Resources | Entersekt

Customer authentication

Written by Jonathan Mervis | Jan 9, 2023, 2:10:00 PM

Customer authentication is the process of verifying that a person accessing an account, service or transaction is the legitimate customer they claim to be. In digital banking and payments, customer authentication helps financial institutions protect accounts, payments and sensitive actions from unauthorised access while providing legitimate customers with a secure and low-friction experience.

Modern customer authentication goes beyond checking a username and password. Financial institutions can combine authentication factors, device intelligence, behavioural signals, transaction context and risk-based decisioning to determine the appropriate level of assurance for each customer interaction.

The goal is not simply to authenticate every customer in the same way. It is to establish trust proportionately to risk.

How does customer authentication work?

A customer authentication process typically involves four stages:

  1. Identify the customer — establish which account or identity is attempting to access the service.
  2. Collect authentication evidence — such as a password, one-time password, biometric, device credential or cryptographic credential.
  3. Assess context and risk — evaluate signals such as device, behaviour, location, session and transaction characteristics.
  4. Apply an authentication decision — allow the interaction, request additional verification, or block it when risk is too high.

This means authentication can be more than a binary "authenticated/not authenticated" decision.

A modern authentication system can determine whether a customer should experience a frictionless journey, step-up authentication or a stronger intervention based on the risk associated with the interaction.

What are the different types of customer authentication?

 

Customer authentication can rely on one or more forms of evidence:

Knowledge factors — something the customer knows, such as a passphrase, PIN or security question

Possession factors — something the customer has, such as a mobile device, authentication app, hardware security key, registered device or cryptographic credential

Inherence factors — something the customer is, such as a fingerprint, facial recognition, voice characteristics or behavioral biometrics

Modern authentication can also consider contextual signals such as device identity, device reputation, location, network, session behaviour, customer behaviour, transaction characteristics, account history and known fraud indicators.

These signals are not always authentication factors in themselves, but they help determine how much authentication is appropriate for a given interaction.

 

Customer authentication vs identity verification

Customer authentication and identity verification are related but different processes.

Identity verification establishes whether a person is who they claim to be, often during onboarding or account opening.

Customer authentication verifies that the person attempting to access an existing account or perform a protected action is the legitimate customer associated with that account.

For example:

  • Identity verification: "Is this person really John Smith?"

  • Customer authentication: "Is the person accessing John Smith's account actually John Smith?"

Identity proofing, identity verification and customer authentication therefore address different stages of the digital identity lifecycle.

Customer authentication vs authorisation

Authentication and authorisation are also different.

  • Authentication answers: "Who are you?"

  • Authorisation answers: "What are you allowed to do?"

A customer may successfully authenticate into a banking application but still require additional authorisation before performing a high-value payment or changing sensitive account information.

What is strong customer authentication (SCA)?

Strong Customer Authentication (SCA) is a regulatory authentication requirement under the European Union's revised Payment Services Directive framework. SCA is particularly important for electronic payments and access to payment accounts, subject to applicable regulatory requirements and exemptions.

Customer authentication and SCA: what is the difference?

Customer authentication is the broader concept; SCA is a specific regulatory approach to authentication that requires multiple independent authentication elements in applicable circumstances.

This distinction is important because not every customer authentication event is necessarily an SCA event.

What is risk-based customer authentication?

Risk-based authentication (RBA) evaluates the risk associated with an authentication event and adjusts the authentication response accordingly.

Instead of applying the same authentication challenge to every customer, the system can consider signals such as:

  • Is the device recognised?
  • Is the customer behaving normally?
  • Is the login consistent with previous activity?
  • Is the location unusual?
  • Is the network suspicious?
  • Is the account showing signs of compromise?
  • Is the customer attempting a high-risk action?
  • Does the transaction match the customer's normal behaviour?

The authentication system can then determine whether to:

Allow → Step up → Block

This approach helps financial institutions balance security with customer experience.

What is adaptive authentication?

Adaptive authentication is an authentication approach that dynamically adjusts authentication requirements according to assessed risk and context.

For example, a customer logging in from a familiar device with normal behaviour may experience minimal friction.

The same customer logging in from an unfamiliar device and immediately attempting a high-value transaction may be required to complete additional authentication.

Risk-based authentication and adaptive authentication are therefore closely related concepts: both aim to apply more authentication when risk is higher and less friction when risk is lower.

How does behavioural intelligence strengthen customer authentication?

Traditional authentication can verify whether a customer has the correct credentials or authentication factor. It may not, however, determine whether the person using those credentials is behaving like the legitimate customer.

Behavioural intelligence adds another layer of evidence by analysing how a customer interacts with a digital service.

Signals can include characteristics of:

  • Mouse movement
  • Touch interactions
  • Typing behaviour
  • Navigation patterns
  • Session behaviour
  • Interaction timing
  • Other behavioural characteristics

Behavioural signals can help identify situations where credentials and even a trusted device appear legitimate but the interaction itself indicates potential fraud.

This is particularly relevant to social engineering and account takeover, where a fraudster may have successfully obtained legitimate credentials or persuaded a customer to complete an authentication step.

Customer authentication and device intelligence

Device intelligence provides information about the device being used during an authentication event.

A financial institution may consider:

  • Whether the device is known
  • Whether the device has previously been associated with the customer
  • Device characteristics
  • Device integrity
  • Network information
  • Signs of automation
  • Signs of compromise
  • Changes in device behaviour

Device intelligence can therefore contribute to risk-based authentication without necessarily requiring another visible authentication challenge.

Why is behavioural and device intelligence important?

A critical limitation of traditional authentication is that a successful authentication event does not necessarily mean that the underlying activity is legitimate.

