Banks Have Spent Years Removing Friction. Now They May Need to Put Some Back.

Banks Have Spent Years Removing Friction. Now They May Need to Put Some Back.

A customer adds a new beneficiary and moves a large amount of money within seconds. The authentication is correct. The device is trusted. The customer approves every step. From a digital banking perspective, the journey has worked perfectly. From a fraud perspective, it could be a disaster. That contradiction is becoming harder for banks to ignore. Years of investment have gone into removing delays and making payments almost effortless, yet modern scams increasingly depend on that same speed. The next phase of digital banking may therefore require a change in thinking: not bringing friction back everywhere, but knowing exactly when a transaction should become a little harder to complete.

Banking Made Speed a Competitive Advantage

The transformation of consumer banking has been built around reducing effort. Opening an account that once required a branch visit can now take minutes. Payments that previously took hours or days can arrive almost immediately. Customers authenticate themselves with a fingerprint or face scan, while saved beneficiaries and simplified payment journeys remove many of the steps that once stood between intention and transaction.

Much of this progress has been beneficial. Faster payments improve cash flow, digital onboarding expands access and simplified authentication reduces abandoned transactions. Mobile banking has made everyday financial services considerably easier for millions of customers.

But removing friction also removes time, and time was once an unintentional layer of protection. A payment moving slowly through banking systems created opportunities for fraud teams to identify suspicious activity, customers to reconsider unusual transactions or banks to intervene before funds disappeared.

Real-time payments fundamentally change that equation. Once money can move between accounts in seconds, fraud detection increasingly has to operate within the same window.

Scammers Are Exploiting the Seamless Experience

Many of today’s most damaging scams do not require criminals to defeat a bank’s security systems. They persuade customers to pass through those systems themselves.

A victim may authenticate the device, enter the correct password, receive the verification code and personally approve the payment. From the bank’s technical perspective, every security control may have worked exactly as designed. The problem is that the customer was being manipulated.

Social engineering, impersonation scams, fake investment opportunities and fraudulent invoices can create enough urgency or credibility to persuade customers to move money voluntarily. AI is making that deception even more convincing by giving criminals increasingly sophisticated tools for impersonation and social engineering.

This creates a difficult problem for banks. Traditional fraud controls were largely designed to identify unauthorised transactions. Scam prevention increasingly requires banks to recognise when an apparently legitimate transaction may have been authorised under deception.

That requires a different type of intervention.

A Warning Screen Is Not Enough

Banks already introduce friction into suspicious transactions, but much of it remains generic. Customers may receive warnings asking whether they know the recipient, whether someone has instructed them to make the payment or whether the transaction could be related to an investment scam.

The problem is familiarity. When customers see similar warnings repeatedly, they learn to dismiss them. The warning becomes another screen between them and what they are trying to accomplish.

Effective friction therefore cannot simply mean adding more confirmation boxes. It needs to be contextual.

A customer sending AED 200 to a familiar recipient does not require the same intervention as someone transferring AED 80,000 to a newly created beneficiary minutes after changing a device setting. A customer making a routine mortgage payment should not experience the same journey as someone suddenly sending their savings to an unfamiliar investment account.

Banks increasingly have the technology to distinguish between those situations. As Finnoex has previously examined, behavioural biometrics can help banks identify unusual digital behaviour even when traditional authentication appears legitimate. How someone interacts with a device can provide additional signals that passwords, biometrics and verification codes cannot capture.

The challenge is using those signals without making everyday banking unnecessarily difficult.

Intelligent Friction Could Become a Security Layer

The next stage of fraud prevention may therefore involve selective friction.

Instead of slowing every transaction, banks can introduce additional checks only when behaviour, transaction characteristics or risk signals suggest something is unusual. That could include a short cooling-off period for certain high-risk payments, additional verification for unusually large transfers to new beneficiaries, contextual questions based on the transaction type or direct intervention from a fraud specialist.

This is already moving beyond theory. In India, the Reserve Bank of India has proposed safeguards including cooling-off periods for certain transfers and additional verification for higher-value transactions. The RBI proposals demonstrate how deliberate payment friction is increasingly being considered as a consumer protection mechanism rather than simply an inconvenience.

