Global fintech and funding innovation ecosystem

Category Archives: Digital Identity, Privacy, KYC, AML/ATF

Interac Adds Verified Identity To Kijiji Transactions

Apr 14, 2026 | NCFA Fintech Market Activity | Identity Privacy And Data Governance, Payments And Money Movement

AI Image identity verification for peer to peer transactions

Trust Layer Expands To Peer to Peer Transactions

On April 14, 2026, Interac and Kijiji introduce verified identity for marketplace users, bringing Interac Verified solutions into peer to peer transactions. The integration allows Canadians to confirm who they are dealing with before messaging, meeting, or completing a purchase.

Interac connects nearly 300 financial institutions and is used more than 20 million times per day to move money across Canada. Kijiji operates at national reach with more than 4 million live listings and over 1 million new listings added each month. This puts verified identity into a place where millions of transactions happen and trust issues show up most often.

Peer to peer marketplaces have historically relied on ratings and reviews. Those signals describe past behaviour, but they don't confirm identity. Verified identity addresses that gap directly. It confirms that the person behind an account is real before a transaction begins, reducing uncertainty in both high-value categories such as automotive and real estate and in everyday transactions.

Amanda Zeffiro, General Manager, Kijiji Canada:

“Integrating Interac Verified solutions to bring verified identity to Kijiji is how we raise that standard, giving Canadians the confidence to transact with people they’ve never met.”

Interac is rolling this out in stages and keeping identity verification in Canada. People can verify their identity today through participating financial institutions, using systems already trusted for payments. Later this year, a second option will let users verify with government-issued ID and a quick liveness check. This gives people different ways to verify depending on what they are comfortable with and the type of transaction.

Interac’s network already supports a large share of how money moves domestically, and this approach uses that same system for identity. At a time when data control is becoming more important, keeping verification tied to Canadian institutions carries weight with both users and regulators.

See:  LinkedIn Identity Checks Show The New Privacy Cost Of Trust

The benefits are clear. Verifying identity upfront can reduce impersonation and fraud, especially in higher risk transactions. It can also make people more confident when buying or selling. Over time, this kind of verification can connect more closely with payments and onboarding, giving platforms a more complete way to manage trust across the full transaction.

Talking Point

Interac is extending beyond payments into identity verification at scale. By placing verified identity before the transaction, Interac is positioning itself as part of the trust infrastructure that reduces risk and helps establish trust and therefore who can safely transact.


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

Bill C-25 Blocks Crypto And Opaque Election Funding

Mar 30, 2026 | NCFA Insight | Regulation And Policy, Digital Assets

AI Image Bill 25 no crypto donations

Canada Tightens Election Funding Controls

On Mar 26, 2026, Bill C-25 was introduced to amend the Canada Elections Act (download 45 page Bill C-25 PDF). The bill blocks third parties from accepting contributions made in cryptoassets, prepaid payment products, or money orders for partisan activity, election advertising, or surveys. If received, those funds must be returned, destroyed, or converted and handed to the Receiver General.

See:  US Financial Surveillance Report Shows Privacy in Crisis

Anonymous contributions are prohibited. Foreign sourced funds, property, and services are prohibited. Regulated expenses must be funded by Canadian individuals, with a limited exception allowing a third party to use its own funds only when prior year contributions are 10% or less of revenue. Disclosure also tightens. Once a contributor exceeds $200, reporting must include name, address, amount, and timing.

In practice, this closes most of the remaining paths for political money that cannot be clearly attributed.

Traceability Sets The Standard

The bill does not regulate crypto markets. It removes funding methods that make source of funds and identity harder to verify. Crypto sits alongside instruments that break clean audit trails.

This is consistent with how Canadian regulators already handle higher risk flows. When identity or intent cannot be confirmed, access gets restricted. That same pressure showed up in rules applied to donation crowdfunding platforms and in guidance on bitcoin ATMs, where operators are expected to treat even smaller transactions within a broader AML framework.

Political finance applies that standard without exception.

