Interviews

Zac Cohen - Building the Next Generation of Digital Trust

Riley Hughes

·

·

3 min read

The Future of Identity episode 044: Zac Cohen – Building the Next Generation of Digital Trust

In this episode of The Future of Identity Podcast, I’m joined by Zac Cohen, Chief Product Officer at Trulioo, one of the world’s leading identity verification platforms. Having helped scale Trulioo from its earliest startup days into a global leader in identity verification, Zac brings a unique perspective on how trust, fraud prevention, reusable digital identities, and AI are reshaping the future of digital identity.

Our conversation explores how identity verification has evolved beyond simple compliance into a continuous trust problem and why digital IDs, agentic AI, and intelligent risk engines are becoming essential building blocks for the next generation of online experiences.

In this episode we explore:

  • Why identity verification is evolving into a broader digital trust problem and how reusable digital identities fit alongside traditional verification methods.

  • How enterprises can balance fraud prevention with seamless customer experiences by giving users multiple trusted verification options.

  • Why continuous risk monitoring, behavioral intelligence, and lifecycle-based verification are becoming just as important as onboarding.

  • How AI agents will transform digital identity and what organizations need to consider when verifying people, businesses, and autonomous agents working together.

  • Why global identity ecosystems require intelligent orchestration across countries, regulations, and digital ID schemes to simplify adoption for enterprises.

This episode is essential listening for anyone building identity, fraud, or trust infrastructure. Zac offers thoughtful insights into how enterprises can prepare for a future where reusable IDs, AI agents, and continuous trust all work together to create safer, lower-friction digital experiences.

Thanks for listening, and if you found this conversation valuable, share it with someone else working to shape the future of digital identity.

Learn more about Trulioo.

Reach out to Riley (@rileyphughes) and Trinsic (@trinsic_id) on Twitter. We’d love to hear from you.

Listen to the full episode on Apple Podcasts or Spotify, or find all ways to listen at trinsic.id/podcast.

Full Transcript

Transcript lightly edited for clarity.

Riley Hughes: Welcome to the Future of Identity podcast, a show that highlights the world’s most innovative digital ID ecosystems and the people behind them. I’m Riley Hughes, co-founder of Trinsic, and we help businesses accept dozens of digital IDs through a single integration. Today, I’m thrilled to be joined by Zac Cohen, Chief Product Officer at Trulioo. Trulioo is one of the most established names in global identity verification, and Zac has been a pivotal player within Trulioo since the very early days. He’s been a general manager, COO, and now is the Chief Product Officer, and so he has a unique vantage point into how the identity verification landscape has evolved over more than a decade. We covered a lot of ground, and we spent time in the weeds of digital trust, especially on how agentic AI is changing the game and on how agentic AI does not change the game, or in other words, what stays the same. We also talked about how eIDs and reusable IDs fit into the future that we are all entering and how it relates to agentic AI.

Riley Hughes: And if this is something that you’re spending time thinking about, I think you’re going to appreciate this episode. So now, on to my episode with Zac. Zac, welcome.

Zac Cohen: Riley, good to hang out. I’m glad to be here.

Riley Hughes: Me too. It’s great to have you on. I’m excited about this one because you’ve been at Trulioo since the very early days. I learned at the last Money20/20, we had a nice conversation at one of the happy hours about your journey there, and I thought that would be a good place to start. So I guess maybe walk me through the arc of, like, how you ended up at Trulioo and how really the market has changed in the decade since, and maybe speak to, like, what is it about Trulioo that has such staying power, both from the market standpoint, but also in, like, retaining you for this period of time, right?

Zac Cohen: I laugh with folks that it’s not just that I couldn’t get a job anywhere else, but I stay because it actually is a great place not only for me, but for anyone. But hey, long overdue for being here, so again, thanks for the invite. For me personally, I’ve been in fintech, regtech for 15 years now, and before that, I ran my own small businesses internationally. So when I joined Trulioo, we had two fantastic visionary repeat founders with super strong business minds, very familiar with data and how it works, and I was brought in to help run the day-to-day. And so most of the company reported to me from day one, and it’s just that journey of sort of scaling a hyper-growth company. So I think about… What it’s been like at this company for this long, people always ask me that. Wow, it’s like you’ve been there for over 10 years, and how do you stay?

Zac Cohen: The company’s been five different versions of itself throughout that time, and I think a lot of people experience this when they’ve grown from a small business to something larger and then scaling up, is that you have these different dimensions and different categories along the way that could be completely different businesses. They’re starting out in that product-market fit. You’re landing your first big customers, then you’re trying to scale pieces, then you’re looking at the next evolution of the market, and then how do you stay relevant? And two big things that really pull out for me is we’ve been able as a business, I think, to continue looking around corners and continuously taking on the hardest, most complex problems in the industry. And I think that that builds an incredible amount of trust with enterprise customers who see how you can help them consistently adapt and evolve to the changing environment and bringing new solutions that help answer the next set of tough questions.

