FFIEC Authentication and Access Guidance

cmp_us_ffiec_authentication_access

US interagency guidance for risk assessments, layered security, multifactor authentication and monitoring in digital banking.

TL;DR:

  • US interagency guidance for risk assessments, layered security, multifactor authentication and monitoring in digital banking.
  • Assess access risk, use layered security and MFA where warranted and monitor anomalous activity.
  • Document risk assessments, testing, incidents and corrective action.

Summary

US interagency guidance for risk assessments, layered security, multifactor authentication and monitoring in digital banking. Its scope covers digital banking access and high-risk transactions.

The main requirements are to assess access risk, use layered security and MFA where warranted and monitor anomalous activity.

Fraud prevention and reimbursement answer different questions. Prevention aims to stop a harmful transaction; reimbursement allocates loss after it occurs. The distinction between an unauthorised transaction and a payment the customer authorised after being deceived can change the applicable rules, as can the customer's status and the payment rail used.

An investigation needs to reconstruct the instruction, authentication, warnings, recipient information and the parties' actions. Successful authentication can establish that credentials were used without proving that a customer understood the true purpose of a payment. Equally, a name-check result can confirm account details without establishing that an underlying invoice or investment is legitimate.

The practical framework connects controls before payment with fair and evidence-based handling of claims afterwards. Eligibility, exclusions, reimbursement limits and procedural requirements belong to the specific instrument. Those conditions should be kept separate from a provider's voluntary goodwill policy and from a commercial dispute with a legitimate merchant.

The instrument also addresses reporting and evidence: document risk assessments, testing, incidents and corrective action.

Keywords

  • FFIEC Authentication and Access Guidance
  • FFIEC Authentication
  • Authentication and Access to Financial Institution Services and Systems
  • FFIEC Authentication and Access Guidance summary
  • FFIEC Authentication and Access Guidance requirements
  • FFIEC Authentication and Access Guidance compliance
  • United States payment regulation
  • United States financial regulation
  • Federal Financial Institutions Examination Council regulation
  • payment fraud and reimbursement