Where This Hits

This is a political funding rule, and doesn't apply to general payments or everyday crypto use.

See:  NCFA Response to FINTRAC’s ‘Knee Jerk’ Regulations Requiring Donation Crowdfunding Platforms to Register and Comply with AML/ATF Legislation

It does show how regulators act when attribution cannot be optional. Funding must be tied to identifiable sources, supported by records, and capable of audit.

Failures to meet that bar already carry real consequences. Major AML breakdowns at large institutions and advances in detection, including AI driven money laundering techniques and shell company structures, show how quickly expectations are rising.

Takeaway

Bill C-25 is focused on political funding. Money used in elections must be attributable, traceable, and tied to identifiable Canadian sources. Fintech and financial institutions dealing with Canadian election flows must be able to prove who sent the money, where it came from, and how it moved, otherwise they'll soon be under pressure.


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

Retail Identity Verification: Stopping Return Fraud and Theft at the Point of Sale

March 29, 2026

Image Unsplash, Priscilla Du Preez

Image: Unsplash/Priscilla Du Preez

Retail shrinkage — the industry term for inventory loss through theft, fraud, and administrative error — costs global retailers hundreds of billions of dollars annually. Within that figure, return fraud has grown into one of the most consistently underestimated line items. Unlike shoplifting, which is immediately visible and operationally disruptive, return fraud is quiet. It enters through the customer service desk, processed by a staff member under time pressure, usually accepted to maintain a positive customer interaction, and absorbed as a cost of doing business. Organized retail crime operations have identified this as a reliable revenue stream, and the scale of exploitation has grown accordingly.

The technology capable of changing this dynamic is retail identity verification: a systematic process of confirming the identity of customers at specific transaction touchpoints — most critically the returns desk — using automated document scanning rather than relying on staff judgment or paper-based log systems. When a fraudulent returner knows their identity is captured and matched against a return history database, the economics of the fraud change. The deterrent effect operates before any individual transaction is evaluated, and the audit trail it creates enables pattern detection that no manual system can replicate at the speed or scale required.

What is also important here is that return fraud does not operate in isolation. The same individuals and organized groups responsible for fraudulent returns are frequently responsible for the theft that enables those returns. Stolen merchandise returned for cash or store credit creates a clean revenue cycle for organized retail crime. That’s why identity verification at the returns desk intercepts not just the return itself but the downstream incentive that makes the preceding theft financially worthwhile.

What Is Retail Identity Verification?

Retail identity verification is the practice of confirming a customer’s identity at a point-of-sale or service transaction using a machine-readable identity document. In the returns context specifically, it means capturing the returning customer’s name and identity document details — typically via OCR, or Optical Character Recognition, the technology that extracts text from photographed documents — and recording that data against the return transaction in the retailer’s system.

In other words, it replaces the manual alternative — a staff member writing a customer’s name and address on a paper return form, or typing it into a terminal — with an automated scan that is faster, more accurate, and creates a structured, searchable record. The identity data captured is not used to authorize or deny the individual transaction in isolation. Its value lies in the cumulative pattern it reveals: a single customer attempting multiple no-receipt returns across locations, or a rotating group of individuals returning the same high-value items across store clusters.

Apart from this, retail identity verification in the age-restricted sales context serves a different but related function. Capturing identity at the point of sale for alcohol, tobacco, vaping products, or lottery tickets creates a documented compliance record that protects the retailer in the event of a licensing inspection or underage sale allegation. Thanks to this, a single scanning infrastructure can serve both loss prevention and compliance functions simultaneously, reducing the cost per use case when deployed across a multi-function retail operation.

The most widely used document capture methods are MRZ reading — the Machine Readable Zone, a standardized two-line strip at the bottom of passports and many national identity cards — PDF417 barcode scanning from the reverse of driving licences, and front-of-card OCR for documents without machine-readable zones. A capable retail scanning solution should handle all three, covering the range of documents customers are likely to present across the retailer’s operating region.