Zac Cohen: I think the other big thing for me personally of why I’ve stuck around so long is I was the COO for a long time, and that was an incredibly exciting component. But I took over the product organization specifically and really fully about a year and a half ago. And if there’s one thing that I’ve seen, the best product people are ones that know how to execute at velocity. And if there’s anything that an operator, and especially I’m sure you can appreciate this as a founder, you’re all about how do we operate at velocity and do things well and set a plan and stick to it. But it’s also that element that’s underrated, which is can you take two steps forward and then one step to the side, and then two steps forward again at pace without moving backwards. And I think that those things have kept me engaged in the business, and I think it’s really what’s made the company and given it that staying power as it’s changed from super small startup, first enterprise customers, a product at scale and globally, and then along the way as we’ve evolved the system along with how the market’s changed.

Riley Hughes: I can relate, even though Trinsic is still at an earlier stage. We have been like five different versions of earlier-stage Trinsic. I think that’ll make sense, especially given how the market has changed. And one of the things that I wanted to ask you is just through your time, I think it’s fair to say you’ve seen identity verification, KYB, et cetera, via like data, documents, right? Obviously, on this podcast, it’s primarily about digital IDs and eIDs. And this is a really hot topic right now, especially in Europe and even in many other parts of the world. So talk to me about, like, what do you think is fundamentally the same with eIDs that is consistent with everything else that’s come before? And then to what extent are eIDs fundamentally different or require a different kind of mindset?

Zac Cohen: You know, when I think about how that market evolution has come, I think that a lot of people right now, because it’s so top of mind, are sort of eIDs is a huge change in the market, and it is. Or AI is a massive change in the market, and it is. And before that—

Riley Hughes: Wait, sorry, what was that one?

Zac Cohen: Like AI, just generally speaking, right?

Riley Hughes: AI, what is that?

Zac Cohen: Yeah, yeah, yeah, totally. We’ve got to take a shot every time we have to say it. Yeah. Biometrics, when it came in, you mentioned after data, that was a massive change. But I don’t think any of those have been the biggest change in our world that we operate in. I think it’s really that identity verification stopped being the product, and really trust became the product. Like 10 years ago when we all started, KYC was largely about, hey, what’s this one question I can answer? Like, who is this person, and are they who they claim to be? It was mostly a compliance-driven motion. You collect documents or identity data, what have you. You check sanctions and PEP screens, all that stuff, right? But now it’s really around, can you trust this person and how do we get at that? And I think to your point around eIDs, I think that it’s new and interesting and definitely a huge impact and evolution of the market. But it’s really driven by, is that a better way to trust that someone is who they say they are?

Zac Cohen: It’s a better trust infrastructure that exists, or at least an alternative path that we think is going to have staying power and have a lot of relevance for answering a really complicated problem. So that’s how I think about those changes in tools. And I don’t know what’s going to be coming next after that, but I think we definitely see that no matter what the road that we take, it’s really all about how do we get to a trust factor? And to me, that’s the biggest market differentiation over that time that’s happened.

Riley Hughes: That makes sense. When I think about all the different waves that have come — documents, biometrics, data, etc. — these are all signals or sources or inputs into this overall trust equation. Digital IDs kind of fall into that same thing. They’re another input into that equation. How do you think, if anything, they differ, right? Like if I’m an enterprise customer or something and I’m thinking about this, what do I need to understand about eIDs to understand where they are fundamentally different than what I’m already familiar with?

Zac Cohen: Yeah. I think the first thing that always comes to mind is that it’s a prescriptive regulatory requirement. Listen, that’s our world, and that’s why we innovate, right? You innovate alongside two pieces, right? We innovate along regulatory requirements, but then we also innovate against fraud prevention. And so those are the two dimensions that I see how eIDs are very different, right? The first is that there has been a huge push, as you very well know and how you’ve taught me a lot, around what the regulators are thinking and why they’re building this kind of infrastructure. And we all know that it’s going to be required that regulated entities provide this as an option for users to be able to use. And so that’s how they’re very different. There’s different prescriptive onboarding and identity verification and authentication methodologies globally. Canada has a piece, Europe has a view, APAC has a view, everywhere has a different view. But very rarely is it prescriptive to the point of you must enable this kind of capability, and it has to be along these standards.

