NIST’s updated Digital Identity Guidelines to Revision 4 (SP 800-63B-4) and added Section 5.3 Session Monitoring (also called continuous authentication). The section recognizes continuous, in-session evaluation of user and device signals to catch fraud after login. When risk is detected, relying parties should coordinate with their identity provider to take action.