Identity fraud caused $27.3 billion in losses and affected 18 million people in 2025, according to a Javelin Strategy and Research study.
Banks have traditionally asked customers to confirm personal information before discussing an account. That can include a date of birth, address or recent transaction. The problem is that much of this information can be found through data breaches, stolen records or social media.
Some financial institutions have responded by adding voice biometrics to their security systems. The technology compares a caller’s speech with a voiceprint previously connected to the customer.
Vishal Shah, a senior engineering manager with more than 22 years of experience, worked on the cloud architecture behind a voice authentication platform at a large U.S. bank.
According to Shah, the system was designed to confirm customers while they were speaking with a call center representative. He said it served tens of millions of accounts and connected the bank’s phone systems, customer service applications and fraud detection tools.
“Passwords ask people to prove they remember something,” Shah said. “Voice asks them to prove they are someone.”
How voice verification works
A voice authentication system begins by recording a customer speaking and converting that sample into a mathematical voiceprint.
During a later call, the system creates a new voiceprint and compares it with the stored version. It then returns a score showing how closely the two samples match.
This process can happen in the background while the customer speaks. A strong match may allow routine service to continue with fewer security questions. A risky request, such as moving money or changing account information, can still require additional verification.
“The best authentication is the kind nobody feels,” Shah said. “If a legitimate customer has to fight their way through it, you have built something that irritates the right people along with keeping out the wrong ones.”
Shah said the platform separated enrollment, voice comparison, fraud analysis and other functions into independent services. That allowed each part of the system to handle more traffic without requiring the entire platform to grow at the same rate.
Why voice cannot work alone
Voiceprints are not passwords, but they are not perfect proof of identity either.
Voices can change because of illness, age, background noise or a poor phone connection. Biometric systems can also produce false matches or reject legitimate customers.
AI voice cloning adds another concern. New tools can create convincing speech from a short recording, giving criminals another way to impersonate customers.
Current National Institute of Standards and Technology guidelines for federal digital identity systems say voice comparison should not be used for authentication. The rules do not apply to every bank, but they show why voice should be treated as one signal rather than a complete security system.
A bank can combine voice analysis with information about the caller’s device, location, account activity and behavior. High-risk requests may also require a one-time code or confirmation through the bank’s mobile app.
Shah said the platform he worked on also looked for signs of manipulated audio and checked callers against voiceprints connected to previous fraud attempts.
“Security is a moving target,” Shah said. “The moment you assume your defense is finished, someone is already building the tool that beats it.”
Building for failures
Banking authentication systems must also remain available during traffic spikes, software problems and cloud service disruptions.
Shah said the platform was designed to keep one failing component from taking down the entire authentication process. Retry systems, fallback paths and circuit breakers allowed other services to continue operating when one dependency had a problem.
The engineering team also tested failures under controlled conditions before they affected customers.
“You do not really understand a system until you have watched it fail,” Shah said. “Uptime is something you earn by breaking your own system on purpose until the failures stop surprising you.”
Shah explores similar ideas in his book, “How Systems Earn Trust,” which focuses on reliability, security and identity in large technology systems.
Security becomes a continuing process
Voice biometrics can make a call easier for a legitimate customer, but its value depends on how it is used.
A voice match may provide one piece of evidence. It should not end the bank’s review of a risky request, especially as AI-generated audio becomes easier to produce.
The stronger approach is continuous and layered. A system can consider several signals throughout a call and request additional proof when the risk changes.
“Every system in a bank is really a promise to a customer that their money and identity are safe,” Shah said. “You keep that promise in the engineering, in the parts nobody sees.”