Zac Cohen: So that’s interesting, and that sounds different. The other piece that sounds very different as well, I think, is really just the fraud prevention mechanisms that are embedded within an eID. And I think that it answers a different question. It provides a different level of both security and authentication. And it’s also used in a way that is, I think, interesting not only at the onboarding component, but along the lifecycle and interactions of the user with a service. We recently launched the technology around device intelligence. So, hey, we can know if the cell phone that you’re using as you’re logging in and interacting with these services, has it been torn down 10 times? Is it within the vicinity of 100 other phones? Is it mirrored? Is it masked? All those different kinds of signals to understand, hey, is this a high-risk device that’s being interacted with? That can be used on KYC, on KYB, at point of enrollment, across authentication, throughout the whole lifecycle.

Zac Cohen: And I think that eIDs is also a really interesting dimension for that from a fraud prevention perspective and how they’re unique and different from maybe other kinds of biometrics, which you could deploy in those same ways. But eIDs is a special flavor of that. There’s obviously some technical differences as well for those that understand it, and I think that’s a piece. But really, when you’re thinking strategically and from a user experience, to me, those are the two big differences and why they’re effective.

Riley Hughes: Yeah, that makes sense. I have this mental model that I’d love to get your feedback on. Tell me if you think this is roughly how you see the world as well. But it’s interesting that many of these prior generations of technologies are fraud prevention tools in the sense that they can kind of help you detect bad behavior, or phones in a farm of phones, right, or masking, or these kind of things. Whereas digital IDs often are less about detecting bad behavior and more about allowing good users to assert some evidence of their authenticity, right? And if we assume for a moment that enrollment into a digital ID is super duper airtight, right, then fraud prevention becomes more about the users who don’t have a digital ID, right? Does that make sense where I’m going? And how do you think about this? Are these different, or are they not actually as different as I’m thinking?

Zac Cohen: No, no. Listen, I have a ton of empathy for compliance and risk professionals because I think we see their struggle every day between growth, fraud prevention. They’re thought of often as the blockers of a digital onboarding program and of successful customer onboarding and experiences. But I think that they can be an absolute growth engine. We help them translate these complex risk challenges into growth opportunities. And so from that perspective, what you’re saying and what we encounter a lot is actually like, hey, listen, stopping the bad applicants and bad actors is an incredibly important piece, but eliminating friction and creating the easiest happy path for good users is equally important, but often forgotten. And so I agree. I mean, I think that eIDs provide a very advantageous opportunity for letting the good onboarding users onto the platform faster and easier.

Zac Cohen: And frankly, when you go to high-density markets where eIDs are synonymous with any type of interaction with a digital service, Singapore, right, some of the bank ID markets, those kinds of places, they use those IDs for everything. It’s not just for opening up an account. There’s a variety of authentication components for everyday usage of tools and behavior and activity because it’s exactly that, because it makes it easier for good users to demonstrate who they are in a seamless way. And the other thing that’s really interesting about them from that perspective is also you get to choose almost how much you share. And so there’s a data limitation factor that’s also advantageous because, frankly, oftentimes the least amount of PII, the better for organizations that are handling that kind of information regularly.

Riley Hughes: One other thing I wanted to kind of double-click on that you mentioned is you brought up the device intelligence aspect, and I know a lot of the offerings, even outside of that, that Trulioo offers enable a more continuous paradigm for building trust in a user as opposed to just a one-off, upfront onboarding transaction or something. I wonder, how does that apply in a world of digital IDs, right, where the user’s in the loop explicitly, right, and, like, the user needs to consent to share their information somehow, right? And I imagine that users aren’t going to want to, like, continuously get redirected out to their eID wallet and, like, consent every time, or, you know what I mean? So the one-off nature or the one-time nature of a sharing of a digital ID, how do you think that relates to the kind of continuous nature of trust building in a profile over time?

Zac Cohen: Yeah, well, I mean, first of all, I think we all know how critical ongoing monitoring, so to speak, is to the whole trust connection between a user and the service that they’re offering. There’s been tools in the market for a long time that say, hey, this user’s acting a little bit differently. What does that mean, and should we take a further step-up action, or is this a sign of ATO or some kind of other fraud technique? And frankly, my answer to that is, and what I’ve seen thus far is actually quite similar to what is traditionally known as a risk-based approach. And I think that you’re right. Just like you wouldn’t want to force someone to re-verify themselves every time they’re interacting with a service before eIDs, or in markets where those aren’t necessarily widely adopted yet, I think it’ll be the same thing when it is highly adopted, is that it will be totally dependent on what kind of behavior and what kind of activity that user is showing.

