Financial institutions should place friction only at higher-risk moments, such as high-value transfers, unusual locations, or account changes. The goal is to reassure users while avoiding unnecessary delays in routine activity. Risk-based authentication, device intelligence, and clear explanations help teams distinguish trusted users from suspicious ones and keep the experience smooth for legitimate customers.
Where Friction Belongs in the Customer Journey
Effective friction is selective, not constant. In financial services, the right moments are those where the consequence of a mistake, takeover, or fraud attempt is materially higher than normal browsing or routine account use. That usually means transfers above a threshold, new payees, profile changes, device changes, and access from unusual geographies or networks.
The practical test is whether the added step changes user confidence more than it changes user effort. If the control only slows down ordinary activity, it becomes background noise. If it appears when behaviour is unusual or the transaction is sensitive, it feels like protection rather than punishment. Clear prompts help users understand why the check exists and reduce abandonment.
Friction is most effective when it is layered onto routine authentication signals and backed by device and session context, rather than bolted on as a blanket challenge. That keeps low-risk interactions fast while reserving extra scrutiny for activity that deserves it.
Designing Controls That Feel Protective, Not Punitive
customer experience improves when the institution makes the reason for friction visible. A short explanation, such as confirming a new device or protecting a high-value transfer, gives the user a mental model for the delay and lowers the chance that security is interpreted as system failure. The same control can feel reasonable or hostile depending on timing and wording.
Good friction also respects the reality of trusted users. If the customer has a consistent device, stable behaviour, and a familiar session pattern, the system should avoid repeated challenges. When risk signals accumulate, the step-up should be proportionate to the exposure, not maximal by default. That is the difference between risk-based authentication and a generic bottleneck.
Institutions can anchor that logic in known abuse paths, including credential theft and account takeover patterns documented in Zacks Investment Research breach and the broader control failures seen in MailChimp Breach. The customer experience goal is to concentrate friction where real fraud paths tend to appear, not where ordinary users are trying to complete routine tasks.
Risk and Threat Considerations
Over-friction creates its own exposure. If legitimate customers are challenged too often, they disengage, bypass controls, or flood support channels, which weakens the institution’s ability to distinguish normal behaviour from suspicious activity. Under-friction is the opposite failure mode, because it gives attackers a smoother path through transfers, account changes, and recovery flows.
Failure mechanism: Poorly tuned step-up logic either normalises friction into user fatigue or leaves high-risk actions too close to routine access, allowing fraud, takeover, or social engineering to exploit the gap.
Impact: The institution either loses trust and conversion on the customer side or loses control over the transactions and account mutations that matter most.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and CIS Controls v8 set the technical controls, while PCI DSS v4.0 and DORA define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-7 — User Authentication, Authorization and Risk-Based Access | Risk-based step-up aligns to adaptive access decisions at sensitive moments. |
| Recommendation — Apply PR.AC-7 to step up verification only when transaction risk increases. | ||
| CIS Controls v8 | 6 — Access Control Management | Selective friction depends on enforcing least privilege and targeted access restrictions. |
| Recommendation — Use Control 6 to restrict sensitive actions and require stronger checks for higher-risk changes. | ||
| PCI DSS v4.0 | 8 — Identify Users and Authenticate Access to System Components | Financial flows need stronger authentication at sensitive access points and account changes. |
| Recommendation — Apply Requirement 8 to strengthen authentication where customer actions raise fraud risk. | ||
| DORA | ICT third-party risk and operational resilience — Digital Operational Resilience and ICT Risk Governance | Customer-facing controls must preserve resilience while managing security friction in critical services. |
| Recommendation — Use DORA to ensure step-up controls do not undermine service continuity or resilience. | ||
Practitioner Guidance
What to prioritise: Start with the journeys that carry the highest business loss and customer impact, especially new-payee setup, payee changes, recovery flows, large transfers, and contact-detail changes. Those are the places where a small amount of friction can prevent outsized harm.
What to verify: Confirm that the trigger is explainable and observable. Teams should be able to show which signals caused the step-up, why the threshold was crossed, and whether legitimate users are abandoning the flow or retrying through support. If the control cannot be explained internally, it will be difficult to defend externally.
What not to automate: Do not let the system escalate every unusual event to the same heavyweight challenge. The best experience comes from graduated responses, where the control intensity matches the risk signal instead of treating all uncertainty as equal.
Practitioner takeaway: Friction should be a precision control, not a tax on the customer journey, so the real test is whether it reduces loss at the moments that matter without training users to fear normal banking interactions.
Related resources from NHI Mgmt Group
- How should financial institutions implement strong customer authentication for open banking without creating avoidable user friction?
- How should teams add user friction without damaging the customer experience?
- How should financial institutions balance DORA compliance with customer authentication experience?
- How should financial institutions govern digital lending workflows without creating more friction?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 18, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org