Financial institutions increasingly use 2-Factor Authentication (2FA) in their mobile apps to protect customer transactions. Traditionally, 2FA combines two different types of verification. This is usually something you know, such as a transaction PIN or one-time password, and something you have, such as your registered phone or a token.
In many modern transaction flows, after a user enters a transaction PIN or token, the app then requests biometric authentication. This could be Face ID or a fingerprint, depending on the user’s device. While this improves convenience, it raises an important question. Should device-level biometrics really count as a valid second factor for transaction authentication when the verification does not happen within the financialinstitution’s systems?
How Biometrics Work in Financial Apps
When a financial app uses Face ID or fingerprint authentication:
● The app does not see or transmit the raw biometric data. Instead, it asks the phone whether the biometric presented matches one of the biometrics already enrolled on the device
● The biometric data itself is stored securely on the phone, within protected hardware designed for this purpose. The app simply receives a yes or no response from the device. The financial institution never receives the actual fingerprint or facial data.
This means the institution is relying on the phone’s confirmation rather than directly verifying the user’s biometric identity.
Can Biometrics Count as a “Second Factor”?
Traditionally, 2FA is based on using two different categories of authentication:
1. Something you know, such as PIN or password
2. Something you have, such as a phone or token
3. Something you are, such as a fingerprint or face
On the surface, combining a transaction PIN with Face ID or a fingerprint appears to meet the definition of 2FA. However, there is an important distinction.
Because the biometric check is performed entirely on the device, the financial institution cannot independently confirm who was authenticated. For this reason, device biometrics are often best viewed as a strong convenience layer rather than a fully independent second factor on their own. They work best when combined with other institution-verified controls, especially for high-risk transactions.
Security Risks and Edge Cases
1. Device Access by Another Person
If another person is able to register their fingerprint or face on a phone, whether intentionally or under pressure, financial apps that rely on biometrics may treat that person as a legitimate user.
2. Device Trust Over User Identity
Because the biometric decision comes from the phone, anyone who can unlock the device and add their biometric may be approved during transactions. The financial institution has no visibility into changes made at the device level.
3. Spoofing and Advanced Attacks
While modern phones include strong protections, biometric systems are not immune to spoofing attempts such as fake fingerprints or manipulated facial images, especially on older or less secure devices.
4. Biometrics Cannot Be Changed
Unlike a PIN or password, biometrics are permanent. If they are compromised, they cannot simply be reset. This makes them riskier as a primary security control over time.
Is It Safe to Use Device Biometrics as Part of 2FA?
Benefits
● Convenience. Transactions are faster and easier for users.
● Device-level protection. Biometric data is stored securely on the phone and is difficult for remote attackers to extract.
Limitations
● Dependence on the device. If a phone is lost, stolen, or compromised, risk increases.
● No direct verification. The financial institution cannot confirm who passed the biometric check.
● Accuracy limits. Biometric systems can sometimes fail or incorrectly approve access.
Regulatory and Legal Considerations
● Most financial institutions clearly state in their terms that enabling biometric login means any biometric registered on the device may be able to access the account.
● Device manufacturers aren’t legally liable for financial fraud from financial app transactions authenticated via device biometrics. Responsibility typically rests with the financial institution’s policies and local financial regulations.
● In many regions, financial institutions must still comply with privacy and data protection laws related to biometric use, even when the data is stored only on the device. However, this does not automatically transfer liability to device providers.
In conclusion, device biometrics add meaningful value by improving convenience and strengthening security at the device level. However, they are not a perfect or fully independent second factor when used alone for transaction authentication. For users, it is important to maintain strong device security, protect phone access codes, and understand how biometric authentication works.
For financial institutions, biometrics are most effective when used as part of a layered 2FA approach rather than as the sole line of defense.
By Sunny Ogbari










