Onboarding wants to drop bank verification to lift signup conversion - what do you own in that call?
answer
- you do not own the conversion number
- what does the step actually buy
- score mass moves, it does not disappear
- verify late, by exposure, or on disagreement
- a deterrent shows up as absence, not catches
basics
~20 sNaming what the step buys: it holds one column the applicant cannot set for free. Removing it moves score mass onto retypeable fields and drops the cheapest successful application to near zero. Price that shift; the conversion appetite is the business's.
solid answer
~50 sDo not answer yes or no on conversion — you do not own that number and pretending to costs you the argument. Own three statements instead. First, how much of the decision currently rests on the verified column, and what the model looks like without it. Second, what the cheapest successful fraudulent application costs today versus afterwards: a funded balance held over a lookback window becomes a retype, and that is the whole finding in one line. Third, which compensating controls genuinely replace the price — an exposure limit on new accounts until priced signals accrue, a review queue with funded hours, verification on a sampled or exposure-weighted subset — and which are theatre. Then offer the graded options, because keep-or-drop is usually a false binary: verify late, verify above a stated exposure, verify a fraction. And say what you will not sign afterwards.
go deeper
Understand that a verification step is not just friction: it is the reason one input costs the applicant money instead of a keystroke, and removing it changes what the model is reading.
Be able to explain where the score mass goes when a priced column is removed, and why the remaining columns then carry decisions their authors set for free.
Show that you would quantify the dependence and the change in the cheapest successful application before the meeting, and that you can tell a real compensating control from one reading the same free fields.
Own the framing: present graded verification options with conversion and adversarial-cost figures attached, state what you will no longer certify, and get the decision and its owner written down with a re-review date.
## Why this is a judgment call and not a technical one The verification step is doing exactly one thing in threat-model terms: it holds a column whose value the applicant cannot set by typing. It costs them real money to move — the funds have to be there — and that price is the only thing standing between the model and an input surface written entirely by its subject. Removing the step does not remove the column's job; it redistributes the score mass onto columns that cost a keystroke. But the step also costs conversion, and conversion is real revenue. The people asking to drop it are not being reckless; they are looking at an abandonment number at that stage of signup. The decision is a trade between two real quantities, and the reason it lands on a lead rather than on an engineer is that neither side owns both numbers. ## What you own **The dependence.** How much of the score currently comes from the verified column, and how the decision distribution changes without it. If it is a rounding error, say so and stop arguing — that is the honest outcome sometimes, and saying it buys you credibility for the cases where it is not. **The price delta.** The cheapest successful fraudulent application today, and afterwards, in currency and calendar time. This is the sentence the room remembers: today it costs holding real funds through a lookback window, afterwards it costs typing a different number. **The compensating-control assessment.** Which alternatives actually re-price the input surface, and which only look like they do. A rules layer reading the same self-declared columns adds nothing to the adversary's bill. An exposure limit on new accounts does something real: it caps loss while priced signals accrue. A review queue works only with funded hours attached and a stated sampling rate. **The claims you withdraw.** If the priced column goes, anything customer-facing, partner-facing or auditor-facing that describes the model as resistant to applicant misstatement has to change. Do not let a claim outlive the control it rested on. ## What you do not own The conversion target, the growth plan, and the organisation's risk appetite. Presenting a refusal in place of a priced option is how a security function makes itself something to route around. The strong move is a graded proposal with numbers on each rung. ## The graded middle, which usually wins - **Verify late.** Move the check after signup and before the first payout or before a limit increase. Most of the conversion is preserved because the applicant has already invested effort, and the priced signal still arrives before real exposure. - **Verify by exposure.** Require it above a stated declared volume or requested limit. The adversary can dodge it only by declaring less, which caps what the attack is worth. - **Verify a sample.** A stated fraction, chosen unpredictably. This is weaker than it sounds against a single determined applicant and stronger than it sounds against volume abuse, and it needs the sampling rate stated to mean anything. - **Verify on disagreement.** Trigger the check when a declared field conflicts with something cheap you already hold. This concentrates the cost on the applications where the free columns are doing something odd. Each rung has a conversion cost and an adversarial-cost benefit, and putting those side by side is the deliverable. ## Handling the 'it never catches anything' argument Somebody will produce data showing the verification step rarely rejects anyone. Ask whether it caught nothing or deterred everything. A control that prices a field shows up as absence: applicants who would have misstated the figure abandoned at that screen, or never applied. Ask for the abandonment population at that step and what they were declaring before it. If the abandoners were declaring systematically higher volumes than the completers, the step is working precisely as intended and the zero-catch figure is evidence for it, not against. ## Closing the decision properly Whichever way it goes, write down what was decided, on what numbers, and by whom, with a re-review date. If the step is dropped, insist on the exposure cap, on monitoring the distribution of the newly free column — a drift in declared volumes is the visible symptom of the attack becoming free — and on the claim withdrawal. That way the next incident is a review of a choice somebody made with the price in front of them, rather than an argument about who warned whom.
- The data shows that step almost never rejects anyone. Does that settle it?No, because a control that prices a field shows up as absence rather than as catches. Ask for the population that abandoned at that screen and what they had declared before it. If abandoners were systematically declaring higher volumes than completers, the step is deterring exactly the applications you care about, and the low rejection count is evidence in its favour.
- How do you avoid this becoming a veto you always lose?Bring a graded proposal with a number on each rung instead of a refusal. Verify late, above a stated exposure, on disagreement, or on a stated sample — each with its conversion cost and its effect on the cheapest successful application. Own the risk statement; let the business own the appetite. Then record which option was chosen and by whom, with a re-review date.
- If they drop it anyway, what do you insist on?An exposure cap on new accounts until priced signals accrue, monitoring on the distribution of the newly free column because drift in declared values is the visible symptom, a funded review path for outliers, and a stated re-review date. And withdraw any customer-, partner- or auditor-facing statement that described the model as resistant to applicant misstatement.
- Is a downstream rules engine an acceptable compensating control here?Only if its rules read priced or attested fields, or compare a declared value against one. A rule keyed on the same self-declared columns inherits the identical price list and adds nothing to the adversary's bill, however many conditions it has. Ask for the column-by-column mapping before accepting it as a substitute for the verification step.
saying these in an interview costs you the question
- Answers with a flat yes or no on conversion
- Claims removing a verified field leaves the model unaffected
- Treats a zero-rejection rate as proof the step is useless
- Offers no graded alternative between keeping and dropping
- Leaves a resistance claim standing after the control is gone