Corbb O’Connor, Director of Accessibility Advocacy, Level Access
Financial institutions have invested heavily to strengthen customer authentication in recent years, but in doing so, they’ve inadvertently created accessibility barriers for many disabled users.
As a leader in the National Federation of the Blind, I regularly support people who have recently lost their vision by helping them learn new ways to use technology. I have also spent several years working within the banking industry. So I’ve witnessed how, in trying to solve one problem, security teams often inadvertently create another.
For example, online customers will often see a simple checkbox to confirm they are not a robot. The most popular CAPTCHA on the web, however, doesn’t appropriately convey that this is a checkbox to blind screen-reader users. If blind users like me do manage to successfully select this option, we’re then presented with a visual challenge such as identifying motorcycles or traffic lights. The alternative option is to transcribe a snippet of audio into text, but even the button for that is mislabelled for us screen-reader users.
And if you’re Deafblind? There is no third option except to rely on someone else, thus defeating the entire purpose of a secure account creation process!
This all adds layers of complication that leave some users locked out of essential services and unable to make critical payments. This could potentially leave financial institutions in breach of laws such as the European Accessibility Act, the Americans with Disabilities Act, and the UK Equality Act. With multi-factor authentication (MFA) solutions, such as one-time codes, face ID, passkeys, and magic links, now commonplace in the banking sector, the need to resolve this issue is more urgent than ever.
The problems posed by MFA
A core flaw in many MFA solutions is that they require users to look at one device and transfer information to a second device. For many people, this is far from ideal. If someone has a motor disability, for example, entering a time-limited code before it expires can be challenging. If you’re listening to screen-reader output mixed with a poor voice recording while trying to find the box in which to enter the text, it’s overwhelming.
If security teams prevent the use of password managers, it also creates another set of issues. Banks also routinely block copy and paste in login fields, making life much harder for people with cognitive and memory-related disabilities who often rely on these functions (as well as for people like me who just like random, secure passwords).
In my role, I’m often brought in to support teams trying to retrofit these types of solutions with greater accessibility. This once involved a team attempting to make a pattern-drawing authentication more accessible. As it turned out, the solution proved overly complex and universally unpopular for people with and without disabilities. If the security and accessibility teams had worked together from the outset, however, they would have most likely developed a simpler solution.
Solving the authentication challenge
It’s not unusual for projects to become overly complicated when these teams work in silos—especially as they have different goals in mind. Security teams often seek to add extra steps and verification hurdles to slow down bad actors, while accessibility teams focus on removing barriers to provide smoother user journeys. Both goals are valid, but if these business functions don’t work together, the potential conflict is obvious.
From a compliance perspective, the need for these teams to work together is clear. But there is also a major commercial incentive. For example, the UK’s Women and Equality Committee has found the “Purple Pound”, the combined spending power of disabled people and their households, is worth approximately £274 billion each year to the UK economy alone.
Meeting the needs of people with disabilities provides a competitive edge that institutions can’t ignore in an increasingly crowded marketplace. When financial services professionals were surveyed by Level Access, 88% said that greater digital accessibility improves customer acquisition, while 89% said it improved customer retention.
Getting accessibility right
Some organisations are proving they can successfully bridge the security and accessibility gap, though. For example, ID.me (http://id.me), which offers a digital identity wallet for people to securely access services across the internet, has developed Trusted Referee, a guided solution for anyone who’d rather verify their identity with a human than go through an automated process. Trusted Referee consists of verifying your identity with a trained specialist via video chat, while still maintaining the highest privacy standards.
Security technology is also trending in the right direction. Phishing-resistant, password-less methods, like passkeys and biometrics, are both more secure and more accessible than one-time codes. It’s worth noting, however, that not every customer has the same level of device literacy, so alternative accessible pathways remain essential.
The institutions getting this right aren’t doing anything radical. They’re simply testing new authentication methods with users with disabilities in mind. Having accessibility and security teams work together, rather than in silos, is also more time and cost-effective— it simplifies the whole process and prevents retroactive workarounds. Collaboration is the key. It ensures financial institutions remain compliant and vital services are accessible to all.

