Skip to content

Customer Authentication: The Control Point Contact Centers Keep Underestimating

Sensitive contact center interactions, such as taking payments, changing account details or disclosing personal information, carry significant risk when identity assurance is weak. These sensitive moments rightly receive close scrutiny, but the control point that determines whether an interaction can be trusted comes earlier: when the customer’s identity is verified.

Strengthening security at the point of action while relying on weak authentication at the start of the journey creates an avoidable gap: every downstream decision depends on the quality of the first identity check. For low-risk inquiries, a weak check may create inconvenience but for sensitive interactions, it becomes a control failure. That is why customer authentication has become a security, compliance and risk issue, beyond a simple operational workflow decision. 

Many contact centers still rely heavily on knowledge-based authentication (KBA), caller cues, and agent judgement. Those methods are familiar but also a weak defense against today’s threat model. Personal data is easier to obtain, fraud tactics are more scalable, and customer interactions are moving across assisted, self-service and AI-enabled journeys. This new landscape widens the gap between the sensitivity of the actions contact centers support and the strength of the controls used to authorize them. 

The gap between the risk and the response 

Contact centers are trusted with actions that carry real exposure: accessing accounts, changing customer details, processing claims, issuing refunds, taking payments and handling personal data. In practice, authentication is still largely human-led. Research shows that in 2025, 88% (US) and 92% (UK) of identity checks in contact centers relied on a live agent, while voice biometrics and speech recognition were each used in roughly 1% of cases.¹,²

But knowledge-based authentication (KBA) was built for a world where personal information was harder to obtain than it is today. Shared secrets, such as a mother’s maiden name or first family pet now circulate in breached datasets, phishing kits and social engineering scripts. Knowing the answer no longer proves who is calling, it only proves that someone has obtained the right information.  

Static checks also create inconsistent policy enforcement. Agents may vary in how they ask questions, interpret answers, handle exceptions or respond to pressure, creating a favorable environment for impersonation attempts. For instance, vishing (or voice phishing) exploits predictable human responses to authority, urgency, and trust. Verizon found that mobile-centric social engineering simulations using voice calls and text messages were 40% more successful than traditional email phishing simulations³, showing why identity decisions based largely on human judgement remain vulnerable. 

From a compliance perspective, agent judgement and inconsistent policy enforcement creates an evidencing problem as it can be difficult to show which control was applied, whether policy was followed, why an exception was allowed and what evidence supported the decision to proceed. For security and risk teams, this is the core issue: traditional security questions have a serious control-quality problem. 

Fraud is scaling faster than manual controls 

Contact center fraud is becoming harder to contain because attackers can combine several techniques at once: 

  • Caller ID spoofing can make an inbound call appear more credible 
  • Phishing can capture personal information before the call 
  • Social engineering can pressure agents into bypassing standard processes 
  • Generative AI can help attackers produce convincing scripts, scale reconnaissance and support more believable impersonation attempts.

Voice deepfakes and synthetic audio add another layer of complexity. They do not make every voice-based interaction untrustworthy, and voice-related authentication methods can still have a role within a layered assurance model. But voice alone is not always as high assurance as it seems when it comes to identity verification, especially where high-risk actions are involved. Furthermore, Fraud-as-a-Service compounds the problem by lowering the technical threshold for fraud, giving a broader range of attackers access to ready-made tools and infrastructure that increase both the volume and sophistication of attempted attacks. 

The broader cyber environment reinforces the importance of stronger identity controls. Verizon’s 2024 Data Breach Investigations Report found that 68% of breaches involved a non-malicious human element, including people falling for social engineering attacks or making errors³. That finding is highly relevant to contact centers: when a control depends on a human interpreting static information under pressure, the human becomes part of the attack surface. 

Weak authentication is becoming a ceiling on automation 

The authentication problem becomes more acute as contact centers adopt AI and automation. Self-service, IVR, chatbots and voice bots can reduce cost and improve availability, but sensitive actions cannot be moved safely into automated journeys without reliable identity assurance. For IT, security and risk teams, the constraint is clear: if the business cannot verify who is engaging, automation remains limited to low-risk tasks, undermining its value in the first place, because the assurance needed to automate sensitive actions safely is not yet in place. 

That constraint becomes even more significant as AI agents and agentic workflows mature. A chatbot answering a general question creates one level of risk, but an AI agent having to support a payment journey or interacting with CRM and billing systems creates a much higher one without the right solutions in place. In 2025, McKinsey’s research found that only 7% of businesses reported AI agents reaching the scaling or fully scaled phase in service operations.⁴ But as AI adoption evolves, authentication increasingly needs to be machine-readable, policy-driven and auditable: 

  • Automated systems need a clear signal that the customer has been verified 
  • Agents need escalation paths that carry identity context when confidence is low 
  • Compliance teams need to know that sensitive actions are governed consistently across channels 

Stronger assurance for the next generation of contact centers 

As fraud tactics become more sophisticated, contact centers need authentication that is stronger, more consistent and easier to govern because static questions, caller presentation, and agent judgment are increasingly difficult to defend as primary control. For contact centers, this matters beyond today’s assisted calls. As CCaaS environments become more automated, AI-driven and omnichannel, identity assurance needs to support both human agents and automated systems. A better model starts with higher-assurance verification before sensitive actions take place.  

Biometrics have grown in relevance because they reduce dependence on remembered information and provide a clearer signal that the person interacting is legitimate. This is especially valuable when biometric verification is bound to the customer’s own device, combining possession of the device (“what I possess”) with local user verification through a biometric (“who I am”). The idea is to strengthen the security and compliance posture of the contact center while providing authentication outcomes that are clear, flexible, auditable and reliable enough to guide what happens next. Passkey-based customer authentication offers a practical path toward stronger, cryptographically secure verification across assisted and automated journeys, helping contact centers move from manual trust decisions to assurance that can scale with the future of customer engagement. 

Learn more about PCI Pal Customer Authentication here. 

 

Sources

  1. 1. ContactBabel. The Inner Circle Guide to Fraud Reduction & PCI Compliance. 2025. US Edition.
  2. 2. ContactBabel. The Inner Circle Guide to Fraud Reduction & PCI Compliance. 2025. UK Edition.
  3. 3. Verizon. 2024 Data Breach Investigations Report.
  4. 4. QuantumBlack, AI by McKinsey. The State of AI in 2025: Agents, Innovation, and Transformation.

Like what you've read?

Why not share: