Account takeover vs onboarding fraud: different checks for different threats
Verification stops fake people getting in. It does very little against a real account being stolen. Know which problem each control solves.
Onboarding fraud
The threat is a fake or stolen identity creating an account. Source verification (PAN, GST, bank, Aadhaar-linked checks) is the right control, run once at signup and again at re-KYC.
Account takeover
The threat is an attacker logging into a genuine user account. Verification does not help here; the controls are strong authentication (passkeys, TOTP), device trust, session management, and alerting the real user on sensitive changes.
Do not confuse the two budgets
Teams sometimes over-invest in re-verifying identities and under-invest in login security, then get hit by credential stuffing. Map your fraud losses to the two categories and fund the controls accordingly.