Insights
|
Share
FFIEC Layered Authentication Was Written for a Different Threat. Here's What's Changed.

The FFIEC guidance on authentication in internet banking environments was a landmark document when it was first published in 2005, and updated with material force in 2011. It established that single-factor authentication was no longer adequate for high-risk online transactions. It called for layered security. It required financial institutions to treat authentication not as a checkbox but as a risk-based, evolving discipline.
It was right. And it was written for a threat that no longer accounts for the majority of fraud losses affecting US financial institutions.
That is not a criticism of the guidance. It is a statement about how quickly the threat has moved, and why careful reading of the FFIEC's own language reveals that it already supports what the current threat environment requires.
What the FFIEC Guidance Was Designed to Address
The 2005 guidance and its 2011 supplement were written in a world where the primary fraud threat was external intrusion: adversaries attempting to access accounts using stolen credentials or exploiting weak authentication mechanisms.
The FFIEC's response was logical. If attackers are getting in because authentication is too easy to defeat, make authentication harder. Require more factors. Require device identification. Apply greater scrutiny at login for high-risk transactions. Layer the controls at the entry point.
This approach was effective against the threat it was designed for. Multi-factor authentication significantly reduced the utility of stolen credentials. Device fingerprinting and behavioural analytics at login added friction for attackers who lacked both the password and the enrolled device.
The door into the session became much harder to force open.
The Threat Has Moved Inside the Door
The fastest-growing fraud vector hitting US banks in 2026 does not attempt to force the door. It walks through it.
Account takeover losses in the US reached $15.6 billion in 2024. In the majority of cases, the mechanism is not a failed authentication event. It is a successful one, followed by a fraudulent session.
Credential theft at scale has industrialised. SpyCloud's annual report found 17.3 billion stolen session cookies in active circulation, credentials that allow attackers to resume authenticated sessions without triggering a new login event. The attacker does not need to authenticate. They inherit a session that already has.
Social engineering has evolved in parallel. Coaching fraud, where a fraudster, often posing as the bank's own fraud team, talks an authenticated account holder through authorising a payment, operates entirely inside a legitimate session. The account holder authenticated correctly. The authentication event offers no defence.
And then there is AI-enabled impersonation. Deepfake-generated voice and video attacks targeting authentication workflows have increased sharply. When these attacks succeed, the subsequent session is authenticated but not legitimate. The platform has no mechanism to detect the difference.
CrowdStrike's 2025 threat intelligence data found that multi-factor authentication had failed to prevent the attack in 84% of incident responses involving account takeover. Not because MFA was technically broken, but because the attack entered through or after the authentication event.
What This Means for Regulation E
Under Regulation E, financial institutions bear the loss for unauthorised electronic fund transfers. The keyword is unauthorised.
When an attacker uses stolen session cookies to resume an authenticated session and initiate a transfer, the question of authorisation becomes legally complex. The account holder did not authorise the transfer. But the platform cannot demonstrate that the person conducting the transaction was not the account holder, because it has no verification mechanism in the session, only at login.
This ambiguity is being resolved increasingly in favour of the consumer. Courts and regulators are applying Regulation E protections where the bank's authentication controls failed to detect that the verified account holder was no longer the person in the session, regardless of whether a legitimate login event preceded the fraud.
For financial institutions with material ATO exposure, the liability calculation is straightforward: if the loss sits with the bank under Regulation E, and the attack enters through the post-authentication session, then security investment at the login layer does not address the risk that carries the financial liability.
The FFIEC Guidance Already Supports the Answer
Here is what most implementation conversations miss: the FFIEC guidance does not restrict layered security to the authentication event. It calls for risk-based, layered controls applied proportionally to the risk of the transaction or activity.
The 2011 supplement specifically stated that financial institutions should implement layered security programs with controls that include monitoring for anomalies and adapting to the sophistication of threats. It explicitly acknowledged that "new and evolving threats" would require institutions to update their approach, not wait for new guidance.
Read against today's threat environment, the FFIEC framework already supports what continuous session-layer verification provides:
A risk-based control applied at the point of highest risk, the transaction, not only at the point of lowest friction, the login. A layered security mechanism that adds a verification layer within the session, without replacing existing login-stage controls. A monitoring capability that can distinguish, in real time, whether the verified account holder is present at the point of authorisation.
This is not a novel interpretation. It is the application of the FFIEC's own risk-based principles to a threat that has evolved since the guidance was written.
The gap is not the framework. The gap is in implementation.
What Continuous Session-Layer Verification Provides
The YEO CFR SDK provides continuous facial recognition at the session layer, operating throughout the authenticated session and at the point of transaction initiation, not only at login.
Three mechanisms work in combination. Advanced facial mapping verifies the account holder's identity against their enrolment profile. Anti-spoofing liveness detection prevents the use of photographs, video, or AI-generated deepfake media. Depth verification confirms physical presence, distinguishing a live person from a screen or mask.
All processing is on-device. No biometric data is transmitted to or stored on external servers. The integration is at the SDK level — it does not require infrastructure change, does not require a new authentication platform, and does not add perceptible friction for legitimate users completing genuine transactions.
For US financial institutions, the architecture addresses the BIPA exposure in parallel. Because biometric data never leaves the device, there is no collection, storage, or transmission for BIPA to regulate. The on-device design is the answer for compliance as well as fraud prevention.
The Implementation Gap
Financial institutions have invested heavily in getting login-stage authentication right. The investment has been appropriate. The return, in terms of reduced credential-only fraud, has been real.
The next investment decision is less about the login and more about what follows it.
The FFIEC guidance supports it. Regulation E liability creates the financial case for it. The threat data confirms that authenticated fraud is now the dominant vector.
What remains is the implementation decision, and for institutions still treating session-layer verification as a future consideration rather than a current control gap, the lost data from 2024 and 2025 suggests that the timeline needs to move.
YEO CFR SDK — Available for US Financial Institutions
YEO Messaging is working with US financial institutions through our GTM partner ReconIQ to integrate continuous session-layer verification into existing banking and payments platforms.
The SDK is available to integrate today.
Request SDK documentation: yeomessaging.com/sdk
Sources: SpyCloud 2025 Annual Identity Exposure Report; CrowdStrike 2025 Global Threat Intelligence Report; Javelin Strategy & Research, Identity Fraud Study 2025; FFIEC Authentication in an Internet Banking Environment (2005); FFIEC Supplement to Authentication in an Internet Banking Environment (2011).
Share
Newsletter
Get weekly updates on the latest compliance changes, product releases, and much more.



