Authentication

Risk-Based Authentication

Risk-based authentication determines authentication requirements according to the assessed risk of a login attempt or transaction.

Acronym
RBA
Synonym
RBA

Definition

Risk-based authentication is a decision model in which authentication requirements are determined from an assessment of the risk associated with a login attempt or transaction. Although often used interchangeably with adaptive authentication, RBA more specifically emphasizes the evaluation engine and policy logic that classify attempts as low, medium, or high risk. The system may then allow, step up, challenge, or block the request accordingly.

Why it matters

Risk-based authentication is essential when static authentication rules are either too weak or too disruptive for the business context.

The Ariovis perspective

Context improves an access decision only when the signals are reliable, understood and governed. Adding more signals does not automatically produce a better policy.

Common pitfalls

  • A common pitfall is assuming the risk engine is inherently reliable without validating data quality, tuning models, and monitoring outcomes.

Standards and protocols

Reference standards
  • NIST SP 800-63B

These concepts matter most inside a real project.

The first conversation helps establish your context, the systems involved and the next useful decision.