Zac Cohen: Trulioo, since I’ve taken over the product and as a company, we’ve really pushed to transform who we are from a sort of a KYC or KYB verification company at onboarding to a full, like, risk intelligence engine across the entire customer lifecycle. And the reason is because that’s a much more effective methodology for fraud prevention and financial crime. And so I don’t think it’s that overcomplicated for eIDs. You’re right. You want to make sure that the user is only asked to take the action that’s required and needed based on what activity they’re presenting or wanting to do in the service, and also to take a look at all the other signals along that evolving lifecycle and consolidate them into a context engine that says, hey, this is normal behavior or it’s not. And if it’s not, let’s do some step-up activities. And if it is, we can do a minimal sweep in terms of how they’re interacting with the service versus a verification or authentication layer, is how I’ve seen organizations approach it thus far, and it’s frankly what I would recommend as a best practice regardless.

Riley Hughes: This is a good segue into something I wanted to ask you about. You taught me this new acronym, AI, earlier. But in all seriousness, right, when people historically maybe they interacted with a service via their browser, and then they started interacting with the service via mobile, right? Now there’s a new interface or a new avenue for users to interact with a service that is new and unique and probably doesn’t have a decade of training data about what is normal versus anomalous. Every three months there’s a new model that might behave differently than the last model, and so inherently there’s going to be some new behaviors showing up every three months with new generations of things. How does this Paradigm we’re talking about, about ongoing trust over time in a user. Help us enter this new world, and what is that going to look like?

Zac Cohen: You know, it is really the most important unsolved question in identity right now is when—

Riley Hughes: I was hoping you had the solution.

Zac Cohen: Yeah, right, I know. We’re getting there, getting there. But it’s a reality, and it’s a pretty agreed-upon crystal ball, is that we as individuals will no longer be the main or the only purveyors of our own identity, right? We will be having agents or other AI technologies, whatever they become next, to run operations for us. To, hey, I’m a gig economy worker. I want to go offer my services on five platforms. Go do that so I don’t have to do it each time myself. I want to open up two new bank accounts. Go find me the best ones and start that process for me. So those kinds of operations are going to be pervasive in the digital economy very soon. I mean, I know everyone sort of defaults to, hey, go buy me a new pair of Nikes or what have you, but in my mind, I think the more challenging ones are going to be those kinds of solutions and businesses themselves for their own operations when they have agents completing a variety of transactions, signing contracts, initiating payments on your behalf, all of those kinds of things.

Zac Cohen: And so I think when it comes to eIDs or any kind of identity, right, we are looking at a scenario where there is a wallet on a device, there is a wallet on someone’s interaction or the service that they’re using, and that will be a collection of their own identity information and other credentials or components that will be needed to actually transport it and validate it by a third party or even the own third party’s agents, and how does that A to A actually end up working? Who’s liable when things go wrong? These are all the frameworks and questions that people are wrestling with right now, and there’s been a lot of work, I think, on closed garden ecosystems for transactions around purchasing. But all the ones that we wrestle with a little bit more around, hey, how do we know that that agent is part of you? How do we know they represent you? How do we know that code hasn’t changed over time? How do we know that you actually asked them to take that action is a really interesting… solution.

Zac Cohen: But what I will say is, the more digital attributes and high assurance systems we have in place, the easier it will be for those to actually connect and communicate effectively. And so I don’t know if it requires data, eIDs, or next frontier. There’ll probably be a collection and combination of everything. But an agent isn’t going to necessarily, like, somehow pop out in real life and hold your phone up and take a picture of your biometric, right? We’re going to need some other solutions that come into play that interoperate well with those systems when they are needed. And I don’t personally believe that it’s a zero-sum game, and I don’t personally believe that it’s going to be everyone doing the same thing everywhere. I think we’ve already seen that the world is a patchwork of different solutions and environments and people and behaviors of consumers. Either one of us is a good example of that. And so you’ll need a bevy of different solutions to approach it the right way. But I think it’s where a lot of investment is going. Trulioo is looking at the problem really closely.

Zac Cohen: We’re building a variety of tools and POCs with large issuing banks, large platform providers to help solve that equation. But it’s a fun time to be building, that’s for sure.

Riley Hughes: Yeah, there’s so many foundational procedures and systems that are embedded deeply into everyday workflows that just get kind of upended in this brave new world where everybody has agents. But one area that I think it seems to me like we can borrow from, and I wanted to ask you about, is the KYB world, where You know, businesses have agents acting on behalf of them all over the place already, right? I’ve seen a few of them walk past you, behind you, in your background, right, who every day act on behalf of Trulioo externally for various things. They might agree to terms of service with places, right? They might spend money on behalf of the company. They might hire other people on behalf of the company. And agent to employee is not a perfect analogy, I’m sure, but maybe speak to, like, what is similar and how do these differ, and, like, what lessons can we learn from, like, that KYB world and, like, what works there that can apply and kind of help us reason about what this KYA world, or know your agent world, will look like?

