A pharmacy use case demonstrating how CardLab and Kvanto connect trusted identity, secure payments and regulatory reporting
For decades, organisations have treated possession of a password, PIN or access card as sufficient evidence of identity. In highly regulated industries, that assumption is becoming increasingly difficult to defend. A valid credential may show that access was granted, but it does not necessarily prove that the authorised individual performed the action.
This distinction marks an important industry transformation. Cybersecurity is moving beyond credential authentication towards identity assurance: the ability to establish and preserve confidence in the person behind every critical physical and digital event. In that environment, compliance begins with trusted identity.
“Compliance begins with trusted identity”
A practical compliance challenge
Pharmacies sit at the intersection of patient safety, controlled medicines, personal data and financial transactions. Employees must work quickly, while every critical activity remains restricted to authorised personnel and traceability afterwards. The relevant question is no longer only whether a valid card or code was used, but whether the organisation can demonstrate who entered a secure area, handled medicine, accessed a system or approved a payment.
That challenge became central in a project for a pharmacy chain seeking to strengthen compliance while modernising its payment and remittance environment. Existing processes relied on conventional credentials for premises, medicine storage, IT systems and payment functions. These tools supported daily operations but did not consistently provide proof of the person behind each event.
During the assessment, the pharmacy identified shortcuts common in busy workplaces. Employees occasionally shared PINs, exchanged access cards or used a colleague’s credentials to avoid delays. These behaviours were not necessarily malicious, but they weakened the audit trail. Management could not always determine with confidence who entered a restricted area, removed medicine from secure storage, prepared a prescription, served a customer or approved a payment. Similar uncertainty complicated attendance reviews and investigations into stock discrepancies.
The requirement: Verify the person, not only the credential
The pharmacy needed to preserve operational speed while preventing identity swapping. It also needed one control model across physical access, digital systems, medicine handling and payments. Separate tools for each environment would have increased complexity and fragmented compliance reporting.
The requirement was simple to state but demanding to implement: every sensitive action should begin with strong verification of the authorised employee, and the resulting record should follow that identity through the workflow. CardLab and Kvanto addressed this as one integrated use case. CardLab provides the biometric Identity Assurance Platform; Kvanto provides secure payment, remittance and transaction infrastructure. Together, they connect a verified employee to the event that follows.
How biometric identity assurance works
Each authorised employee receives a CardLab biometric smart card. Fingerprint matching takes place on the card itself, so the biometric reference does not need to be exposed to an online service during routine authentication. Possession alone is therefore insufficient: a lost, borrowed or stolen card cannot be activated without the authorised holder’s fingerprint.
After successful on-card verification, the card generates the authentication code required by the connected reader, terminal or application. CardLab backend capabilities, including FIDO-based integration, allow the verified identity to be recognised across digital and physical services. Access rights remain governed through the pharmacy’s role model and Active Directory, ensuring that identity assurance confirms the individual while existing policies determine what that person may do.
Trusted identity meets trusted transactions
Once CardLab establishes the identity of the authorised employee, Kvanto provides the secure digital payment and remittance infrastructure that completes the transaction. Kvanto’s resilient gateway architecture integrates payment processing, acquiring services, fraud management and backend business systems while maintaining high operational availability. Together, the platforms establish a continuous chain of trust – from verified employee identity through secure transaction processing to regulatory reporting.
A traceable pharmacy workflow
In practice, an employee verifies their identity before entering a controlled area or opening a protected application. The system can then register that the authorised person entered a medicine vault, accessed the pharmacy system, prepared or released prescription medicine and processed the related payment. Unauthorised attempts can also be recorded. The workflow can be adapted to the pharmacy’s policies and role structure so that access is granted only to employees authorised for the specific task.

This removes the operational value of sharing a password, PIN or access card. A colleague’s credential is no longer a useful shortcut because it cannot be activated without its authorised holder’s fingerprint. At the same time, employees can avoid remembering and managing multiple passwords across separate systems.
Implementation centred on roles and usability
Technology alone does not create compliance. The pharmacy must define which roles may enter each area, use each application and approve each transaction. Those permissions are mapped in the AD to verified employee identities and updated as responsibilities change. This produces access decisions that are easier to explain and review than shared accounts or locally managed codes.
Deployment can be phased around the highest-risk workflows. A pharmacy may begin with medicine-vault access and payment approval, then extend the same identity model to system login, prescription preparation and attendance. This limits disruption and allows reporting formats and exception rules to be refined against real operating data.
Usability remains a control in its own right. Security that adds excessive friction often creates new workarounds. When biometric identity assurance is fast, consistent and available at the point of work, it becomes part of the workflow rather than a barrier around it.
Compliance based on verified events
The strongest business benefit is the quality of the resulting audit trail. Each event can be associated with a biometrically verified employee, a time, a system or location and the action performed. Instead of reconstructing activity from disconnected logs and shared accounts, the pharmacy can build a unified compliance record from trusted operational data.
Reporting can cover physical entry, medicine-storage access, digital logins, prescription handling and payment approval. Reports are customised to the pharmacy chain’s requirements, but the objective is consistent: evidence should be available rapidly, without a lengthy manual investigation. This supports faster internal control, focused exception handling and greater confidence when information must be presented to authorities or auditors.
The same data can strengthen stock investigations. When actual medicine levels differ from forecasts, management has a more reliable basis for identifying who accessed the relevant storage and which activities occurred. Biometric identity assurance does not replace sound procedures, staff training or segregation of duties; it makes those controls more dependable by linking them to verified identity data.
Why identity assurance matters
Cybersecurity is no longer defined solely by protecting systems from external attack. Organisations must increasingly prove that every regulated action can be traced to the authorised individual who performed it. Traditional credentials were never designed for this level of accountability. Passwords can be shared, access cards borrowed and PINs observed or disclosed.

Biometric identity assurance changes the discussion. Rather than trusting possession or knowledge of a credential, the organisation establishes trust in the individual. Once that identity is verified, subsequent actions – from entering a medicine vault to approving a payment – can be linked to the correct employee. Authentication therefore becomes more than an IT control; it becomes an operational and compliance control.
Local on-card matching also supports privacy by design. The fingerprint reference remains protected on the card, while the backend receives the authentication code result and dynamic data needed to validate access. Organisational data can remain within the customer’s chosen infrastructure and governance model, supporting requirements for data residency, ownership and sovereignty.
Operational value follows the same principle. Passwordless access can reduce reset requests, forgotten credentials and temporary-access administration. Employees gain one consistent way to verify identity across relevant environments; IT teams face fewer password-related support cases; and management receives more dependable records. The value therefore extends beyond cybersecurity to workflow efficiency, audit readiness and reduced compliance uncertainty.
A foundation for trusted digital operations
The pharmacy project illustrates a broader transformation across regulated industries. As organisations digitise operations and face greater scrutiny, confidence in credentials alone is no longer sufficient. Trust must begin with the person behind each critical action.
By combining CardLab’s biometric Identity Assurance Platform with Kvanto’s secure payment and transaction infrastructure, organisations can create a continuous chain of trust linking employees, systems, payments and compliance. For pharmacies, that means greater certainty that only authorised personnel handle medicine, enter restricted areas and approve transactions – while employees gain a fast and privacy-conscious authentication experience.
Identity Assurance is no longer simply a cybersecurity capability.
It is becoming the foundation for trusted digital operations.
Please Note: This is a Commercial Profile
Please note, this article will also appear in the 27th edition of our quarterly publication.