Join our Newsletter — 33% off our NHI Course
Home› Guides› Financial Services Identity Security Guide
Guide Governance, Risk & Compliance

Financial Services Identity Security Guide

← All guides
By Lalit Choda, NHI Mgmt Group Updated 27 September 2026 5 min read
On this page

Financial services firms face the widest range of identity obligations of any sector. They must know their customers, authenticate payments strongly, control privileged access to critical systems, manage ICT third-party risk and prove all of it to regulators and auditors. They are also prime targets: account takeover, payment fraud, insider bribery and attacks on cloud and developer credentials all end in stolen money or data. This guide maps identity controls to the main financial services regulations in the EU, UK and US, covering customer identity, workforce and privileged access, non-human identities and AI agents. It is a practitioner summary, not legal advice.

Key takeaways

  • Customer identity obligations centre on KYC and AML at onboarding and strong customer authentication for payments.
  • DORA makes ICT risk management, including access control and third-party risk, a legal requirement for EU financial entities.
  • US regulators increasingly name MFA explicitly, for example NYDFS Part 500 and the FTC Safeguards Rule.
  • Non-human identities in cloud, trading, payments and developer pipelines are in scope of the same access control expectations.
  • Build one identity control set and map it to every applicable regime.

Regulations and frameworks at a glance

Regulation / frameworkApplies toIdentity-relevant themes
EU DORAEU financial entities and critical ICT third-party providers; applies since 17 January 2025ICT risk management, identity and access management, least privilege, strong authentication, logging, ICT third-party risk
PSD2 and the SCA RTS (EU)Payment service providersStrong customer authentication with two independent factors; dynamic linking of payments to amount and payee
PSD3 and the Payment Services Regulation (EU)Payment service providersProvisionally agreed reforms strengthening fraud prevention, SCA and liability for impersonation fraud; check final text and dates
EU AML Regulation 2024/1624Obliged entities; applies from 10 July 2027Customer due diligence, beneficial ownership, ongoing monitoring
UK Money Laundering Regulations 2017 and FCA rulesUK regulated firmsCDD, operational resilience, systems and controls
NYDFS 23 NYCRR Part 500Entities regulated by the New York Department of Financial ServicesMFA for remote and privileged access, privileged access management, access reviews
FFIEC authentication guidance (US)US banks and credit unionsRisk-based authentication and access controls for customers, employees and third parties
FTC Safeguards Rule (GLBA)US non-bank financial institutionsMFA for anyone accessing customer information systems; access controls
SOXUS public companiesAccess to financial systems, segregation of duties, access reviews
PCI DSS v4.0.1Entities handling card dataMFA into the cardholder data environment, management of system and application accounts, logging

Customer identity

  • Onboarding: proof identity and perform CDD to the level the product's risk demands. See the Identity Proofing and KYC Guide and, for business customers, the KYB Guide.
  • Authentication: meet SCA with passkeys and device-bound credentials where possible; SMS one-time codes are increasingly seen as weak. See the MFA Guide.
  • Payments: dynamic linking binds approval to the amount and payee, which defeats many relay attacks.
  • Fraud: combine identity signals with fraud analytics to catch account takeover, mule accounts and authorised push payment scams. See the Identity Fraud Prevention Guide.
  • Recovery: re-proof for high-value account recovery rather than relying on SMS or email. See the Account Recovery and Help Desk Security Guide.
  • Digital identity wallets: EU banks will be required to accept European Digital Identity Wallets for strong user authentication. See the Digital Identity Wallets Guide.

Workforce and privileged access

Non-human identities

Third parties

DORA requires a register of ICT third-party arrangements and contractual controls, and critical ICT providers face direct oversight. Identity obligations sit inside those arrangements: supplier access, SaaS integrations holding tokens and outsourced operations. See the Third-Party Access Guide and the SaaS and OAuth App Governance Guide.

AI agents in financial services

AI agents that handle customer requests, reconcile accounts or initiate payments must act within delegated, auditable authority, with human approval for material actions and full attribution of what they did for whom. See the Agentic Commerce Identity Guide and the Agentic AI Compliance Guide.

Practitioner checklist

  • Map identity controls once to DORA, PSD2, AML rules, NYDFS, PCI DSS and SOX as applicable.
  • Proof customers by risk and meet SCA with dynamic linking, moving customers towards passkeys.
  • Enforce phishing-resistant MFA for all staff and hardware keys for privileged and payment roles.
  • Apply JIT privileged access, session recording and SoD to payment and production systems.
  • Limit bulk access to customer data and monitor support activity.
  • Govern cloud, pipeline, data platform and API credentials as in-scope identities.
  • Maintain a register of third-party identity access and integration tokens.

Standards and references

This guide summarises identity themes for security practitioners and is not legal advice. Related NHI Mgmt Group resources: Identity Security Regulatory Map · Identity Fraud Prevention Guide · KYB Guide · Privileged Access Management Guide

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 27 September 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org