The objective is not to create obstacles. It is to create a moment of resistance precisely when it is most valuable.

Instant Payments Create an Instant Decision Problem

The growth of real-time payment infrastructure makes this challenge more urgent. Banks cannot rely on fraud processes designed around transactions that take hours to settle when money can now disappear in seconds.

That compresses the decision-making window dramatically. A bank may have only seconds to determine whether a transaction should proceed, whether the customer should receive an additional warning or whether the payment should temporarily stop.

It also creates tension between two customer expectations. Customers want legitimate transactions to happen immediately, but when something goes wrong, they also expect their bank to have recognised that the transaction was unusual.

Delivering both requires far more sophisticated risk assessment than simply making payments faster.

Modern payment infrastructure is being built specifically around real-time processing, with banks moving away from fragmented systems towards platforms capable of supporting instant transactions. Finnoex has previously examined how banks are modernising payment infrastructure to support real-time processing at scale. As that transition accelerates, fraud controls will have to become equally real-time.

The Customer Experience Metric May Need to Change

Banking technology teams have traditionally measured digital experiences through metrics such as completion time, abandonment rates, clicks and conversion. Those measures remain important, but fraud may force banks to rethink what constitutes a successful digital journey.

A payment completed in six seconds is not a successful customer experience if the customer has just transferred their savings to a scammer. Equally, a legitimate payment unnecessarily delayed for several hours can frustrate customers and undermine confidence in digital banking.

The optimal experience sits somewhere between those extremes.

That means customer experience and fraud prevention teams may need to work much more closely together. Fraud controls cannot simply be added after a digital journey has been designed. Risk decisions increasingly need to become part of the experience itself.

The best digital banking journey may therefore not be the one with the fewest steps. It may be the one that knows when another step is necessary.

AI Makes the Question More Complicated

Artificial intelligence will increase pressure on both sides of this equation. Banks can use AI to analyse transactions, behavioural patterns and contextual signals faster than traditional rules-based systems. But criminals can use the same technology to create more convincing impersonations, automate social engineering and personalise scams at scale.

The assumption that an informed customer will simply recognise a suspicious request is therefore becoming less reliable. As synthetic voices, convincing messages and personalised scam approaches improve, customers may believe they are responding to a genuine bank employee, family member, executive or trusted organisation.

Banks may consequently need to intervene earlier.

That does not mean blocking customers from controlling their own money. It means recognising that authentication proves who is making a transaction, not necessarily whether that person understands why they are making it.

That distinction could become one of the most important challenges in digital banking security.

Trust May Sometimes Require Slowing Down

The banking industry’s obsession with frictionless experiences came from a legitimate objective: make financial services easier to use. That objective should not disappear.

But the environment around digital banking has changed. Payments are faster, scams are more sophisticated and criminals increasingly attack human decision-making rather than banking infrastructure.

Banks therefore face a different design challenge. The question is no longer simply how quickly a customer can complete a transaction. It is whether the bank can recognise the handful of moments when speed becomes a risk.

In those moments, a pause is not necessarily poor customer experience.

It may be the service the customer needed most.

What it means for the industry

  • Frictionless banking cannot remain an absolute objective. Banks will increasingly need to balance transaction speed against the probability and potential impact of fraud.
  • Context will determine whether friction works. Generic warnings risk becoming background noise, while interventions based on transaction and behavioural signals can be more meaningful.
  • Fraud prevention and customer experience are converging. Security controls will increasingly need to be designed as part of the banking journey rather than added after it.
  • Real-time payments require real-time risk decisions. Banks have dramatically less time to identify suspicious transactions before funds become difficult to recover.
  • Authentication alone cannot solve scam fraud. Banks increasingly need to distinguish between a transaction that is genuinely authorised and one authorised because the customer has been manipulated.
Notice an error or have additional information about this story? Contact the Finnoex newsroom: newsroom [at] finnoex [dot] com.

Discover more from Finnoex

Subscribe now to keep reading and get access to the full archive.

Continue reading