User intent

User intent refers to what a customer is trying to accomplish through a digital interaction, including the action they intend to take, the recipient or destination involved, and the outcome they expect. In digital banking, understanding and preserving user intent is important because a customer can be correctly identified and authenticated while still being manipulated into approving an action they did not knowingly intend.

What is user intent?

User intent is the purpose behind a customer's digital action. In banking and payments, it describes what the customer is trying to accomplish and the outcome they expect from the interaction.

For example, a customer may intend to transfer money to a specific recipient, make a particular purchase, add a beneficiary or authorise access to their financial information. The customer's intent therefore includes more than simply proving their identity; it relates to the specific action they are attempting to complete.

User intent becomes particularly important when the action a customer approves does not match what they believe they are authorising. Social engineering and other forms of fraud can manipulate a customer into performing a legitimate authentication step while pursuing an outcome they did not knowingly intend.

Key points about user intent

  • User intent describes what a customer is trying to do and the outcome they expect from a digital interaction.
  • Identity verification establishes who is interacting with an account but does not necessarily establish what that person intends to do.
  • Authentication can confirm that a customer participated in an action without confirming that the customer understood or intended the underlying transaction.
  • Preserving user intent means maintaining a clear connection between what the customer originally intended and the action ultimately approved.
  • Transaction confirmation can bind customer approval to specific transaction details rather than treating a general authentication event as approval for subsequent activity.
  • Context and risk signals can help financial institutions identify situations where additional verification or confirmation may be appropriate.

User intent and identity

Identity and intent are related but different concepts.

Identity, authentication and intent: key distinctions
Concept Key question Banking example
Identity Who is interacting? Is this the legitimate account holder?
Authentication Has the customer demonstrated control of an authentication factor? Did they complete the required authentication check?
User intent What is the customer trying to accomplish? Do they intend to pay this amount to this recipient?
Transaction confirmation What specific action did the customer approve? Did they approve the displayed recipient and amount?

A financial institution may successfully establish that a customer is the legitimate account holder while still having limited visibility into whether the customer understands the action they are approving.

This distinction underpins the ATO prevention shift from identity to intent: verifying who is acting must be complemented by understanding the action and its surrounding context. A scammer may persuade a customer to log in, disclose information or approve a transfer. The authentication event can be valid even though the resulting transaction does not reflect the customer's informed intent.

User intent and authentication

Authentication establishes confidence that a customer is authorised to access an account or perform an action. It does not, by itself, establish that the customer understands the purpose or consequences of that action.

For this reason, digital banking security can consider the broader context of an interaction. Relevant signals may include device identity, location, behaviour, transaction details, recipient history and activity across channels.

How user intent can be preserved during a transaction

Preserving user intent means maintaining a clear connection between the customer's original request and the action ultimately approved. This can involve transaction context, customer confirmation, fraud decisioning and an appropriate evidence trail.

SixStage User Intent Banking Infographic

 
  1. Capture the original request. Record what the customer initiated, including the action, amount, recipient and relevant account details.
  2. Display meaningful transaction details. Present the information that matters to the customer's decision in a clear and understandable approval experience.
  3. Bind approval to those details. Use transaction signing or another appropriate method so that approval applies to the specific request presented to the customer.
  4. Assess context and risk. Consider device, behaviour, location, account, transaction and cross-channel signals alongside the request.
  5. Respond when context changes. A new device, unusual recipient, suspicious session or altered transaction may require an additional control or confirmation step.
  6. Maintain an evidence trail. Record what was presented, what was approved, when approval occurred and which approval method was used.

User intent and transaction confirmation

Transaction confirmation is the practice of collecting explicit consent for a specific action rather than treating a general login or authentication event as approval for subsequent activity.

The FIDO Alliance describes transaction confirmation as a way to establish both that a user participated and that the transaction matched what the user intended.

This distinction is relevant to high-value transfers, changes to account controls, payment initiation and consent to share sensitive information. A confirmation step is more meaningful when it presents the material transaction details and binds the customer's approval to those details.

Why user intent matters in digital banking

User intent is particularly important in digital banking because scams can change the meaning of an otherwise legitimate customer action. A customer may believe they are moving money to a safe account, approving a refund or helping a support agent, while the financial institution sees a valid authentication event associated with a different underlying outcome.

Understanding the context around an action can help financial institutions identify situations in which the customer's intended outcome may not align with the transaction being attempted.

