Back to case studies // authentication

Retail Banking Step-Up Auth

A consumer bank cut account-takeover risk by replacing blanket OTP prompts with context-aware step-up authentication, challenging customers only when the request actually warranted it.

October 14, 2024 · Veripass
Retail Banking Step-Up Auth

A retail bank’s authentication strategy used to be binary: log in, then get an OTP for almost everything. Customers were challenged when they checked a balance and challenged again when they moved money, which trained them to approve prompts reflexively — the exact habit attackers exploit. The bank wanted friction where risk was, and nowhere else.

The challenge

Account-takeover fraud was rising even though MFA coverage was near total. The problem was not the absence of a second factor; it was that the second factor was constant and therefore meaningless. A customer who approves twelve prompts a day stops reading them. Meanwhile, genuinely high-risk events — a transfer to a new payee from an unrecognized device — got the same treatment as viewing a statement.

The bank needed authentication that scaled with the request, not against it.

What Veripass deployed

Veripass replaced the blanket policy with context-aware, policy-based evaluation. Every request carries context — the customer’s role, the application, the recognized state of the session, and the sensitivity of the action — and policy decides whether the existing session is sufficient or a step-up is required.

Low-risk reads pass through on the established session. When the context shifts — a new device, a dormant account waking up, a large or first-time transfer — the policy demands a step-up. Veripass first reaches for adaptive MFA over email or phone TOTP, and for the most sensitive operations it can escalate to biometric verification using face or ID-document checks. The factor matches the stakes.

Underneath, authorization is expressed through claims, capabilities, roles, and access profiles, so the policy that decides “this customer, this action, this context” composes cleanly rather than living as one-off rules per screen. Every challenge and every decision lands in an immutable audit trail, giving fraud and compliance teams a reconstructable record of why a step-up fired.

  • Context-aware, policy-based authentication decisions
  • Adaptive step-up MFA over email and phone TOTP
  • Biometric verification (face, ID document) for high-stakes actions
  • RBAC via claims, capabilities, roles, and access profiles
  • Immutable audit trails for every challenge and decision

Outcome

Routine sessions got quieter and sensitive ones got stricter. By challenging only when context warranted it, the bank reduced everyday authentication prompts substantially while raising the bar precisely where fraud concentrates. Customers stopped rubber-stamping OTPs because the prompts became rare enough to be meaningful again.

Account-takeover attempts that previously slipped through a numbed customer now hit a step-up the customer actually paused for. And because every decision is auditable, the fraud team can answer — for any disputed transaction — exactly which context triggered the challenge and which factor cleared it.

More deployments

Campus-Wide Student SSO

Campus-Wide Student SSO

A university gave every student one login for the entire campus stack by federating Google Workspace and the student directory through Veripass, ending the credential sprawl across portals and services.

Clinician EHR Single Sign-On

Clinician EHR Single Sign-On

A hospital network gave clinicians one federated sign-on across the EHR and clinical applications, cutting repeated logins at the bedside while keeping every access policy-governed and audited.

Fingerprint Turnstile Entry

Fingerprint Turnstile Entry

A manufacturing site replaced badge tailgating at its turnstiles with fingerprint biometric verification bound to identity, so every entry proved the person was physically present and authorized.