Zac Cohen: Yeah, it’s a super interesting thing to map because what I’m building a lot in KYB is a direct reflection of how I saw KYC evolve over time and the most effective tools that emerged as that industry matured. And so the challenging thing with KYB that’s different a little bit for people is we house an enormous amount of business data in-house. We refresh it against all the registries every minute, every hour. We have a huge amount of proprietary business data because it allows you to make insights and intelligence layers and graphs and models that are much more effective than just, you know, calling things in real time. And it’s fascinating when you actually house that data for a long period of time, the amount of change that a business undergoes from, like, point A to point B over a course of a year is actually immense. As individuals, we might change our address once every, what, I don’t know, like three, four, five years. Might get a new phone number every now and again, although nowadays it’s rarer. We might change our last name once in our lives, maybe twice.

Zac Cohen: Very little change, right? The behavior is what changes. In a business, the actual, like, makeup of the business changes dramatically over time, whether it’s firmographic information, location information, ownership information, and their behavior is another dimension that also changes over time. So what I learned very quickly, and what we’ve built and I’m very proud of, is having that insight into the global aspect of businesses and how their makeup changes over time and those complex relationships is allowing us to build the world’s, I think, most effective business fraud consortium. And that’s something that we know as consumers, and we don’t have today in businesses to a high degree. And so it’s something that I’m really excited about. Now, being savvy about that and mature in that road, how does that relate to some things that we see in KYA?

Zac Cohen: It’s again like a whole new mode around what are the different signals that you want to be looking at to identify an agent in the right way, and then what are those different kinds of changes in agent behavior that would alert us to risk or fraud. False positives is a huge issue across like a variety of these tools, right? Whether it’s AML, whether it’s consumer, whether it’s business, agents will be no different. And so I think the biggest learning we’ve had as we’ve been building our KYA solutions, our Know Your Agent solutions, is understanding like what are the fine-tuned nuance between agent to agent, between system to system, so that you can identify those and really start monitoring those to create your models and your graphs around that’s normal behavior and that’s irregular behavior. And how do you create a system where you can compare those, where you can alert those, and where you can track those. And again, I think anyone that tells you that this is a solved problem for agents is trying to raise money or sell you something.

Zac Cohen: But there are a lot of cool solutions being built right now that I think map to that same complexity that KYB really unraveled around, hey, these are different things you need to look at, and it’s a different way to look at it. Whether it’s going to be the IP trails, whether it’s going to be a registry of agents, whether it’s going to be the instruction commands that the user gave, the prompts, like whatever it is, it’s going to be different than KYB, and you need to have a holistic view such that you can start making better determinations and recommendations for decisioning. And that’s really where it comes down to. And the players are unique and the situations are unique, but that’s where the world is going. And so there will be solutions that come on the market that will effectively answer it, but it’s going to take some time.

Riley Hughes: It strikes me that this like KYABCs, right? Like KY agent, business, consumer, or something, right? Or customer. Are these really different letters? or are these really just like—like imagine a B2B invoice that you’re paying or something like that, right? You’ve got, like, an agent, maybe they’re using my, like, bank’s MCP to, like, actually release the authentication, but there’s a person there who’s authorized that, and they’re acting on behalf of a business, right? So there’s, like, agents, humans, and businesses that are all intertwined in bespoke and complicated ways that differ by use case, right, with different risk profiles in all these different scenarios. And I wonder if these things become more specialized, or if actually the reverse happens, where somehow these things become more generalized, and it’s just an engine that uses the right tools at the right points in time to get the job done. I don’t know. I wonder how this all evolves, given that the lines between what is delegated authority—is it delegated to a person or a bot or whatever?

Riley Hughes: These lines are blurring, it feels like. So I don’t know. What are your thoughts on that?

Zac Cohen: What’s super interesting about that—two things. One of the biggest reasons why our KYB solution is so effective is because we interlay all of—like, owners of a business are just people. So there’s a huge amount of KYC and fraud prevention of people that unlock what the risk profile of a business is. And not only that, but, like, the actual compliance obligation to verify a business is verifying the owners in many jurisdictions. When Trulioo transformed more to, like, risk intelligence tools and really driving signals for decisioning and recommendations, It was all about consolidating the signals from KYC and KYB, and then you’re absolutely right, now from KYA. If you’re running one in a silo, you’ll never actually have the full connectivity, and it will always be a weaker solution than looking at all those different things. And so you’re absolutely right. I think of it in exactly the same way. You’ll need specialized tools, and there’ll be nuanced use cases and deployment techniques, obviously.

