They should not treat experience and verification as a zero-sum trade-off. The better decision is to reserve heavier checks for higher-risk activities and streamline low-risk paths. That approach preserves customer completion while keeping strong controls where FINTRAC scrutiny and fraud exposure are greatest.
How to balance customer experience with verification
The right question is not whether to choose friction or control, but where additional verification actually changes risk. Heavy steps are most defensible when they protect high-value actions, unusual behaviour, or regulated workflows. In routine low-risk journeys, excessive checks usually add abandonment without meaningfully reducing exposure.
Good design separates the customer journey into risk tiers. A payment, limit increase, address change, or account recovery event may justify stronger verification than a simple login, browsing step, or low-value update. That lets organisations preserve speed for the common path while still escalating scrutiny when the potential loss or compliance impact rises.
Experience also suffers when verification is applied indiscriminately. Customers interpret repeated prompts, step-up loops, and duplicated data entry as poor service, but the deeper issue is often misaligned control design. If every user is treated as high risk, the organisation spends control budget where it has little marginal value and creates avoidable drop-off.
When extra checks are worth the friction
Verification should tighten when the action can change funds, entitlements, or sensitive account state. That includes moments where the business would struggle to reverse the event, where fraud loss can scale quickly, or where policy requires stronger proof. For a useful control posture, OWASP ASVS is a practical reference for thinking about authentication, session handling, and authorisation strength in ways that map to user-facing risk.
The same principle applies to step-up verification: trigger it on risk signals, not on habit. Examples include a new device, geolocation anomaly, sudden profile change, repeated failed attempts, or a transaction that is materially different from prior behaviour. The goal is not more checks everywhere, but better checks where they are most likely to prevent abuse.
For organisations operating in regulated environments, verification design should also reflect compliance expectations rather than purely product metrics. In practice, that means aligning the most stringent controls to the activities that draw the highest scrutiny, while keeping low-risk interactions fast enough that users can complete them without workarounds or support contact.
What good decision-making looks like
The strongest programmes define a policy for step-up based on activity risk, customer impact, and fraud history. They measure completion rates, challenge rates, abandonment, and downstream fraud or exception rates together, rather than optimising only for fewer prompts. If friction drops but losses rise, the design is too loose; if controls look strong but completion collapses, they are too blunt.
Organisations can also anchor their control baseline in a wider safeguard programme. CIS Controls v8 is useful here because it reinforces disciplined access, account, and logging practices that support selective verification instead of blanket friction.
FATF Recommendations matter where customer due diligence or transaction monitoring drives the verification requirement, because they remind teams that more friction is justified when the activity creates material financial crime exposure. In those cases, the objective is to keep the control proportionate to the risk signal and the regulatory obligation.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP ASVS and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP ASVS | V6 — Authentication | Risk-based verification depends on strong authentication design for customer actions. |
| Recommendation — Apply V6 to step up authentication only for higher-risk customer actions. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Selective verification relies on disciplined access and account controls. |
| Recommendation — Use CIS-6 to tighten checks around sensitive account changes and access paths. | ||
Practitioner Guidance
What to prioritise: build a tiered verification policy around high-impact actions first, then simplify routine paths that do not materially change exposure. That usually gives a better customer outcome than trying to make every step feel equally secure.
What to verify: confirm that step-up triggers are tied to observable risk indicators and that the control actually reduces fraud or abuse for the specific action it protects. If a challenge does not change the outcome, it is probably friction without value.
What good looks like: low-risk journeys complete with minimal interruption, high-risk journeys reliably escalate, and support teams see fewer avoidable complaints about repeated verification. The practitioner test is whether the control is proportionate, defensible, and measurable.
Practitioner takeaway: prioritise customer experience only where the activity is genuinely low risk, because the best verification strategy is selective friction, not universal friction.
Related resources from NHI Mgmt Group
- When should organisations prioritise fraud prevention controls over smoother customer experience in regulated gambling flows?
- When should organisations prioritise non-documentary verification over document-based checks for customer onboarding?
- When should organisations prioritise trusted electronic ID systems over manual onboarding for customer verification?
- When should organisations prioritise identity verification over a smoother checkout or transfer experience?