A global BPO recently rolled out password-less authentication to their entire team of 450,000 agents across 80 countries. It was implemented in just 6 months and sees over ten million authentications per week.
Congratulations to the team. They have an amazing system which provides multiple layers of defence against attackers trying to login as a user. It's fantastic.
But it's not Identity Verification
This solution solves one piece of the puzzle: ensuring that when someone tries to login to an agent's account it's definitely them typing at the keyboard. But that solution relies on one assumption: that the agent's identity was verified when they were hired. If there are any errors or gaps in identity verification it will be baked into their authentication solution forever.
How can a BPO be sure they've done everything possible to ensure they know who they're hiring?
Trust is a BPOs Product
Trust is a big deal in BPOs. In fact it's pretty much their product. You can't touch it, see it, feel it. It's an abstraction but it's represented in contracts, attestations, certifications, SOC 2 reports, questionnaires and answers. It's mentioned in HIPAA business agreements, employee handbooks, client meetings and RFPs. It's a promise.
Recently that promise has become even more important to enterprises. Clients are digging deeper and scrutinising BPOs to ensure that they can be trusted with sensitive data. Compliance requirements such as PCI DSS have raised the bar. Version 4.0.1 was mandatory from the start of 2025 and includes enhancements to controls around user management including targeted risk assessments, multi-factor authentication, automated monitoring of user behaviour and more.
How can BPOs respond to clients wanting reassurance around identity and access management? Many will proudly proclaim, "we run background checks". But could you take it one step further? Could you tell them, "We biometrically verify every agent's identity before onboarding, and we can produce the evidence per agent"?
Identity Verification in Contact Centres is Critical
Agents are onboarded at scale, often with minimal verification. High turnover and attrition means new employees are being hired continuously. Speed is key. Remote or work-from-home policies mean identities can't be verified in-person or checked for compliance as they roam the office. Agents may be given broad access to systems and data such as billing, identity flows, ticketing, and payments very early on (within days). All of this makes a contact centre an ideal target.
For example, it's claimed that in 2026 Adobe's third-party outsourcing partner for customer support in India allowed a bad actor access to 13 million support tickets. The attacker reportedly delivered a remote access tool by phishing, pivoted to a manager's account, and reached the helpdesk environment.
EY's research on call centre insider risk describes how agents facing financial pressure are recruited via social media to participate in schemes or hand over non-public information. Indicators include agents assigning cases to themselves to bypass normal authorisations, logging unusually long call times, or accessing more customer profiles than their role explains.
Complicit agent fraud is the mature version of this. But it gets worse, because why would an attacker try and recruit an employee when they could infiltrate the call centre and sit at a workstation from day one?! Recent raids in the US have exposed DPRK IT workers using stolen identities to apply for US-based remote jobs. Workers hid behind residential proxies, applied for jobs, and accessed company data.
Agents may be multi-jobbing which could lead to commingling of data. For example, an agent works for Company A, who outsource to Company X, and also Company B who outsource to Company Y. If the agent doesn't follow process and uses their home machine they could contaminate Company A's IP into Company B's network, if they didn't realise Company A and B both use Company X and Y. This might not happen today but could lead to data breaches down the track. Proxies could be used to mask multi-jobbing.
Why identity verification?
Identity verification may seem like a step above background checks but it's actually a lot less costly. Identity verification during the application process will save time and money. If an employee has been provisioned, trained, onboarded and then a background check reveals an issue, all of that time and money has been wasted. Identity verification can be automated and scaled to accommodate continuous hiring. It can provide a foundation of trust that gives peace of mind to leadership, agents, clients, and stakeholders.
Cerebrum specialises in identity verification ahead of onboarding. We provide the strongest, most flexible suite of identity verification solutions for organisations who want to verify people's identities for compliance, risk, or competitive advantage.
Want to learn more? Book a demo →
The compliance bar keeps rising
January's Notice of Proposed Rulemaking (NPRM) could result in the largest changes to the Health Insurance Portability and Accountability Act (HIPAA) Security Rule since its implementation in 2003, including annual attestations of technical safeguards and a proposed change to breach notification from 60 days to 72 hours. These changes would have an impact on business process outsourcing (BPO) companies, especially those who process protected health information offshore.