Zac Cohen: But all of those signals should feed a single engine to get a holistic view on activity, behavior, and risk. And that’s exactly what we’ve seen on our journey in transformation from just, like, verification at onboarding to intelligent signals across the entire journey of the lifecycle. That’s the first thing. So absolutely, I couldn’t agree more. Those signals do need to consolidate and be shared across an entity’s or organization’s different motions and activities. The second thing I really noticed is there’s no shortage of what I’ll call a control surface where they are, hey, listen, I want to be a centralized engine where I push all of these different signals into so I can actually build some rules around it, build some alerting around it, build some workflows around it. And listen, they’re great organizations and they have a huge amount of value.

Zac Cohen: But what I’ve seen from my vantage point is that having proprietary access to those tools in the sense of building these kinds of functionality yourself as an organization and really touching the data, living on top of the signals, driving those motions, provides a level of visibility that is really unmatched when you combine that with the AI agent and AI technology that we have at our disposal as builders, as technology builders today. And so being a little bit removed from that and just sort of focusing on the workflows and the engines, again, important piece, but you lose a lot of that signal alpha. That you get when you’re actually in the middle of those transactions and helping facilitate the motions. And so the intelligence that we can siphon off of those interactions and those consolidated shared signals across those different activities is, I mean, we’re just getting started on this journey, right? But it’s fascinating.

Zac Cohen: And when you layer in like an agentic infrastructure for context, for pattern matching, for canceling the noise, like you were saying, and for really fine-tuning a context-driven decision based on the data fabric layer and the activities, it unlocks a huge amount of operational automation, but also just fraud prevention tooling. And again, we’re on the cusp of this wave, but it’s a really exciting time. And I think you hit the nail on the head in terms of you need to look at these things as different pieces of the same whole system. Absolutely.

Riley Hughes: Yeah, I appreciate that. Where I think it’s a helpful framing to think about Trulioo as like a holistic engine or risk intelligence and how you’re describing it. If we maybe take a step back, right, think back maybe five years ago or something like this, you’re looking at the reusable identity space. You’re looking at the very early, like Louisiana just launches a mobile driver’s license, right? One of the first ones. And there’s like the bank IDs in the Nordics, and there’s like little emerging eIDs in other European countries, right? You’re seeing this stuff emerge. Maybe there’s decentralized identity, self-sovereign identity companies like Streetcred ID, which was our name before we rebranded to Trinsic, right, that have wallets, right, and verifiable credentials. And it’s all going to be standards-based, and it’s all going to be whatever. Think back to that era. And then think through to now, which I know Trulioo’s position on digital IDs and how they interact with this holistic model of risk that you’re talking about. But fill in the gaps for me of in between.

Riley Hughes: The common narrative, like five years ago or something, was this is going to cannibalize identity verification companies.

Zac Cohen: Yeah, this is like a risk or a threat or something.

Riley Hughes: What has your journey been like? And what’s your experience been internally at a major identity verification company like Trulioo? Like, what has the narrative been? Did it start out scary and then now look like an opportunity? Is it still an opportunity and scary? What’s been the arc, and how do you think about it now?

Zac Cohen: Yeah. Well, I mean, Riley, listen, I’m a fan of what you build. I’m not just saying that because you invited me. on the podcast. We think what you’ve done and what you’re doing is phenomenal and a super important network, like a super important bridge and web for organizations to actually take advantage of the benefits of reusable IDs and eIDs and the like of it. And honestly, I think that adoption—it was really interesting watching the European Union come out and they’ve done these pilots to really try and drive the standardization and the delivery of the wallets and the EUDI, et cetera. But what I first really noticed the difference between their motion and what I think was originally started was self-sovereign ID, reusable ID. All these things are cool technologies, but the use cases and the drivers behind them that would enable an actual demand was limited. It was cool, but hey, the regulator wouldn’t let you do it. Bank A is never sharing data with Bank B. And the utility of having an eID was cool, like now what do I do with it, right?

Zac Cohen: What I think’s been really interesting now is they’ve actually been really solidifying the value driver for a user and for a consumer to have that past just fraud prevention. Because as most users, as we’ve seen, I think consumers, fraud prevention is very important to them verbally and in their mind, but in the actual day-to-day activity of what they do, like it’s all about low friction, right? It’s all about what’s easy, and I’ll share data with anybody as long as I get my service fast and easy. I think that’s what’s really changing is the utility of the eID itself to be able to be used in market, and that’s what’s proving out to have this effective or more effective adoption, and that’s what we’re really driving. So, like, that’s been the big change, frankly, is the utility of the eID itself. Where can I use it? How can I use it? Is it easy? What I also believe over that time, and for an organization like Trulioo, who will leverage a variety of these tools, is that there’s a time and a place for everything.

