofing once, as well as possible, then bind something to it: an email confirmed by a one-time passcode during proofing, or a facial biometric. Those bindings carry the trust through every later interaction, and the company returns to full proofing only when trust has dissolved, such as a full account recovery.

Assurance does not have to be uniform either. A user who verified a passport by NFC and a user who failed the automated checks and ended up in a live agent interview carry very different grades, Gouard said. She wants standardized receipts attached to each user so authorization engines can see the gap and gate what each can do.

> For the 95% that got through no problem, you don't impose that level. But for the 5%, yeah, you're gonna make them do it again or do it a different way because they deserve that monitoring because it's just not the same. — Diana Gouard, Product Lead, Neo, Ping Identity

For the CIO or fraud leader signing off on a verification stack, the design question is where step-up sits. Gouard said most banks she sees start with frictionless device and data signals, including silent authentication built on telco integrations, and graduate to a camera or document check only when a decision engine calls for it. The same passive signals, IP intelligence and confidence in a phone number or email, serve both point-in-time proofing and runtime risk decisions, she said, and teams sometimes mistake that overlap for duplication.

## NIST's revision 4 favors the methods Gouard wants

According to the National Institute of Standards and Technology, Special Publication 800-63-3, the Digital Identity Guidelines first issued in June 2017, was superseded by SP 800-63-4 as of August 1, 2025. NIST says the guidelines set technical requirements for identity proofing and authentication in federal systems and may be adopted voluntarily by nongovernmental organizations. Gouard said the new version highlights cryptographic verification, which she takes as a signal of where the industry is heading.

She is less satisfied with identity assurance level 2 as many practitioners know it. IAL2 focuses on particular forms of evidence, she said, and leaves out the context signals she considers essential, such as whether someone is verifying from North Korea or North America. A standard that layered that telemetry on top of the evidence check would look very different, Keithley agreed.

The broader analyst view runs in the same direction without touching the specifics. Gartner lists Digital Provenance and AI Security Platforms among its top 10 strategic technology trends for 2026, presented at the Gartner IT Symposium/Xpo by analysts Gene Alvarez and Tori Paulman. Gartner's list does not address fraud-prevention friction, mobile driver's licenses or NFC, so the case for those methods rests on Gouard's field experience and the NIST revision rather than on trend research.

## Paper IDs in India show why one method is never enough

Gouard said the biggest disparities in who can verify come from the documents themselves rather than from model bias, which she said Ping, as a Mitek customer, does not encounter in support tickets. In India it is common to print an identity document on plain paper and self-laminate it, and traditional document authentication performs poorly against that. Measured against a driver's license with real ID security features and a barcode, a printed document looks riskier even when it is legitimate.

Her fix is to supplement rather than replace. In India that means DigiLocker and the Aadhaar registry, where the country has invested in electronic identity, along with other eID programs and, as they come online, mobile driver's licenses and wallets. A verification program built on a single method will fail somewhere in the world, she said.

Ping has run its own version of this debate. Gouard said the company introduced identity verification on an employee's first day and at its help desk, and when some employees cannot pass the automated process, one option is to have them come into an office. HR's objection was that its staff cannot judge whether a document is legitimate; Gouard's response was that companies verified this way for years, and that the fraud Ping is trying to stop, state actors and candidates who outsource their interviews, is strictly digital, so showing up in person defeats it.

## Where a fraud leader should start

Asked what a fraud leader could change in the near term, Gouard's first answer is cryptographic verification: mobile driver's licenses in Google and Apple wallets and in state apps, and NFC reads of the chip in a document, which in the United States means the passport. An mDL check is a tap rather than a camera session, so it removes friction while narrowing error.

> Nothing is unspoofable. But the margin of a false positive is so much more narrow when you have a deterministic binary pass fail of these certificate checks or it doesn't. — Diana Gouard, Product Lead, Neo, Ping Identity

Procurement teams evaluating a verification vendor can ask a concrete question now: does the flow prompt for a mobile driver's license before it opens a camera? Gouard said Ping is investing in flows that prioritize that path first. Keithley noted that Europe has many NFC-enabled documents beyond passports, which widens the field for chip-based checks.

The signal Gouard points to is adoption. Multifactor authentication moved from one-time passcodes to passkeys across service providers, and she expects digital credentials to follow the same curve over years, on both the issuer side and the user side. When customers tap a wallet instead of photographing a card, and tellers stop adjudicating documents at the window, that is the change she says the industry should be watching for.

## Sources

- [NIST Special Publication 800-63-3, Digital Identity Guidelines](https://pages.nist.gov/800-63-3/sp800-63-3.html) (NIST)
- [Gartner Top 10 Strategic Technology Trends for 2026](https://www.gartner.com/en/articles/top-technology-trends-2026) (Gartner)
- [Identity Trends for 2026 & Beyond](https://www.pingidentity.com/en-us/docs/assets/4281-identity-trends-2026) (Ping Identity / Deloitte)

Tags: Mitek Systems, Ping Identity, identity verification, fraud prevention, mobile driver's license, enterprise security

---
Source: MarketScale, https://www.marketscale.com/industries/software-and-technology/ping-says-mobile-driver-s-licenses-cut-false-positives-better-than-document-scans. Published for AI indexing and citation; cite the canonical URL. Site guide for agents: https://www.marketscale.com/llms.txt
