E-signatures · Glossary

What is knowledge based authentication (KBA)?

Knowledge based authentication verifies somebody by asking questions only they should be able to answer, generated from credit files and public records. The signer picks from multiple choice options about old addresses, lenders or vehicles, and must answer enough of them correctly within a time limit.

It was the standard way to check a stranger online for a decade, and it is now widely treated as a weak control. Understanding why explains a lot about how identity checking has moved on.

· Co-founder

5 min read · Published

KBA against two alternatives
Knowledge based questionsOne time codeDocument check
What it testsRecall of record dataControl of a channel nowA credential matched to a face
Beaten byData breaches, relatives, public recordsAccess to the mailbox or handsetSkilled forgery, which is rare
Signer experienceStressful, and honest people failOne extra stepA few minutes with a camera
CoverageMostly United States residents with credit filesAnyone with an inbox or phoneAnyone with a government document
Cost per checkA per lookup feeCents, or free by emailThe highest of the three

How a check is put together

A provider takes the name and address supplied and queries data aggregators for records tied to that identity. From those records it generates multiple choice questions with plausible wrong answers, such as which of these streets you have lived on or which lender holds a loan opened in a given year. The signer usually gets a short window and a limited number of attempts. Some deployments ask for a second round if the first is inconclusive. The whole exchange takes a couple of minutes and produces a pass or fail result rather than a confidence score the relying party can weigh.

Why confidence in it collapsed

Large scale breaches put exactly the underlying data into circulation, which turns secret knowledge into purchasable knowledge. Public records and social media supply much of the rest. Meanwhile the people most likely to fail are the honest ones: somebody who has moved often, changed names, or never held credit. National guidance in the United States moved away from treating these questions as an acceptable factor, and providers have steadily repositioned toward document and biometric checks. The result is a control that inconveniences legitimate signers while offering limited resistance to a determined impostor.

Where it still turns up

Remote online notarisation in several United States states, where the statute or the rules prescribe credential analysis plus knowledge based questions as part of the identity proofing. Certain title, lending and government processes that codified it years ago. And a residual layer inside legacy identity products. Outside the United States it is uncommon, largely because the credit reference data it depends on is either unavailable or restricted by privacy law, which is why an Australian or European signing product will rarely offer it at all.

The privacy question

The check works by consulting third party records about a person, usually at the moment they are trying to sign a document with somebody else. That raises questions about lawful basis, disclosure and retention that vary sharply by jurisdiction. In Europe and Australia the data protection analysis alone deters most vendors. Even where it is lawful, telling a signer their identity will be verified against credit records is a conversation that some counterparties will not welcome, particularly for consumer facing agreements.

What to use instead

For most documents, a second channel is both cheaper and more useful: a code delivered to a phone, or at minimum a code that must be entered at signing time rather than a link that could have been forwarded weeks earlier. Where genuine assurance about a stranger is required, a supervised document check with a liveness step is the modern answer and costs less than the reputational damage of a disputed signature. The middle ground, questions about old addresses, no longer sits in a sensible place on either axis.

Whether this product offers it

It does not. The three verification methods are an emailed personal link, an access code of at least four characters shared out of band by the sender, and an emailed six digit code that expires in ten minutes. There is no integration with credit bureaux or identity data providers, no question set, and no configuration that would add one. Where a transaction genuinely requires knowledge based proofing or a notarial identity check, that step happens outside this signing flow. Where proofing does happen elsewhere, record it properly rather than leaving it in somebody's memory. Note who performed the check, what they examined, when, and what the result was, and keep that note with the signed document rather than in a separate system nobody will find. A signature supported by a documented identity check performed by a named person is strong evidence even when the check happened outside the signing platform, and a signature supported by an undocumented check is indistinguishable from one supported by nothing at all. Six lines in a file note are enough to avoid that.

Questions people ask

Is KBA the same as security questions?

They are cousins. Security questions are chosen and answered by the user in advance, so the service already holds the answer. Knowledge based authentication generates questions from external records the user never supplied, which is why it can be used with somebody who has no prior relationship with the service.

Why do honest people fail it?

Because the questions come from records rather than memory. People forget a lender from eleven years ago, misremember which of two similar street names they lived on, or are asked about a relative's account that shares their address. Failure rates in the double digits are common, and every failure is a stalled transaction.

Does passing KBA prove identity?

It provides some evidence that the person had access to information associated with that identity. Given how much of that information has been exposed in breaches, it is weak evidence on its own, and it is best read as one signal among several rather than as proof.

Is it required for remote online notarisation?

Several United States states require identity proofing that includes credential analysis and knowledge based questions for a remote notarial act. Those rules are specific to notarisation rather than to ordinary electronic signing, and they differ between states, so check the rule for the state whose notary is acting.

Can I add KBA through another provider?

Not within this signing flow, since there is no integration point for it. Businesses that need that level of proofing usually verify identity in a separate process before sending the document, and record the outcome in their own files alongside the completed signature evidence.

What replaced it in practice?

Document verification with a liveness check, reusable digital identity schemes, and simple second channel codes for lower risk work. The direction is toward proving control of something at the moment of signing, or matching a credential to a face, rather than testing recall of historical records.

Make one with e-signatures

The button opens the generator with this use case already described. Change the wording to match your own.

Send a document for signing

Related questions

Sources

Written and checked by the OneCraft team. Last checked .