Verification and authentication
Transaction approval
Signing in securely and approving the right transaction are different tasks. A strong sign-in control can reduce the use of stolen credentials, but it cannot decide whether the payment a person has been persuaded to make is legitimate. A World Bank review states that multifactor authentication can combat unauthorized fraud but does not prevent authorized-payment fraud.1
Transaction approval is most useful when it identifies what is being authorized. European Union payment rules require a payer making a remote payment with strong customer authentication to be shown the amount and payee. The resulting authentication code must be specific to those details, and changing either detail invalidates the code.2 This binds the approval to a particular transaction rather than to a vague instruction to confirm activity.
Broader payment evidence supports the distinction. In European Economic Area industry reports for 2024, transactions using strong customer authentication were generally less susceptible to fraud, especially card payments, while the effect was less clear for credit transfers.3 The European Banking Authority has also reported that fraudsters shifted toward social engineering as authentication reduced fraud based on stolen credentials.6
A recipient-name check supplies another transaction detail. The United Kingdom's Confirmation of Payee service compares the name entered by the payer with the account details held by the recipient's payment provider. Pay.UK states that a match does not guarantee detection of a fraudulent payment or reimbursement after one occurs.4 A match should therefore be read as a match, not as a verdict on the story behind the transfer.
Screen design can affect decisions in simulations. A UK behavioral experiment using high-fidelity payment journeys found that making cancellation or postponement prominent outperformed behavioral warnings and risk information. Warning effects weakened with repetition, while redesigned calls to action remained more effective.5 The experiment did not observe losses from live bank accounts.
The available warning experiment was simulated, and the supplied evidence does not establish how much transaction-approval design prevents consumer losses in the field. It also does not establish whether synthetic voice, video, or text changes the effectiveness of payee displays, name checks, or payment warnings.
Boundary. Transaction details help only when they are read and compared with the intended payment. Even accurate details cannot authenticate the person who requested the transfer or establish the request's legitimacy. Strong authentication may stop an unauthorized transaction while still permitting a payment that the account holder was deceived into approving. Name checks and warnings are therefore decision aids, not fraud guarantees.
参考文献
- [1]World Bank review of fraud in fast payments
- [2]European Banking Authority guidance on amount and payee binding
- [3]European Central Bank and European Banking Authority fraud findings
- [4]Pay.UK Confirmation of Payee guidance
- [5]UK simulated payment-journey experiment
- [6]European Banking Authority press release on social engineering and payment fraud
测验
A payment approval screen displays a payee and amount. What action best uses that protection?
- Compare the payee and amount before approval
- Trust the displayed name check as a guarantee that the payment is not fraudulent
- Let the caller explain what the screen means
Transaction approval is useful when the displayed details are compared with the payment the account holder actually intends.
A payment completed with strong customer authentication cannot still be a scam payment.
- True
- False
Strong authentication can reduce unauthorized fraud while still allowing a person to authorize a payment after being deceived.
评论
还没有评论,来说第一句吧。