Hello everyone
Weâre Chris, Giselle and Priyesh from the Product Security team.
As a team, weâre focused on building security and privacy features to give customers peace of mind and make Monzo the safest place for you to manage your money.
We wanted to tell you about some new controls weâve been working on that weâll be launching soon.
The security feature will let you add an extra layer of protection on payments and pot withdrawals over a daily allowance â to help stop fraudsters in their tracks, even if they get hold of your phone.
Nothing like this exists in the industry yet and we think it solves a really pressing problem, so weâre excited to share it with you!
Weâre currently testing it with staff and getting ready to roll it out to customers in the coming weeks. You might spot this piece in the press so we wanted to jump on here and share more about our work.
Update: itâs out now!
To get started with added security, update to the latest version of the Monzo app and then head to âPrivacy & Security" settings. You can get there by tapping on your profile at the top left of the Overview screen, then tapping on âSettingsâ. From there head to âPrivacy & Securityâ settings, tap on âAdded Securityâ and follow the prompts that will take you through the set-up flow.
Why we built it
If you manage your financial life on your phone, it can feel like youâre carrying all your money around with you in your pocket and taking it everywhere you go.
And it doesnât help that phone theft has been rising, with one stolen every 6 minutes in London last year.
We challenged ourselves to tackle this problem, and see if we could give customers more protection when moving larger amounts of money.
How it works
If you choose to add extra security, weâll ask you to set up daily allowances for sending bank transfers and withdrawing money from an Instant Access Savings Pot.
If you want to move money over these allowances, weâll do an extra security check (on top of the usual biometric or PIN authentication and fraud checks we already use).
Three new security controls
To pass the extra security check, weâre introducing a trio of new controls. Choose at least two of these three security controls for an extra layer of protection on payments over your daily allowance.
Each one has different benefits, so you can pick the ones that suit you best.
Known locations â leave your savings at home
Choose a known location only you can send large sums from â it could be your home, or where you work.
Theyâre places where youâre comfortable moving large amounts of money that fraudsters are unlikely to have access to!
Trusted contacts â choose a trusted friend or family member to double check payments
Ask a close friend or family member with Monzo to double check any bank transfers and savings withdrawals over your daily allowance.
Youâll consent to them seeing some details about the action youâre taking. Then weâll ask them to confirm itâs really you and check that it looks safe - for example by calling or video calling you. As someone who knows you, theyâll be able to provide a safety check and flag if anything looks suspicious, for example if they know your phone has been stolen or that youâre not planning any large purchases.
If you choose to ask a trusted contact to review a bank transfer or savings withdrawals, we temporarily put the payment on hold until they complete their review. Once theyâve done that, weâll ask you to confirm the payment with biometrics or PIN as usual, as only you can actually approve a payment.
Secret QR codes â scan to confirm itâs you
Weâll email you a secret QR code to print out and keep somewhere safe, or store digitally on another device you donât carry around. So when you want to move money over your daily allowance, you scan the QR code to confirm itâs you.
Each secret QR code includes a high-security password that only works with your account. And it only works when you scan it in the Monzo app during an extra security check. It doesnât include any personal information or allow access to your account by itself.
Choose at least two controls
When we ask you to do an extra security check on a larger payment, you can pick from any of your chosen controls. You need to have at least two of the three set up so you have a backup.
If for some reason you canât use any of your chosen controls, you can still proceed with your payment by confirming your identity with a short selfie video. So youâll always be able to access your money.
And if you want to change your controls or allowances, youâll have to pass an extra security check. So if a fraudster does access your phone without your consent, they canât switch off your added security or add any new controls.
Designing a delightful, high-friction security experience
Our aim with these new controls is to create an experience thatâs both secure and simple â so we wanted to delve deeper into how we approached the design and product development process.
We had to think carefully about how to add a new layer of (optional) friction over our existing security measures, to help stop fraudsters and reassure customers. While still making sure people can make payments and move money in a way thatâs easy to use and convenient.
Across our work in Product Security, we take the same user-centred approach we do in other product teams. For us, this means prioritising our usersâ needs for security, speed and simplicity â and considering their unique requirements in a range of different contexts.
We have to give people options that adapt to their situation. Security needs can vary greatly depending on where a person is, what device theyâre using, and their immediate environment.
For instance, you might feel comfortable making a large transaction from the safety of your home. But when youâre out on the go or in an unfamiliar place, you might need different security measures.
If we donât want to slow people down when they need to access or move their money around, we have to adapt to their needs depending on their unique situations.
Security checks should be simple and quick. We prioritised a minimal visual design and a lightweight flow during security challenges to avoid overwhelming users with multiple steps or excessive work on their part.
Weâve optimised the process for a quick, forward-moving experience that lets people focus on their tasks without being bogged down by cumbersome security procedures.
However, this does mean we had to make the onboarding process a bit longer with a few more steps, so we can gather the preferences and information we need to provide the most simple and seamless of experiences afterwards!
Getting started
To get started with added security, update to the latest version of the Monzo app and then head to âPrivacy & Security" settings. You can get there by tapping on your profile at the top left of the Overview screen, then tapping on âSettingsâ. From there head to âPrivacy & Securityâ settings, tap on âAdded Securityâ and follow the prompts that will take you through the set-up flow.
Weâd love to hear any feedback or questions that you have, or thoughts on what youâd like to see next in this space!