The Return Fraud Problem: Why Manual Controls Have Failed

Understanding why manual return controls consistently fail is essential context for designing an effective automated alternative. The failure modes are structural, not simply the result of inadequate staff training.

The No-Receipt Return Exploit

The majority of return fraud operates through the no-receipt return pathway. Retailers offering goodwill returns without a receipt — a policy designed to serve legitimate customers who have lost their proof of purchase — inadvertently create a channel through which stolen merchandise can be converted to cash or credit without any connection to the original transaction. From a financial perspective, restricting no-receipt returns too aggressively damages customer satisfaction and increases returns friction for honest customers. Capturing identity at the no-receipt return point resolves the dilemma: the policy can remain customer-friendly while the identity record creates the accountability that deters systematic abuse.

Cross-Location Fraud Rings

Organized retail crime groups exploit the siloed nature of most retail loss prevention systems. An individual executing multiple returns at different store locations generates no alert in any single store’s records, even if their cumulative return volume is clearly abusive. Identity capture linked to a centralized return history database changes this dynamic entirely: the pattern that is invisible store-by-store becomes immediately visible at the network level. These mechanics boost the detection rate for organized cross-location fraud without requiring any change to individual store return policies.

Staff Judgment Under Transaction Pressure

Return desk staff are typically trained to prioritise customer experience and process transactions efficiently. Challenging a customer on a suspicious return requires judgment, confidence, and a willingness to create conflict — qualities that vary significantly across individuals and that diminish under queue pressure. Automated identity capture removes the judgment element: the scan is a standard part of the process applied to every return, not a discretionary challenge that a staff member must decide to initiate. This positively affects consistency and removes the interpersonal friction that causes staff to avoid challenging transactions they should be questioning.

When Retail Identity Verification Makes the Strongest Case

Identity verification at the point of sale delivers its strongest returns in specific retail contexts. Here’s when the investment is most clearly justified:

  • High-value electronics and consumer goods retail. Electronics, gaming equipment, power tools, and premium beauty products are the categories most targeted by organized return fraud, because their high unit value makes individual return transactions financially significant and their resale market is robust. Deploying identity verification at the returns desk for transactions above a defined value threshold — or for all no-receipt returns — concentrates the deterrent where the financial exposure is highest.
  • Multi-site retail chains with centralized loss prevention. The full value of identity verification in a return fraud context is only realized when identity data is aggregated centrally and cross-referenced across locations. A chain with a single store gains a deterrent effect; a chain with fifty locations gains a network-level detection capability that can identify cross-location fraud rings within days of their first transactions.
  • Age-restricted product categories. Alcohol, tobacco, vaping products, and lottery ticket retailers face dual compliance obligations: age verification at the point of sale and, in many jurisdictions, identity capture requirements tied to licensing conditions. A scanning infrastructure serving both functions delivers compliance value across both regulatory frameworks from a single integration point.
  • High-return-rate product categories. Clothing, footwear, and furniture categories with inherently high legitimate return rates are also disproportionately targeted by wardrobing fraud — the practice of purchasing an item, using it once, and returning it as unworn. Identity capture combined with return frequency analysis can identify individuals whose return patterns are statistically inconsistent with legitimate shopping behaviour across this category.

What a Reliable Retail Identity Verification System Should Have

When evaluating identity verification solutions for retail deployment, pay attention to the following criteria:

  1. Multi-format document reading capability. You should look for systems that read MRZ strips, PDF417 barcodes, and front-of-card OCR text, covering the full range of identity documents customers are likely to present across the retailer’s geographic footprint.
  2. On-device processing with no cloud image transmission. Document images contain personal data. The system should process captured document data locally, returning structured fields — name, date of birth, document number — without transmitting raw document images to external servers. This is both a data protection requirement and a practical security measure.
  3. Centralized return history database with cross-location matching. The detection value of identity verification in a return fraud context depends on centralizing return records and querying that database in real time at every scan. You should attentively analyze whether the vendor’s architecture supports multi-site data aggregation and whether the query latency is low enough to avoid adding visible delay to the return transaction.
  4. Configurable alert thresholds by return value and frequency. Not every return warrants the same response. The system should allow the retailer to configure alert triggers — a specific number of returns within a defined period, a cumulative return value threshold, or a combination — that generate a staff notification or supervisor escalation rather than applying uniform scrutiny to every scan.
  5. EPOS integration with minimal workflow disruption. Typical integrations include direct API connection to EPOS — Electronic Point of Sale — systems, tablet-based standalone operation for dedicated return desks, and SDK embedding within existing retail management applications. It will be helpful to confirm that the integration path does not require modifications to the EPOS that would affect the primary sales workflow.
  6. Data retention and privacy compliance documentation. Identity data captured at the returns desk is personal data subject to GDPR and equivalent frameworks. We recommend confirming the vendor’s data retention policy, the legal basis for processing, and their approach to data subject access requests before deployment, as these obligations fall on the retailer as the data controller.

How to Implement Identity Verification at the Returns Desk

Implementing identity verification in a retail returns workflow requires attention to three dimensions simultaneously: the technical integration, the operational process design, and the customer communication approach. Neglecting any one of these dimensions will limit the effectiveness of the others.

Image Unsplash, Simon Hattinga Verschure person wearing pink shirt typing on gray laptop computer on desk

Image Unsplash, Simon Hattinga Verschure

Define the Scan Policy Before Deployment

Before any technology is deployed, it is crucial to define precisely when identity capture is required: all returns without a receipt, all returns above a defined transaction value, all returns in specific high-risk product categories, or some combination. This policy decision shapes the entire implementation — the workflow design, the staff training, and the customer communication. We recommend starting with a narrowly defined scope — no-receipt returns above a value threshold — rather than attempting to capture identity on every return transaction from the outset, as this allows the team to refine the process before extending it.

Train Staff on the Customer Communication Script

The most operationally sensitive element of identity verification at the returns desk is not the technology — it is how staff present the requirement to customers. A customer who understands that identity capture is a standard policy applied consistently to all no-receipt returns is significantly more likely to comply without conflict than one who perceives it as a personal accusation. Staff training should include a specific, practiced script for introducing the scan request, handling common objections, and escalating to a supervisor when a customer refuses. It will be helpful to role-play these interactions during training rather than relying on written guidance alone.

Communicate the Policy Visibly at Return Points

Displaying clear signage at the returns desk indicating that identity may be required for no-receipt returns serves two functions simultaneously. First of all, it sets customer expectations before the interaction begins, reducing the likelihood of conflict when the scan is requested. Secondly, it functions as a deterrent in its own right: a fraudulent returner who sees that identity will be captured may elect not to proceed with the transaction before any staff interaction occurs. Given this, the signage itself delivers measurable loss prevention value at zero incremental operational cost.

Conclusion

Return fraud and organized retail theft are not problems that goodwill policies and staff vigilance can solve at scale. The economics favour the fraudster in any system where returns are processed on trust, where no identity record is created, and where pattern detection requires manual cross-referencing of paper logs. Retail identity verification changes those economics by creating a structured identity record at the transaction point, aggregating that data centrally, and making cross-location and cross-time patterns immediately visible to loss prevention teams.

See:  LinkedIn Identity Checks Show The New Privacy Cost Of Trust

The implementation investment is modest relative to the shrinkage it addresses. A well-deployed system pays for itself within the first promotional season it covers by reducing the no-receipt return abuse that concentrates around high-value product launches and seasonal promotions. Apart from this, the compliance value it delivers for age-restricted product categories converts what might otherwise be a single-purpose loss prevention tool into a shared infrastructure investment with returns across multiple operational functions. Given this, retailers evaluating their loss prevention strategy should treat identity verification at the returns desk not as a future consideration but as a near-term priority.


