IRS Testing Behavioral Analytics to Verify Online Users
When taxpayers use online systems, the IRS really wants to make sure the people accessing information are who they say they are. The agency has implemented a number of authentication tools over the years—with varying degrees of success—and is now looking at behavioral analytics as an option.
The IRS announced a sole-source contract to BioCatch for a proof-of-concept that would incorporate behavioral analytics for the agency’s eAuthentication system. BioCatch’s technology tracks how a user interacts with their device and the agency’s apps to continually verify their identity.
“BioCatch collects behavioral metrics—i.e., left/right handedness, pressure—while a user is interacting with eAuth without impacting user experience and establishes a profile for the user,” IRS contracting officers wrote in the statement of work. “Once this profile is established, this data is used to detect fraud on subsequent login attempts and to prevent account takeover during the user’s session.”