Shufti's CTO on Winning Best Fraud Prevention Solution and Building a Glocal Platform
Shufti was recently recognized with the Best Fraud Prevention Solution award for its Glocal Identity Verification Platform, which brings identity verification and compliance together across global markets while adapting to local requirements. In this interview, Frayyam Asif, Chief Technology Officer of Shufti, discusses the changing fraud landscape, building technology in-house, tackling identity challenges across different markets, and what comes next for Shufti.

Shufti has won the 2026 Tech Ascension Award for Best Fraud Prevention Solution. What does this recognition mean for the team and for your clients?
This recognition is a strong reminder of the engineering work behind our fraud prevention technology. We have spent years building the platform ourselves and testing it against increasingly sophisticated attacks, so it is good to see Shufti leading in an area that is becoming increasingly important for businesses today.
For our clients, I think it gives them another reason to have confidence in the technology they rely on to protect their customers. Fraud is changing very quickly, and staying ahead of those changes has always been a big part of what we are trying to achieve at Shufti.
In May 2026, Shufti became the first European company to achieve iBeta Level 3 conformance for fully passive liveness. Why do you think iBeta Certification matters?
What makes it important to me is that it gives us a much clearer view of how the technology performs under difficult conditions.
In the iBeta testing, we recorded 0% APCER and 0% BPCER across 900 mask attacks. The standard permits up to 45 attacks to succeed, but none succeeded with Shufti. The testing also covered both newer and older devices, which I think is important. In practice, you cannot assume everyone is using the latest devices. If you want to understand how robust a liveness system is, you have to test it across the range of devices and attack conditions that customers actually encounter.
Shufti recorded 99.63% deepfake detection at a 0.46% false accept rate. What makes Shufti's approach effective?
We do not rely on a single signal to identify a deepfake. Our system evaluates seven independent signals simultaneously and combines their results to make a more reliable decision.
But detection is only part of the challenge. The threats keep changing, so our models are continuously trained and improved against new attack techniques. We are constantly looking at how attacks are changing and where existing controls could be bypassed.
The goal is to make sure our detection keeps working as deepfake technology evolves.
A fully proprietary technology stack is a key theme in Shufti's approach. How does owning every component in-house help build trust with clients?
The biggest advantage is control. We build, train, and operate the technology ourselves, so when we encounter a new fraud pattern or an edge case, we can address it directly rather than waiting on a third-party provider.
That is particularly important in some of the toughest markets in the world, where identity systems and documents can be very different. Our OCR model, for example, is trained on these variations and achieves over 98% accuracy on complex scripts such as Arabic, Kanji, and Cyrillic, while also handling name transliteration.
It also gives our clients more flexibility in how they deploy the platform, including private cloud and on-premise environments.
The platform is described as Glocal. How do you reconcile global reach with the fact that identity infrastructure is intensely local?
The reality is that identity is very local. The documents people use, the databases available, the languages involved, and the regulatory requirements can all be different from one country to another.
We have built the underlying technology to work globally, but we adapt the identity intelligence to the requirements of each market.
Today, we process more than 10,000 active document types, 150 languages, authoritative identity sources across more than 85 countries with 4.29 billion verifiable identities, and help businesses work with one platform and integration while still giving customers a verification experience that makes sense in their own market.
Looking back, what achievements of Shufti are you most proud of?
I’m probably most proud of how far we have taken the technology. Today we support more than 2000 businesses, cover 240+ countries and territories, and have processed more than 400 million verifications. But the numbers are only part of the story.
We have continued investing in our own technology and testing it against difficult fraud scenarios. Performing strongly in the DHS RIVR evaluation was a major milestone for Shufti.
We were one of only five out of 16 vendors to meet all of the programme’s performance goals. Our deepfake detection results are also important to me because they give us independent evidence that the technology can perform against serious attack scenarios.
What's next for Shufti, and what excites you most right now?
There is a lot happening at Shufti right now. We are expanding beyond traditional identity verification with QES, transaction monitoring, and Travel Rule compliance. We are also working on five new product areas covering Bank Account Verification, Geolocation, Journey Builder, AI, and Model Context Protocol.
Our recognition from G2 has also been encouraging because it shows that customers are seeing value in the direction we are taking, and our recognition by Liminal further reinforces that our capabilities are making an impact across the identity verification and age assurance space.
What excites me most is bringing these capabilities together. Businesses should not need a different system for every part of their fraud and compliance process. We want to give them a platform that can handle more of that journey while making the experience simpler for genuine customers.
