28.1 Authentication, access and layered security
Key Takeaways
Authentication should reflect the transaction, access rights and assessed threats.
Layered security combines controls rather than treating a single login factor as sufficient in every setting.
Monitoring and recovery should address employees, customers and third parties under the institution’s risk assessment.
Authentication is part of a risk system
The FFIEC’s 2021 Authentication and Access to Financial Institution Services and Systems guidance replaced the older internet-banking authentication guidance and supplement. It addresses customers, employees, third parties and service accounts, reflecting risks from compromised credentials, remote access and digital financial services. It supplies risk-management principles and examples rather than prescribing one product that every bank must buy.
Authentication verifies an asserted identity; authorization determines what that identity may do. A successful login does not itself authorize a user to change every payment limit, create every recipient or access every customer record. Access management should connect identity, role, device, activity and privilege. A service account without a human user still needs an owner, a purpose and appropriate restrictions.
Assess users, activities and threats
A bank should inventory services, users, data and access paths, then assess threats and control effectiveness. Remote employees, vendors, customer-permissioned applications and administrators create different exposures. Push payments can cause losses quickly after a compromised credential; a risk assessment that considers only password length misses transaction risk.
Consider how credentials are issued, reset, recovered and revoked. A strong login control can be undermined by a weak help-desk reset process or a vendor account left active after termination. Customer enrollment, employee transfers and third-party offboarding all belong in the access lifecycle. Test those paths rather than measuring security only during the routine successful login.
Factors and layers
Multi-factor authentication (MFA) combines distinct factor types, such as something known, something possessed and an inherent characteristic. Two passwords are two knowledge secrets, not two independent factor types. MFA can reduce risk but can still be attacked through phishing, prompt fatigue, device compromise or weak recovery. Evaluate the method and threat, not just a vendor label.
Layered security combines controls at different points. Examples include device or behavior analysis, restrictions on high-risk transactions, limits, alerts, independent confirmation, monitoring and segregation of duties. A layer should address a real risk and work with the others. Requiring an extra question whose answer is easily found online may add little protection.
| Risk | Possible layer |
|---|---|
| Compromised credential | Appropriate MFA and anomaly detection |
| Unauthorized recipient change | Confirmation and controlled change workflow |
| Excessive administrator access | Least privilege and review of privileged activity |
| Dormant vendor credential | Inventory, expiration and offboarding |
| Fraudulent recovery request | Verified recovery procedures and escalation |
These examples are choices to tailor and test; the guidance does not require the same exact list for every institution. High-risk activities and users warrant stronger controls than a one-size-fits-all single-factor approach. Record why the controls fit the risk and what residual exposure remains.
Privilege and third-party access
Least privilege means granting access needed for the authorized role and limiting unnecessary capabilities. Review entitlements when an employee changes jobs, not only when leaving the bank. Segregate duties where one person otherwise could create, approve and conceal a sensitive transaction. Emergency access can be appropriate with logging, limited duration and review rather than an unmonitored permanent override.
Third-party access requires knowing the users, service accounts, systems and information involved. Customer-permissioned access creates risks even when the customer requests the connection. Evaluate credential sharing, API authorization, data scope, revocation and contractual responsibilities. An authorized vendor relationship does not imply that every vendor employee should have unrestricted production access.
Coordinate these controls with the bank information security program and incident-response procedures. Authentication failure can be an early sign of account compromise, but incident-notification duties depend on their actual legal triggers. A fraud alert is not automatically a thirty-six-hour regulator notification incident; investigate and assess the applicable definition.
Do not substitute login evidence for legal error analysis
Suppose a consumer reports an unauthorized electronic transfer after a correct password and one-time code were used. Security should investigate the mechanism, while deposit operations applies Regulation E’s definition, notice and investigation requirements. Valid credentials do not conclusively prove that the consumer authorized the transfer. Negligence or falling for a scam is not a universal exception to consumer protections; assess the facts and controlling interpretation.
For an employee account, repeated MFA prompts followed by a successful privileged login may indicate compromise. Review approvals, devices, recipient changes and logs, preserve evidence and limit risky access. An examiner expects a supported control response, not an assertion that MFA guarantees legitimacy.
Validate effectiveness
A monitoring plan should test enrollment, recovery, user changes, termination, privileged access and high-risk payment paths. Reconcile the entitlement population to employee and vendor inventories. Document exceptions, responsible owners and remediation. Training should explain suspicious prompts, safe recovery procedures and customer reporting routes without asking users to share secret codes publicly.
Review the assessment after material system or product changes, incidents and new threats. Report significant gaps and unresolved risk to appropriate management. The FFIEC 2021 guidance provides the current framework. Its lesson is to assess and validate a complete access system rather than equate one authentication feature with effective security or consumer-law compliance.
A bank uses a password and a second password as its only login factors. How should it classify them?
As two knowledge secrets, not independent MFA types.
As biometric authentication.
As two independent factor types.
As proof that every transfer is authorized.
Sections you finish are checked off in the contents.