Skip to content
Skip to main content
Payments & Banking Operational Explainer

Does a payment identify the person who made it?

Usually it identifies an account, card, wallet or service event first. Naming the person who caused it requires evidence of control at the relevant time.

Authentication identifies a completed step

Login, device registration, IP-related data, session IDs, beneficiary creation and password, biometric or one-time-code events can narrow the route. Successful authentication shows that the system's requirement was satisfied; it does not automatically identify who satisfied it or whether they understood the payment.

Build a converging attribution case

Compare provider records with device possession and activity, communications, CCTV, location, delivery evidence and witnesses. Consider authorised additional users, shared cards, compromise, coercion, remote access and scheduled transactions where facts support them.

Report account- or instrument-level activity where the evidence stops there. Move to personal attribution only when independent records connect the person, endpoint and event time.

The point to remember

Attribute the payment to its account or instrument first, then identify the human user through time-specific authentication, device and contextual evidence.

Reference: PAY-003Payments & Banking