Step-Up Authentication: When to Ask for a Face Check
Step-up authentication asks a logged-in user for a stronger check only when an action is risky, such as a large withdrawal, a new device or a change of phone number. For banks, e-wallets and crypto exchanges, a face re-check matched to the onboarding selfie is the strongest step-up factor. It proves the account owner is present, which an OTP cannot.
What Step-Up Authentication Is
Step-up authentication is a security pattern that keeps everyday actions easy and makes risky ones harder. A user logs in with a light check. Then, when they try something that could cause real harm, the system asks for an extra, stronger proof of identity before it continues.
In short, the idea follows the risk, not the session. Checking a balance does not need the same assurance as sending money to a new payee. So step-up adds friction only at the moments that matter, which is why users tolerate it far better than constant prompts.
Standards bodies also frame it the same way. NIST’s Digital Identity Guidelines describe authentication assurance levels, and step-up is simply the move from a lower level to a higher one when an action demands it.
Step-Up vs MFA vs Adaptive vs Continuous Authentication

However, these terms overlap, and vendors use them loosely. The table separates them by what triggers the check and when it happens.
| Approach | When it runs | What triggers it | Typical use |
|---|---|---|---|
| Multi-factor authentication (MFA) | At login | Every login, by policy | Baseline account protection |
| Step-up authentication | Mid-session | A specific high-risk action | Transfers, withdrawals, profile changes |
| Adaptive (risk-based) authentication | At login or mid-session | A risk score from device, location and behaviour | Deciding whether to step up at all |
| Continuous authentication | Throughout the session | Passive signals such as typing and touch patterns | Spotting a session takeover in progress |
| Reverification | Later in the customer lifecycle | Time, a risk event or a regulatory review | Confirming the account holder is still the same person |
In practice, these approaches work together. Adaptive scoring decides when to step up, step-up delivers the stronger check, and continuous signals watch for trouble in between. Reverification is the same face check, but triggered by time or a review rather than by a single action.
Triggers That Justify Step-Up Authentication
Still, the hardest design question is when to step up. Too often, and users abandon the app. Too rarely, and fraud walks through. Broadly, good triggers fall into three groups.
Action Triggers
- Large transfers or withdrawals above a value or daily total threshold.
- New payees or new withdrawal addresses, especially for crypto.
- Limit increases, which fraudsters raise just before cashing out.
- Profile changes to the phone number, email or password, since these control recovery.
Context Triggers
- A new or unfamiliar device, or a phone that someone recently factory reset.
- Risky device states such as root access, an emulator or a virtual camera.
- Unusual location or network, for example a VPN or a country the customer never uses.
Behaviour Triggers
- Patterns that break the customer’s normal behaviour, such as a first-ever transfer at 3 a.m.
- Signs of a scam in progress, for example an active phone call or screen sharing during a transfer.
- Rapid sequences such as a login, a profile change and a large transfer within minutes.
Regulators already define some of these triggers. For example, Vietnam’s Decision 2345 sets transfer thresholds and demands biometrics when a customer first transacts on a new phone.
Face Re-Verification vs OTP as the Step-Up Factor

Once a trigger fires, the system then needs a factor that is meaningfully stronger than the login. The choice of factor decides whether step-up actually stops fraud.
| Step-up factor | What it proves | Weak spot |
|---|---|---|
| SMS OTP | Someone can read messages for that number | SIM swaps, SMS-reading malware and real-time phishing relays |
| App push approval | Someone holds the registered phone | Approval fatigue, and a stolen or coached phone |
| Device biometrics (phone unlock) | A person registered on that handset is present | Anyone the owner, or a thief, enrolled on the phone |
| Face re-verification with liveness | The account holder from onboarding is present now | Needs good capture conditions and liveness to resist spoofs |
Face re-verification, by contrast, is different in kind. It matches a live capture against the selfie from onboarding, so it ties the action to the person who originally signed up, not to a phone or a number. That is why it suits the riskiest triggers, such as device changes and large withdrawals. A check like this depends on reliable face verification plus a liveness check.
Malaysia offers a clear signal. Back in September 2022, its central bank instructed lenders to phase out SMS one-time passwords in favour of stronger methods. Many banks in the region therefore use face checks as their step-up factor.
How to Implement Step-Up Authentication in Six Steps
Most teams roll out step-up in stages. This sequence keeps the scope manageable and gives you data before you tighten anything.
- List sensitive actions. Start with every action that moves money, adds a payee or address, or changes recovery details.
