
Mark Donohue, Managing Director iSky, Global
From payment prompts to channel locks, leading providers are using carefully placed friction to help customers spot risk, act earlier and recover with confidence.
Friction has become one of digital banking’s most charged design words. Teams measure success through speed and the removal of unnecessary steps. In fraud and security, however, the quickest experience is not always the safest.
The better question is whether friction earns its place. A protective pause should capture attention at a meaningful moment, provide relevant context and lead to clear action. Otherwise, it is simply another obstacle.
Five priorities stand out across the global journeys tracked by RFI Global’s iSky Radar UX platform. They are less about adding security content than making each intervention more purposeful.
Security journeys are often designed around what the institution needs a customer to complete. Onboarding checklists are a familiar example. This can miss the factors shaping how an individual understands and manages risk.
Accessibility needs, travel, bereavement, financial hardship and household changes can alter the support a customer needs. So can digital confidence. Terms such as ’autofill’ or ’device registration’ may be obvious to a product team and meaningless to the person receiving a warning.
The opportunity is to adapt language, depth and format. Singlife’s former ’Simplify for me’ option pointed to a useful model: offer the same essential message in a form that matches the customer’s capability. Effective security communication starts with the person, not the process. A message customers cannot decode cannot change behaviour.
Digital needs restraint. Long fraud explanations, dense login copy and generic scam carousels can all be accurate yet easy to ignore. They compete with the customer’s task.
Account-summary space is especially valuable. Using it for important security or operational communication, rather than routine sales, can teach customers that what appears there deserves attention. Every message still needs a clear call to action.
At higher-risk moments, the interruption should be direct. Garanti BBVA uses login to surface recent failed attempts and the last transaction date. In payments, TSB asks customers to consider their relationship with the recipient, while First Direct challenges a close payee-name match. These prompts interrupt autopilot while harm may still be preventable.
Good friction is active, specific and proportionate. It asks the customer to make an informed decision.
Card locking is now basic. Emerging iSky Radar examples extend the same logic to payments, accounts, channels and customer profiles.
Controls can disable high-risk services, switch off internet banking, set payment parameters, nominate a trusted contact or place funds behind a time lock. Monzo’s trusted-contact model adds a second set of eyes for selected payments. Hang Seng lets customers deactivate risky services, while Up delays access to locked funds, with trusted-contact support for urgent situations.
Security hubs can make these settings coherent, but only if they do more than catalogue features. A better hub shows the customer’s position, identifies gaps and explains each choice, supporting both simple and granular control. It should also show how individual settings work together.
Control must also be reversible. Customers need to know what a lock affects, how long it lasts and how to restore access. Otherwise, a preventive tool may move demand elsewhere.
Protective systems see more than customers do. Stronger experiences close that gap by exposing useful activity, not merely offering reassurance.
Bank Australia and Cash App show how activity histories can combine transactions with password changes, security-setting updates and profile access, helping customers decide whether to act.
The principle also applies to processes. CIBC explains payment limits and reset times. ZA Bank provides a journey for requesting the return of a misdirected payment while setting realistic expectations. Wells Fargo shows the status of a transaction dispute. Each answers the question that might otherwise drive a call: what is happening now?
Information creates value when it is timely, understandable and connected to action. Persistent status is particularly valuable after an event, when uncertainty is highest. A raw log is not enough.
When something feels wrong, fast lockdown matters. Kill switches can stop transactions, end sessions or deactivate digital access. But the button is only the beginning.
Customers need to know what is blocked, what remains available and what to do next. Westpac’s SafeBlock connects emergency response with other controls. Alinma combines device deregistration with ending active sessions. Truist uses a registered mobile app and QR scan to help customers recover web access.
Recovery should be a guided journey, not disconnected security events. The institution’s job is to turn urgency into orderly action.
The choice is not between a frictionless experience and a heavily restricted one. It is between friction that protects and friction that merely delays.
Before adding another warning, confirmation or lock, teams should ask: Is this the right moment? Does the customer understand why? Is there a meaningful action? Is the route forward clear?
When the answer is yes, friction becomes a moment of clarity that helps customers recognise risk, decide and regain control. The challenge is not to remove every pause, but to make every protective pause do useful work.
If you’d like to find out more about best practice UX, join our free webinar where we will reveal the top 20 banking apps worldwide and explore what drives their success.