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

OSFI and GRI Workshops Reveal What Regulated AI Needs

Mar 24, 2026 | NCFA Feature | AI Finance And Data Governance

AI Image Risks in AI Finance

OSFI And GRI AI Workshops Show What Regulated AI Needs

On Mar 23 2026, OSFI and the Global Risk Institute published the FIFAI II final report based on four workshops held between May and November 2025. More than 170 participants took part across banks, insurers, asset managers, fintechs, vendors, regulators, academics, and consumer voices.

The report confirms that AI adoption is here, citing 72% AI use at work in financial services and 75% organizational support for AI. While AI is already in use.  The real issue is what still limits its use in regulated decisions and customer outcomes.

The series covered four areas that affect operational, prudential, consumer, and system-wide risk at the same time. Full report and framework: FIFAI II final report and AGILE framework PDF

  1. Security and Cybersecurity workshop PDF
  2. Financial Crime workshop PDF
  3. Financial Stability workshop PDF
  4. Financial Well-being and Consumer Protection workshop PDF

AI Won't Spread At The Same Speed

One of the clearest takeaways is that AI will not spread across finance at the same speed. The first gains will come in internal functions such as fraud detection, surveillance, reporting, cyber defence, and operations. Those areas already have strong data, measurable outputs, and clearer accountability.

Customer-facing decisions are different. Underwriting, advice, product recommendations, and self-serve tools carry more pressure around explainability, fairness, consent, and complaints handling.

AI powered Canadian finance will likely grow faster in control functions than in customer-facing decisions.

Third Party AI Is No Longer Just A Vendor Issue

The report treats third party AI as more than a procurement issue. It highlights growing dependence on external providers for models, infrastructure, and data, along with limited visibility into how those systems work and who sits behind them.

It's important because a failure, outage, or change in access at one provider can affect more than one function at the same time. Fraud controls, underwriting tools, customer service, and risk monitoring can all be exposed together. The financial stability workshop adds to that concern by linking third party dependency to concentration and system level risk.

See: Inside the Feedback Loops Driving AI Failure

Banks, insurers, and fintechs will need stronger oversight of models and providers, better audit access, tested fallback plans, and clearer visibility into the wider supply chain behind key AI services.

Fraud Is Becoming Harder To Contain

AI is improving both offence and defence. The final report points to synthetic identity, deepfakes, voice spoofing, AI assisted cyberattacks, fraud as a service, and disinformation. It notes a sharp rise in deepfake attacks and growing concern about voice verification as AI voice cloning improves.

This reality changes the operating environment. Static controls lose value faster when attack tools get cheaper, stronger, and easier to use. Manual review and occasional rule updates will not be enough. Firms will need faster detection, stronger identity controls, better information sharing, and systems that can adjust while attacks are happening.

Weak Identity And Poor Data Still Limit What AI Can Do

Data problems come up across the whole series, but the larger issue is bigger than data quality alone. Weak identity and fragmented data still limit how far AI can go in regulated finance. The report points to inconsistent data, incomplete records, fragmented platforms, offshore storage concerns, and weak data lineage as barriers to both efficiency and safety.

See:  AI Agents Gain Identity and Wallet Access WCGW

The report doesn't mince words on identity. Canada still doesn't have a widely adopted secure digital identity layer. That leaves onboarding, authentication, consumer channels, remote work, and agent based systems more exposed than they should be. If identity and data remains weak, AI will keep working best in narrower internal use cases and face more limits in customer facing execution.

Board Oversight Has To Show Up In Real Controls

The final report introduces the AGILE framework as part of its overall findings, which stands for Awareness, Guardrails, Innovation, Learning, and Ecosystem Resiliency. The framework calls for stronger governance and oversight, stronger data and risk controls, continued investment in technology and talent, and deeper public private collaboration.

AI oversight cannot remain just at the strategy level. If AI is used in lending, fraud, underwriting, complaints, or customer recommendations, governance has to show up in controls, evidence, escalation, and accountability. In regulated finance, that's what turns AI use from experimentation into something firms can defend and scale.

