Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk Why do MFA and other step-up controls still…
Governance, Ownership & Risk

Why do MFA and other step-up controls still need careful tuning in fintech environments?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 7, 2026 Domain: Governance, Ownership & Risk

They are necessary because attackers use credential stuffing, phishing, and account takeover techniques against valuable accounts. But if every session is challenged, legitimate users experience friction and may abandon the journey. Effective tuning aligns challenge frequency with risk, so security controls protect high-value interactions without undermining conversion, retention, or customer trust.

Why Fintech Step-Up Controls Fail When They Are Treated as Static Friction

MFA and step-up controls are not simply about adding another barrier. In fintech, they sit at the intersection of fraud reduction, transaction assurance, and customer experience, so the tuning problem is operational as much as it is technical. If the challenge policy is too aggressive, legitimate customers encounter needless interruptions; if it is too loose, attackers get a cleaner path through credential stuffing, phishing, and session abuse. For identity-heavy services, the control has to reflect account value, device confidence, user behaviour, and transaction context rather than applying one fixed rule to every login. The OWASP Non-Human Identity Top 10 is relevant here because fintechs often overlook how machine and service identities can also amplify the same access-trust problem. In practice, many teams discover their step-up policy is mis-tuned only after conversion drops or fraud patterns shift faster than their control thresholds.

How Step-Up Authentication Should Behave in a Real Fintech Journey

Careful tuning means the control should respond to context, not just identity presence. A low-risk balance check, a known device, and a normal geo-velocity profile may justify a silent session, while a beneficiary change, payout instruction, password reset, or sudden device shift should trigger stronger verification. The point is not to remove challenge, but to place it where it changes the risk equation. If every interaction gets the same challenge, customers learn to expect disruption and may be pushed toward weaker workarounds or support channels.

Good tuning usually combines multiple signals: authentication strength, device reputation, behavioural anomalies, transaction value, payee novelty, IP reputation, and session age. It also distinguishes between authentication events and high-impact actions. A user may be safely logged in yet still need step-up before money movement, profile changes, or credential recovery. This is especially important in regulated financial services, where the control must protect both the account and the transaction path.

A practical implementation also needs exceptions. High-risk customers, first-time devices, travel scenarios, or assisted-service channels often require different thresholds. The control should therefore be measurable, reviewed, and adjustable, not treated as a permanent rule. Where tuning is too blunt, the result is often either fraud leakage or alert fatigue. The guidance breaks down when organisations cannot distinguish normal variation from suspicious behaviour with enough confidence to set meaningful thresholds.

Where Fintech Teams Over-Correct or Under-Correct Step-Up Policies

Tighter authentication usually improves fraud resistance, but it also increases abandonment and support burden, so organisations need to balance loss prevention against user friction.

One common mistake is to equate “more prompts” with “more security.” That is not always true. Excessive prompting can teach users to approve requests reflexively, reduce trust in the journey, and create a service pattern that fraud teams cannot realistically sustain. Another edge case is delegated or shared access, such as family, business, or support-assisted accounts, where step-up logic may misclassify legitimate behaviour as hostile. In those cases, the question is not whether to challenge, but whether the policy understands the relationship and action being authenticated.

There is also a governance tradeoff in how fast tuning changes. Frequent threshold changes can reduce fraud exposure, but if they are not validated against user impact and event data, teams may create moving targets that are difficult to explain or audit. The consensus view is that adaptive step-up is preferable to fixed, one-size-fits-all challenge rules, but there is no single universal threshold model that fits every fintech product. The right answer depends on the transaction type, customer segment, and fraud tolerance of the business.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while CIS Controls v8, NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Inventory and Ownership of Non-Human IdentitiesFintech step-up tuning often depends on service and machine identity trust paths.
Recommendation — Inventory service identities and require step-up on high-risk privilege changes.
CIS Controls v86 — Access Control ManagementStep-up policies are an access control measure that must be tuned to risk.
Recommendation — Enforce least-privilege access and raise authentication only for higher-risk actions.
NIST CSF 2.0PR.AA — Identity Management, Authentication, and Access ControlThe question centers on authentication strength versus user friction.
Recommendation — Adjust authentication requirements to match transaction risk and user context.
MITRE ATT&CKT1110 — Brute ForceCredential stuffing and takeover attempts are core adversary drivers for step-up.
Recommendation — Detect brute-force and stuffing patterns and trigger step-up when abuse indicators rise.
NIST SP 800-63AAL — Authenticator Assurance LevelStep-up controls should align assurance strength with transaction sensitivity.
Recommendation — Map transaction sensitivity to the required authenticator assurance level.

Practitioner Guidance

What to prioritise: Tune step-up around the actions that change financial exposure, not around every authenticated session. The highest-value checkpoints are usually payments, payee changes, account recovery, and device or contact-detail changes.

What to verify: Check that the policy distinguishes between authentication assurance and transaction risk. If the same challenge rate applies to low-risk browsing and high-risk money movement, the control is probably too blunt to be reliable.

What practitioners underestimate: User friction is a security variable, not just a UX concern. When challenge volume is too high, customers and support agents invent bypass patterns that weaken the intended control.

Practitioner takeaway: The best step-up policy is selective enough to protect high-impact actions, but predictable enough that legitimate customers do not learn to distrust or defeat it.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 7, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org