Financial services firms face the widest range of identity obligations of any sector. They must know their customers, authenticate payments strongly, control privileged access to critical systems, manage ICT third-party risk and prove all of it to regulators and auditors. They are also prime targets: account takeover, payment fraud, insider bribery and attacks on cloud and developer credentials all end in stolen money or data. This guide maps identity controls to the main financial services regulations in the EU, UK and US, covering customer identity, workforce and privileged access, non-human identities and AI agents. It is a practitioner summary, not legal advice.
Key takeaways
- Customer identity obligations centre on KYC and AML at onboarding and strong customer authentication for payments.
- DORA makes ICT risk management, including access control and third-party risk, a legal requirement for EU financial entities.
- US regulators increasingly name MFA explicitly, for example NYDFS Part 500 and the FTC Safeguards Rule.
- Non-human identities in cloud, trading, payments and developer pipelines are in scope of the same access control expectations.
- Build one identity control set and map it to every applicable regime.
Regulations and frameworks at a glance
| Regulation / framework | Applies to | Identity-relevant themes |
|---|---|---|
| EU DORA | EU financial entities and critical ICT third-party providers; applies since 17 January 2025 | ICT risk management, identity and access management, least privilege, strong authentication, logging, ICT third-party risk |
| PSD2 and the SCA RTS (EU) | Payment service providers | Strong customer authentication with two independent factors; dynamic linking of payments to amount and payee |
| PSD3 and the Payment Services Regulation (EU) | Payment service providers | Provisionally agreed reforms strengthening fraud prevention, SCA and liability for impersonation fraud; check final text and dates |
| EU AML Regulation 2024/1624 | Obliged entities; applies from 10 July 2027 | Customer due diligence, beneficial ownership, ongoing monitoring |
| UK Money Laundering Regulations 2017 and FCA rules | UK regulated firms | CDD, operational resilience, systems and controls |
| NYDFS 23 NYCRR Part 500 | Entities regulated by the New York Department of Financial Services | MFA for remote and privileged access, privileged access management, access reviews |
| FFIEC authentication guidance (US) | US banks and credit unions | Risk-based authentication and access controls for customers, employees and third parties |
| FTC Safeguards Rule (GLBA) | US non-bank financial institutions | MFA for anyone accessing customer information systems; access controls |
| SOX | US public companies | Access to financial systems, segregation of duties, access reviews |
| PCI DSS v4.0.1 | Entities handling card data | MFA into the cardholder data environment, management of system and application accounts, logging |
Customer identity
- Onboarding: proof identity and perform CDD to the level the product's risk demands. See the Identity Proofing and KYC Guide and, for business customers, the KYB Guide.
- Authentication: meet SCA with passkeys and device-bound credentials where possible; SMS one-time codes are increasingly seen as weak. See the MFA Guide.
- Payments: dynamic linking binds approval to the amount and payee, which defeats many relay attacks.
- Fraud: combine identity signals with fraud analytics to catch account takeover, mule accounts and authorised push payment scams. See the Identity Fraud Prevention Guide.
- Recovery: re-proof for high-value account recovery rather than relying on SMS or email. See the Account Recovery and Help Desk Security Guide.
- Digital identity wallets: EU banks will be required to accept European Digital Identity Wallets for strong user authentication. See the Digital Identity Wallets Guide.
Workforce and privileged access
- Phishing-resistant MFA for all staff, with hardware keys for administrators and payment operators.
- Just-in-time privileged access with session recording for production, payments and trading systems. See the Privileged Access Management Guide.
- Segregation of duties across payment initiation, approval and release. See the Segregation of Duties Guide.
- Limits on bulk data access in customer support tools, which the Coinbase breach showed can be abused by bribed insiders. See the Insider Threat and Identity Guide.
Non-human identities
- Cloud roles and keys: the Capital One breach showed how an over-privileged cloud role can expose millions of customers. See the Cloud PAM and CIEM Guide.
- Developer and pipeline credentials: the Bybit hack turned a developer's session tokens into a $1.5 billion theft. See the CI/CD Pipeline Identity Security Guide.
- Data platform credentials without MFA led to the Snowflake customer breaches, including at banks.
- Open banking and API credentials need strong client authentication, such as mTLS and private key JWT. See the OAuth 2.0 and OpenID Connect Guide.
Third parties
DORA requires a register of ICT third-party arrangements and contractual controls, and critical ICT providers face direct oversight. Identity obligations sit inside those arrangements: supplier access, SaaS integrations holding tokens and outsourced operations. See the Third-Party Access Guide and the SaaS and OAuth App Governance Guide.
AI agents in financial services
AI agents that handle customer requests, reconcile accounts or initiate payments must act within delegated, auditable authority, with human approval for material actions and full attribution of what they did for whom. See the Agentic Commerce Identity Guide and the Agentic AI Compliance Guide.
Practitioner checklist
- Map identity controls once to DORA, PSD2, AML rules, NYDFS, PCI DSS and SOX as applicable.
- Proof customers by risk and meet SCA with dynamic linking, moving customers towards passkeys.
- Enforce phishing-resistant MFA for all staff and hardware keys for privileged and payment roles.
- Apply JIT privileged access, session recording and SoD to payment and production systems.
- Limit bulk access to customer data and monitor support activity.
- Govern cloud, pipeline, data platform and API credentials as in-scope identities.
- Maintain a register of third-party identity access and integration tokens.
Standards and references
- Regulation (EU) 2022/2554 (DORA)
- Commission Delegated Regulation (EU) 2018/389 (SCA RTS)
- NYDFS: 23 NYCRR Part 500
- FFIEC: Authentication and Access to Financial Institution Services and Systems (2021)
- FTC Safeguards Rule
- PCI DSS v4.0.1
This guide summarises identity themes for security practitioners and is not legal advice. Related NHI Mgmt Group resources: Identity Security Regulatory Map · Identity Fraud Prevention Guide · KYB Guide · Privileged Access Management Guide