Mark Donohue
Managing Director iSky, Global
Mark Donohue is Managing Director of iSky at RFI Global, working with clients globally on data-led financial services intelligence.
View full profileBanks should not aim to remove all friction from fraud and security journeys. Instead, they should use appropriate friction at moments when customers need to recognise risk, make an informed decision or regain control. Each intervention should explain why it is needed, offer a meaningful action and provide a clear route forward.
Effective security friction is timely, specific and relevant to the customer’s situation. It captures attention at a meaningful moment, provides understandable context and leads to a clear action. Banks should also adapt the language, detail and format to customers’ accessibility needs, circumstances and level of digital confidence.
Fraud warnings should appear at the point of decision, particularly during higher-risk activities such as logging in or making a payment. Direct prompts can interrupt automatic behaviour and encourage customers to consider unusual activity, their relationship with a payment recipient or a close payee-name match before proceeding.
Banks can give customers greater control by allowing them to restrict high-risk services, disable digital banking access, set payment parameters, nominate a trusted contact or place funds behind a time lock. These controls should clearly explain what will be affected, how settings work together and how customers can restore access.
| Cookie | Duration | Description |
|---|---|---|
| __cf_bm | 1 hour | This cookie, set by Cloudflare, is used to support Cloudflare Bot Management. |
| __hssc | 1 hour | HubSpot sets this cookie to keep track of sessions and to determine if HubSpot should increment the session number and timestamps in the __hstc cookie. |
| __hssrc | session | This cookie is set by Hubspot whenever it changes the session cookie. The __hssrc cookie set to 1 indicates that the user has restarted the browser, and if the cookie does not exist, it is assumed to be a new session. |
| AWSALBCORS | 7 days | Amazon Web Services set this cookie for load balancing. |
| AWSALBTG | 7 days | Amazon Web Services set this cookie for load balancing. |
| AWSALBTGCORS | 7 days | Amazon Web Services set this cookie for load balancing. |
| cookielawinfo-checkbox-advertisement | 1 year | Set by the GDPR Cookie Consent plugin, this cookie records the user consent for the cookies in the "Advertisement" category. |
| cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
| cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
| cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
| cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
| cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
| CookieLawInfoConsent | 1 year | CookieYes sets this cookie to record the default button state of the corresponding category and the status of CCPA. It works only in coordination with the primary cookie. |
| elementor | never | The website's WordPress theme uses this cookie. It allows the website owner to implement or change the website's content in real-time. |
| rc::a | never | This cookie is set by the Google recaptcha service to identify bots to protect the website against malicious spam attacks. |
| rc::c | session | This cookie is set by the Google recaptcha service to identify bots to protect the website against malicious spam attacks. |
| viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |
| wpEmojiSettingsSupports | session | WordPress sets this cookie when a user interacts with emojis on a WordPress site. It helps determine if the user's browser can display emojis properly. |
| XSRF-TOKEN | 2 hours | This cookie enhances visitor browsing security by preventing cross-site request forgery. |
| Cookie | Duration | Description |
|---|---|---|
| AWSALB | 7 days | AWSALB is an application load balancer cookie set by Amazon Web Services to map the session to the target. |
| AWSALBTG | 7 days | Amazon Web Services set this cookie for load balancing. |
| AWSALBTGCORS | 7 days | Amazon Web Services set this cookie for load balancing. |
| Cookie | Duration | Description |
|---|---|---|
| __hstc | 6 months | Hubspot set this main cookie for tracking visitors. It contains the domain, initial timestamp (first visit), last timestamp (last visit), current timestamp (this visit), and session number (increments for each subsequent session). |
| _ga | 1 year 1 month 4 days | Google Analytics sets this cookie to calculate visitor, session and campaign data and track site usage for the site's analytics report. The cookie stores information anonymously and assigns a randomly generated number to recognise unique visitors. |
| _ga_* | 1 year 1 month 4 days | Google Analytics sets this cookie to store and count page views. |
| hubspotutk | 6 months | HubSpot sets this cookie to keep track of the visitors to the website. This cookie is passed to HubSpot on form submission and used when deduplicating contacts. |
| wmc | 1 year 1 month 4 days | Workable sets this cookie to assign a unique visitor ID for statistical purposes. |
| Cookie | Duration | Description |
|---|---|---|
| _cfuvid | session | Description is currently not available. |