- Home
- Whitepapers, reports & articles
- How Banks Can Disrupt Scams Without Ruining UX
How Banks Can Disrupt Scams Without Ruining UX
Contents
29 September 2026
Over the past ten years, digital banking made speed its main priority. Onboarding that used to take days was compressed into minutes. Drop-off rates plummeted, and removing every minor hurdle from a user interface became standard practice. That effort solved genuine problems and saved millions of hours.
Along the way, though, speed became a proxy for quality. Fewer taps meant a better product, while any moment of hesitation was treated as a design flaw that needed fixing. That logic is worth questioning. It overlooks how real people actually act when something important is on the line.
People choose friction when the stakes are high
Look at how people handle an alarm clock. If it sits on the bedside table, you can slap the snooze button while half-asleep and forget you ever did it. Put that same clock on the far side of the bedroom, and the forced walk across the carpet breaks the mental haze.
You see the exact same impulse in online payments. When someone needs to send money to a new account for the first time, they almost always send a one-pound test payment first. It adds extra steps and takes longer, but it gives them peace of mind before moving the rest.
Contractual cooling-off periods work on the same logic. They introduce an intentional delay because major financial commitments shouldn’t be finalised while someone is under intense pressure. A forced pause isn’t useless latency; it’s room to think clearly.
Software already relies on this thinking in plenty of places:
- Deleting an item usually asks for confirmation first, simply because you can’t easily undo it. Removing a saved payee, closing an account, or cancelling a booking carries weight. Where an action is easily reversible like moving an email to a trash bin app asks for far less.
- E-commerce sites show a summary screen before charging a card, giving the customer one last chance to review item quantities and addresses.
People don't just tolerate these extra steps, they welcome them because the level of effort matches the risk involved.
Two clear principles drive this:
First, resistance makes sense when an action is permanent and hard to fix. Second, a pause only works if it disrupts a habit, forcing the user to stop and pay real attention.
Location matters far more than volume
The vast majority of an app should stay fast. Checking a balance, moving funds between your own savings accounts, or paying a regular utility bill should take seconds. There is no reason to slow anyone down during routine, low-risk moments.
Irreversible actions need to be handled differently. The right metric isn't how risky a feature feels to a product designer, but what happens immediately after the user taps the button:
- Can the transfer be recalled?
- How much money stands to be lost?
- Will the user spot an error quickly enough to stop it?
- Can the bank help them fix it if things go wrong?
Updating security credentials, adding a new payee, or sending an unusually large sum carry entirely different consequences than checking a balance. Yet transferring money remains one of the most immediate, irreversible digital actions a consumer can take. In far too many payment flows, that essential pause is missing entirely.
Scams represent the worst-case scenario
Nowhere is a missing pause more dangerous than in an Authorised Push Payment (APP) scam. Money leaves an account instantly via rails like Faster Payments, and nothing about the user interface looks out of place while it happens.
Recent figures from consumer protection reports show reported fraud losses topping 15.9 billion USD in 2025, with direct bank transfers accounting for the largest share of overall damage. Scams operate quite differently from traditional account takeover, which is precisely why standard security controls fail to catch them.
Traditional fraud is an identity problem: an unauthorised stranger breaks into an account. Banks have built strong defences against this using device tracking, IP monitoring, and behavioural checks.
In a scam, the genuine customer logs in, passes two-factor authentication, and approves the transfer themselves. When an automated system asks, "Is this really you?", the answer is yes. The question the interface fails to ask is: "Whose idea was this payment?"
Scammers rely on three simple tactics to control the dynamic:
-
Urgency: Creating a fake crisis forces people to move fast.
-
Authority: Impersonating police, tax agents, or bank fraud teams stops people from asking questions.
-
Isolation: Ordering the victim to keep quiet prevents them from getting a second opinion.
Combined, these elements create a narrow window where a customer acts quickly, under stress, and alone.
To make matters worse, scammers actively prepare victims for bank interventions. They tell the target exactly what warnings will pop up, write them off as "routine system checks," and coach them on which buttons to press. A standard warning modal that the customer was warned to expect actually reinforces the scammer's credibility instead of breaking it.
Confirmation prompts already use the right basic mechanism by stopping the user before an action completes. The real challenge is making that brief pause carry genuine weight. The moment between tapping and sending needs to do more than simply confirm that a finger touched the glass.
What sensible friction looks like in payment design
-
Interrupt autopilot instead of adding screen count. Vague "Are you sure?" pop-ups are so common that people clear them without reading. Effective interventions force a moment of thought, such as asking the user to type a short reason for the payment or pick from dynamic risk scenarios.
-
Use background protections that work automatically. Checks like Confirmation of Payee (CoP) help prevent impersonation by matching names directly. Similarly, short hold periods or spending limits on initial transfers to brand-new payees take away the scammer's biggest advantage: speed.
-
Tackle isolation head-on. Asking a direct question like "Has anyone instructed you to keep this payment secret from family or bank staff?" brings back the outside perspective that manipulation strips away. Even if a coached victim bypasses it, the question provides a valuable safety check at no added complexity.
-
Ask for unscripted input. Getting a user to explain a payment in their own words is far harder for a fraudster to coach than tapping an "OK" button. In phone-based or in-branch banking, asking someone to describe the payment out loud forces them to process what is actually happening.
-
Tailor friction to actual risk. Interventions shouldn't treat every transaction the same way. Low-risk payments to long-standing payees should stay fast. High-risk triggers—like a large transfer sent to a payee account created three minutes ago—should trigger mandatory, multi-step checks.
Designing meaningful pauses into banking
Sandstone Technology builds internet banking and mobile app solutions for financial institutions across Australia, the UK, and New Zealand. Features like Take 5, Scam Safe Messages, Scam Check, and Confirmation of Payee are built into our platform, directly shaping how we design payment flows.
Our goal isn't to make banking slow for the sake of it. It’s to make sure the person approving a transfer is the one actually making the decision. Sometimes that calls for a delay, sometimes a direct question, and often the fastest path available.
Want to see how these protective interventions work in practice?
If you are balancing friction, conversion, and scam prevention across your own digital channels, our team would be glad to share how our internet banking and mobile app platforms integrate these safeguards into everyday banking journeys. Contact us here.
Read more
- All
- Article
- Whitepaper
- Reports
