Contact us

Fill out the form to start a conversation. Can’t wait to connect? Give us a call. (833) 816-2562

Request a demo

Fill out this form to request a demo. Can’t wait to connect? Give us a call. (833) 816-2562

Blog
|
What KBA is costing banking call centers

What KBA is costing banking call centers

And what to do instead

By
Kyra Loew
Created:
August 21, 2026
Last Updated:
August 21, 2026
Contact Center
7
minute read
  • Knowledge-based authentication (KBA) is a growing security liability. It relies on information that should be known only to the user, but has been increasingly exposed through data breaches, public records, social media, and IVR reconnaissance, contributing to a 250% surge in account takeovers (ATO) reports in 2024.  
  • The contact center is part of the fraud attack surface. Fraudsters don't always need to defeat a bank's digital defenses directly; they can target agent-assisted workflows such as account recovery, device re-enrollment, and card replacement.
  • The ongoing cost of KBA can be significant. Verification tools or efforts can cost $0.50–$3 per attempt. At 100,000 calls per month, 30 seconds of additional handle time represents roughly $50,000 in agent capacity (assuming a $1-per-minute loaded agent cost).  
  • Regulators are shifting toward layers of stronger, risk-based signals. The latest Digital Identity Guidelines from the National Institute of Standards and Technology (NIST) no longer treat KBA as an acceptable secret for digital authentication, while emerging voice-provider requirements are placing greater emphasis on customer verification and risk-based controls.  
  • Pre-call risk intelligence offers a faster, more secure alternative. FreeClimb Risk Scoring Services identifies calls before they connect using billions of historical records and real-time signals, enabling institutions to eliminate 1–2 KBA questions per call and cut 10+ seconds of handle time.  

For banks, knowledge-based authentication (KBA) can seem like a low-cost way to protect customer accounts by asking users questions only they should know. But at contact center scale, the price of keeping it in place can be higher than it appears.

Security questions are increasingly easy to bypass, frustrating for over half of customers, and add unnecessary time and cost to every interaction. Yet KBA remains deeply embedded in authentication. Legacy systems, implementation complexity, and the perceived risk of change have kept security questions in place long after their effectiveness began to decline.  

But what if the status quo is actually creating a greater burden for banks? This article explores what KBA is really costing banking call centers and what a modern, frictionless alternative looks like.  

Why the call center has become a fraud attack surface

Banks have invested years making the digital front door harder to break into with multi-factor authentication, device recognition, transaction monitoring, and other security controls. But fraudsters don't always need to bypass them directly; they can target the call center instead.  

KBA questions rely on personal information – such as a mother’s maiden name or previous address – that is now widely available through social media, public records, data breaches, or, in some cases, systematically mined by fraudsters who exploit IVR prompts.  

Armed with these details, social engineers can convince an agent to reset a password, re-enroll a device, or replace a card. With compromised credentials as a leading entry point, account takeover (ATO) reports surged 250% in 2024. Human error follows close behind, contributing to an estimated 60% of breaches.

In these situations, the agent leg becomes the final decision point in the authentication process. And that’s the challenge: a caller's ability to provide personal information doesn't necessarily prove that they’re legitimate.

What KBA costs banking contact centers

KBA can cost anywhere from $0.50 to $3 per verification attempt depending on the third-party vendor, volume, and implementation. Authentication can add 30 seconds to typical calls and up to 90 seconds to high-risk calls as agents ask questions, listen to responses, verify answers, and potentially repeat the process.  

Across 100K monthly calls, that handle time represents approximately $50,000 in monthly agent capacity, assuming a loaded agent cost of $1 per minute. And that’s before accounting for the downstream cascade of escalations, longer queues, abandoned calls, and agent burnout, turning KBA into a recurring operating cost that scales with every interaction.

The shift away from KBA

Regulators have also taken notice of the security impacts of KBA. The National Institute of Standards and Technology (NIST) no longer recognizes knowledge-based security questions as an acceptable, primary form of authentication, pushing organizations toward stronger identity proofing methods like validated documents, biometric matching, and liveness detection.

