On Tuesday, the Federal Financial Institutions Examination Council issued a supplement to its 2005 guidance for financial institutions that let customers conduct transactions online. The goal of the supplement, Authentication in an Internet Banking Environment, is to โreinforce the risk-management framework described in the original guidance, and update the FFIEC member agencies’ supervisory expectations regarding customer authentication, layered security, and other controls in the increasingly hostile online environment,โ the FFIEC said in its announcement.
The supplement offers updated regulatory expectations regarding customer authentication, layered security, and other controls. For example, because more businesses and consumers are conducting online financial transactions than was the case in 2005, the Supplement recommends implementing more robust controls as the risk of a transaction increases, as well as a layered approach to security. That is, different controls are used at various points in the process, so that a weakness in one control is compensated for a different control. Among the controls that might be part of this approach: fraud detection systems and controls on account activity, such as limits on the number of transactions allowed daily.



