Use risk-based step-up verification so trusted users on known devices face little friction, while unusual sessions, contact changes and payout changes trigger stronger checks. The goal is not maximum friction. The goal is to concentrate controls where fraud concentrates and keep routine actions smooth.
How risk-based step-up verification reduces friction
The practical move is to make verification proportional to signal quality. A known device, stable session history and ordinary behavior should pass with minimal interruption. A fresh device, suspicious location, payout change or contact detail change should trigger a stronger step, because those are the moments when fraud and account takeover attempts tend to surface.
This is why the model works better than a universal challenge. It preserves conversion and completion for routine users, while concentrating delay and scrutiny on the transactions and profile changes that are most likely to be abused.
Which signals should carry the most weight?
Not every signal deserves the same response. Device familiarity, session age, velocity, geolocation shifts, payment instrument changes and beneficiary or payout changes are usually more useful than isolated noise such as a single failed login. The control should also distinguish between low-risk navigation and high-risk actions, because a user can browse safely even when a later action deserves a stronger step.
Strong programs also separate authentication friction from transaction friction. If a user is already authenticated but moves toward a risky action, the system should add challenge only at that point rather than forcing repeated checks across the whole journey.
When identity confidence matters, teams should anchor the step-up policy in strong authentication guidance such as NIST SP 800-63 Digital Identity Guidelines, because assurance level and phishing resistance shape how much trust you can place in the session before adding more friction.
How to keep fraud controls effective without overloading customers
The best operating model is layered: authenticate the user, score the session, then evaluate the action. That ordering lets teams keep routine interactions smooth while reserving stronger checks for high-risk moments. It also helps reduce false positives, because the decision is based on behavior plus context rather than a single rigid rule.
Friction also stays lower when the challenge itself is targeted. For example, a trusted customer on a known device may only need a light step-up for a small transfer, while a changed payout destination may justify a stronger challenge or a temporary hold. The important judgment is to protect the action, not punish the whole session.
For teams building the fraud signal layer, Identity Fraud Prevention Guide is a useful companion for the device intelligence, account takeover and bot patterns that usually sit behind these decisions.
Risk and Threat Considerations
The main risk is tuning the system too loosely or too aggressively. If step-up triggers are weak, attackers can blend into normal traffic and move from login abuse into payout diversion or contact takeover. If triggers are too sensitive, legitimate customers hit repeated challenges and abandon critical flows, which can create support burden and business loss.
Failure mechanism: The control fails when fraud signals are either underweighted, easy to spoof, or applied only at login instead of at the moment of value-moving action. Attackers then exploit the gap between a trusted session and a risky downstream change.
Impact: Under-control creates avoidable fraud exposure, while over-control increases abandonment, call-center load and customer frustration. In both cases, the institution loses either money or conversion, and often both.
Where payouts, beneficiary changes or contact updates can move value, the fraud model should be treated as an action-control problem, not just an authentication problem. For broader fraud and identity pattern coverage, the Twilio 0ktapus breach 2022 is a reminder that strong-looking sign-in flows can still be bypassed when attackers target the trust path around them.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP API Security Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-63 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | Digital Identity Guidelines | Phishing-resistant assurance levels directly shape step-up decisions for risky sessions. |
| Recommendation — Apply phishing-resistant assurance where higher trust is required before allowing sensitive actions. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Friction reduction depends on how authenticators are managed and challenged across sessions. |
| AC-6 — Least Privilege | Step-up controls should minimize access while still allowing routine low-risk activity. | |
| Recommendation — Manage authenticators so step-up checks can be targeted without weakening assurance. Apply least privilege so only sensitive actions incur stronger verification. | ||
| OWASP API Security Top 10 | API5 — Broken Function Level Authorization | High-risk payout or profile actions need action-level authorization, not just session trust. |
| Recommendation — Enforce function-level authorization on value-moving actions before they execute. | ||
| MITRE ATT&CK | T1111 — Multi-Factor Authentication Interception | Fraud actors often target the verification step itself, not just credentials. |
| Recommendation — Hunt for interception and relay patterns around step-up authentication flows. | ||
Practitioner Guidance
What to verify: Confirm that the policy is tied to high-risk events, not just login state. If contact edits, device changes and payout changes do not produce different challenge levels, the control is probably too coarse.
What to prioritize: Put the strongest checks on actions that create irreversible loss or account change. Routine browsing should stay low friction; high-risk state changes should absorb the added cost.
Common mistake: Teams often instrument many signals but keep one universal challenge rule. That usually means neither good UX nor good fraud defense.
Practitioner takeaway: The goal is selective friction, not blanket friction, and the best programs decide based on the action being attempted rather than the user’s existence in the system.
Related resources from NHI Mgmt Group
- How should security teams use mobile proximity signals to reduce fraud without creating unnecessary friction?
- How should fraud teams use device and browser signals to reduce account takeover risk without creating too much friction for legitimate users?
- How should fintech teams combine device intelligence and AI risk decisioning to reduce fraud without adding too much friction?
- How should fintech teams embed fraud controls without creating too much customer friction?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org