Customer Experience · August 8, 2026
When Verification Destroys Customer Experience
Verification protects the business but often punishes the customer. Here's how to design security that doesn't corrode trust across the journey.
When Proving You Exist Destroys the Experience
Verification is the moment a business says, in effect, "We don't quite trust you yet." That's a reasonable operational stance. It becomes a CX catastrophe when the customer hears it fifty times across a single journey — at login, at checkout, at the call centre, at the branch, and again when they try to change their address. The verification step that protects the business is often the same step that teaches the customer to resent it.
This is the central tension in modern customer experience: security and friction are not the same thing, but organisations routinely treat them as inseparable. The result is customer experience that is technically safe and emotionally corrosive. Understanding where verification helps, where it hurts, and how to design the difference is one of the most consequential skills a CX practitioner can develop in 2026.
What verification actually does to the emotional arc of a journey
Daniel Kahneman's peak-end rule tells us that customers don't remember an experience in its entirety — they remember its emotional peak and its ending. Verification events are disproportionately likely to be that peak, and almost never in a good way. A customer who sails through onboarding but hits a six-step identity check at the point of first transaction will encode that friction as the defining memory of the brand. The pleasant homepage, the smooth browsing, the well-written confirmation email — all of it recedes. The OTP that didn't arrive stays.
This is not a hypothetical. It is the lived experience of most digital journeys in banking, telecoms, healthcare, and government services across the MENA region and beyond. The verification layer was designed by a risk or compliance team, handed to IT for implementation, and dropped into the customer journey without anyone mapping what it would feel like at the moment it fires. The result is what Richard Thaler would call sludge — friction that serves the institution's interests, not the customer's.
"The verification step that protects the business is often the same step that teaches the customer to resent it. Security and friction are not the same thing — but organisations routinely treat them as inseparable."
Why banking gets this wrong more than almost any other sector
Banks have legitimate reasons to verify. Regulatory requirements are real, fraud losses are real, and the consequences of identity failure are severe. But the customer experience in banking has been shaped less by those requirements than by a risk-minimisation culture that defaults to asking for more rather than designing for less.
Consider what a typical retail banking customer encounters across a single month: a biometric check at app login, a PIN at the ATM, a knowledge-based authentication challenge when calling the contact centre, a branch visit with two forms of ID to change a mailing address, and a re-verification email when logging in from a new device. Each of these is defensible in isolation. Cumulatively, they signal that the bank views the customer as a persistent suspect rather than a valued account holder. The emotional residue is not security — it is exhaustion.
The banks that have closed this gap have done so not by reducing security but by making verification contextual. Risk-based authentication — where the verification burden scales with the actual risk of the transaction — is both more secure and dramatically less intrusive. A customer checking their balance from a recognised device in their home city should face near-zero friction. The same customer initiating a large international transfer from an unfamiliar location should face more. This is not a radical idea; it is basic behavioral economics applied to security design: match the cost imposed on the customer to the actual risk being managed.
The three failure modes of verification design
Most verification failures in customer journeys fall into one of three patterns. Recognising them is the first step to fixing them.
- Blanket verification: Every customer, every transaction, every channel faces the same check regardless of risk level. This is the compliance team's default — it is auditable, defensible, and deeply inefficient. It also penalises the majority of legitimate customers to catch a minority of bad actors.
- Siloed verification: Each department or channel owns its own identity layer. The customer who verified at onboarding must verify again at the contact centre, again at the branch, again on the app. There is no shared trust signal across the organisation. The customer experiences this as the business having no memory — which, from a CX standpoint, it doesn't.
- Opaque verification: The customer is asked to prove something without understanding why, what will happen if they can't, or how long it will take. Uncertainty amplifies the perceived cost of friction. Loss aversion means that customers weight the fear of being locked out far more heavily than the inconvenience of the check itself. Organisations that explain the reason for a verification step — briefly, plainly — consistently see higher completion rates and lower abandonment.
How verification fits into the broader customer experience strategy
Verification is a touchpoint. It sits inside a journey. And like every touchpoint, it should be designed — not merely implemented. That means it belongs on the journey map, it carries an experience score, and it is owned by someone accountable for the customer outcome, not just the technical outcome.
The discipline of CX journey design forces this conversation. When you map the onboarding journey for a new banking customer and you plot the emotional arc, the verification cluster almost always produces a visible dip. That dip is not inevitable — it is a design choice. The question is whether the organisation is willing to treat it as one.
A well-constructed customer experience strategy will specify, for each verification touchpoint: what is the minimum information genuinely required; what channel is least intrusive for this customer segment; what happens when verification fails and how quickly can it be resolved; and what signal does this moment send about the brand's relationship with the customer. Most organisations answer none of these questions explicitly. They inherit the verification design from a vendor's default settings and call it done.
What good verification design actually looks like
Good verification is invisible when it works and human when it doesn't. That is the design standard worth holding.
Invisible verification means the customer is authenticated through signals they generate naturally — device recognition, behavioural biometrics, location context, transaction history — without being asked to perform a ritual. The friction is absorbed by the system, not offloaded to the customer. This is the direction in which mature digital experience is moving, and it is achievable today with technology that is widely available.
Human verification means that when the automated system fails — and it will — the recovery path is staffed, fast, and empathetic. The customer who cannot complete an OTP because they changed their phone number should not face a dead end. They should reach a person who can resolve the issue in a single interaction, with the authority to do so. The customer crisis management capability that handles fraud also needs to handle the false positive — the legitimate customer who looks, briefly, like a risk.
