For a mid-size U.S. bank ($10B–$100B in assets), the contact center is now the identity layer under the most pressure. Digital channels have moved to device binding, passkeys, and step-up multi-factor authentication, while the phone line often still runs on security questions a fraudster can buy for a few dollars. This guide, part of Matellio’s Voice Security for Banks coverage, compares the three dominant call center authentication solutions head-to-head, explains how each works technically, shows where U.S. regulators (NIST and the FFIEC) now stand, and lays out a layered architecture that holds up against AI voice cloning.
Why call center authentication is failing banks in 2026
The phone channel carries the highest-trust, highest-value interactions a bank has — wire confirmations, account recovery, card disputes — and fraudsters have followed the value. The public, verifiable data is stark:
- U.S. consumers reported $16.6 billion in cyber-enabled crime losses in 2024, up 33% year over year, with phishing/spoofing the single most-reported crime type at 193,407 complaints. (FBI IC3 2024 Internet Crime Report)
- Consumers reported $12.5 billion lost to fraud in 2024 (up 25%); imposter scams were the second-largest loss category at $2.95 billion. (FTC Consumer Sentinel Network Data Book 2024)
- The phone was the second most common contact method for reported fraud — and victims contacted by phone lost the highest amount per person, a median of about $1,500. (FTC, 2024)
The tools most banks still lean on in the IVR and at the agent desk — security questions and PINs — were designed for a world before mass data breaches and generative voice AI. Both are now failing on security and on experience at the same time, which is why authentication has become a joint agenda item for the CISO, the fraud team, and the contact-center leadership.
The three call center authentication solutions, explained

1. Knowledge-based authentication (KBA)
KBA verifies a caller by asking for information presumed to be known only to the account holder — date of birth, last four of the SSN, mother’s maiden name, a recent transaction amount, or pre-set security questions. It is a “something you know” factor. Technically, it is a shared secret challenge: the agent or IVR compares the caller’s spoken answer against stored profile data. Its fatal weakness is that the underlying data is no longer a secret. After a decade of large-scale breaches, most KBA answers are for sale on data markets or discoverable on social media, and AI voice cloning lets an attacker deliver those answers convincingly. NIST formally withdrew KBA as an acceptable authenticator (more below), yet it remains the default in many bank contact centers.
2. PIN verification
PIN (or telephone passcode) verification asks the caller to enter or speak in a numeric code tied to the account. Like KBA, it is a “something you know” memorized secret, but with a fixed, higher-entropy value rather than biographical trivia. It is stronger than KBA against open-source research — a random 6-digit PIN is not on the caller’s Facebook page — but it inherits every shared-secret weakness: PINs get phished, reused across accounts, written down, socially engineered out of customers, and exposed in breaches. A single memorized secret is also, by definition, single-factor authentication, which regulators no longer consider adequate for high-risk banking transactions.
3. Passive voice biometrics
Passive voice biometrics authenticate a caller from the unique characteristics of their voice — a “something you are” factor — while they speak naturally to the IVR or agent, with no separate step, passphrase, or questions. During enrollment, the platform builds a mathematical voiceprint from the physical and behavioral traits of the speaker (vocal-tract shape, cadence, pronunciation). On later calls it scores the live audio against that voiceprint in the background and returns a match of confidence, often within the first several seconds of conversation. Because there is nothing for the customer to remember and nothing to type, it removes the interrogation step entirely — which is where it wins on both friction and handle time.
The critical technical caveat: liveness and deepfake detection
A voiceprint match alone can be fooled by a recording or an AI clone. Production-grade passive voice biometrics must be paired with liveness detection and synthetic-speech (deepfake) detection, and treated as one factor inside a layered, risk-based decision — never as a standalone “open sesame.” This is the difference between a checkbox deployment and one that actually resists 2026-era voice fraud.
Passive voice biometrics vs. KBA vs. PIN: head-to-head comparison
Here is how the three call center authentication solutions compare across the dimensions banks actually weigh — security factor, customer friction, fraud resistance, handle-time impact, deepfake resistance, and regulatory standing.
| Dimension | Passive Voice Biometrics | KBA (Security Questions) | PIN Verification |
|---|---|---|---|
| Security factor | Something you are (biometric) | Something you know (biographical) | Something you know (memorized secret) |
| Customer friction | Very low — works during natural speech, nothing to recall | High — multiple questions; legitimate customers fail and get locked out | Moderate — must remember and enter a code; reset friction |
| Impact on handle time (AHT) | Reduces AHT — removes the Q&A/verification step | Increases AHT — questioning plus failed-KBA escalations | Slight increase — prompt, entry, and reset handling |
| Fraud resistance | High vs. human impostors; strong when paired with liveness/anti-spoof | Low — answers are breached, bought, or found on social media | Low–moderate — phishable, reusable, socially engineered |
| Deepfake / voice-clone resistance | Only with dedicated synthetic-speech + liveness detection | None — a clone reads the stolen answers aloud | None — a clone or attacker reads the stolen PIN |
| Regulatory standing (U.S.) | Recognized biometric factor; strong inside MFA/layered security | Withdrawn by NIST 800-63B; FFIEC: don’t rely solely on KBA | Valid single memorized secret, but single-factor — inadequate alone for high-risk |
| Enrollment effort | Voiceprint enrollment (can be passive, from prior calls) | Low setup, but weak by design | Low setup; ongoing reset overhead |
| Best role in the stack | Primary low-friction factor + fraud signal | Deprecate / retire as a primary control | Fallback or secondary factor, not sole control |
KBA loses on every axis and has been formally withdrawn by NIST. PIN is a marginal step up but is still a single shared secret. Passive voice biometrics wins on friction and handle time and is the strongest identity factor — provided it is deployed with liveness and deepfake detection inside a layered decision.
What U.S. regulators actually require
NIST has withdrawn KBA outright
NIST Special Publication 800-63B (Digital Identity Guidelines), updated in Revision 4 in 2025, no longer recognizes knowledge-based authentication as an acceptable authenticator. NIST’s guidance states plainly that KBA “does not constitute an acceptable secret for digital authentication,” having been withdrawn because such questions rely on information that is “private but not secret.” For a bank, continuing to authenticate high-value phone interactions on security questions is running a control the national standards body has explicitly retired. (NIST SP 800-63B; NIST 800-63 FAQ)
The FFIEC requires layered security and multi-factor for high-risk activity
The interagency FFIEC guidance, Authentication and Access to Financial Institution Services and Systems (2021, conveyed via OCC Bulletin 2021-36 and FDIC FIL-55-2021), states that single-factor authentication has “shown to be inadequate” for high-risk users and transactions, directs institutions toward layered security and multi-factor authentication, and notes that reliable identity verification methods “generally do not depend solely on knowledge-based questions.” Examiners increasingly expect the phone channel to meet the same bar as digital. (FFIEC 2021; OCC 2021-36)
Read together, the standards point in one direction: retire KBA as a primary control, stop treating any single memorized secret as sufficient for sensitive calls, and move to layered, risk-based authentication in which a biometric factor does the heavy lifting with low friction.
A layered, risk-based architecture for the phone channel