What Financial Institutions and Fintechs Do Now

The workshop series points to a practical sequence:

First, identify where AI already impacts decisions and controls.

Second, separate the use cases that can scale now from the ones that still need stronger explainability and customer safeguards.

See:  AI Governance Gaps Exposed By Legal Leaders

Third, tighten vendor oversight before dependency grows further.

Fourth, invest more in identity, data lineage (origin and how it's used and updated), and real time fraud controls.

Fifth, show boards stronger evidence instead of high level claims and broad assurance language.

The report also carries a warning worth taking seriously. Firms that move too slowly can fall behind on productivity, resilience, and customer expectations while still facing external AI enabled threats.  One participant line stands out: “The biggest risk is not doing enough.”

Why This Matters For Canada

Canada’s national AI strategy work has focused heavily on trust, safety, and responsible adoption. That is necessary, but this workshop series adds something more useful for operators. It shows where AI use slows once it enters regulated finance: concentrated provider risk, weak identity, fragmented data, explainability pressure, fraud risk, and unclear accountability.

There's a call to action policy lesson here too. Canada doesn't just need AI ambition and adoption. It needs stronger execution layers around Digital ID, data governance, third party oversight, and information sharing if it wants regulated financial AI to scale beyond contained pilots.

The OSFI and GRI workshop series is useful because it takes a holistic approach to identifying and adapting to AI risks in finance. AI is already inside financial systems. The advantage now goes to firms that can prove control, trust, and accountability in live decisions.


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

Gilles Brassard Turing Award Puts Quantum Security In Focus

Mar 20, 2026 | NCFA Market Activity | Quantum Security And Digital Finance

Pixabay geralt, Quantum security

Image: Pixabay/geralt

Quantum Standards and Timelines Now Drive Financial Security Changes

On Mar 18, 2026, the 2025 ACM A.M. Turing Award recognized Gilles Brassard and Charles H. Bennett for foundational work in quantum information science, including the development of quantum cryptography. The award carries a $1 million prize and marks one of the highest global honours in computing.

See:  Google’s Willow Quantum Chip Breakthrough

Brassard’s work established early methods for secure communication using quantum mechanics, a field now directly tied to the future of encryption. While he didn't develop today’s post quantum standards, his research helped define how information can be secured against quantum-enabled attacks. That body of work went from advanced research to execution in August 2024 when NIST finalized the first post quantum cryptography standards for encryption and digital signatures used across financial systems.

As ACM President Yannis Ioannidis stated:

“Their work is an important foundation for the field of quantum computing and has fundamentally changed how we process, transmit, and secure information.”

Post Quantum Cryptography Enters Implementation

Post quantum cryptography (PQC) refers to new encryption methods designed to remain secure even if future quantum computers can break today’s widely used systems today, such as RSA and elliptic curve cryptography that currently protect payments, digital identity, secure messaging, APIs, and financial data.

On Aug 13, 2024, NIST finalized three post quantum cryptography standards and announced that organizations should begin transitioning to them as soon as possible. NIST states these standards support encryption and digital signatures used to secure electronic information, including financial transactions and sensitive data.

NIST also states that no one knows exactly when a cryptographically relevant quantum computer will arrive, but some experts estimate it could be possible in less than 10 years. That uncertainty increases the risk because encrypted data can be collected today and targeted for future decryption under the harvest now, decrypt later threat model.

Canada has already set execution timelines. The Canadian roadmap for post quantum cryptography migration requires departments to begin planning in April 2026, report progress annually, transition high priority systems by the end of 2031, and complete remaining migration by the end of 2035. Canada’s national strategy for quantum communication and cryptography states that advances in quantum computing could undermine current encryption and threaten digital systems and data security.

What It Means for Fintechs

For financial services, encryption now affects what gets built and what gets bought. Payments, identity, onboarding, APIs, messaging, custody, and long term data all rely on encryption that may need to be replaced or upgraded.

