Zyphe's Glossary
Our glossary page keeps you informed and helps you better understand key terminology and concepts related to digital identity and online security.
A
AML vs CFT CFT stands for Combating the Financing of Terrorism. What it means, how it differs from AML, why the two are regulated as one AML/CFT program, and what that changes operationally.
AMLID AMLID stands for the Anti-Money Laundering International Database, a secure information platform developed by the United Nations.
Account Takeover (ATO) fraud Account Takeover (ATO) is fraud where attackers gain unauthorized access to legitimate users' online accounts, compromising personal data.
Agentic compliance Agentic compliance is the use of AI agents that work a compliance case end to end, gathering evidence, resolving entities, drafting the rationale and proposing or executing a decision, inside limits a human sets and the law reserves. It differs from rules-based automation, which flags activity and leaves the whole investigation to an analyst.
Anti-Money Laundering (AML) Anti-money laundering is the framework of laws and controls that stops criminals disguising illicit funds. See what AML covers, the key rules, and how it works.
B
Bank Account Verification & Validation Service A bank account verification and validation service confirms an account exists, is open, and belongs to the claimed owner before money moves, cutting failed payments and fraud.
Bank Secrecy Act (BSA) The Bank Secrecy Act (BSA) requires financial institutions to report and track transactions to detect and prevent money laundering and terrorist financing.
Bot protection Understand Bot Protection, its meaning, benefits, and how it helps safeguard your website and apps from harmful automated bot traffic and attacks.
Business lien Understand what a business lien is—a legal claim by creditors on company assets like property, receivables, or equipment used to secure debts owed.
C
CIP (Customer Identification Program) A Customer Identification Program (CIP) is a US anti-money-laundering rule requiring financial institutions to verify the identity of every customer who opens an account. Mandated by Section 326 of the USA PATRIOT Act, a CIP must collect four data points, name, date of birth, address and an identification number, and verify them within a reasonable time after the account is opened.
CLARITY Act The CLARITY Act (Digital Asset Market Clarity Act, H.R. 3633) is the US bill that would split crypto oversight between the CFTC and the SEC and give registered exchanges explicit KYC and AML duties. It passed the House in July 2025 and failed a Senate cloture vote 49-50 on 15 September 2026.
California Consumer Privacy Act (CCPA) Explore the California Consumer Privacy Act (CCPA), a law granting California residents enhanced rights over personal data collection, privacy, and use.
Children’s Online Privacy Protection Act (COPPA) Understand the Children's Online Privacy Protection Act (COPPA), a U.S. law protecting data privacy for children under 13 on websites, apps, and services.
Compliance as a Service (CaaS) Compliance as a Service (CaaS), a cloud-based solution helping businesses meet regulatory requirements efficiently, reduce costs, and manage risks.
Customer Due Diligence (CDD) Understand Customer Due Diligence (CDD): how FinCEN’s rule helps financial institutions verify identities, assess risk & prevent financial crime.
D
Data Subject Access Request (DSAR) A subject access request (DSAR) lets a person obtain the personal data an organisation holds on them. Here's what it covers, the timeline, and how to respond.
Data breach Discover what a data breach is, how unauthorized access to sensitive data occurs, its potential impact, and best practices for prevention and response.
Deepfake Learn about deepfakes: AI-generated synthetic media that convincingly mimics real people, explores risks, ethics & detection methods.
Dirty money Dirty money is money obtained through crime, such as fraud, drug trafficking, corruption, tax evasion or theft, that cannot be spent or invested openly without revealing its origin. Money laundering is the process of turning dirty money into clean money: funds that appear to come from a legitimate source and can be used without attracting attention.
Document check Explore Document Check in KYC: verifying customer identity documents for authenticity and compliance to prevent fraud and financial crime.
Domestic PEPs Domestic PEPs hold prominent public roles in their own country. See how domestic PEPs differ from foreign PEPs, their risk, and the due diligence that applies.
