KBA (Knowledge-Based Authentication)
An identity verification method that asks users questions based on personal information, such as past addresses or account history. It is commonly used in online verification flows.

KBA, short for Knowledge-Based Authentication, is a method of verifying someone's identity by asking them to answer a question only they should reasonably know the answer to. Think of the classic security question: a mother's maiden name, a first pet, the street someone grew up on. For years, this was one of the go-to tools banks and payment providers used to confirm that the person on the other end of a call or login really was who they claimed to be.
It's worth separating two things that often get lumped together under the same acronym. Static KBA relies on a pre-agreed set of shared secrets the customer set up in advance, like the security questions above. Dynamic KBA works differently, generating questions on the spot from a wider pool of personal information, such as a previous address or a recent transaction amount, without the customer having pre-selected anything. Both approaches share the same underlying idea: prove identity through knowledge rather than through something a person has, like a device, or something they are, like a fingerprint.
Where KBA Is Still Used Today
Despite growing scepticism about its reliability, KBA hasn't disappeared. It still shows up in call centre identity checks, password reset flows, and some consumer authentication processes, particularly where a faster, lower-friction option is genuinely needed and stronger alternatives aren't readily available. Plenty of legacy systems were also built around KBA years ago and haven't been fully replaced, so it persists in places even where it isn't the first choice for new deployments.
Why KBA Has Fallen Out Of Favour With Regulators
The core weakness of KBA is that the information it relies on often isn't as private as it once was. A mother's maiden name, a childhood street, a first school: much of this can be found through public records, social media, or a handful of previous data breaches. The US National Institute of Standards and Technology (NIST) made this concern explicit in its digital identity guidelines, stating that knowledge-based authentication is no longer recognised as an acceptable authenticator on its own, largely because attackers can often discover the answers with relatively little effort. That doesn't mean KBA is banned everywhere or automatically non-compliant in every context, but it does mean regulators and standards bodies increasingly treat it as a weak link rather than a dependable one.
How KBA Compares To Other Authentication Methods
Security professionals often describe authentication as resting on three possible factors: something you know, something you have, and something you are. KBA sits entirely in the first category, which is exactly why it's considered weaker on its own than methods that combine factors. A one-time code sent to a registered device adds a possession factor. Biometric checks add an inherence factor. Multi-factor approaches that combine two or more of these are generally considered more resistant to fraud than knowledge alone, since an attacker typically needs to compromise more than one type of factor to succeed.
What Businesses Are Moving Toward Instead
Many payment and financial services businesses have been shifting away from KBA toward document-based ID verification, biometric checks, or device-based signals that are harder to reconstruct from publicly available information. Some have kept a lighter version of KBA as one signal among several, rather than relying on it as a standalone gatekeeper. The general direction has been toward layering multiple weaker signals together, or replacing knowledge-based checks entirely with something that doesn't depend on information an attacker might already have access to.
KBA And Fraud Risk In Practice
Fraudsters engaged in identity fraud or account takeover have specifically targeted KBA because the information it depends on is so often available through data broker sites, leaked databases, or basic social engineering. A well-resourced attacker researching a specific target may be able to answer standard KBA questions correctly, which reflects a concern NIST's guidance addresses. This doesn't mean KBA offers zero value, but it does mean treating it as sufficient on its own, particularly for higher-risk transactions, carries real risk.
A Reasonable Way To Think About KBA Today
For lower-risk interactions, such as a routine password reset, KBA may still serve a limited purpose as one layer among others. For anything involving money movement, account changes, or sensitive personal data, most current guidance points toward pairing it with, or replacing it entirely with, stronger authentication methods. Businesses still relying heavily on standalone KBA for authorisation decisions are generally well advised to review that approach against current NIST and industry guidance rather than assuming a method that worked adequately a decade ago still holds up against today's fraud tactics.
Frequently Asked Questions
KBA is a method of verifying identity by asking a person to answer a question based on private information they should know, such as a security question or a detail from their personal history.
Static KBA uses pre-agreed questions the customer set up in advance, like a security question. Dynamic KBA generates questions on the spot from a wider pool of personal information the customer didn't pre-select.
Increasingly, no. NIST's digital identity guidelines no longer recognise knowledge-based authentication as an acceptable standalone authenticator, largely because much of the underlying information can be discovered through public records or data breaches.
Many businesses are shifting toward document-based ID verification, biometric checks and device-based signals, often combined with other factors rather than relying on knowledge alone.
Not universally banned, but current NIST guidance treats it as a weak authenticator on its own, and many jurisdictions and standards bodies now discourage relying on it as a standalone verification method.

Still Have Questions?
Let’s Find the Right Solution for You
Stay Connected with Us!
Follow us on social media to stay up to date with the latest news, updates, and exclusive insights!