"Good verification is invisible when it works and human when it doesn't. The friction should be absorbed by the system, not offloaded to the customer."
The ordered steps below represent a practical design sequence for any organisation reviewing its verification touchpoints:
- Audit the current state. Map every verification event across every channel and journey. Count how many times a customer is asked to prove identity in a typical month. Most organisations are surprised by the number.
- Score each event. Assign a friction cost and a risk value to each verification touchpoint. Where the friction cost is high and the risk value is low, that is the first target for redesign.
- Consolidate identity signals. Build or integrate a shared identity layer that allows a verified signal from one channel to be trusted by others. This is an architectural decision, but it is a CX decision first.
- Introduce contextual risk-scoring. Replace blanket verification with rules that scale the check to the actual risk of the transaction. Start with the highest-volume, lowest-risk journeys.
- Design the failure path. For every verification step, specify the recovery journey when it fails. Staff it, time it, and measure it separately from the success path.
- Communicate the reason. At each verification step, tell the customer why — in one sentence. "We're confirming it's you before processing this transfer" is more reassuring than a blank OTP field. Transparency reduces perceived friction without changing the actual requirement.
- Measure the experience, not just the completion rate. A verification step with a 95% completion rate can still be destroying customer sentiment. Track CSAT or effort scores at the verification moment itself, not just at the end of the journey.
The employee experience dimension that most teams overlook
Verification problems are not only felt by customers. Frontline staff who are required to enforce verification protocols they cannot explain, using systems that flag legitimate customers as risks, face their own form of friction. The contact centre agent who must tell a long-standing customer that they cannot process a request because the verification system has locked the account — and who has no override authority and no clear escalation path — is experiencing a failure of employee experience that directly produces a failure of customer experience.
This is one of the clearest illustrations of the upstream relationship between EX and CX. Empowering frontline staff with the tools, authority, and information to resolve verification failures quickly is not a soft HR initiative. It is a hard CX intervention with measurable impact on resolution time, first-contact resolution rates, and customer sentiment at the moment that matters most.
Verification as a trust signal, not just a security gate
The most sophisticated reframe available to CX leaders is this: verification, designed well, is not a cost imposed on the customer — it is a demonstration of care. When a bank sends a real-time alert and asks the customer to confirm an unusual transaction, that is verification. It is also the bank saying: we are watching out for you. The customer's response to that moment depends almost entirely on how it is designed and communicated.
The same principle applies to data verification in healthcare, identity checks in government services, and age verification in regulated retail. Every sector has its version of this tension. The organisations that resolve it well share a common approach: they treat verification as a service design problem, not a compliance problem. The compliance requirement sets the floor; the design determines how far above it you build.
This matters particularly in the MENA context, where digital adoption has accelerated sharply and customer expectations have moved with it. Customers who use frictionless payment experiences in one context will not tolerate unnecessary verification burdens in another. The reference point shifts constantly, and the tolerance for poorly designed security theatre is lower than it has ever been.
"Verification, designed well, is not a cost imposed on the customer — it is a demonstration of care. The compliance requirement sets the floor; the design determines how far above it you build."
Measuring what you're actually doing to customers
Most organisations measure verification through a security lens: completion rates, fraud detection rates, false positive rates. These are necessary metrics. They are not sufficient ones. A Voice of Customer programme that does not capture sentiment at verification touchpoints specifically is missing one of the highest-impact moments in the journey.
Customer Effort Score (CES) is particularly well-suited to verification measurement. The question "How easy was it to confirm your identity?" captures the friction dimension directly. Tracking CES at the verification moment, segmented by channel and journey type, will surface the specific touchpoints causing the most damage — and give the organisation a baseline against which to measure redesign.
If you want a rapid diagnostic of where verification sits in your overall CX maturity, the CX Maturity Assessment can surface the gap between your current security-driven defaults and a genuinely customer-centred approach to identity and trust.
The competitive advantage hiding in plain sight
Here is the contrarian case: in sectors where verification friction is universal and accepted as inevitable, the organisation that solves it first gains a disproportionate advantage. Customers notice when something that was hard becomes easy. They tell people. They stay.
This is the goal-gradient effect in reverse — customers who have been conditioned to expect friction respond with unusual loyalty when that friction disappears. The bar is low precisely because everyone else has left it low. The organisation willing to treat verification as a CX design challenge rather than a compliance checkbox has a genuine differentiator available to it, at relatively modest cost compared to the brand campaigns and loyalty programmes that typically absorb the CX budget.
The question is not whether your verification process is technically compliant. It almost certainly is. The question is whether it is designed — whether someone with accountability for the customer's experience has looked at every identity check in your journeys and asked: does this need to be here, does it need to be this hard, and does the customer understand why we're asking? If the answer to any of those questions is "we've never discussed it," you have found your next CX initiative.
Verification will never be glamorous. It will never feature in a brand campaign. But it sits at the intersection of trust, security, and experience — three things that determine whether a customer stays or leaves. Getting it right is not a technical project. It is, at its core, a question of what kind of relationship you want to have with the people you serve.
Further reading
FAQ
Questions we get on this topic
Related reading
Stay ahead of CX
Get the Journal in your inbox.
Insights, frameworks and event round-ups from the Renascence team. No spam, ever.