E
Enhanced due diligence (EDD) Understand Enhanced Due Diligence (EDD): in-depth risk assessments, increased customer scrutiny & compliance measures combating high-risk financial crime.
eKYC Explained: How Electronic KYC Works eKYC (electronic Know Your Customer) is the digital, remote verification of a customer's identity using document capture, biometric checks, and database screening, replacing in-person KYC review.
F
False negative Learn what a false negative is: when a detection system fails to flag real threats, risks in compliance, and strategies to reduce missed cases.
False positive Learn what a false positive is: when a detection system wrongly flags legitimate activity as a threat, its impacts, and methods to reduce such errors.
FedNow Service FedNow Service: Real-time payment platform for U.S. banks. Glossary definition for instant payments and financial infrastructure.
Federal Trade Commission (FTC) The Federal Trade Commission (FTC) protects consumers and promotes competition by enforcing antitrust, privacy, and consumer protection laws.
Federated identity management (FIM) Federated identity management (FIM): Secure, unified access across organizations. Key term for enterprise security and compliance glossary pages.
Financial Crimes Enforcement Network (FinCEN) Financial Crimes Enforcement Network (FinCEN): U.S. bureau for AML and financial crime prevention. Glossary entry for compliance terms.
Financial Industry Regulatory Authority (FINRA) Financial Industry Regulatory Authority (FINRA): U.S. self-regulatory body for broker-dealers. Glossary term for financial compliance.
First-party fraud First-party fraud is fraud committed by a customer in their own name: applying for credit or an account with no intention of paying, misrepresenting income or circumstances, disputing legitimate charges, or abusing refunds and promotions. Unlike third-party fraud, no identity is stolen, so identity verification alone does not catch it.
Form W-9 Form W-9: IRS form for collecting taxpayer identification. Glossary entry for U.S. business tax and compliance terms.
Fraud investigations Fraud investigations: Process of uncovering and analyzing fraud. Essential glossary term for enterprise risk management.
Fullz Fullz: Complete stolen personal data set for ID fraud. Glossary entry for cybersecurity and financial risk terms.
G
General Data Protection Regulation (GDPR) General Data Protection Regulation (GDPR): EU law on personal data protection. Key glossary entry for privacy and compliance.
Generative AI fraud Generative AI fraud: Use of AI to create deceptive content for fraud. Glossary entry for cybersecurity and risk management terms.
Genius Act The Genius Act (2025) sets federal rules for stablecoins: full reserves, public audits, and legal protection for users if issuers fail.
Governance, risk, and compliance (GRC) Governance, risk, and compliance (GRC): Framework aligning business goals with regulations. Key glossary term for enterprise compliance.
Gramm-Leach-Bliley Act (GLBA) Gramm-Leach-Bliley Act (GLBA): U.S. law for financial data privacy and security. Glossary entry for banking and compliance.
Graph database Graph database: Database optimized for managing relationships. Glossary term for data analysis and fraud detection.
H
I
INFORM Consumers Act INFORM Consumers Act: U.S. law increasing transparency for online sellers. Glossary entry for marketplace compliance and risk.
Identity Assurance Levels (IAL) Identity Assurance Levels (IAL): NIST-defined levels of identity proofing rigor. Glossary entry for digital identity and compliance.
Identity and access management (IAM) Identity and access management (IAM): Controls user access to systems and data. Key glossary term for enterprise security.
Identity authentication Identity authentication: Verifying a user’s claimed identity. Glossary term for cybersecurity and access control.
Identity graph Identity graph: Database linking identifiers to a single user. Glossary entry for digital identity and fraud prevention.
Identity proofing Identity proofing: Verifying a person’s real-world identity. Key glossary term for onboarding and compliance checks.
Identity verification (IDV) Identity verification (IDV): Confirms a user’s identity at onboarding or transaction. Glossary term for fraud prevention and compliance.
Inherent risk Inherent risk: Risk level before controls are applied. Glossary term for enterprise risk management and assessment.
K
KBA (knowledge-based authentication) KBA stands for knowledge-based authentication: verifying identity with questions only the genuine person should be able to answer. Once standard in US banking, it is now considered weak because breached data makes the answers easy to buy.
KYB (Know Your Business) Know Your Business (KYB) is the process of verifying that a business customer is legitimate: confirming its legal registration and status, mapping its ownership structure, and identifying and screening its ultimate beneficial owners. KYB is the corporate equivalent of KYC and is required of regulated firms that onboard company customers.
KYC (Know Your Customer) KYC, or Know Your Customer, is how firms verify who their customers are. See what the KYC process involves, why it matters, and how it differs from AML.
Know Your Employee (KYE) Know Your Employee (KYE): Due diligence to verify employee identity and background. Glossary entry for internal risk management.
Know Your Patient (KYP) Know Your Patient (KYP): Verifies patient identity in healthcare. Glossary term for medical compliance and data accuracy.
Know Your Seller (KYS) Know Your Seller (KYS): Verifies legitimacy of marketplace sellers. Glossary entry for e-commerce compliance and fraud prevention.
L
Layering (money laundering) Layering is the second stage of money laundering, in which illicit funds already placed in the financial system are moved through a series of transactions, accounts, entities and jurisdictions to break the audit trail between the money and the crime. Typical layers include wire transfers between shell companies, conversions between currencies and assets, and loans a launderer makes to themselves.
Link analysis Link analysis: Technique to analyze relationships between data points. Glossary entry for fraud detection and cybersecurity.
Liveness detection Liveness detection is the check that confirms a real, present person is in front of the camera during identity verification, rather than a photograph, a screen, a video replay, a mask or a synthetic image injected into the capture stream. It is what makes a selfie-to-document face match worth anything, and it is tested against presentation attacks under ISO/IEC 30107-3.
M
Marketplace account suspension Marketplace account suspension: Temporary or permanent deactivation due to policy violations. Glossary term for e-commerce risk management.
Marketplace risk Marketplace risk: Exposure to fraud, non-compliance, or illegal activity on online platforms. Glossary entry for digital business risk.
Money Laundering Reporting Officer (MLRO) An MLRO is the person responsible for a firm's suspicious activity reporting. See what the role does, the legal duty, and the personal liability it carries.
Money mule A money mule is a person who receives money from a third party into their own account and transfers it onward, in return for a fee or because they have been deceived, so that criminals can move the proceeds of fraud or other crime without the funds being traced to them. Mules may be complicit, careless or genuine victims of a job or romance scam.
Money services businesses (MSB) A money services business (MSB) is a company that transmits or converts money: money transmitters, currency dealers and exchangers, check cashers, issuers and sellers of traveller’s cheques or money orders, providers and sellers of prepaid access, and most cryptocurrency exchanges. MSBs must register with FinCEN, maintain an AML programme, and report suspicious activity.
Multi-factor authentication Multi-factor authentication: Security requiring two or more credentials for access. Glossary entry for cybersecurity best practices.
O
P
Personally identifiable information (PII) Personally identifiable information (PII): Data that can identify an individual. Glossary term for privacy and data protection.
Placement money laundering Placement money laundering: First stage of laundering introducing illicit funds into the system. Glossary entry for AML processes.
Politically Exposed Person (PEP) A politically exposed person (PEP) is an individual entrusted with a prominent public function, together with their family members and known close associates. The position carries a higher risk of bribery and corruption, so regulated firms apply enhanced due diligence.
Progressive risk segmentation Progressive risk segmentation: Adjusts verification based on user risk profile. Glossary term for adaptive fraud prevention.
Proof of address (POA) Proof of address (POA) is a document that ties a person to a residential address, usually a utility bill, bank statement, tax letter or tenancy agreement dated within the last three months. Regulated firms collect it under customer due diligence rules.
R
S
Sanctions Sanctions: Legal restrictions on individuals, entities, or countries. Glossary entry for compliance and international trade.