Quantum also reaches into blockchain based finance like stablecoins, tokenized deposits, wallet infrastructure, custody controls, and smart contract connected payment flows all depend on digital signatures and key management. NCFA’s earlier coverage of quantum safe stablecoins points to a market approaching US$250 billion and highlights how quantum safe controls are already being added to stablecoin settlement systems.

See:  Photonic $180M Financing Puts Quantum In Focus in 2026

Buyers are starting to ask direct questions. Where is encryption used in the product. Which parts rely on current standards. What is the plan to upgrade. These questions and decisions are part of core financial workflows now and show up across payments messaging, identity systems, API access, document signing, custody, and stored data.

Vendors that can clearly show where encryption sits in their systems and how they plan to upgrade it will have an advantage as requirements tighten.

In Conclusion

NIST standards are finalized and Canada has set migration timelines starting in April 2026, with high priority systems due by the end of 2031 and full migration by the end of 2035. That puts a clock on encryption used across payments, identity, APIs, messaging, custody, and long term data.


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

Treasury Reopens Crypto Mixer Privacy Debate

Mar 9, 2026 | NCFA Fintech Market Insight | Digital Assets And Policy And Regulation

Unsplash J K, Money laundering

Image: Unsplash/J K

Crypto Mixers Sit Between Financial Privacy And AML Risk

On March 9 2026, the U.S. Treasury released a report to Congress on innovative technologies to counter illicit finance involving digital assets under the GENIUS Act. Treasury says successful monthly transactions on public blockchains reached 3.8 billion in early 2025, up 96% year over year. Treasury also reviewed more than 220 public comments while preparing the report. Against that backdrop, the report goes on the record to say crypto mixers can support laundering and sanctions evasion, but they can also serve legitimate privacy needs on public blockchains.

Treasury doesn't overlook the enforcement case against cyrpto mixers, saying criminals commonly use mixing, bridging, and swapping to obscure transaction trails and frustrate investigations. Treasury links these techniques to ransomware groups, darknet markets, sanctions evasion schemes, and DPRK cyber actors. The scale of harm remains large.

See:  Tornado Cash virtual currency mixer sanctioned by the U.S.

Victims reported more than $9 billion in digital asset related fraud to the FBI in 2024, including $5.8 billion tied to digital asset investment schemes, up 47% from the prior year. Treasury also says DPRK cybercriminals stole at least $2.8 billion in digital assets from January 2024 to September 2025, including a $1.5 billion theft in February 2025 that Treasury describes as the largest digital asset heist to date.

Privacy Enters The Policy Record

The report states that lawful users may use mixers to enable financial privacy when transacting through public blockchains. Treasury gives practical examples. Individuals may want to protect sensitive information such as personal wealth, business payments, charitable donations, or consumer spending patterns from appearing on public ledgers.

That statement changes the tone of the policy debate. The question is no longer whether mixers exist only for criminals. The policy challenge is whether privacy tools can operate with sufficient accountability, recordkeeping, and supervision inside the financial system.

Treasury also notes that custodial mixers that accept and transmit value must register with FinCEN as money services businesses, maintain records, and file suspicious activity reports. When compliant, these services can provide customer identities, off chain transaction data, and behavioural information to regulators or law enforcement.

Treasury Says Stablecoins Are Inside The Laundering Chain

Treasury also describes how mixers interact with broader digital asset infrastructure. Stablecoins frequently appear in laundering chains when illicit actors transfer assets across blockchains or prepare to convert digital assets into fiat.

Read: FinCEN proposes new rules targeting crypto mixers

Since May 2020, Treasury says more than $37.4 billion in withdrawals from over 50 bridges were denominated in the two largest stablecoins by market capitalization. During the same period those bridges received about $1.6 billion in deposits originating from mixing services. Treasury says more than $900 million of those deposits flowed into one specific bridge that faced scrutiny for DPRK linked laundering (North Korea state-sponsored).

The Compliance Stack Needed

A large part of the report focuses on the technologies Treasury believes financial institutions should use to strengthen anti money laundering and sanctions compliance programs. Treasury highlights four priority tools: artificial intelligence, digital identity, blockchain analytics, and application programming interfaces.

