The Federal Financial Institutions Examination Council issued updated guidance on authentication and access risk management in November 2023. This guidance establishes examiner expectations for layered security controls, risk-based customer authentication and continuous monitoring of access activity across systems holding customer data and supporting financial operations.
Leadership at banks, credit unions and other FFIEC-examined institutions is now accountable for demonstrating a security outcome that typically lacks a clear owner, implementation sequence or method of measuring progress. This article explains what the guidance requires, who owns it and what steps establish adequate governance.
Why Authentication and Access Management Matters to Financial Institution Leadership
Authentication and access management determine who can reach customer accounts, transaction systems and sensitive data. Inadequate controls create regulatory findings, operational risk and potential customer harm. Examiners assess these controls as part of safety and soundness reviews, and deficiencies can result in enforcement actions, consent orders or limitations on business activities.
The November 2023 guidance reflects examiner expectations shaped by increased sophistication of authentication bypass techniques, credential-based attacks and insider risk. Financial institutions that cannot demonstrate layered controls, risk-based authentication decisions and monitoring of privileged access face regulatory criticism regardless of whether a breach has occurred.
Leadership accountability extends beyond IT implementation. The guidance expects governance that connects authentication decisions to enterprise risk appetite, board oversight of access risk and clear assignment of authority for authentication policy and exception approval.
What the Guidance Requires
The FFIEC guidance establishes expectations across customer-facing authentication, employee and third-party access controls, and monitoring. While the guidance does not mandate specific technologies, it sets performance standards examiners will assess.
Layered Security for Customer Authentication
Financial institutions must implement authentication that adjusts to transaction risk. Higher-risk activities—such as funds transfers, account changes or access from unrecognized devices—require stronger authentication than routine balance inquiries. The guidance expects institutions to assess risk using multiple factors including transaction type, amount, destination, user behavior and device characteristics.
Single-factor authentication using only a password or PIN no longer meets examiner expectations for transactions that could result in unauthorized fund movement or data exposure. Institutions must deploy multifactor authentication or equivalent risk-based controls that verify identity through something the user knows, has or is.
The guidance also addresses out-of-band authentication, device fingerprinting and challenge questions, noting that methods must resist current attack techniques including social engineering, SIM swapping and session hijacking.
Access Controls for Employees and Third Parties
Institutions must enforce least-privilege access principles, granting only the permissions necessary for each role. Privileged accounts—those with administrative rights, database access or transaction approval authority—require enhanced controls including multifactor authentication, session monitoring and regular recertification.
Third-party access to institution systems or customer data must be governed by the same standards as employee access, with formal approval processes, time-limited credentials and monitoring. Examiners expect institutions to maintain current inventories of who has access to what systems and data, and to demonstrate periodic reviews that remove unnecessary permissions.
The guidance requires segregation of duties for sensitive functions, preventing any single individual from initiating, approving and reconciling transactions without independent verification.
Continuous Monitoring and Incident Response
Financial institutions must monitor authentication events and access activity for anomalies that may indicate compromise, insider threat or control failure. This includes logging authentication attempts, tracking privileged account usage and alerting on unusual access patterns such as geographic anomalies, after-hours activity or bulk data extraction.
Monitoring alone does not satisfy the guidance. Institutions must demonstrate that alerts trigger investigation, that findings inform access policy adjustments and that incidents result in documented response actions. Examiners review logs, alert configurations and incident records to assess whether monitoring produces actionable intelligence.
Who Owns Authentication and Access Management
Authentication and access management sits at the intersection of information security, IT operations, compliance, audit and business units. This distributed responsibility creates gaps where no single executive owns the outcome examiners will assess.
Adequate ownership requires executive accountability for authentication strategy, risk decisions and regulatory position. The chief information security officer or equivalent executive must own the authentication framework, approve risk-based authentication rules and authorize exceptions to policy. This executive reports access risk posture to the board and translates regulatory expectations into testable controls.
IT operations implements and maintains authentication systems, but cannot decide acceptable risk or approve authentication methods without security leadership involvement. Compliance monitors regulatory developments and examiner feedback, but cannot design controls or assess technical adequacy. Audit tests control effectiveness but does not operate authentication systems.
Business unit leaders own access decisions for their functions, approving who needs what access and recertifying permissions periodically. They cannot delegate this accountability to IT or security without losing the business context required for least-privilege enforcement.
Many financial institutions lack a full-time CISO or equivalent security executive with authority to make authentication decisions, manage access risk and represent the institution's security position to examiners. This gap is precisely what [virtual CISO (vCISO) leadership](/vciso/) addresses: executive ownership of the strategy, governance and risk decisions that close the accountability gap the FFIEC guidance exposes.
How This Relates to Identity and Access Management Strategy
Authentication and access management are components of a broader identity and access management strategy. IAM strategy defines how the institution proves identity, grants permissions, monitors usage and removes access across all systems and data.
The FFIEC guidance does not prescribe IAM architecture, but examiners will assess whether the institution has a coherent strategy rather than disconnected point solutions. Strategy includes policy that sets authentication requirements by risk tier, standards that govern account provisioning and de-provisioning, and processes that ensure access decisions align with business roles and regulatory obligations.
Institutions with mature IAM strategies can demonstrate to examiners how authentication methods tie to risk assessment, how access permissions derive from documented roles and how monitoring detects deviations from expected patterns. Institutions without strategy face examiner criticism even if individual controls are adequate, because disconnected controls cannot produce the risk-based decisions and continuous improvement the guidance expects.
IAM strategy also addresses identity lifecycle management—the processes for creating, modifying and terminating access as employees join, change roles or leave. The FFIEC guidance expects timely de-provisioning, particularly for privileged accounts, and periodic recertification that confirms current access remains appropriate.
What Leadership Should Do Next
Establishing accountability for the FFIEC's authentication and access management expectations requires clarity about current state, gaps and ownership.
First, confirm who owns authentication and access risk at an executive level. If no single executive can describe the institution's authentication strategy, explain how access decisions align with risk appetite or represent the security position to examiners, ownership is unclear. Clarify this accountability before addressing technical controls.
Second, inventory current authentication methods for customer-facing systems and employee access. Document which systems require only single-factor authentication, which support multifactor authentication and which transactions trigger risk-based authentication challenges. Identify gaps where high-risk transactions lack layered controls.
Third, review access governance processes. Determine how often privileged accounts are recertified, how quickly access is removed when employees depart and whether business units actively approve access requests or simply rubber-stamp IT provisioning. Weak governance creates risk regardless of technical control sophistication.
Fourth, assess monitoring and response capabilities. Confirm that authentication logs are collected, retained and reviewed, that alerts exist for high-risk access events and that incidents trigger documented investigation and remediation. Monitoring without response does not satisfy examiner expectations.
Fifth, prepare to explain authentication and access strategy to examiners. Leadership must articulate how the institution determines acceptable authentication methods, how access decisions align with least privilege, how monitoring informs risk management and how the board oversees access risk. Inability to answer these questions creates examination findings.
For institutions without full-time security leadership, establishing this accountability and preparing a defensible regulatory position requires external expertise. Heights Consulting Group provides virtual CISO leadership that closes this gap: strategy development, governance design, risk decisions and examiner engagement. If you need executive ownership of your authentication and access management program to meet the FFIEC's November 2023 guidance, a confidential consultation will clarify your position and next steps. Contact Heights directly to schedule that conversation.
Sources
- Cybersecurity Framework | NIST , www.nist.gov
- Privacy and Security | Federal Trade Commission , www.ftc.gov
- Privacy Framework | NIST , www.nist.gov
Related service: Identity and Access Management Strategy
A defensible answer to who has access to what, how they got it, and how it is removed, the question every assessment asks and most organizations answer from memory.