Second-party fraud Second-party fraud: Fraud involving a legitimate user sharing their account with a third party. Glossary term for fraud types.
Secretary of State (SOS) filing Secretary of State (SOS) filing: Official business registration with a state. Glossary entry for business verification.
Securities and Exchange Commission (SEC) Securities and Exchange Commission (SEC): U.S. agency regulating securities markets. Glossary term for financial regulation.
Self-sovereign identity (SSI) Self-sovereign identity (SSI): Decentralized digital identity under user control. Glossary entry for identity management.
Selfie check Selfie check: Biometric verification comparing a selfie to an ID. Glossary term for identity proofing methods.
Single sign-on (SSO) Single sign-on (SSO): One login for multiple systems. Glossary entry for authentication and access management.
Smurfing in Money Laundering: Definition and Examples Smurfing is a money laundering technique that splits a large sum of illicit cash into many small transactions across multiple people and accounts to stay below reporting thresholds and avoid detection.
Social media profiling Social media profiling: Analyzing digital footprints to assess risk or verify identity. Glossary term for fraud detection.
Spear phishing Spear phishing: Targeted email scams impersonating trusted sources. Glossary entry for cybersecurity threats.
Stages of Money Laundering The stages of money laundering are placement, layering and integration. See what happens at each stage, why it matters for AML, and how each one is detected.
Strong Customer Authentication (SCA) Strong Customer Authentication (SCA): EU requirement for multi-factor authentication in payments. Glossary for payment security.
Structuring (money laundering) Structuring is the deliberate splitting of a large sum of cash into smaller deposits, withdrawals or transfers so that each one stays below a reporting threshold, such as the 10,000 dollar currency transaction report limit in the United States. It is a federal crime in its own right under 31 U.S.C. 5324, whether or not the money is criminal in origin.
Subject access request (SAR) Subject access request (SAR): Request under data laws for a copy of personal data held. Glossary entry for privacy and compliance.
Suspicious Activity Report (SAR) A suspicious activity report (SAR) alerts authorities to possible financial crime. Here's when to file, the thresholds and deadlines, and what it must contain.
Suspicious transaction report (STR) Suspicious transaction report (STR): Report filed for potentially illegal or suspicious activity. Glossary term for AML compliance.
Synthetic ID Synthetic ID: Fake identity built from real and fabricated data. Glossary term for fraud detection and risk management.
Synthetic fraud Synthetic fraud: Fraud using fake identities made from real and false data. Glossary entry for financial crime prevention.
T
The National Institute of Standards and Technology (NIST) The National Institute of Standards and Technology (NIST): U.S. agency setting technical and security standards. Glossary entry.
Third-party fraud Third-party fraud: Fraud using someone else’s identity without their knowledge. Glossary term for identity theft and financial crime.
Transaction monitoring Transaction monitoring is the automated review of customer transactions against rules and risk models to identify activity that may indicate money laundering, terrorist financing or fraud, generating alerts for investigation. Regulated firms must run it for the life of each customer relationship, and the alerts it raises are the main source of suspicious activity reports.
Types of Fraud A clear guide to the main types of fraud: identity, synthetic identity, payment, account takeover, APP and business fraud, and how each one is detected.
U
USA PATRIOT Act USA PATRIOT Act: U.S. law for anti-money laundering and security. Glossary term for financial compliance and regulation.
Ultimate beneficial owner (UBO) An ultimate beneficial owner (UBO) is the natural person who ultimately owns or controls a company, directly or through layers of intermediate entities. Most jurisdictions set the threshold at 25 percent of shares or voting rights, or effective control by other means. Regulated firms must identify, verify and screen every UBO before onboarding a business customer.
V
VAT validation VAT validation confirms a business’s VAT number is legitimate, supporting tax compliance and fraud prevention in cross-border trade.
Vishing Vishing is a phone scam where attackers trick unsuspecting victims into revealing sensitive info like passwords or bank details using fake calls.