Compliance · Banking

FFIEC MFA for Banks

The FFIEC authentication guidance tells examiners and institutions what good access control looks like at a bank or credit union: risk assessments, layered security, and multi factor authentication for high-risk users and transactions. For banking providers, Spriv delivers an essential layer of security above username-and-password, built to satisfy the FFIEC MFA requirements without adding friction to every login.

Adaptive Multi Factor Authentication authorization prompt on the Spriv mobile app for a banking login
FFIEC MFA · Risk-based, out-of-band
0
Year the current FFIEC guidance was issued
0+
Issued Spriv patents, including transaction validation
0
Separate channels for every out-of-band check
0 ms
Typical second-factor time on a trusted pair
FFIEC authentication guidance

What the 2021 FFIEC guidance says about MFA

In August 2021 the FFIEC issued Authentication and Access to Financial Institution Services and Systems. It replaced the 2005 internet banking authentication guidance and its 2011 supplement, and it is broader: it looks at everyone and everything that accesses the institution's systems, not only online banking customers.

Risk-based, not prescriptive

It is guidance, not a regulation. Institutions are expected to assess risk and choose controls to match, and examiners use it to evaluate those choices.

MFA for high-risk access

It recommends MFA, or controls of equivalent strength, for high-risk users and high-risk transactions, and treats single-factor authentication as weak for those cases.

Every type of user

Customers, employees, third parties and system-to-system access are all in scope, including privileged and remote access.

Layered security

Authentication is one layer among several. The guidance also calls out risk assessments that are kept current and monitoring for suspicious access.

Confirm with your examiners. How the guidance applies depends on your institution's risk assessment and the expectations of your regulator. This page is general information, not legal or examination advice; confirm scope with your compliance team and auditors.
MFA for banks

Where banks and credit unions need multi factor authentication

The guidance asks institutions to match the strength of authentication to the risk of the activity. These are the activities most risk assessments rate highest.

Online and mobile banking login

Customers reuse passwords, and credential stuffing turns old breaches into account takeovers. Spriv's API lets your platform check the customer's paired phone against the device and location of the login, so routine logins clear silently and unusual ones are challenged. Risk based MFA.

Wire transfers and payee changes

A logged-in session can still be hijacked. Authenticating the transaction itself, on the second channel, catches the fraud a login check never sees: an Allow/Deny prompt or two-way SMS for a wire above a threshold, a new payee or an address change. Transaction authentication.

Employee remote access and RDP to core systems

Staff and vendors connecting remotely to core banking, loan origination or back-office servers need more than a password. Spriv adds MFA to Windows and RDP logins and to SSH on Linux and Unix servers.

Administrator and privileged access

Privileged accounts can change configurations, limits and permissions. Keep them on an explicit Allow/Deny step for production access, alongside adaptive checks for routine work.

Spriv for banks

Layered, risk-based MFA for financial institutions

Spriv's patented approach lines up with the layered, risk-based model the guidance describes.

LAYER 01

Risk-based engine

Each request is weighed on geographic location, device reputation, login history, behavioral patterns, time of access and network characteristics.

LAYER 02

Out-of-band confirmation

The second factor is verified on the phone, a channel separate from the browser or session an attacker may control.

LAYER 03

Impossible travel detection

Spriv's patented check compares the distance and speed between the phone's location and a second transaction, flagging moves no one could make. Impossible travel detection.

Deployment

Run Spriv in your own data center

Banks and large institutions can host Spriv on Custom Servers in their own data center. Everyone else uses Spriv's shared cloud servers.

  • Transaction validation patents

    Titles include "Method and system for validating electronic transactions". Patents

  • Zero PII transferred

    Spriv confirms the phone and computer locations align, without sharing the phone's actual location.

  • REST API for customer logins

    Sample code in five languages for online and mobile banking. API reference

Questions

FFIEC MFA questions

Is the FFIEC guidance a legal requirement?

It is supervisory guidance rather than a regulation, but examiners at the FFIEC member agencies use it when they review an institution's authentication and access controls, so in practice it sets expectations.

Does the guidance apply to credit unions?

Yes. The NCUA is an FFIEC member, so multi factor authentication for credit unions follows the same risk-based guidance as for banks.

Do customers have to approve every login?

No. Adaptive MFA approves a matching phone-and-device pair in the background, and prompts only on abnormal information. That keeps prompts rare enough that customers read them instead of approving out of habit.

Does Spriv guarantee FFIEC compliance?

No vendor can. Spriv's MFA is built to satisfy FFIEC expectations and helps you meet them; your risk assessment, policies and controls decide how examiners view your program.

Checkit!

MFA your examiners and customers can live with

Two free users and two free servers, no credit card. Try it on your own servers, then talk to us about Custom Servers for your data center.