Skip to content
PAY-015 Payments & Banking

What is payment authentication?

Payment authentication is the process used to check that the person or device attempting a payment can satisfy the provider’s security requirements.

Avoid this assumption: Successful authentication proves the identity of the person who made the payment.

Authentication may involve something the user knows, such as a password or PIN; something the user has, such as a phone, card or security token; or something linked to the user, such as a biometric.

A payment may use one method or several. Examples include chip-and-PIN, one-time passcodes, banking-application approval, device biometrics or card-security checks.

Successful authentication usually proves only that the required step was completed. It may not prove who completed it, whether credentials were shared, whether the device was compromised or whether the user understood the payment they were approving.

A victim can authenticate a payment after being deceived. An offender may intercept a code, use an existing authenticated session or remotely control the victim’s device. A family member or employee may also have legitimate access.

Different payment types apply different authentication rules. A recurring payment or merchant-initiated transaction may not require fresh authentication every time. A low-value contactless transaction may use a different process from an online transfer.

Relevant evidence may include authentication method, success or failure result, timestamp, device identifier, IP address, session reference, one-time-passcode delivery record and any risk decision made by the provider.

Do not confuse authentication with authorisation. Authentication checks the security step. Authorisation is the provider’s decision to allow the payment to proceed.

When reporting, use precise wording. Say that the transaction was successfully authenticated by a particular method if that is what the record shows. Avoid saying that a named person authenticated it unless the evidence supports that attribution.

Operational takeaway

Use authentication records to show which security steps were completed, then seek separate evidence to establish who completed them and under what circumstances.


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.