Relevant signals may include a newly added recipient, unusual transfer timing, remote-control software, a change in device posture, a sudden shift in behaviour or instructions originating from another channel.

User intent and customer experience

User intent also has implications for the digital banking experience. An approval experience that hides important transaction details can make it difficult for customers to understand what they are authorising, while indiscriminate security challenges can add friction to routine banking activity.

Building digital banking journeys that resist social engineering attacks requires clear, context-specific prompts at meaningful decision points rather than repetitive warnings during routine activity. 

Presenting relevant information at the point of approval helps customers understand what they are authorising. It can also give fraud and service teams a clearer record of the request, displayed details, approval method and surrounding risk signals when disputed activity needs to be investigated.

User intent in digital banking and payments

User intent can be relevant across a range of digital banking and payment journeys, including:

  • Account login and high-risk account access.
  • Beneficiary or recipient creation.
  • Payment initiation and approval.
  • Card-not-present purchases.
  • Account recovery.
  • Consent journeys.
  • Changes to customer or account information.
  • High-risk changes to account controls.

User intent in open banking

In open banking, a customer may begin a journey through a third-party provider and authorise access through their bank. Preserving user intent requires the bank, provider and authentication flow to maintain a clear connection between the customer's original request and the action ultimately approved.

User intent in card payments

In card payments, the same principle can connect the authentication decision to the transaction context. This helps distinguish authentication of the customer from confirmation of the specific transaction being authorised. This is one of the four shifts redefining trust in digital payments, where payment security increasingly connects authentication with intent, risk and evidence.

User intent: key considerations for financial institutions

Financial institutions considering controls around user intent should evaluate how their authentication, fraud and transaction processes handle the following areas:

  • Transaction details: Which transaction fields must the customer see before approval?
  • Integrity: Can the institution detect if transaction details change after initiation?
  • Context: Which device, behavioural, location, recipient and channel signals inform the decision?
  • Timing: Can controls operate before and after login, including during sensitive actions?
  • Authentication choice: Can the institution use customer-preferred authentication methods while maintaining appropriate assurance?
  • Evidence: Does the audit trail show what the customer approved and how approval was collected?
  • Regulatory alignment: Does the design support applicable requirements for strong customer authentication, dynamic linking, privacy and payment security?

How context-aware authentication can support user intent

Context-aware authentication evaluates signals such as device information, behaviour, location, transaction characteristics and activity across channels. These signals can help determine whether an action fits the expected context and whether additional assurance may be appropriate.

Entersekt's Context Aware Authentication connects risk signals across channels and adapts the security response to transaction context. This approach can support additional assurance when an interaction presents higher risk while allowing lower-risk customer journeys to remain more streamlined.

Frequently asked questions about user intent

➡️ What is user intent in digital banking?

User intent is what a customer is trying to accomplish through a digital banking interaction and the outcome they expect. It can include the action, recipient, amount, account or other relevant details associated with that intended outcome.

➡️ What is the difference between identity and user intent?

Identity concerns who is interacting with an account or service, while user intent concerns what that person is trying to accomplish. A financial institution can establish a customer's identity without necessarily establishing whether the customer understands or intends the specific transaction being approved.

➡️ Can a customer authorise a fraudulent transaction?

Yes. A customer may approve a transaction after being deceived by a scammer. The authentication event can confirm that the customer participated while failing to establish that the customer understood the true recipient, purpose or consequence of the action.

➡️ How can financial institutions preserve user intent?

Financial institutions can connect the customer's original request to the transaction ultimately approved by using clear transaction information, transaction confirmation, appropriate authentication, contextual risk signals and an evidence trail.

➡️ What is transaction signing?

Transaction signing binds a customer's approval to defined transaction details. When those details are displayed and protected from alteration, the institution has stronger evidence that the customer approved the specific action rather than providing approval for a generic session.

➡️ How does context-aware authentication support user intent?

Context-aware authentication evaluates signals such as device information, behaviour, location, transaction characteristics and activity across channels. It can use this context to determine an appropriate response, including additional confirmation for activity that does not fit the expected context.

Sources and related articles


Keep exploring

U
All insights

Find the right path forward

Explore the solutions most relevant to your organization

Solutions by outcome

Explore the outcomes that matter most, from fraud reduction to lower friction.

Solutions by use case

Find the right path for the challenges you need to solve across channels and journeys.

Solutions by industry

See how Entersekt supports banks, credit unions, and other financial institutions.

We don't just protect - we revolutionize

See how Entersekt helps financial institutions move forward