This is Part 2 of a multi-part blog series: Live signals, bank implications, and building a complete control framework
In Part 1, we explored why the EU Digital Identity Wallet, whilst a meaningful step forward for identity assurance, it does not resolve the fraud challenges that sit within authenticated journeys. In this second part, we look at the role of live and contextual signals, what the wallet rollout means for banks in practice, and why an integrated approach to controls remains essential.
The role of live and contextual signals
Whilst the wallet provides a strong identity anchor, we have explored above that additional signals are still required to assess whether activity is trustworthy throughout a session.
The way to think about these signals is not as another checklist of fraud indicators, but as a running narrative of the journey. A payment, login or account change is rarely risky because of one isolated event. Risk emerges from the combination: what has changed, how quickly it changed, whether the customer has taken a similar path before, and whether the wider environment supports the story the session is telling.
- Journey continuity: whether the customer moves through the flow in a way that fits the purpose of the interaction
- Change velocity: whether new payees, new limits, new devices or unusual account actions appear in a compressed window
- Intent signals: whether the activity looks self-directed or appears to follow a pattern associated with pressure, coaching or scripted behaviour
- Control interaction: whether prompts, warnings, step-up checks or fallback routes are passed naturally or create further anomalies that need investigation.
The value sits in interpretation rather than collection. A single signal may only create noise; a sequence of signals can create a decision. That is why the operating model matters. Businesses need the ability to join signals across channels, apply them in real time, and decide whether the right response is to let the journey continue, introduce proportionate friction, route for review or stop the action altogether.
That operating challenge is growing. Industry research shows that 55% of organisations in EMEA and APAC expect fraud losses to increase in the year ahead [6], while many firms are still managing risk across multiple tools and fragmented processes. The issue is therefore not simply whether more data exists, but whether it can be turned into timely, explainable action.
This is also where the regulatory direction becomes important. PSD3 and the Payment Services Regulation point towards a model where fraud prevention is judged not only by the presence of authentication controls, but by the effectiveness of monitoring, intervention and accountability across the payment journey. In that context, live signals move from being a technical enhancement to part of the evidence base for responsible decisioning.
This is particularly relevant in a wallet ecosystem built around user control, privacy and minimised data sharing, where users share only the information required for a given interaction [2]. While this improves privacy, it also reduces the amount of contextual information available, making behavioural and environmental signals more important, not less.
Implications for banks
For banks, the introduction of the EU Identity Wallet should be seen as an enhancement to identity assurance and portability, rather than as a replacement for broader risk controls or a guaranteed improvement in end-to-end fraud outcomes.
In practice, that means identity, authentication, fraud and payments teams cannot operate in silos.
There is also a practical implementation reality as rollout will remain phased, with large-scale pilots, a common toolbox and national implementation work all running ahead of full deployment [7]. This creates a hybrid identity environment that banks will need to manage for several years.
Akif Khan, an analyst from Gartner® suggests that businesses take action: "Well first, I'd suggest finding out whether you fall into the category of one of the regulated entities that is legally obliged to accept the EUDIW from the end of 2027. If you are, then - like it or not - you have that deadline to work toward. If you offer services to citizens or customers, you'll need to start planning for how to incorporate the EUDIW into your processes." [8]
There is also a risk that focusing too heavily on compliance with the wallet requirements could divert attention from other areas where fraud is more likely to occur, particularly within authenticated and high-trust journeys.
Taking a more integrated approach allows institutions to benefit from stronger identity assurance while maintaining visibility and control throughout the customer lifecycle.
Where this leaves live behaviour and counter fraud signals
This is where the role of live signals becomes clearer. As explained above, they are not competing with digital identity wallets but complementing and enhancing them.
A high-assurance identity input is of course, valuable, but it becomes significantly more effective when combined with continuous assessment of behaviour, device and environment.
In that sense, the wallet strengthens who the user is — while live signals determine what the user is doing.
That becomes even more relevant in a wallet model built around selective disclosure and data minimisation, where less contextual data is available by default at the point of entry.
In summary
The EU Digital Identity Wallet is a significant step forward for digital identity collaboration and direction in Europe. It should make identity easier to use, more consistent across markets, and more trusted within public and private-sector journeys.
Its impact, however, should be understood in the right place. The wallet strengthens the foundation for proving identity, but the fraud challenges discussed above increasingly sit within authenticated journeys, where legitimate credentials, genuine users and completed authentication do not always mean the activity within them is inherently trustworthy.
That is why live and contextual signals remain central. As identity assurance improves, the focus shifts towards interpreting what happens around that identity, the way controls are passed and whether the session still fits the expected pattern.
The organisations that benefit most will be those that place the wallet inside a broader control framework, one that uses stronger identity assurance as a starting point but continues to assess risk throughout the interaction.
The wallet can raise the trust baseline, but it should not be treated as the end of the risk.
References
[2] EUR-Lex – Regulation (EU) 2024/1183 establishing the European Digital Identity Framework https://eur-lex.europa.eu/eli/reg/2024/1183/oj/eng
[6] Experian – Global Fraud Snapshot 2025 https://www.experian.com/blogs/global-insights/wp-content/uploads/2025/09/Global_Fraud_Snapshot_2025_V1_D8.pdf
[7] European Commission – EU Digital Identity Wallet pilot implementation and rollout materials https://digital-strategy.ec.europa.eu/en/policies/eudi-wallet-implementation
[8] Gartner – Analyst Take: It's Time to Start Paying Attention to the EU Digital Identity Wallethttps://www.gartner.com/document-reader/document/7995137
GARTNER is a trademark of Gartner, Inc. and/or its affiliates.