Treasury cites FinCEN analysis showing about 1.6 million identity related BSA reports in 2021, equal to 42% of reports filed that year and tied to $212 billion in suspicious activity. Treasury says AI can help institutions analyze large datasets and reduce false positives, digital identity systems can strengthen customer onboarding and fraud detection, blockchain analytics tools can trace wallet activity across networks, and APIs can improve secure monitoring and information sharing.

Why It Matters

The next evolution of digital asset infrastructure will likely reward firms at the forefront of regulatory accountability that can distinguish lawful privacy from criminal abuse, strengthen identity and monitoring controls, and provide institutions with faster and more accurate compliance tools.


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

LinkedIn Identity Checks Show The New Privacy Cost Of Trust

Mar 4, 2026 | NCFA Fintech Market Insight | Regtech And Identity And Privacy

AI image digital identity and data trust ecosystem

Identity Verification Privacy And Consent Risk

On Feb 16 2026, an interesting post at The Local Stack conducted a recent LinkedIn identity verification analysis via a real user experience of a larger fintech issue: modern identity checks now collect far more than most people expect, and the privacy tradeoff is becoming harder to ignore as regulated onboarding expands across financial services, platforms, and digital marketplaces.

Persona’s identity verification policy shows the scale of that collection. The policy lists government ID images, selfies, biometric information, NFC chip data, device data, geolocation, usage data, and checks against third party data sources. It also states that uploaded ID images may be used to train or improve the service, and that information may be shared with service providers, data partners, affiliates, and government authorities in some circumstances.

Three Things Fintech Leaders (and Consumers) Need To Know

1. Identity verification now reaches well beyond document review. A current verification flow can combine document capture, face matching, biometric analysis, device signals, location data, and external database checks in one session. That means the onboarding event is no longer just a fraud control. It is a multi layer data collection workflow that carries legal, operational, and reputational risk.

2. The trust layer often sits with a specialist vendor, not the brand the user sees. A customer may think they are verifying with LinkedIn, a bank, or a fintech app. In practice, the verification is often run by a third party with its own privacy terms, data sources, subcontractors, retention rules, and model improvement rights. That gap between front end trust and back end processing is where privacy friction starts.

See:  AI Governance Gaps Exposed By Legal Leaders

3. Privacy design now affects conversion. When users feel overexposed, abandonment risk rises. Firms that explain what's collected, why it's needed, who processes it, and how long it's kept are more likely to keep trust intact through onboarding. In identity verification, transparency is becoming part of product design.

Trust First Onboarding Design

Map every data field in the verification flow, not just the front end prompts. Disclose which vendor runs the check and what that vendor can do with the data. Remove optional collection that doesn't improve the actual risk decision. Review training, retention, and subcontractor clauses in vendor contracts. Put the plain language explanation before the scan starts, not after the user has already submitted a passport and selfie.

These steps become more important as Canada moves toward broader data portability and consumer directed finance. NCFA has already covered the wider privacy backdrop in North America privacy trends and the policy direction in CSA data portability consultation. Canada’s consumer-driven banking framework and the Consumer-Driven Banking Act push the market toward safer, permissioned data sharing. As that framework matures, identity credentials may become more reusable across providers, which could reduce repeated document collection while increasing pressure for stricter consent controls, narrower data use, and clearer liability when verification vendors sit in the middle.

Where This Is Heading

Identity verification is moving from a hidden compliance step to a visible trust product. More onboarding flows will combine biometrics, device intelligence, and third party data. More enterprise buyers will ask whether vendors can use customer data to improve models. More regulators will look at whether the scope of collection matches the actual risk being assessed. The firms that win will not be the ones that collect the most data. They will be the ones that collect the least data needed to deliver a defensible result.

Talking Point

When identity checks collect more than most users expect, do the firms with the clearest privacy design earn more trust than the firms with the most aggressive control stack?


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter