Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What do banks get wrong when they treat…
Governance, Ownership & Risk

What do banks get wrong when they treat generational preferences as a pure technology problem?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 29, 2026 Domain: Governance, Ownership & Risk

Banks get it wrong when they assume younger customers only want more technology and older customers only want traditional service. The real issue is matching verification, support, and communication to the customer journey. If the bank optimizes for speed alone, it can create abandonment, confusion, or weak controls. If it overrelies on human review, it slows legitimate onboarding and frustrates digital users.

Why the customer journey matters more than age stereotypes

Banks get into trouble when they assume preference is really a generational trait. In practice, the right channel depends on the task, the customer’s confidence, and the level of assurance required. A payments dispute, a new-device login, and a mortgage application do not deserve the same interaction model, even for the same person.

That means the bank should design around journey friction, not demographic shorthand. A fast path is useful when the decision is low risk and the customer is already known; a guided path is better when the bank needs more verification, explanation, or exception handling. The mistake is treating “digital” and “human” as opposites instead of complementary controls.

The strongest programs make the journey adaptive. They let customers self-serve where speed matters, then insert support or stronger checks where uncertainty, value, or regulatory exposure rises. That is a service design issue, but it is also a control design issue, because the interaction model affects who can proceed, how errors are caught, and whether the bank can explain a decision later.

Where speed-first design breaks trust and control

When banks optimize only for speed, they often remove the very steps that protect both customer and institution. Simple flows can fail if they do not give enough room for identity proofing, exception review, fraud screening, or disclosure of why a step is required. The result is not just a poor user experience, it can become abandonment, confusion, or unsafe acceptance of risk.

Conversely, when banks keep too much manual review in the path, they create their own bottlenecks. Customers who are ready to transact get stuck waiting for approval, repeated document checks, or inconsistent branch callbacks. That can push legitimate users away while still not guaranteeing better outcomes, because human review is only as good as the evidence it receives.

The practical lesson is that friction should be deliberate, not accidental. If the bank requires extra verification, it should be because the risk level changed, not because the process is old. If it offers a faster digital route, it should still preserve the ability to challenge anomalies, escalate uncertainty, and prove the bank exercised appropriate control.

Designing for verification, support, and communication together

The bank usually needs three things working at once: verification that is proportionate, support that is reachable when needed, and communication that explains the journey in plain language. When any one of those is missing, customers interpret the process as arbitrary, even if the control itself is sound.

A good rule is to match the service layer to the risk layer. Low-risk actions can be streamlined, but higher-risk actions should add explanation, not just more friction. That may mean clearer prompts, better escalation paths, or a human handoff at the exact point where the customer is most likely to abandon the process or make a mistake.

It also means measuring completion, not just adoption. A channel may look successful because many customers start it, but if too many fail at verification, call support, or restart elsewhere, the design is not actually serving the journey. The bank should compare completion rates, exception rates, and customer drop-off across the same task rather than assuming one channel is universally better.

Risk and Threat Considerations

When banks oversimplify preferences into “digital versus traditional,” they can weaken both security and resilience. A process that is too fast may miss anomalies or encourage shallow verification, while a process that is too manual can create predictable failure points, reduce visibility into what customers actually experienced, and make workarounds more attractive.

Failure mechanism: The institution applies the wrong control intensity to the wrong journey, either removing necessary verification from a sensitive path or adding so much friction to a routine path that users abandon it or seek informal shortcuts.

Impact: The bank can end up with preventable abandonment, higher support load, inconsistent evidence quality, and weaker assurance over who was authenticated, who was helped, and why a decision was made.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-2 — Identification and Authentication (Organizational Users)Customer journeys still depend on strong authentication at sensitive steps.
AC-6 — Least PrivilegeJourney design should limit what each step can approve or expose.
AU-6 — Audit Review, Analysis, and ReportingBanks need evidence for why a journey succeeded, failed, or escalated.
Recommendation — Apply IA-2 to gate higher-risk actions with appropriate authentication. Apply AC-6 to keep each channel step limited to its needed authority. Use AU-6 to review journey events and exception handling for control gaps.
NIST CSF 2.0PR.AA-05 — Identity Management, Authentication, and Access ControlThe answer centers on matching verification to task risk and customer journey.
ID.AM-01 — Physical devices and systems are inventoriedJourney choice depends on knowing which customer touchpoints and systems are in play.
Recommendation — Use PR.AA-05 to align authentication strength with journey risk. Map customer-facing touchpoints so channel controls match the actual journey.

Practitioner Guidance

What to verify: Test the bank’s most common customer journeys end to end, especially onboarding, login recovery, dispute handling, and high-value requests. Check where customers fail, where they request help, and where controls force them into an unsafe workaround.

Decision rule: If the journey affects identity, funds movement, account recovery, or regulatory obligation, favour proportionate verification plus a clear human escalation path. If the issue is convenience only, remove friction before you remove assurance.

What good looks like: Customers can complete routine tasks quickly, get clear reasons when extra checks are needed, and reach support without restarting the entire process. The bank can show that speed, support, and control were designed as one system rather than three separate teams.

Practitioner takeaway: The real design question is not which generation likes which channel, but where the bank can safely reduce friction without losing enough context to verify, assist, and explain the journey well.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org