Authentication Should Be Built Around Customer Segments

USER AUTHENTICATION
BANKING SECURITY
COMPLIANCE
USER AUTHENTICATION
August 20, 2026
Authentication flow connecting different customer needs and devices to a successfully authenticated online banking session, illustrating a flexible approach to banking authentication.

Banks spend considerable effort segmenting customers for products, communications, and risk. A mortgage customer is treated differently from a primary current account holder. A corporate treasurer has different needs from a retail savings customer. Yet when it comes to authentication, many banks still design around a single primary approach: mobile-first authentication.

That gap is becoming harder to ignore. As authentication requirements evolve and customer expectations diversify, a one-size-fits-all model creates real problems: unnecessary hassle for some customers, inadequate accessibility for others, and limited ability to apply stronger controls where the risk actually warrants it.

How Banks Got Here

The shift toward mobile-first authentication made sense when it happened. Following PSD2's strong customer authentication requirements, mobile apps combined secure hardware, biometric authentication, modern cryptography, and a familiar user experience, making them the most practical option for most banks. Banks moved quickly, and the approach worked well for the majority.

The problem is that "the majority" is not everyone. And in many institutions, what started as a pragmatic default became a hard dependency. Authentication was often built into legacy systems in ways that made adding alternatives difficult. The result is a mobile-first monoculture that was never designed to be the only option but has become one in practice.

Why One Method Is Not Enough

Different customer segments interact with banking services in fundamentally different ways, and their authentication needs reflect that.

A retail customer who checks their banking app daily will barely notice a biometric login. A mortgage-only customer who logs in twice a year to check a statement faces a meaningfully different experience: they may have forgotten their PIN, be unfamiliar with the app, or simply find the process disproportionate to the task.

Elderly customers or those with limited digital confidence may struggle with mobile apps entirely. Customers with accessibility needs may find touch-based authentication physically difficult. Business users managing multiple accounts often require higher-assurance authentication methods than a standard mobile authenticator provides.

None of these are edge cases that can be dismissed. Together, they represent a significant portion of most banks' customer bases, and PSD3/PSR is now making the point explicitly: strong customer authentication must remain accessible and cannot depend exclusively on the use of smartphones.

Starting with Segments, Not Technologies

Circular framework mapping banking customer segments and typical personas to suitable authentication methods, including mobile authentication, passkeys, hardware keys, biometrics, and accessible alternatives.

The more productive question is not "which authentication method should we support?" but "which customer segments do we serve, and what does authentication look like for each of them?"

For most retail banks, a workable segmentation starts with a small number of dimensions: how frequently does this customer use digital channels, what device do they have access to, and are there accessibility or digital literacy considerations that affect their options? Overlapping these dimensions produces a manageable set of authentication profiles that can be matched to appropriate methods.

A daily mobile banking user is well served by embedded app-based authentication. A desktop-primary user benefits from a standalone token or passkey. An occasional user of a secondary product needs something they can rely on without having to maintain a dedicated app. A customer with accessibility needs may require a hardware alternative with stronger physical affordances.

The point is not to offer every possible method to every customer. It is to ensure that each segment has at least one method that genuinely fits their situation, rather than one method that fits most situations and creates problems for the rest.

What This Means in Practice

Moving from a single authentication method to a segmented approach is not purely a technology project, though it has a technology component. It also requires understanding which segments exist in the customer base, what friction they currently experience, and which alternative methods would meaningfully improve their situation.

Banks that have already invested in authentication platforms capable of supporting multiple authentication methods will find this transition considerably easier. For others, legacy authentication systems may need to be modernized before meaningful diversification becomes practical.

Either way, the starting point is the same: understand your customers before evaluating products.

A Broader Shift

The move toward segmented authentication reflects something larger than a regulatory requirement. It reflects a more mature understanding of what authentication is for. It is not a security checkbox applied uniformly. It is a mechanism for establishing trusted access that works for real people in real situations.

Banks that design authentication around their customers rather than around a single technology will be better positioned as the methods available continue to evolve, whether that means passkeys and mobile-first authentication, FIDO2 hardware tokens, biometric authentication, or digital identity wallets as those ecosystems continue to mature.

To learn more, download our whitepaper, which explores this topic in depth, including a reference segmentation framework, authentication method recommendations for each segment, and a practical transition roadmap for banks at different stages of their authentication journey.

Frequently asked questions

No items found.

Related articles

CONTACT US

Get in touch

Consider partnering with Wultra to meet compliance standards, deliver a secure and seamless user experience, and deliver additional value to your customers while improving your bottom line.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.