In-House Identity Teams Face Higher KYA Losses As Bots Rise
A PYMNTS Intelligence study found 53% of fully in-house identity teams recorded KYA incidents or losses, compared with lower rates for hybrid and external models as bot traffic increases.

Companies running digital identity verification entirely in-house are seeing a sharper exposure to bot-driven identity risk, PYMNTS reports, with 53% of those teams recording know-your-agent incidents or losses.
The gap is wide enough to make operating model a security issue rather than a procurement detail.
Firms using a mix of internal and external identity teams recorded KYA incidents or losses at 28.8%, while companies relying on external providers recorded 24.1%.
The finding points to a practical split: internal control can keep verification close to the business, but it may also leave teams carrying more of the burden when automated agents and adversarial bots probe onboarding and monitoring systems.
The figures come from a PYMNTS Intelligence study titled “How Enterprises Can Build a ‘Know Your Agent’ Defense: Digital Identity Verification in the Age of Bots,” produced with Trulioo.
The study surveyed 350 leaders in compliance, risk management, fraud, underwriting, supplier acquisition and merchant monitoring across global companies.
Bot traffic is not a fringe problem for those respondents.
Overall, 89.5% of organizations described bot-traffic management as a challenge, and 52.3% recorded an increase in bot traffic over the prior year.
That combination gives identity teams two linked tasks: they have to catch automated abuse while still letting legitimate customers, suppliers or merchants complete checks without unnecessary friction.
The trade-offs differ by setup.
Internal programs were tied to more direct KYA incidents and more onboarding friction.
External programs showed lower incident rates, but the source linked them to technology inconsistency and limits on expansion.
Hybrid-program data lowered the incident rate from the in-house level while still showing exposure to credential-based attacks.
For enterprises, the control path is not simply to outsource verification or keep it inside the company.
The study frames the harder question as how to combine verification accuracy, automation and layered defenses without turning identity checks into a new security gap or a barrier for legitimate users.
That makes KYA a governance problem as much as a fraud-control problem.
A team that centralizes identity work may gain visibility, but the incident gap shows that visibility has to be paired with bot-specific controls if the in-house model is to avoid the 53% incident level.




















