Loading...

FFIEC, KBA and the rest of the alphabet soup

Published: October 4, 2011 by Guest Contributor


With the most recent guidance newly issued by the Federal Financial Institutions Examination Council (FFIEC) there is renewed conversation about knowledge based authentication. I think this is a good thing.  It brings back into the forefront some of the things we have discussed for a while, like the difference between secret questions and dynamic knowledge based authentication, or the importance of risk based authentication.

What does the new FFIEC guidance say about KBA?  Acknowledging that many institutions use challenge questions, the FFIEC guidance highlights that the implementation of challenge questions can greatly impact efficacy of its usefulness. Chances are you already know this.  Of greater importance, though, is the fact that the FFIEC guidelines caution on the use of less sophisticated systems and information that can be easily guessed or obtained from an Internet search, given the amount of information available. 

 

As mentioned above, the FFIEC guidelines call for questions that “do not rely on information that is often publicly available,” recommending instead a broad range of data assets on which to base questions.  This is an area knowledge based authentication users should review carefully.  At this point in time it is perfectly appropriate to ask, “Does my KBA provider rely on data that is publicly sourced”  If you aren’t sure, ask for and review data sources. 

At a minimum, you want to look for the following in your KBA provider: 

  

·         Questions!  Diverse questions from broad data categories, including credit and noncredit assets

·         Consumer question performance as one of the elements within an overall risk-based decisioning policy

·         Robust performance monitoring.  Monitor against established key performance indicators and do it often

·         Create a process to rotate questions and adjust access parameters and velocity limits.  Keep fraudsters guessing!

·         Use the resources that are available to you.  Experian has compiled information that you might find helpful: www.experian.com/ffiec

Finally, I think the release of the new FFIEC guidelines may have made some people wonder if this is the end of KBA.  I think the answer is a resounding “No.”  Not only do the FFIEC guidelines support the continued use of knowledge based authentication, recent research suggests that KBA is the authentication tool identified as most effective by consumers.  Where I would draw caution is when research doesn’t distinguish between “secret questions” and dynamic knowledge based authentication, which we all know is very different. 

Related Posts

Day 1 of Vision 2025 is in the books – and what a start. From bold keynotes to breakout sessions and networking under the Miami sun, the energy and inspiration were undeniable.  A wave of change: Jeff Softley opens Vision 2025  The day kicked off with a powerful keynote from Jeff Softley, Experian North America CEO, who issued a call to action for the industry: to not just adapt to change, but to lead it.  “It isn’t a ripple – it’s a tidal wave of technology,” Jeff said. “Together we ride this wave with confidence.”  His keynote set the tone for a day centered on innovation and the future of financial services – where technology, insight and trust converge to create lasting impact. Jeff continues this conversation in the latest Experian Exchange episode, where he explores three forces shaping the industry: the rise of AI, the demand for personalized digital experiences and the mission to expand credit access for all.  Turning vision into action: Alex Lintner on agentic AI  Building on Jeff’s message, Alex Lintner, CEO of Experian Software and Technology, took the stage to show how Experian is turning innovation into measurable results. His keynote explored how agentic and advanced AI capabilities are redefining financial services ROI and powering the next generation of the Ascend Platform™.  For a deeper look into how Experian is reshaping the economics of credit and fraud decisioning, read the latest American Banker feature.  Unfiltered insights from “Mr. Wonderful”  The day’s highlight came from Kevin O’Leary, investor, entrepreneur and the always-candid “Mr. Wonderful.” With his trademark wit and honesty, Kevin shared sharp insights on thriving in a disruptive economy, offering candid advice on leadership, risk and opportunity. He even gave attendees a peek behind the Shark Tank curtain, revealing a few surprises and the mindset that drives his bold business decisions.  Breakouts that inspired and informed  The conference floor buzzed with energy as attendees joined breakout sessions on fraud defense, AI-driven personalization, regulatory trends and consumer insights. Sessions highlighted how Experian’s unified value proposition is fueling double-digit growth, how to future-proof credit risk strategies and how data and innovation are redefining customer engagement across the lifecycle.   Hands-on innovation and connection  The Innovation Showcase gave attendees an up-close look at Experian’s latest tools and technologies in action. Meanwhile, friendly competition kept the excitement high through the Vision mobile app leaderboard – with every check-in and connection earning points toward the top spot.  Networking beyond the conference hall walls  As the sun set, Vision 2025 shifted into high gear with unforgettable networking events across Miami – from golf at the Miller Course to art walks, brewery tours and a scenic cruise through Biscayne Bay.   An evening to remember  The day closed with the first-ever Vision Awards Dinner, celebrating standout leaders who are shaping the future of financial services.   Up Next: Day 2  The momentum continues tomorrow as more keynote speakers take the stage. Stay tuned for more insights, innovation, and inspiration from Vision 2025. 

