Free guide: How to use AI in compliance
Back

KBA (knowledge-based authentication)

Updated September 18, 2026

Table of contents

KBA stands for knowledge-based authentication: verifying someone’s identity by asking questions only the genuine person should be able to answer, such as a previous address, the lender on a car loan or a mother’s maiden name. It was standard in US banking for two decades. It is now considered weak, because most of those answers have been exposed in data breaches and can be bought as fullz.

How knowledge-based authentication works

There are two kinds. Static KBA uses answers the user set up in advance, the classic security questions. Dynamic KBA generates questions on the spot from a credit file or public records, for example which of four street names the person lived on in 2015. Dynamic KBA was considered the stronger of the two because nothing had to be stored in advance; the weakness turned out to be that the underlying records were not secret either.

Why KBA failed

The questions assume the answers are private. After two decades of breaches, they are not: credit-file data, addresses, loan details and family names circulate in criminal markets bundled as fullz, and account-takeover crews pass KBA at a higher rate than the legitimate customer, who often forgets which car loan the question means. NIST’s Digital Identity Guidelines (SP 800-63A) dropped knowledge-based verification as an acceptable way to prove identity, and most regulators now treat it as a low-assurance signal at best.

What replaced KBA

Document verification with liveness: the person presents a government-issued ID, the document is authenticated, and a live capture is matched to its photo, evidence a breach cannot supply. Zyphe’s KYC software runs this against over 4,000 document versions from 213 countries and territories, with active liveness and injection-attack detection, and stores the result in the user’s own encrypted vault rather than a central database. A verified user can then reuse that result through the KYC Passport instead of answering questions again.

Where KBA still fits

As a low-assurance step-up for returning users on low-risk actions, or as one signal among several in a risk engine. Never as the primary check at onboarding, and never as the only gate on a password reset or a payout change.

Michelangelo Frigo Written by Michelangelo Frigo (Co-Founder at Zyphe) Reviewed September 18, 2026 Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

Knowledge-based authentication: identity verification by answering questions drawn from a person’s credit file, public records or pre-set security questions.

No, not as a primary control. The answers are static and widely exposed in breached data, so identity thieves routinely pass KBA. NIST’s digital identity guidelines no longer accept knowledge-based verification as a way to prove identity, and document verification with liveness has replaced it.

Compliance without the data honeypot

Zyphe verifies identity without holding your customers' PII. See it in action.

Book a demo