Insurers and banks have invested significant effort in securing internal employee and customer access. Internal access now uses phishing-resistant multi-factor authentication (MFA), whereas consumer and policyholder-facing applications have shifted toward passkeys and passwordless access. It is usually the middle of this stack that is weak: MGAs, brokers, reinsurers, claims vendors, auditors, consultants, and external contractors all log into carrier and bank infrastructure under significantly less stringent conditions.
There are numerous examples of third-party access to financial services infrastructure based on outdated authentication methods, common passwords, manual user creation, and a general lack of governance controls. The exposure to that risk increases rapidly as partner ecosystems grow and cloud integration deepens, and insurance carriers, with their dense networks of agents, brokers, and claims partners, are as exposed as any bank.
That gap is becoming harder to ignore because the identity surface itself is expanding rapidly. Research from Enterprise Strategy Group (ESG), commissioned by Thales, found that 74% of BFSI organizations, spanning banking, insurance, and financial services, report third-party identities growing faster than employee identities, with third-party identity volumes projected to grow 37% over the next 12 months. At the same time, 89% say they already have a prioritized strategy to modernize identity solutions used by contractors and partners.
The question is: what standard should financial institutions adopt?
The Partner Access Model is Already Failing at Scale
The operational signals emerging from partner identity environments increasingly look like security warnings.
The 2026 Thales Digital Trust Index found that 92% of partner users experienced access issues with external partner systems during the last 12 months. Only 22% received login access immediately when starting with a new partner relationship. More concerning, 66% admitted to sharing or borrowing credentials, with 53% blaming slow official access processes.
These figures are often viewed as productivity issues. In reality, they highlight an identity control model under operational stress. Shared credentials eliminate traceability, making it difficult to distinguish between legitimate and compromised activity.
The same report found that 71% of partner users were worried about maintaining access they no longer needed, and only 19% said access changes were implemented as soon as responsibilities changed. This joiner-mover-leaver problem extends beyond the enterprise perimeter.
ESG’s BFSI research reinforces the point. Lifecycle management across disconnected systems, compliance reporting across identity boundaries, and deprovisioning identities when no longer needed were all ranked among the top third-party identity and access management (IAM) challenges by respondents.
Governance gaps are operational, structural, and currently exist at scale.
Third-Party Access Now Maps Directly to the Attack Surface
When the identity trends map to attack data, the security concerns become more evident. The 2026 Thales Data Threat Report: Financial Services Edition found that, according to 70% of those surveyed, the top emerging attack technique targeting cloud infrastructure in the financial sector is credential theft and the misuse of secrets.
Vulnerabilities originating from third parties, including external code and APIs, ranked second at 65%. Third-party vendor networks also ranked among the top attack targets for financial services organizations. Businesses are building connected SaaS ecosystems, fintech integrations, outsourced capabilities, and cloud processes even as credential-based attacks continue to skyrocket.
Yet the authentication layer protecting many of those external connections is inconsistent, which fuels risk because attackers don’t distinguish between employee and partner credentials.
The threat environment further complicates the issue. According to the Thales Bad Bot Report for 2026, the financial services sector accounted for 46% of account takeovers in 2025, even though it makes up just 24% of all bot attacks worldwide. In addition, there has been a 70% increase in account takeovers from July 2024 to July 2025.
Banks understand they need phishing-resistant authentication internally, and the same logic should apply to partner ecosystems.
Why FIDO Fits the Partner Authentication Problem
The value of fast identity online (FIDO) in partner access scenarios is not simply stronger MFA. It is the removal of the shared secret itself.
Passwords, OTPs, and reusable credentials create a transferable authentication artifact that can be stolen, replayed, borrowed, or phished. FIDO-based authentication replaces that with cryptographic key pairs tied to the user, device, and relying party domain. There is nothing to steal, share, or replay.
For banks that rarely control the identity infrastructure their partners use, FIDO's open standard design means strong authentication can extend beyond the corporate IAM perimeter without requiring partners to adopt the bank's full identity stack.
Not Every Partner Requires the Same Assurance Level
Partner authentication is not a single-tier problem. The right credential depends on what the partner can access and the consequences of a compromise.
For lower-risk external relationships, such as broad partner networks, suppliers, and fintech integrations where the priority is reducing friction and eliminating shared passwords, synced passkeys operating at AAL2 are a practical starting point. They raise the authentication bar without imposing hardware requirements across a diverse and distributed partner base.
For higher-risk access, device-bound hardware security keys at AAL3 are the appropriate standard. Auditors in controlled environments, privileged contractors, external administrators, and partners with direct access to regulated financial data are scenarios in which the bank's compliance posture is contingent on the partner's authentication holding. Synced passkeys, which can move between devices, do not provide that assurance.
Matching credential strength to access risk is not a novel principle. NIST SP 800-63B formalizes it through the AAL2 and AAL3 assurance levels that already underpin most phishing-resistant MFA frameworks.
Authentication Alone Will Not Solve the Governance Problem
Deploying FIDO in partner ecosystems without addressing lifecycle management extends the existing vulnerabilities rather than closing them. Delayed provisioning increases the likelihood of credential reuse; absent deprovisioning, access remains in place long after it is needed. The 2026 Thales Digital Trust Index found that only 19% of partner users see access changes implemented immediately after responsibilities change, and 66% retain access they no longer need.
Banks still need automated provisioning, entitlement management, and revocation across siloed systems — and the regulatory pressure to get this right is building. DORA, NIS2, and PSD2 all treat third-party access management as an institutional liability, not a partner problem. The ESG research found compliance and regulatory mandates were the primary driver of third-party identity modernization for 46% of BFSI respondents.
Choosing the Right FIDO Enrollment Model
Large-scale FIDO key enrollment typically follows one of three models.
In admin-driven enrollment, IT centrally configures and issues security keys before delivery, giving full control over credentials and setup policies. This is well-suited to large, time-sensitive deployments.
Self-service enrollment lets users configure their own key through a portal within defined policy parameters, reducing IT overhead but requiring a well-designed process and investment in user communications.
Vendor-managed enrollment goes furthest: keys are pre-registered before shipping, so recipients receive a device that is already enrolled and ready to use, with no IT involvement at the point of receipt.
A large automotive organization used this third model to deploy FIDO security keys to employees and contractors at scale. Using a centralized authenticator lifecycle management platform, it bulk-enrolled security keys into its internal identity providers before distribution, then shipped pre-registered keys directly to contractors and partners. The result was a faster rollout and a consistent authentication experience across a distributed user base, without placing the enrollment burden on internal IT teams.
The Next Step in Identity Security
FInancial institutions that treat partner authentication as a downstream problem will find it becomes an immediate one. Credential data theft, access failure rates, and the regulatory trajectory all point in the same direction. Phishing-resistant authentication is already the standard for employees. Extending it to partner ecosystems completes the strategy.