For example, a fraudster may:

  • Steal a customer's credentials
  • Use the customer's legitimate device
  • Manipulate the customer into providing an OTP
  • Convince the customer to authorise a payment

In each case, a traditional authentication control may see evidence that appears legitimate.

Combining authentication with behavioural, device and transaction intelligence gives the financial institution a broader view of the interaction.

This is particularly important for modern scams, where the customer may be authenticated but manipulated into performing the fraudulent action themselves.

What is step-up authentication?

Step-up authentication is the process of requiring additional or stronger authentication when an interaction presents elevated risk.

For example:

Low risk: Recognised device + normal behaviour + familiar transaction → frictionless authentication

Elevated risk: Unfamiliar device + unusual behaviour → additional authentication

High risk: Suspicious device + abnormal behaviour + high-risk transaction → block or investigate

Step-up authentication allows financial institutions to increase assurance without applying maximum friction to every customer.

Customer authentication and fraud prevention

 

Customer authentication is an important fraud control, but it cannot stop every type of fraud on its own, particularly when threats such as account takeover, phishing, social engineering and payment fraud are involved. This is why modern fraud prevention connects authentication with real-time risk assessment and fraud decisioning to identify suspicious activity even when a customer appears to authenticate successfully.

 

Customer authentication in digital banking

Digital banking requires authentication across multiple stages of the customer journey, including:

  • Account login
  • New-device registration
  • Password reset
  • Profile changes
  • Beneficiary changes
  • Payment creation
  • Payment approval
  • High-risk transactions
  • Account recovery

Authentication should therefore be considered part of the entire digital banking journey, rather than a single event at login.

Customer authentication in payments

In payment environments, authentication helps establish that the legitimate cardholder or customer is participating in a transaction.

3-D Secure (3DS) is an important example for card-not-present payments. A 3DS transaction can be assessed using risk signals to determine whether authentication can occur frictionlessly or whether the customer should be challenged.

The objective is to provide the appropriate level of assurance while minimising unnecessary friction.

Customer authentication and passkeys

Passkeys are a modern authentication technology based on public-key cryptography that can provide phishing-resistant authentication without requiring users to enter a password or OTP.

Passkeys can strengthen customer authentication by replacing shared secrets with cryptographic credentials associated with an authenticator.

However, modern authentication does not necessarily mean that every customer or every transaction should immediately move to one authentication method.

Financial institutions still need to consider risk, customer context, device trust, transaction characteristics and regulatory requirements when determining the appropriate authentication journey.

Customer authentication and fraud decisioning

The strongest modern authentication architectures connect authentication with real-time risk decisioning.

Instead of asking only:

"Can this customer authenticate?"

the system can evaluate:

"What level of assurance is appropriate for this customer, device, session and transaction right now?"

This enables financial institutions to orchestrate authentication and fraud controls according to risk.

The resulting model can be:

Signals → Risk assessment → Authentication decision → Customer intervention → Outcome

This creates a more adaptive approach than applying the same authentication method to every interaction.

What is the future of customer authentication?

 

Customer authentication is moving towards continuous, context-aware and risk-based trust assessment, shaped by advances such as passkeys, behavioural biometrics, device intelligence and AI-assisted decisioning. The goal is not more authentication, but better authentication decisions that apply the right level of assurance at the right moment.

 

Key takeaway

Customer authentication is evolving from a simple credential check into a dynamic process of establishing trust across the entire digital customer journey. Financial institutions can strengthen authentication by combining authentication factors with behavioural, device, transaction and contextual intelligence, enabling them to provide frictionless experiences for legitimate customers while applying stronger intervention when risk increases.

FAQs

What is customer authentication?
➡️ Customer authentication is the process of verifying that a person accessing an account, service or transaction is the legitimate customer they claim to be.

What are the main types of customer authentication?
➡️ Common approaches include passwords and PINs, OTPs, mobile devices, biometrics, security keys, passkeys and behavioural authentication.

What is the difference between authentication and identity verification?
➡️ Identity verification establishes whether a person is who they claim to be, often during onboarding. Authentication verifies that someone accessing an existing account is the legitimate customer.

What is the difference between authentication and authorisation?
➡️ Authentication establishes who the customer is. Authorisation determines what that authenticated customer is permitted to do.

What is Strong Customer Authentication (SCA)?
➡️ SCA is a regulatory authentication requirement in applicable European payment contexts that requires at least two independent elements from knowledge, possession and inherence categories.

What is risk-based authentication?
➡️ Risk-based authentication evaluates contextual and behavioural signals to determine the appropriate level of authentication for an interaction.

What is adaptive authentication?
➡️ Adaptive authentication dynamically adjusts authentication requirements based on factors such as customer behaviour, device, location and transaction risk.

Can customer authentication prevent account takeover?
➡️ Authentication can significantly reduce unauthorised access, but it cannot prevent every account takeover attack. Stronger protection combines authentication with device, behavioural and risk intelligence.

Can a customer be successfully authenticated during a fraudulent transaction?
➡️ Yes. In social-engineering and authorised fraud scenarios, a legitimate customer may authenticate successfully while being manipulated into performing a fraudulent action.

How does behavioural biometrics strengthen authentication?
➡️ Behavioural biometrics analyses how a person interacts with a digital service, providing additional evidence that can help identify suspicious or manipulated sessions.

What is step-up authentication?
➡️ Step-up authentication requires additional or stronger verification when an interaction is assessed as higher risk.

Are passkeys more secure than passwords?
➡️ Passkeys use public-key cryptography and are designed to provide phishing-resistant authentication, addressing several weaknesses associated with password-based authentication.

What is the future of customer authentication?
➡️ Customer authentication is increasingly moving towards risk-based, contextual and continuous approaches that combine authentication factors with device, behavioural and transaction intelligence.