Behavioral biometrics in banking
Behavioral biometrics recognizes a bank customer by the way the person types, swipes and holds the phone. The European Banking Authority accepts keystroke dynamics and the angle of the device as inherence elements for strong customer authentication on payments, if the implementation leaves a very low probability that someone else is authenticated. Dated events on fraud and AI in finance are in the calendar below.
What behavioral biometrics measures
Physical biometrics read a body part, such as a fingerprint or an iris. Behavioral biometrics reads how a person acts. Keystroke dynamics, the oldest method, measures the rhythm of typing: the time it takes to find and press a key and how long the key stays down. On a phone the same idea covers swiping patterns and the angle at which the device is held, and on a wearable body movement or heart rate.
The output is a confidence score that the bank compares with a threshold. The Wikipedia article on keystroke dynamics notes that typing changes over a day and from one day to the next, that every system makes false-positive and false-negative errors, and that the threshold can be set for each person.
Behavioral biometrics and strong customer authentication
Under PSD2, an electronic payment needs two independent elements from the categories knowledge, possession and inherence. In its opinion on the elements of strong customer authentication (EBA-Op-2019-06, June 21, 2019), the EBA states that inherence includes biological and behavioral biometrics. Its table of examples marks keystroke dynamics, the angle at which the device is held and heart rate or other body movement patterns as compliant, next to fingerprint, face and voice recognition. A swiping path that the user has memorized is a knowledge element. Data exchanged through EMV 3-D Secure did not count as inherence for the approaches the EBA saw in the market.
The EBA ties each case to the quality of the implementation. The approach must give a very low probability that an unauthorized party is authenticated as the payer, as Article 8 of the regulatory technical standards on SCA requires. The strong customer authentication page covers the exemptions and the liability rules for card payments.
Where banks use it against fraud
A password or a one-time code is checked once, at login. A behavioral signal can be read throughout a session, which research calls continuous authentication. If someone else takes over a session after a correct login, typing and touch patterns change. That fits account takeover, where the fraudster initiates the payment: in the 2025 report on payment fraud by the EBA and the ECB, this type accounted for more than 90 percent of the value of card payment fraud.
Scams in which the real customer is talked into paying are harder to catch, because the right person is typing. The same report puts manipulation of the payer at 74 percent of the value of fraudulent credit transfers in 2024. Here a behavioral score is one input to the fraud model, next to device, payee and amount, as described on the AI fraud detection page. Biometric data counts as personal data under the GDPR, as the Wikipedia article on biometrics notes.
Upcoming events on fraud and AI in finance in Germany
Is behavioral biometrics the same as biometric authentication?
Behavioral biometrics is one branch of biometric authentication. Fingerprint, face and iris checks read physical traits, while behavioral biometrics reads how a person types and moves the phone. For strong customer authentication the EBA places both in the inherence category.
Can behavioral biometrics replace a password?
For a payment it can replace the knowledge element, but it cannot stand alone. Strong customer authentication needs two elements from different categories, so a behavioral check as inherence still needs a second element, such as possession of the registered phone. The passkeys in banking page covers a possession element built on a key pair.
Behavioral biometrics and Finance Loop
Finance Loop is the meeting place for the teams that build authentication and fraud controls at banks and payment firms in Germany, Austria and Switzerland. Finance Loop highlighted fAInance by Sopra Steria and Fraunhofer IAIS, which had a station on AI against financial crime, and announced KI Exchange 2026, whose program included fraud detection.
Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, digital payments, cloud and blockchain solutions. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.