Merging Identities, Not Just Ledgers: Account Porting After a Financial Services Acquisition
DOI:
https://doi.org/10.64137/31078699/IJETET-V1I2P107Keywords:
Financial Services M&A, Account Porting, Identity Resolution, Customer Data Migration, Core Banking Integration, Entity Deduplication, Post-Merger Integration, Data Governance, Regulatory Compliance MigrationAbstract
In financial services acquisitions, the identity migration is harder than the ledger migration and it is where the fraud, privacy and continuity risk actually concentrates. This article sets out the architecture and control pattern that made a large brokerage and banking integration tractable.
References
[1] D. Temoshok et al., "Digital identity guidelines," Aug. 2025, National Institute of Standards and Technology, Proofing and Enrollment, NIST Special Publication 800-63A-4, U.S. Department of Commerce, doi: 10.6028/nist.sp.800-63a-4.
[2] Federal Trade Commission, "Safeguards Rule," Federal Trade Commission, Jan. 28, 2014. https://www.ftc.gov/legal-library/browse/rules/safeguards-rule
[3] D. Temoshok, "Digital Identity Guidelines: National Institute of Standards and Technology," (2025), Authentication and Authenticator Management, NIST Special Publication 800-63B-4, U.S. Department of Commerce, doi: 10.6028/nist.sp.800-63b-4.
[4] “FFIEC Information Technology Examination Handbook: New Architecture, Infrastructure, and Operations Booklet,” OCC.gov, 2021. https://www.occ.gov/news-issuances/bulletins/2021/bulletin-2021-30.html
[5] "12 CFR Part 1016 - Privacy of Consumer Financial Information (Regulation P) | Consumer Financial Protection Bureau," Consumer Financial Protection Bureau, 2025. https://www.consumerfinance.gov/rules-policy/regulations/1016/
[6] "1017. Application for Approval of Change in Ownership, Control, or Business Operations | FINRA.org," Finra.org, 2020. https://www.finra.org/rules-guidance/rulebooks/finra-rules/1017
[7] P. Fellegi and A. B. Sunter, "A Theory for Record Linkage," Journal of the American Statistical Association, vol. 64, no. 328, pp. 1183–1210, Dec. 1969, doi: 10.1080/01621459.1969.10501049.
[8] P. Christen, Data Matching: Concepts and Techniques for Record Linkage, Entity Resolution, and Duplicate Detection, Berlin, Heidelberg: Springer Berlin Heidelberg, 2012. doi: 10.1007/978-3-642-31164-2.
[9] S. Rose, O. Borchert, S. Mitchell, and S. Connelly, "Zero trust architecture," NIST Special Publication 800-207, vol. 1, no. 800–207, Aug. 2020, doi: 10.6028/nist.sp.800-207.
[10] D. Temoshok et al., Federation and Assertions, NIST Special Publication 800-63C-4, U.S. Department of Commerce, "Digital Identity Guidelines: Federation and Assertions," 2025, doi: 10.6028/nist.sp.800-63c-4.
[11] CISA, “Phishing Guidance: Stopping the Attack Cycle at Phase One | CISA,” www.cisa.gov, Oct. 18, 2023. https://www.cisa.gov/resources-tools/resources/phishing-guidance-stopping-attack-cycle-phase-one
Downloads
Published
Issue
Section
License

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.


