Written by: Kamil Ponicki, Director of Talent Acquisition, Digital Colliers
Three seconds of audio. That's the going rate for a usable voice clone in 2025. Meanwhile, most call centres still ask for a date of birth, a postcode, and maybe the last four of a card. If you work in fraud or ops at a mid-market bank, you already know this maths doesn't work. The knowledge-based question is a shared secret that isn't secret anymore, delivered over a channel where the caller's voice is no longer proof of anything.
This piece is about what replaces it. Not the vendor pitch version. The version you can actually build against a call centre that still runs on an on-prem switch and a core you're not about to rip out.
Why voice biometrics alone won't save you
The first instinct is to bolt voice biometrics onto the IVR and call it a day. It helps. It's not enough.
Modern generative voice models defeat single-factor voiceprint checks under the right conditions, especially passive ones that score a few seconds of speech. Liveness challenges push the bar up, but attackers now run real-time synthesis with prompt-driven responses. Treating a voice match as sufficient auth is the 2025 equivalent of treating an SMS OTP as strong. It's a signal, not a verdict.
The deeper issue is that voice, like SMS, is one channel. Any single-channel auth model can be attacked on that channel. What you actually want is a set of independent signals that an attacker has to defeat simultaneously.
The joined signal model
The pattern working banks are moving toward has three signal families running in parallel, scored together, before the agent ever asks a security question.
Telephony signals. ANI validation, carrier metadata, SIP header analysis, spoofing detection, and repeat-caller behaviour across your estate. A call from a number that's dialled twelve institutions this week is not the same call as one from a number tied to the account for six years.
Device and channel signals. If the customer also has the mobile app installed, is the app open on a device you recognise, in a plausible location, at the same time as the call? A silent push-based possession check on the enrolled device turns a phone call into a two-channel event without asking the customer anything.
Behaviour and transaction context. What did this customer do in the last 72 hours? Password reset, new payee added, unusual login geography, a pattern that looks like social engineering in flight. The call itself is the last step of a longer story. Score the story, not just the call.
Voice biometrics sits inside this as one more input, weighted appropriately. So does the KBA question, if you keep it at all. Nothing is load-bearing on its own.
What you can actually ship without touching the core
Most of this lives at the edge, not in the core banking system. That's the good news for mid-market operators who can't schedule a switch replacement.
A decisioning layer that sits between the IVR, the CRM, and the agent desktop, consuming events from each and returning a risk score plus a recommended step-up.
Telephony metadata via your SIP trunk provider or a specialist API. This is often a config change and a contract, not a build.
Device possession signals via your existing mobile app SDK. If you already do push notifications, you already have most of what you need.
A feedback loop from confirmed fraud cases back into the scoring model. Without this, the model rots inside a year.
One warning on the model side. Around 95% of enterprise AI projects don't reach production or return. The failure mode is almost always the same: a model built in isolation from the operational reality it's supposed to serve. Build the decisioning against real agent workflow, real hold-time budgets, and real false-positive tolerance, or it dies in pilot.
The left-behind risk is regulatory, not just operational
Fraud losses are the visible cost. The quieter one is regulatory posture. DORA has been in force across the EU since 17 January 2025, and it treats ICT-related fraud resilience as a board-level operational risk topic. GDPR fines already reach up to €20M or 4% of global turnover for handling failures, and automated decisioning carries additional exposure after the SCHUFA ruling in December 2023. From 2 August 2026, EU AI Act transparency obligations begin to bite on systems that interact with customers, including voice.
If your call centre auth model in 2027 still rests on a postcode and a voice sample, you won't just be losing money to fraud. You'll be explaining to a regulator why you didn't move when the evidence was already public.
Sources
This article was originally published on the Digital Colliers Blog. Digital Colliers helps DACH and UK companies implement AI — see our AI consulting services or contact us.
Top comments (0)