News

|

Share

Continuous Biometric Authentication for Banking: Why Login Is No Longer Enough

Banks have become very good at establishing identity at specific points in the customer journey.

Identity checks help confirm who a customer is during onboarding. Passwords, device signals, passkeys, biometrics and one-time codes help determine whether access should be granted at login.

But what happens next?

A successful authentication event confirms that the required evidence was presented at a particular moment. It does not necessarily confirm that the same person remains behind the screen throughout the session.

That distinction creates an important gap in digital banking security.

The identity gap after login

Once a customer has authenticated, the banking session is usually treated as trusted until it ends or another step-up check is triggered.

During that time, the customer may:

  • Add or change a beneficiary

  • Approve a high-value payment

  • Register another device

  • Change contact or security details

  • Access sensitive financial information

  • Begin an account-recovery journey

These actions can take place several minutes after the original authentication event.

The bank may have clear evidence of who entered the session. It may have less certainty about who is present when the most consequential action occurs.

This is the session-level identity gap.

How a trusted session can become untrusted

A banking session can be compromised without a failed login.

A customer might leave an authenticated device unattended. Another person may take control of a shared device. Malware or remote-access software can allow a fraudster to operate an existing session. Stolen session data may enable an attacker to resume access without repeating the original authentication process.

An attacker might also obtain valid credentials or successfully complete a point-in-time challenge. In that situation, the authentication control has worked as designed, but the person operating the account is still not the authorised customer.

The problem is therefore not always that a bank failed to authenticate someone.

The problem may be that identity was established once and then assumed for the remainder of the session.

Why repeated authentication does not fully close the gap

Banks already use additional authentication for sensitive actions. A customer may be asked to enter a one-time code, approve a request inside a banking app or repeat a biometric check.

These controls remain important, but they can introduce additional friction. They also continue to confirm identity or possession at individual moments rather than maintaining assurance throughout the journey.

Possession-based challenges answer questions such as:

  • Does this person know the password?

  • Do they have access to the registered device?

  • Can they retrieve or approve the code?

Those questions are valuable, but they do not always answer another important question:

Is the enrolled customer still the person present and in control?

What continuous biometric authentication changes

Continuous biometric authentication extends identity assurance beyond the login event.

Instead of treating identity as established for the entire session, it allows a bank to reassess whether the person present continues to match the enrolled customer.

Depending on the bank’s risk policy and customer journey, verification could operate:

  • During an approved active session

  • At configurable intervals

  • Before or during a high-risk action

  • When another fraud or device signal indicates increased risk

The resulting identity signal can feed into the bank’s existing decisioning process.

When confidence remains above the bank’s approved threshold, the journey can continue without unnecessary interruption. When confidence declines, the bank can request reverification, restrict a sensitive action, initiate another control or refer the event for investigation.

This turns identity from a one-off access decision into an active session control.

Where continuous biometric authentication can add value

Continuous biometric authentication is especially relevant to journeys where the identity of the person present matters as much as the credentials being used.

Payment and beneficiary approval

A bank can add identity assurance before or during a high-value payment, the creation of a new beneficiary or an unusual change in payment behaviour.

Active digital-banking sessions

The bank can continue to assess whether the enrolled customer remains present after login, rather than assuming that the authenticated user controls the entire session.

Account recovery

Recovery journeys are frequently targeted through credential compromise and social engineering. Continuous biometric authentication can add identity evidence while sensitive access is being restored.

Card controls and account settings

Actions such as registering a new device, changing contact details or modifying security settings can receive additional identity assurance.

Customer service and secure communications

Where customers access sensitive information or issue instructions digitally, continuous verification can help confirm who remains present throughout the interaction.

An additional layer, not a replacement

Continuous biometric authentication should not replace the wider banking security stack.

Banks still need strong onboarding, authentication, device intelligence, behavioural analysis, transaction monitoring and fraud controls.

Each of these controls answers a different question.

Device intelligence can identify whether a device or connection presents known risk. Behavioural biometrics can identify unusual interaction patterns. Transaction monitoring can detect anomalous payments or account actions.

Continuous biometric authentication adds another signal: whether the physical person present continues to match the enrolled customer.

Together, these signals give the bank a more complete view of the session.

The limits also matter

Continuous biometric authentication does not solve every type of banking fraud.

In a coached authorised push payment scam, for example, the genuine customer may be present and acting under manipulation. A facial match would confirm their identity, but it would not determine whether the payment decision was safe.

Those scenarios still require behavioural, transaction-risk and customer-protection controls.

The direct role of continuous biometric authentication is more specific: helping identify when an unauthorised person is operating a trusted session or when the enrolled customer is no longer present.

Being precise about that role is essential to deploying the technology responsibly.

Privacy must be part of the architecture

Any use of biometric technology raises legitimate questions:

  • Where is the biometric information processed?

  • Does facial imagery leave the customer’s device?

  • Who can access the information?

  • What does the bank record?

  • How long is the data retained?

  • What happens when the customer changes device?

YEO’s Continuous Facial Recognition SDK performs facial matching, liveness analysis, and depth verification on the user’s device. It does not require a central YEO database of customer facial images or biometric templates to perform session verification.

The bank remains responsible for its legal basis, customer notices, accessibility, data protection impact assessment, and retention policies. On-device processing does not eliminate those obligations, but it can reduce the amount of sensitive biometric information that must leave the customer’s device.

From authentication event to identity assurance

The banking industry has spent years strengthening the point of entry.

That investment remains essential. But digital trust cannot end when the customer passes the login screen.

Banks also need confidence at the moments when money moves, security details change or sensitive information is accessed.

Continuous biometric authentication adds that missing session-level identity signal. It helps banks move from asking who authenticated at the beginning to understanding who remains present when it matters.

Verified at login should not mean trusted indefinitely.

Discover how YEO’s CFR SDK can add continuous identity assurance to digital-banking journeys.


Get the

Document

Solution Mentioned

Ready to Know Who's There?

Share

About us

We stopped asking "who logged in." We started asking "who's still there." YEO began as a secure messaging app. Today we build the patented continuous identity verification infrastructure that regulated industries trust to prove who's really there.

© 2026 YEO messaging Ltd is registered in England and Wales 10785061.

🇺🇸 US Patent No: 10,607,035 (Granted March 31, 2020)
🇬🇧 GB patent No: 1713943.7 (Granted February 2022)
🇨🇳 Chinese patent 201880071020.4 (Granted April 2nd 2024)
🇪🇺 EU patent No: PCT/EP2018/073464 (Granted July 2026)

© 2026 YEO messaging Ltd is registered in England and Wales 10785061.

🇺🇸 US Patent No: 10,607,035 (Granted March 31, 2020)
🇬🇧 GB patent No: 1713943.7 (Granted February 2022)
🇨🇳 Chinese patent 201880071020.4 (Granted April 2nd 2024)
🇪🇺 EU patent No: PCT/EP2018/073464 (Granted July 2026)

© 2026 YEO messaging Ltd is registered in England and Wales 10785061.

🇺🇸 US Patent No: 10,607,035 (Granted March 31, 2020)
🇬🇧 GB patent No: 1713943.7 (Granted February 2022)
🇨🇳 Chinese patent 201880071020.4 (Granted April 2nd 2024)
🇪🇺 EU patent No: PCT/EP2018/073464 (Granted July 2026)