TL;DR: The European Accessibility Act now extends into consumer banking authentication, so login and transaction security controls must also be usable by elderly users and people with disabilities, according to OneSpan. For IAM teams, accessibility is no longer separate from authentication design, which changes how banks evaluate devices, interfaces, and back-end compatibility.
Editorial analysis by NHI Mgmt Group, based on content published by OneSpan: “Meeting the European Accessibility Act with Digipass®”.
Key questions
Q: How should banks adapt authentication journeys for accessibility requirements?
A: Banks should design consumer authentication so that it remains perceivable, operable, understandable, and robust for people using assistive technologies or alternative interaction modes.
Q: Why do secure banking controls fail when accessibility is ignored?
A: A banking control can be secure in theory and still fail in practice if customers cannot use it reliably.
Q: What are the signs that consumer authentication is not accessible enough?
A: Common warning signs include repeated customer drop-off during verification, reliance on support workarounds, user complaints about unreadable prompts, and inconsistent behaviour across browsers, devices, or assistive technologies.
Practitioner guidance
- Map consumer authentication journeys against accessibility requirements Review login, step-up, and transaction approval flows against the European Accessibility Act and the POUR principles.
- Test authenticators with real accessibility scenarios Validate devices and mobile or web flows with users who rely on voice output, larger controls, keyboard navigation, or screen readers.
- Treat accessibility requirements as part of IAM control design Assign ownership for accessible authentication to the team that governs identity assurance, not only to UX or compliance.
Bottom line: The article reframes accessibility as a requirement that applies directly to consumer banking authentication, not just to general digital interfaces.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Accessibility is now an authentication governance requirement, not a usability add-on. The European Accessibility Act pushes banking teams to treat accessible authentication as part of the control design itself. That matters because a control that cannot be used by part of the customer base is not fully operational, even if it is technically secure. Practitioners should treat accessibility as a lifecycle property of the authentication control, not a front-end embellishment.
A question worth separating out:
Q: What should IAM teams own when accessibility affects authentication?
A: IAM teams should own the authentication control standard, the approval path, and the compatibility criteria that define whether access journeys are usable for all intended customers. Accessibility is not only a front-end issue, because device design, backend support, and policy decisions all shape whether the control actually works.
👉 Read our full editorial: European Accessibility Act compliance reshapes banking authentication