No single factor should be an on/off switch for account access. The resilient pattern is a risk-based decision that combines several signals and only escalates to active challenges when risk is elevated:
- Pre-answer risk scoring: validate the calling number against network signaling (ANI/spoof detection) and score carrier metadata before the call is routed.
- Passive voice biometrics + liveness: authenticate the enrolled caller in the background during natural speech, with synthetic-speech detection to defeat clones and recordings.
- Behavioral and device signals: layer in call-pattern and device reputation, so a weakness in one control is compensated by another — exactly the FFIEC’s layered-security principle.
- Risk-based step-up: reserve additional challenges for genuinely high-risk calls, instead of interrogating every legitimate customer.
Matellio delivers this as an orchestration layer over your existing telephony — no rip-and-replace — through its OCCAS voice security implementation. Passive voice biometrics and deepfake detection sit alongside inbound spoof scoring and branded outbound calling, with routing and step-up logic tuned to each bank’s risk policy. For institutions on cloud contact-center stacks, the same layer applies during an Amazon Connect migration, so authentication modernization and platform modernization happen together rather than as two disruptive projects.
FAQ’s
1. What are the best call center authentication solutions for banks?
2. Is knowledge-based authentication (KBA) still secure for call centers?
3. Passive vs. active voice biometrics — what is the difference?
4. Can voice biometrics be fooled by AI voice cloning or deepfakes?
5. Does replacing KBA with voice biometrics reduce average handle time?
6. What do NIST and the FFIEC require for phone-channel authentication?
7. How do banks deploy voice biometrics without replacing their contact center?
References
- FBI IC3 2024 Internet Crime Report — $16.6B losses, +33% YoY, phishing/spoofing top complaint type — https://www.ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf
- FTC — New data show fraud losses of $12.5B in 2024; imposter scams #2; phone is #2 contact method — https://www.ftc.gov/news-events/news/press-releases/2025/03/new-ftc-data-show-big-jump-reported-losses-fraud-125-billion-2024
- FTC Consumer Sentinel Network Data Book 2024 — https://www.ftc.gov/reports/consumer-sentinel-network-data-book-2024
- NIST SP 800-63B, Digital Identity Guidelines (Rev. 4) — KBA withdrawn — https://pages.nist.gov/800-63-4/sp800-63b.html
- NIST SP 800-63 FAQ — KBA no longer an acceptable authenticator — https://pages.nist.gov/800-63-FAQ/
- FFIEC — Authentication and Access to Financial Institution Services and Systems (2021) — https://www.ffiec.gov/sites/default/files/media/press-releases/2021/authentication-and-access-to-financial-institution-services-and-systems.pdf
- OCC Bulletin 2021-36 — FFIEC authentication guidance — https://www.occ.gov/news-issuances/bulletins/2021/bulletin-2021-36.html
Author Bio

VP- Account Management at Matellio
