The Paradigm Shift: Toward Continuous Authentication and Security Journeys in Digital Banking | Veridas
The Paradigm Shift: Toward Continuous Authentication and Security Journeys in Digital Banking
- May 20, 2026
- 4 mins read
Contents
The financial sector is undergoing an unprecedented transformation. Despite 53% of financial institutions increasing their fraud prevention budgets over the last three years, 70% of banks continue to experience rising economic losses due to fraud. This revealing statistic proves that spending more on technology isn’t enough if the strategy itself fails to evolve.
For years, the industry’s technological efforts focused on digitizing customer onboarding (initial identity verification) to comply with AML (Anti-Money Laundering) regulations and facilitate account opening. However, the threat landscape and the sophistication of attacks have changed drastically. Today, the real challenge is not just verifying who enters the bank for the first time, but securing every subsequent user interaction while providing a seamless experience.
The financial market is in the midst of what we at Veridas call “The Shift”: the indispensable transition from static, one-time identification toward continuous authentication. This evolution protects processes in both the front and back office, spanning from customer sign-up to every transaction, product enrollment, or mobile payment. We have fully entered the era of Security Journeys.
Real Market Trends: Production Data from Veridas
To understand the magnitude of this transformation, we look at real-world technology usage data from Veridas globally. Over the last 12 months, production in the financial sector has seen 1.9x growth in the consumption of authentication and identification solutions.
This growth is not just about volume; it reflects a structural change in how banks use biometrics today:
- April 2025: 80% (4 out of 5) of Veridas processes in the financial sector were for Identity Verification (IDV) during onboarding (document verification and selfies), while only 20% were for subsequent authentication to secure operations.
- March 2026: The ecosystem has mutated drastically. Out of every 10 current processes, 5 are IDV (onboarding), 3 are authentication, and 2 are identification (1:N biometric comparison against customer databases to detect duplicates).
The conclusion is definitive: one out of every two biometric processes we handle in the financial sector is now dedicated to authenticating and securing the customer journey, not just signing them up.
Gartner’s Backing: Traditional MFA and New Threats
This “Shift” toward continuous authentication aligns directly with recent Gartner analyses. According to their latest reports, 95% of banks rely on Multi-Factor Authentication (MFA), with SMS-based One-Time Passwords (OTP) being the most common method. However, attackers easily bypass these barriers through social engineering, phishing, and SIM swapping, creating a false sense of security that requires layered controls.
Gartner further warns of a skyrocketing emerging risk: AI-enabled fraud, which includes synthetic identities and deepfake attacks (both presentation attacks in front of the camera and direct digital injection of fake video). Traditional rule-based systems are no longer effective against these threats.
To combat this, the industry must move toward a “Perpetual KYC” (Know Your Customer) model, where customer profiles and data are continuously updated and monitored to identify discrepancies in real time. This is where biometric controls with liveness detection, which analyze subtle skin cues or require dynamic actions, become essential to ensure a genuine person is on the other side of the screen. In this landscape, identity solutions lacking CEN/TS 18099 certification against injection attacks will become obsolete; a technological gap that will primarily leave banks unprotected against the most critical vulnerabilities.
Global Use Cases: Securing the Customer Lifecycle
To illustrate how these Security Journeys are built, we analyzed the operational evolution of a leading global bank. This entity has moved from basic tech usage to deploying 67 active use cases across 10 different countries powered by the Veridas platform. A deployment of this scale is only viable when security doesn’t hinder business, which is possible thanks to technology that eliminates daily friction.
Their evolution is the perfect example of adapting to fraud:
- Regulatory Origins (2017-2018): They began in Spain using digital onboarding purely for remote customer acquisition and AML compliance.
- The Leap to the “NBA of Fraud” (2019-2020): Expanding into Latin America—a region considered the “NBA” of identity fraud—the bank realized biometrics were a vital defensive shield. They introduced 1:N identification (database clustering), comparing every new face in milliseconds against millions already on file to detect duplicates and scammers.
- The Maturity of Security Journeys (Present): Today, the bank has launched 100% digital subsidiaries (such as in Italy and Germany) and expanded through Central Europe using facial and voice biometric identity solutions to authorize critical operations.
Key Examples of Secured Security Journeys:
- Sensitive Data Modification (Changing Mobile Numbers): One of the most common routes for account takeovers. The entity now requires a biometric selfie with liveness detection before allowing a number update, mitigating SIM swapping and deepfakes.
- Device Tokenization: Veridas supports financial entities in flows designed to protect sensitive operations without adding user friction.
How does it work?
- IDV Verification: Confirming who is behind the screen via ID validation and a biometric selfie.
- Tokenization: Linking that verified identity to the mobile device to create a “trust token.” The phone becomes a secure channel based on the person, not just the device’s local passcode.
- Continuous Trust: During critical operations (resets, account changes), the security chain remains intact. If a user changes devices, trust isn’t lost because it always reverts to the source: the real person.
- Biometric Signing of Contracts and Loans: Authorizing complex financial operations (consumer loans or mortgage signing) with full legal validity and security.
- Proof of Life for Pensioners: Pioneering use of voice biometrics so users can provide proof of life and collect pensions without traveling to a branch.
Conclusion
Driven by a “fraud pandemic,” the financial industry is being pushed from a static view of identity to one that is in constant motion. As Gartner reports and Veridas’s client demand confirm, throwing money at obsolete security systems will not stop modern fraud. Implementing Security Journeys and Perpetual KYC models is no longer just a competitive edge for onboarding; it is the fundamental standard for ensuring fluid interactions, meeting regulations, and protecting every link in the customer relationship through real-time, continuous authentication.