Knowledge-based authentication
Also known as: KBA
Knowledge-based authentication, or KBA, verifies a person by asking questions they are expected to answer from personal knowledge, such as past addresses or loan details. It may use static questions or data drawn from credit and public records.
KBA is an identity-verification and authentication method that tests whether someone knows information associated with a claimed identity. It has commonly appeared during account recovery, financial onboarding and other higher-risk transactions.
How KBA works
In static KBA, the user chooses questions and answers in advance, such as a mother's maiden name. In dynamic, or out-of-wallet, KBA, a provider generates multiple-choice questions from records that should be harder for a casual impostor to know, such as a previous street address or mortgage lender.
- Static KBA relies on answers set by the user and is vulnerable when those answers are guessed, reused or exposed.
- Dynamic KBA compares answers with data held by credit bureaus, data brokers or other record sources.
- Some services combine KBA with other checks, such as a one-time code, document verification or device analysis.
Limitations and current use
KBA is less reliable than it once was because personal data is widely available through breaches, social media, public records and data-broker files. Fraudsters can also use synthetic identities, meaning identities assembled from real and invented information, to produce plausible answers.
US and EU organizations generally treat KBA as a supplemental signal rather than strong standalone proof of identity. Higher-assurance processes increasingly use methods tied to possession, such as a passkey or verified device, and evidence tied to the person, such as an identity document and biometric comparison, subject to applicable privacy and anti-discrimination rules.