Zac Cohen: And I think just like we saw, hey, using documents and biometrics as part of this motion is now a very popular and commonplace behavior. But there’s still just as many motions of data-driven onboarding and identity. I think that eIDs hold a very interesting and fascinating methodology. I don’t think it will make the other ones extinct, but you do give choice and you do give behavior. And I think that that’s critical in a market, right? You want to have choice and you want to improve and you want to be able to offer the best user experience or fraud prevention or whatever your lever is. So the drivers that have changed this over five years, from what I’ve seen, are the same drivers that started the whole thing in the first place. We have a regulatory driver, we have a consumer behavior driver, we have a fraud prevention driver, and we have technological innovation that is exciting and that creates these pieces that are going to be used. I hope that answered your question. But I mean, for me, it’s again, it’s another tool in our toolbox that gets used.

Zac Cohen: And I think that eIDs have a huge amount of promise and applicability. And you’ve seen, you track this all day long about adoption. And like, where are we in the mDLs versus, again, like the bank IDs? Where will we be this time next year in Europe? It will be interesting to see because in countries where it’s been deployed the right way, like Singapore, different countries in Eastern Europe, Estonia, it’s huge. And then you have things like yesterday Coinbase comes out with its own reusable ID for crypto and for their utility. It’s 100 million users right there. So like, it’s a really dynamic market and I think that it will continue to evolve again in just a method that what’s easiest for the user and how do they best go about their business.

Riley Hughes: Yeah. And if you’d like, I’ve got in this drawer over here my crystal ball. I can just, you know, let you know where it’s going to be in a year. This idea of bringing in the right eID, the right user, you know, into the right step of the workflow to optimize this friction and fraud and compliance equation. I think that that just feels like obvious to me right now. I mean, it feels hard to imagine another answer being the answer. But I do feel like there was a point in time where, I mean, has that always been obvious to you, right? Or has it been like a journey, or has there been evidence from customers or Signal or something that’s led you there, versus where it felt like maybe four years ago or something, the consensus was much more threatening or something, and this is going to be a much bigger shift and, like, disruption to the existing platforms?

Zac Cohen: I remember as well as I do when documents and biometrics first became available, nobody wanted to use them, right? Nobody, because it was high friction. Now I think it’s become ubiquitous with an onboarding motion, and people get comfortable with it. So no, I don’t think it was obvious. I think before it was mostly a waterfall. Okay, if this one doesn’t work, then let’s go to this one so we don’t lose the customer, right? So you don’t have to automatically go to some manual process where they’ll never actually sign up for your service. But there’s that adoption arc, right? And there’s that comfortable feeling of what do we get used to in terms of technologies as we interact with digital services. So no, I don’t think it was obvious, but I think today it’s very clear that every user will go into an onboarding journey, and it will say, How do you want to verify yourself? Like, how do you want to onboard? Would you like to use this? Would you like to use that? Would you like to go this path, that path? And that’s for consumers. And businesses, we’re not there yet necessarily, right?

Zac Cohen: Because you still have to submit business information. But I think, again, truly, we’ve tried to take that approach where you can do a lot of things to pre-fill for Business Globally, or, Hey, tell me the smallest amount of information you can about the business, and we will collect that and give you options. Is this the business you have? Is that the one you have? And make it as simple as possible to then go do other onboarding mechanisms. But I think choice is key when you have more than one option that makes sense and that the user will happily go through. All product people talk about happy paths. When there’s multiple happy paths, that creates choice. And I think that which eID you want to choose in the market is just as powerful as what kind of method you want to verify yourself and go through. That’s absolutely where I think we’re at, and I think that you’ve had a big part of driving that motion, to be honest.

Riley Hughes: I think I have just one more follow-up question. I’ve really enjoyed this conversation because we’ve been pretty in the weeds, and it’s going to be a good episode for people who are, like, very in this industry, right? Because I think that’s the kind of stuff I love to riff on. So my question is, if I’m an enterprise customer and I want to provide my customers with that choice, right, to choose their path, but I operate in 40 countries or six countries or whatever the case may be, and the regulations are different in each country, and the eID in those countries outputs different data types, and the level of assurance for these things is all a little different, and the adoption rates are all maybe different—it’s high in one place, lower in another, whatever—it seems to me that, like, with something like documents, every country’s got passports. They’ve all got some equivalent to a plastic ID card, right? People in every country have biometrics that are pretty much similar in terms of just the user experience.

Riley Hughes: But even things like the user experience of the eIDs across countries can vary pretty significantly.

Zac Cohen: Dramatically.

Riley Hughes: And so if I’m an enterprise, I want to offer customers that choice, how much do you think that enterprises will need the idiosyncrasies and the details of, like, why all these things are different and become experts almost in how all these different eIDs work, versus be able to just hand it over to a platform like a Trulioo or whatever and just say, Just cover it for me, right? Whatever options there are that—

Zac Cohen: Solve my problem, just like you’ve got this.

Riley Hughes: It’s probably not either of those extremes, but how do you think that will play out? And do you have any thoughts there?

Zac Cohen: Yeah, absolutely. So it’s super interesting because this is exactly the problem that the early data verification methodology posed. Exactly the same. Every single country has multiple nuances. Do you have an ID? Are there influences in your name? What’s the address typology in France? How do they collect the data? All these different data sources that you’re checking against have different database structures, different search algorithms, different components, different schemas. It’s a huge issue. And so that’s when really, originally, the first hosted solutions that were dynamic started to come up. Like, let’s look at the IP address of the user and let’s look at the account and then map that against our performance analytics across all the thousands of customers we have running hundreds of millions of transactions to automatically serve up the best, most highly effective pieces of data that will automate your transaction with the highest likelihood.

Zac Cohen: Now, that was built with very manual work and a lot of years of pain and misery and learning, and that’s sort of how you build software, right? How do we make that dynamic and feel seamless to the customer? Because enterprises aren’t going to do that themselves. And anytime you ask an enterprise to change their onboarding form, very challenging, right? Because there’s all these different dynamics that happen there. The eIDs and then just the motion that you’re talking about overall with the different potential methods of verification is the same exact problem. And KYB has a really big component of that as well because there’s so many different fields and mappings and understanding what a limited company means in different languages, etc. Companies that just focus on one market with one type of customer never experience this. Companies that are global, that live and breathe on this, it’s everything for us. And so, A, I completely agree it’s a huge issue. B, I don’t think enterprises are prepared, nor willing, nor wanting. To do that themselves. It’s just too big.

Zac Cohen: It’s not their main thing, so it’s why we exist in part. And C, we’re already building technologies and tools like that, but the coolest thing about building today is that is the perfect task for a highly complex, robust, and sophisticated IA agent that takes a look at all of the different transactions, schemas, databases, industry information, and in real time can start collating, serving up the best recommendation for that almost the middleware between the user onboarding interaction and the actual service provision. We’ve had some very good results with that from certain components of our solutions and technology for that exact reason, but more on the back-end mapping and results presentation of information for decision. However, I believe, and we’re actually experimenting with this right now with a few things, is that being actually live and enabled on the front end. And so when you’re actually integrating an SDK or you’re doing some kind of deployment with our platform, you’ll have that capability built in in the user experience.

Zac Cohen: And hey, I think that’s where it’s going and what’s needed. And that’s, I think, in a lot of ways, who will have the most compelling solutions for enterprise users that are facing these kind of challenges.

Riley Hughes: Great. Well, it seems like that’s where the rubber is going to meet the road, is at the enterprise onboarding form.

Zac Cohen: Yeah, I know. Always comes back to the enterprise onboarding form.

Riley Hughes: That’s right. Yeah, yeah. Well, this has been an awesome conversation, Zach. I really appreciate it. I feel like I learned a lot, and I think our listeners will as well. If people want to get in touch with you or work with Trulioo or understand more about what you’re building, where should they go? And if you have anything to plug, please feel free.

Zac Cohen: Oh, I know. Listen, man, it’s been an absolute pleasure. Again, I’m a big fan of Trinsic, and I appreciate you inviting me on. Trulioo with two O’s at the end dot com is where you go. And if anyone wants to shoot me an email, it’s just my first name at Trulioo. So there you go.

Riley Hughes: All right. Well, thanks a lot, Zach. You said a lot of nice things. Makes me think we need to do another round, round two. Thanks a lot.

Zac Cohen: Thanks, Riley.

Riley Hughes: Thanks so much for listening. If you enjoyed this content, the best way to signal to us that the content is valuable is to share it with others who will benefit from it. Meanwhile, if your organization is interested in accepting digital IDs, you can find me or Trinsic on LinkedIn or X, or on our website at trinsic.id. And if you haven’t already, visit trinsic.id/podcast to subscribe to the Future of Identity newsletter and listen to any of our prior episodes. Thanks so much for listening.

Riley Hughes

Co-founder & CEO @ Trinsic

Riley is the founding CEO of Trinsic, which he started in 2019 after making an impact on the digital identity industry as the first employee of Sovrin Foundation. He regularly writes and speaks on digital ID, including by hosting Trinsic’s podcast, “The Future of Identity.”

Newsletter

Subscribe to weekly insights and updates in the digital ID ecosystem.

sphere background icon