Strong customer authentication
Verifying a customer with at least two independent factors, such as something they know, have or are.
Strong customer authentication verifies a customer's identity using at least two independent elements from different categories: knowledge, such as a password, possession, such as a phone, and inherence, such as a fingerprint. The Central Bank of the UAE's regulation requires institutions to apply at least two-factor authentication of this kind and additional procedures in higher-risk circumstances. It protects both data sharing and service initiation.
Sources
This entry explains a term; it is not a Shariah ruling. Approving a product is for each institution's own Shariah board and regulator.
Related terms
Consent (open finance)The customer's explicit, informed permission for a provider to access specified data or initiate a transaction.Service initiationAn open finance service in which a licensed provider initiates a transaction on a customer's account or product, with consent.Data holderThe licensed institution that holds a customer's data and must make it available to authorised providers with the customer's consent.Application programming interface (API)A defined way for software systems to request data or actions from each other; the technical channel of open finance.