FB pixel

US financial regulators cite biometrics in urging stricter customer authentication

US financial regulators cite biometrics in urging stricter customer authentication
 

U.S. financial institutions are being encouraged to improve their security provisions through methods ranging from password controls to biometrics with a new set of guidelines on customer authentication.

To address the fast-changing technological landscape within finance (and potentially faster-moving security threats), the Federal Financial Institutions Examination Council (FFIEC), made up of five banking regulatory bodies, has published Authentication and Access to Financial Institution Services and Systems. This replaces Authentication in an Internet Banking Environment (2005) and the Supplement to Authentication in an Internet Banking Environment (2011).

The guidelines provide examples of effective authentication procedures and risk management principles for access. The guidance is for financial institutions’ handling of customers, third parties and their own employees as well as digital banking services.

The document outlines the threats as online and mobile access to financial services and banking increases. It cautions against the weaknesses of single-factor authentication and explains how multi-factor authentication (MFA), including biometrics, can prove more secure. An appendix on authentication solutions lists one-time passwords, behavioral biometrics, and device-based verification, which may also be triggered with biometrics.

Banks should tighten their onboarding procedures and call center processes as bad actors have been able to manipulate call handlers into resetting account passwords. Voice biometrics are listed as an example of strengthened call center security.

Article Topics

 |   |   |   |   |   |   |   |   | 

Latest Biometrics News

 

Face biometrics use cases outnumbered only by important considerations

With face biometrics now used regularly in many different sectors and areas of life, stakeholders are asking questions about a…

 

Biometric Update Podcast explores identification at scale using browser fingerprinting

“Browser fingerprinting is this idea that modern browsers are so complex.” So says Valentin Vasilyev, Chief Technology Officer of Fingerprint,…

 

Passkeys now pervasive but passwords persist in enterprise authentication

Passkeys are here; now about those passwords. Specifically, passkeys are now prevalent in the enterprise, the FIDO Alliance says, with…

 

Pornhub returns to UK, but only for iOS users who verify age with Apple

In the UK, “wanker” is not typically a term of endearment. However, the case may be different for Pornhub, which…

 

Europol operated ‘shadow’ IT systems without data safeguards: Report

Europol has operated secret data analysis platforms containing large amounts of personal information, such as identity documents, without the security…

 

EU pushes AI Act deadlines for high-risk systems, including biometrics

The EU has reached a provisional agreement on changes to the AI Act that postpone rules on high-risk AI systems,…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events