Published: October 7, 2025 by Sharis Rostamian

Tenant screening fraud is rising, with falsified paystubs and AI-generated documents driving risk. Learn how income and employment verification tools powered by observed data improve fraud detection, reduce costs, and streamline tenant screening.

Published: September 4, 2025 by Ted Wentzel

In today’s digital lending landscape, fraudsters are more sophisticated, coordinated, and relentless than ever. For companies like Terrace Finance — a specialty finance platform connecting over 5,000 merchants, consumers, and lenders — effectively staying ahead of these threats is a major competitive advantage. That is why Terrace Finance partnered with NeuroID, a part of Experian, to bring behavioral analytics into their fraud prevention strategy. It has given Terrace’s team a proactive, real-time defense that is transforming how they detect and respond to attacks — potentially stopping fraud before it ever reaches their lending partners. The challenge: Sophisticated fraud in a high-stakes ecosystem Terrace Finance operates in a complex environment, offering financing across a wide range of industries and credit profiles. With applications flowing in from countless channels, the risk of fraud is ever-present. A single fraudulent transaction can damage lender relationships or even cut off financing access for entire merchant groups. According to CEO Andy Hopkins, protecting its partners is a top priority for Terrace:“We know that each individual fraud attack can be very costly for merchants, and some merchants will get shut off from their lending partners because fraud was let through ... It is necessary in this business to keep fraud at a tolerable level, with the ultimate goal to eliminate it entirely.” Prior to NeuroID, Terrace was confident in its ability to validate submitted data. But with concerns about GenAI-powered fraud growing, including the threat of next-generation fraud bots, Terrace sought out a solution that could provide visibility into how data was being entered and detect risk before applications are submitted. The solution: Behavioral analytics from NeuroID via Experian After integrating NeuroID through Experian’s orchestration platform, Terrace gained access to real-time behavioral signals that detected fraud before data was even submitted. Just hours after Terrace turned NeuroID on, behavioral signals revealed a major attack in progress — NeuroID enabled Terrace to respond faster than ever and reduce risk immediately. “Going live was my most nerve-wracking day. We knew we would see data that we have never seen before and sure enough, we were right in the middle of an attack,” Hopkins said. “We thought the fraud was a little more generic and a little more spread out. What we found was much more coordinated activities, but this also meant we could bring more surgical solutions to the problem instead of broad strokes.” Terrace has seen significant results with NeuroID in place, including: Together, NeuroID and Experian enabled Terrace to build a layered, intelligent fraud defense that adapts in real time. A partnership built on innovation Terrace Finance’s success is a testament to what is  possible when forward-thinking companies partner with innovative technology providers. With Experian’s fraud analytics and NeuroID’s behavioral intelligence, they have built a fraud prevention strategy that is proactive, precise, and scalable. And they are not stopping there. Terrace is now working with Experian to explore additional tools and insights across the ecosystem, continuing to refine their fraud defenses and deliver the best possible experience for genuine users. “We use the analogy of a stream,” Hopkins explained. “Rocks block the flow, and as you remove them, it flows better. But that means smaller rocks are now exposed. We can repeat these improvements until the water flows smoothly.” Learn more about Terrace Finance and NeuroID Want more of the story? Read the full case study to explore how behavioral analytics provided immediate and long-term value to Terrace Finance’s innovative fraud prevention strategy. Read case study

Published: September 3, 2025 by Allison Lemaster