- Collect risk signals. Feed device, location, behaviour and transaction data into one score that decides when to step up.
- Match factors to tiers. Reserve the face re-check for the highest tier, and keep lighter checks for medium risk.
- Integrate and verify server-side. Run the face capture in your app, then confirm the result on your backend rather than trusting a client flag.
- Pilot and measure. Track step-up rate, pass rate, abandonment and fraud losses on protected journeys for a few weeks.
- Review every quarter. Fraud patterns shift, so revisit triggers and thresholds with fresh data.
Two numbers tell you most of what you need. The step-up rate shows how often customers meet the check, and the post-step-up fraud rate shows whether it works. If both are low, the design is doing its job.
Designing Step-Up Friction: Thresholds and Fallbacks
Step-up only works if genuine customers can pass it quickly. So treat the design as a product problem as well as a security one.
- Tier the response. Low risk passes silently, medium risk gets a light check, and high risk gets a face re-check.
- Set thresholds from data. Start with regulatory minimums, then adjust using your own fraud and drop-off numbers.
- Explain the check. A one-line reason, such as “we check your face for transfers above your usual amount”, reduces abandonment.
- Remember trust, carefully. After a successful face check, a short trust window on the same device avoids repeated prompts.
- Plan the fallback. If the face check fails twice, route the user to an assisted channel, not to a weaker factor that fraudsters prefer.
- Add a cooling-off period where needed. For new devices or new payees, a short delay on large transfers gives victims time to react.
The fallback deserves special attention. If a failed face check simply falls back to an SMS code, attackers will learn to fail the face check on purpose. So the fallback should be at least as strong, even if slower.
Step-Up Authentication in Crypto Withdrawals and Bank Transfers
Two sectors in particular show the pattern most clearly. In both, the moment of greatest risk is when value leaves the account.
Crypto Exchanges
Crypto withdrawals are fast and also hard to reverse. So exchanges often step up on new withdrawal addresses, on withdrawals above a threshold, and after any password or two-factor reset. A face re-check at that moment stops an attacker who has taken over the login but cannot reproduce the owner’s live face. For the onboarding side, see how KYC in crypto works.
Banks and E-Wallets
Banks usually step up on large transfers, new payees, limit increases and device changes. In practice, the device change is the most important trigger. Account takeover typically starts with the fraudster registering the victim’s account on a new phone, so a face check at that point blocks the takeover before any money moves.
Even so, step-up has one honest limit. If a scammer coaches the real customer through a transfer, the face check simply verifies the genuine owner. So pair step-up with scam signals, for example a phone call running while the customer sends money, and use warnings or delays when those signals appear.
How Verihubs Supports Face-Based Step-Up
Verihubs face recognition matches the live capture against the template from onboarding, which makes it suitable as a step-up factor for transfers, withdrawals and device changes. Combined with liveness detection, the result shows that the account holder is present and live, rather than a photo or video.
Frequently Asked Questions About Step-Up Authentication
What is step-up authentication?
Step-up authentication asks a logged-in user for a stronger check only when they attempt a risky action, such as a large transfer, a new payee or a change of phone number. Everyday actions stay quick.
What is the difference between step-up authentication and MFA?
MFA usually applies at every login. Step-up happens mid-session and only for specific high-risk actions, so it adds friction only when the risk justifies it.
What is the difference between step-up authentication and reverification?
A single risky action triggers step-up. Reverification confirms the account holder again because of time, a risk event or a regulatory review. Both often use the same face check, matched to the selfie from account opening.
What triggers step-up authentication?
Common triggers include large transfers, new payees or withdrawal addresses, limit increases, profile changes, new devices, risky device states and behaviour that breaks the customer’s normal pattern.
Is a face check better than OTP for step-up?
For high-risk actions, usually yes. An OTP proves access to a phone number, which SIM swaps and malware can steal. A face check with liveness shows that the real owner is there in person.
Step-Up Authentication Puts the Strongest Check Where the Money Moves
The logic of step-up is simple: spend friction where fraud happens. Most customers rarely meet it, and those who do meet it at moments when they expect extra care, such as moving a large sum or changing their phone.
What decides success is the factor and the fallback. A step-up that relies on SMS codes inherits the weaknesses of SMS. A face re-check matched to onboarding, with liveness and a strong fallback, ties each risky action to the real account holder. That is the version worth building.
Building step-up into your app? Talk to Verihubs about face re-verification for withdrawals and new devices.