One of the most significant challenges banks encounter today is the ability to remotely verify the identity of their digital customers in a way that’s reliable, secure and easy to use.
In response, more U.S. financial institutions are taking action. They’ve replaced cumbersome onboarding processes and supplanted outdated authentication methods with advanced technologies like facial biometrics to remotely onboard and authenticate existing online banking customers.
AI can be a boon for fraudsters
As banks advance their technologies to meet this increased demand for remote banking activities, risks also advance. When a remote user applies for an account, product or service, an institution must verify if that user is the real owner of a genuine identity. Banks must also ensure that a remote customer is the same person each time they return and not an imposter or even a synthetic identity, like a deepfake.
Synthetic identities can be used to establish accounts that behave like legitimate accounts and may not be flagged as suspicious using conventional fraud detection models.
Detection and prevention are particularly critical given the rising pervasiveness of artificial intelligence (AI) in our lives. There’s little doubt AI has and will continue to revolutionize aspects of our lives, including the way we bank.
However, one emerging threat is the use of AI in banking fraud. Criminals are leveraging AI to execute scams that are increasingly sophisticated and difficult to detect by traditional authentication methods like passwords, one-time passcodes (OTPs), or even voice biometrics that can be subject to cloning attacks.
Digital identity technology: Overcoming barriers to adoption
The U.S. financial services sector has been slower to adopt advanced digital identity technologies than some other global regions, which could be attributed to the challenges the banking industry here faces around regulating interoperability and data exchange. Yet, with synthetic identity fraud expected to generate at least $23 billion in losses by 2030, according to Deloitte, pressure to act is mounting.
Today’s banking customers expect to open accounts and access services remotely with speed and ease. And on the flip side, fraudsters undermine security through online channels and siphoning money. All the while, there is the serious threat of Know Your Customer (KYC) and Anti Money Laundering (AML) non-compliance. Penalties for non-compliance include huge fines and even criminal proceedings. These cyber dangers also present an increased risk of bypassing sanctions and financing state adversaries.
The rise of facial biometrics
Facial biometrics represents a fusion of science and security and promises a paradigm shift in how we authenticate, identify, and safeguard in the digital banking realm.
Specifically, facial biometric verification technology delivers unmatched convenience and accessibility for customers, while at the same time creating significant security obstacles for adversaries.
More financial institutions will recognize in the year ahead how this type of biometric verification can reshape and redefine technology’s positive impact in balancing security with customer experience and will make the switch.
The security of biometrics relies not on the fact that faces are secret – they’re not. But faces are unique, non-sharable, cannot be stolen and never need to be reset. Face verification binds digital identities to real-world users by matching a selfie image with a government-issued ID.
This contrasts with voice biometrics, which have shown deep vulnerabilities due to increasingly advanced, effective, and accessible synthetic voice cloning techniques. Voice biometrics have also come under fire for failing to meet performance and accessibility expectations.
Facial verification resolves the usability issues of passwords, OTPs and voice cloning – since there’s nothing to remember or forget as a person carries their face wherever they go. The technology is also fully accessible, even for those who are speech impaired.
Consumers also have said they appreciate the convenience and accessibility of facial biometric technology. According to an of 16,000 global banking customers, 64% of respondents who use mobile banking either use face verification to access their accounts already or would do so if they could.
Not all facial biometrics technologies are created equal
Banks need to choose their facial biometric technology with care, as not all solutions are created equally. The digital injection of synthetic imagery, particularly deepfakes, is one of the latest and fastest growing threat vectors, and not all facial biometric technologies are resilient to it. As face verification gains traction and becomes more prevalent, threat actors are developing ever more sophisticated ways to circumvent these weaker systems to commit fraud.
Most face biometric technology incorporates some form of liveness detection to verify and authenticate customers. Liveness detection technology determines whether the user asserting their identity is a real, “live” person and not a presented artifact, such as an imposter posing with a mask over their face or a deepfake. The most effective method to defend against digital injection attacks and retain high levels of customer usability is through passive authentication, such as a unique one-time biometric, where the technology is not dependent on an individual having to follow complex instructions therefore enhancing security, user experience and inclusivity.
One-time biometrics assures both liveness and that a user is verifying in real-time, which is essential to a bank’s defense strategy against synthetically created media such as a deepfake. A one-time biometric is never repeated in a user’s lifetime and has a limited duration.
The unpredictability of one-time biometrics makes it extremely challenging for threat actors to replicate or reverse-engineer the authentication process since, once used, it can’t be replayed by a person attempting to use a previous authentication to spoof the system. It’s also worthless if stolen, mitigating the risk of a data breach. Lastly, privacy is enhanced because consumers knowingly opt into the authentication transaction and data is only stored for a limited time.
Biometric face verification remains the most secure and convenient way to verify unknown customer identities at onboarding, grant returning users access to accounts, and authenticate transactions.
This year, I expect to see the digital identity landscape poised for significant advances, with innovations set to redefine verification, elevate security standards, and enhance user experiences. This will protect banking institutions and help ensure customer satisfaction.
Joe Palmer is Chief Product & Innovation Officer at iProov.