FFIEC MFA for Banks
The FFIEC authentication guidance tells examiners and institutions what good access control looks like at a bank or credit union: risk assessments, layered security, and multi factor authentication for high-risk users and transactions. For banking providers, Spriv delivers an essential layer of security above username-and-password, built to satisfy the FFIEC MFA requirements without adding friction to every login.
What the 2021 FFIEC guidance says about MFA
In August 2021 the FFIEC issued Authentication and Access to Financial Institution Services and Systems. It replaced the 2005 internet banking authentication guidance and its 2011 supplement, and it is broader: it looks at everyone and everything that accesses the institution's systems, not only online banking customers.
Risk-based, not prescriptive
It is guidance, not a regulation. Institutions are expected to assess risk and choose controls to match, and examiners use it to evaluate those choices.
MFA for high-risk access
It recommends MFA, or controls of equivalent strength, for high-risk users and high-risk transactions, and treats single-factor authentication as weak for those cases.
Every type of user
Customers, employees, third parties and system-to-system access are all in scope, including privileged and remote access.
Layered security
Authentication is one layer among several. The guidance also calls out risk assessments that are kept current and monitoring for suspicious access.
Where banks and credit unions need multi factor authentication
The guidance asks institutions to match the strength of authentication to the risk of the activity. These are the activities most risk assessments rate highest.
Online and mobile banking login
Customers reuse passwords, and credential stuffing turns old breaches into account takeovers. Spriv's API lets your platform check the customer's paired phone against the device and location of the login, so routine logins clear silently and unusual ones are challenged. Risk based MFA.
Wire transfers and payee changes
A logged-in session can still be hijacked. Authenticating the transaction itself, on the second channel, catches the fraud a login check never sees: an Allow/Deny prompt or two-way SMS for a wire above a threshold, a new payee or an address change. Transaction authentication.
Employee remote access and RDP to core systems
Staff and vendors connecting remotely to core banking, loan origination or back-office servers need more than a password. Spriv adds MFA to Windows and RDP logins and to SSH on Linux and Unix servers.
Administrator and privileged access
Privileged accounts can change configurations, limits and permissions. Keep them on an explicit Allow/Deny step for production access, alongside adaptive checks for routine work.
Layered, risk-based MFA for financial institutions
Spriv's patented approach lines up with the layered, risk-based model the guidance describes.
Risk-based engine
Each request is weighed on geographic location, device reputation, login history, behavioral patterns, time of access and network characteristics.
Out-of-band confirmation
The second factor is verified on the phone, a channel separate from the browser or session an attacker may control.
Impossible travel detection
Spriv's patented check compares the distance and speed between the phone's location and a second transaction, flagging moves no one could make. Impossible travel detection.
Run Spriv in your own data center
Banks and large institutions can host Spriv on Custom Servers in their own data center. Everyone else uses Spriv's shared cloud servers.
-
Transaction validation patents
Titles include "Method and system for validating electronic transactions". Patents
-
Zero PII transferred
Spriv confirms the phone and computer locations align, without sharing the phone's actual location.
-
REST API for customer logins
Sample code in five languages for online and mobile banking. API reference
FFIEC MFA questions
Is the FFIEC guidance a legal requirement?
It is supervisory guidance rather than a regulation, but examiners at the FFIEC member agencies use it when they review an institution's authentication and access controls, so in practice it sets expectations.
Does the guidance apply to credit unions?
Yes. The NCUA is an FFIEC member, so multi factor authentication for credit unions follows the same risk-based guidance as for banks.
Do customers have to approve every login?
No. Adaptive MFA approves a matching phone-and-device pair in the background, and prompts only on abnormal information. That keeps prompts rare enough that customers read them instead of approving out of habit.
Does Spriv guarantee FFIEC compliance?
No vendor can. Spriv's MFA is built to satisfy FFIEC expectations and helps you meet them; your risk assessment, policies and controls decide how examiners view your program.
Related pages
MFA your examiners and customers can live with
Two free users and two free servers, no credit card. Try it on your own servers, then talk to us about Custom Servers for your data center.