The FCC has also proposed enhancements to Know Your Customer requirements that point toward risk-based authentication for voice providers. Aiming to reduce robocalls and scams, the proposals consider a set of richer signals, like device reputation, geolocation, IP address, behavior, and transaction context, to identify suspicious call activity.  

How pre-call risk intelligence improves call center efficiency and CSAT

Organizations need authentication that minimizes reliance on costly KBA questions without jeopardizing security.  

FreeClimb Risk Scoring analyzes incoming calls using billions of historical call records, real-time network signals, and cross-industry behavioral patterns to provide call-level risk intelligence before an agent, IVA, or IVR makes an authentication decision.

Instead of asking every caller the same set of questions, organizations can give agents additional context about the call and use that information to determine when stronger authentication is actually warranted. Or risk thresholds can be set to automatically determine authentication actions for an IVA/IVR.  

FreeClimb can help organizations:

  • Reduce unnecessary KBA: Low-risk calls can eliminate one or two questions when ANI match, ANI velocity, and overall call risk signals support a lower-risk assessment, increasing CSAT.
  • Low authentication costs: Reducing manual verification can deliver an estimated $0.25 – $0.50 savings per call, or $25,000 – 50,000 monthly across 100,000 calls
  • Make decisions more explainable: SIP-level metadata and supporting risk signals provide clearer context for why a call was assessed as higher or lower risk.

By adding risk scoring intelligence to IVR and agent workflows before the conversation begins, contact centers can streamline low-risk calls while signaling elevated-risk interactions to automated systems and agents, giving them a clear reason to apply stronger verification before making sensitive account changes.

Take the first step toward a more trusted experience

KBA may seem like a simple way to verify callers, but for banking contact centers, it can introduce security gaps, customer friction, and significant operational cost. As fraudsters increasingly target the call center, relying on static personal information to authenticate callers is becoming harder to justify.  

Financial institutions need verification strategies that keep pace with modern fraud tactics while still meeting customer expectations for fast, seamless service. By supplementing static knowledge questions with passive pre-call authentication and intelligent risk scoring, contact centers can reduce authentication costs, improve agent efficiency, and deliver a better experience without compromising security.

Table of Contents

FreeClimb Blog FAQs

What is Knowledge-Based Authentication (KBA)?

Knowledge-Based Authentication (KBA) is an identity verification method that asks customers to provide information associated with their account or identity, such as a previous address, recent transaction, account balance, or mother's maiden name.

Why is KBA no longer considered secure?

KBA relies on personal information remaining private. Data breaches, social media, phishing attacks, and identity theft continue to make much of that information accessible to fraudsters. That makes it easier for attackers to research answers and use them in social engineering attacks.

How does KBA increase Average Handle Time (AHT)?

One authentication step typically adds 10 seconds to 3 minutes of handle time before an agent can begin resolving the customer's issue. Asking multiple security questions, correcting failed responses, and escalating unsuccessful authentication attempts all increase Average Handle Time (AHT), reducing overall contact center efficiency.

How much can KBA cost a contact center?

Each verification attempt can cost $0.50 – $3 with third-party services. The added handle time of 30 seconds across 100,000 monthly calls represents approximately $50,000 in agent resources, assuming a loaded cost of $1 per minute.

What regulatory changes are affecting how banks use KBA?

The National Institute of Standards and Technology (NIST) now requires static security questions to serve only as a supplementary trust signal rather than a primary method, and the FCC has proposed KYC enhancements for voice providers that favor risk-based authentication using signals like device reputation, geolocation, and behavior.

What is the alternative to KBA?

Pre-call risk intelligence passively identifies and assesses callers before the call connects, using a combination of historical call data and real-time network signals, rather than asking the customer questions during the call.

What are the benefits of implementing risk intelligence to authentication?

Risk intelligence can reduce unnecessary KBA, give agents better fraud context, and shorten handle time. FreeClimb's case study reports 10+ seconds saved per call —roughly 278 agent hours, or $16,700 in monthly capacity across 100,000 calls, assuming $1 per minute.