---
title: "What is Strong customer authentication? | IslamicOpenFinance™"
description: "Verifying a customer with at least two independent factors, such as something they know, have or are."
url: https://islamicopenfinance.com/glossary/strong-customer-authentication/
lang: en-GB
source: "IslamicOpenFinance"
---

[Glossary](https://islamicopenfinance.com/glossary/) / [Open finance and APIs](https://islamicopenfinance.com/glossary/#open-finance)

Open finance and APIs

# Strong customer authentication

Verifying a customer with at least two independent factors, such as something they know, have or are.

Strong customer authentication verifies a customer's identity using at least two independent elements from different categories: knowledge, such as a password, possession, such as a phone, and inherence, such as a fingerprint. The Central Bank of the UAE's regulation requires institutions to apply at least two-factor authentication of this kind and additional procedures in higher-risk circumstances. It protects both data sharing and service initiation.

## Sources

- [Central Bank of the UAE Rulebook, Open Finance Regulation: Article 18, authentication](https://rulebook.centralbank.ae/en/rulebook/open-finance-regulation)

This entry explains a term; it is not a Shariah ruling. Approving a product is for each institution's own Shariah board and regulator.

## Related terms

[**Consent (open finance)** The customer's explicit, informed permission for a provider to access specified data or initiate a transaction.](https://islamicopenfinance.com/glossary/consent/) [**Service initiation** An open finance service in which a licensed provider initiates a transaction on a customer's account or product, with consent.](https://islamicopenfinance.com/glossary/service-initiation/) [**Data holder** The licensed institution that holds a customer's data and must make it available to authorised providers with the customer's consent.](https://islamicopenfinance.com/glossary/data-holder/) [**Application programming interface (API)** A defined way for software systems to request data or actions from each other; the technical channel of open finance.](https://islamicopenfinance.com/glossary/api/)

**Open finance and APIs**

1. [Open finance](https://islamicopenfinance.com/glossary/open-finance/)
2. [Application programming interface (API)](https://islamicopenfinance.com/glossary/api/)
3. [Consent (open finance)](https://islamicopenfinance.com/glossary/consent/)
4. [Data sharing (open finance)](https://islamicopenfinance.com/glossary/data-sharing/)
5. [Service initiation](https://islamicopenfinance.com/glossary/service-initiation/)
6. [Data holder](https://islamicopenfinance.com/glossary/data-holder/)
7. [Open finance provider](https://islamicopenfinance.com/glossary/open-finance-provider/)
8. [API hub](https://islamicopenfinance.com/glossary/api-hub/)

[All 221 terms](https://islamicopenfinance.com/glossary/)