At the same time, security questionnaires continue to become more pointed. Personnel security and access management controls are core components of PCI DSS v4.0.1, SOC 2 and other compliance requirements and attestations, and are asked about frequently in RFPs and vendor assessments.
When responding to security questionnaires and RFPs, many companies will check the box and indicate that they "run background checks." Background checks are a good start. But what else can you say to convince clients that agents aren't DPRK IT workers on residential proxies accessing US-based data through laptop farms, and that employees don't have multiple jobs? How can BPOs stand out and differentiate themselves from competitors?
A great answer would be something along the lines of: "We biometrically verify every agent's identity before onboarding, and we can produce the evidence per agent." This answer communicates a few things:
- Agents are remote, but we've seen the person and their government-issued identification
- We have a process in place to verify agent identity, and can show evidence of identity verification if asked
- We've invested in identity verification beyond what's typically asked for
These points help BPOs win bids and provide comfort to clients that agents are who they say they are. Identity verification is a product that can be marketed. It's not just a risk mitigation strategy and compliance requirement.
Three questions, three controls
At Cerebrum, we've been asked how identity verification differs from authentication. Many of the controls in place to manage workforce identity conflate three separate controls that answer three separate questions.
- Who are you? This is identity verification and should happen before granting credentials and access. This is the overlooked control.
- Are you really you? This is authentication and happens at login. Companies have spent millions on strong, frictionless authentication like multi-factor authentication (MFA). These controls answer this question very well.
- Are you still you? This is user and entity behavior monitoring and happens after login. This area of identity and access management (IAM) has gotten a lot of attention recently and rightfully so. EY's recent publication on insider risk provides some helpful tips for call center monitoring, specifically EY on insider risk and safeguarding call centers.
While strong authentication and monitoring are important controls, they make an assumption that identity is properly established during onboarding. These controls are good at authenticating the wrong person. For example, MFA can ensure the person logging into an agent's account controls the phone, email, etc. tied to the account. But it doesn't answer the question of whether the account was created by a legitimate employee. This doesn't mean MFA and monitoring aren't valuable. It just means that identity verification is the control that isn't getting as much investment and should.
Adobe's recent BPO-related hack didn't involve a DPRK IT worker hired under a stolen identity. Rather, it involved phishing and access management issues. But it's an example of the amount of data and actions an agent's access provides. Access to billing systems, identity data and the ability to create tickets that others act upon means that agents need to be who they say they are. Agents are distributed and hired quickly, especially during peak season. Fraudsters are motivated to hire DPRK IT workers or recruit agents using fake job postings on social media. Agents may also engage in bad acts for financial reasons.
How can you implement identity verification?
Cerebrum is laser-focused on the overlooked control. Our platform isn't focused on passwordless logins or user and entity behavior monitoring, and doesn't seek to replace MFA or SSO. Cerebrum is about identity.
Our solution starts with vID, which answers the question: is this really you? Our video-based identity verification uses biometrics and liveness detection to make sure that the person being onboarded controls a government-issued ID. vID occurs before granting credentials or access. After establishing identity, Synapse helps with other forms of employee and customer due diligence. Wallet makes verified identity a portable asset to improve onboarding when agents leave your company.
A few pointers:
- Make sure your solution is modular. Identity verification and screening are different products. vID works stand-alone if you'd prefer to perform background checks elsewhere or leave certain checks out of scope. You may be hiring thousands of people per month and can't disrupt the onboarding funnel.
- Perform identity verification as soon as possible, ideally at application, not offer. This allows for quicker rejection of fraudulent job seekers and prevents spending money on background checks, training and provisioning.
- Document coverage matters. With more work-from-home agents and a focus on hiring globally, there's no office that agents report into, so make sure you're able to verify agents' government-issued IDs across the countries you hire in.
Subscribe to our newsletter to get the latest updates and news