A fraudster calls your card services line with a stolen card. Your agent asks for the last four digits of the Social Security number and the card's expiration date. The caller provides both correctly, and the card is unlocked.
This scenario isn't hypothetical. FiCare Federal Credit Union claims fraudsters reactivated stolen cards at least 18 times in August by calling Fiserv's call center and answering knowledge-based questions. The Federal Financial Institutions Examination Council warned against this vulnerability in 2021, stating that reliable authentication "generally does not depend solely on knowledge-based questions."
If your call center still relies on information printed on the card or data readily available on the dark web, you're authenticating the card, not the cardholder.
Purpose of This Script
This template offers a structured authentication script for call center agents handling card unlock requests, fraud disputes, and account access restoration. It replaces knowledge-based questions with multifactor authentication steps that verify the caller controls a device or channel your institution already has on file.
Use this when:
- A cardholder calls to lift a fraud block
- Someone requests a PIN reset or credential change
- A caller disputes a transaction or reports unauthorized activity
- Any high-risk account change originates through your call center
Prerequisites
Before deploying this script, confirm you have:
Technical infrastructure:
- SMS or email delivery system capable of generating one-time passcodes
- Call-back capability to phone numbers stored in your core system
- Agent access to view (but not share) the last device or channel used for authentication
- Logging that captures which authentication method succeeded
Policy foundation:
- Written policy stating knowledge-based questions alone are insufficient for high-risk actions
- Vendor contract language requiring your processor's call center to follow your authentication standards (if you outsource card services)
- Incident response plan for when authentication fails repeatedly
Staff readiness:
- Agents trained to recognize social engineering tactics
- Supervisor escalation path for callers who can't complete multifactor authentication
- Documentation protocol for failed authentication attempts
The Authentication Script
Opening: "Thank you for calling [Institution Name] Card Services. To protect your account, I'll need to verify your identity using a secure method. This will take about two minutes."
Step 1: Confirm the request type "What can I help you with today?"
[Listen for: unlock card, dispute transaction, reset PIN, change address]
Step 2: Verify basic account ownership "I'll need your full name as it appears on the card and the last four digits of the card number."
[Agent confirms these match the account on screen. Do NOT ask for full card number, expiration date, or CVV.]
Step 3: Initiate multifactor authentication "For security, I'm going to send a one-time code to the [phone/email] we have on file for you. Can you confirm you have access to [read last two digits of phone number OR domain of email]?"
If caller confirms access: "I'm sending the code now. It will arrive within 60 seconds and expire in 10 minutes. Please read me the six-digit code when you receive it."
[Agent generates and sends code. Logs the attempt.]
If code matches: "Thank you. I've verified your identity. Now let me help you with [original request]."
If code doesn't match or caller can't receive it: "I'm unable to verify your identity through our automated system. For your security, I'll need to transfer you to a specialist who can verify you through an alternative method. Please hold."
[Transfer to supervisor or fraud team. Log the failed attempt and flag the account.]
Step 4: Complete the request and document After resolving the request, agent logs:
- Authentication method used (SMS code, email code, callback)
- Whether authentication succeeded on first attempt
- Any red flags (caller hesitation, background noise suggesting call center, requests to skip verification)
Customizing the Script
Choose your authentication methods based on your infrastructure:
If you have SMS capability: Replace bracketed text with: "text message ending in [XX]"
If you use email one-time passcodes: Replace with: "email address ending in @[domain]"
If you use callback verification: "I'm going to end this call and call you back at the number we have on file within two minutes. Please answer when you see our caller ID and provide the reference number I'm about to give you: [generate random 6-digit number]."
Adjust for your risk tolerance:
Higher security institutions should:
- Require callback for any unlock request over $X transaction amount
- Add a mandatory 24-hour waiting period for credential resets
- Require in-person verification for address changes
Lower-friction environments might:
- Allow one retry if the first code doesn't arrive
- Permit email codes for lower-risk requests, SMS for higher-risk
Vendor-specific customization:
If Fiserv or another processor runs your call center:
- Add this script to your vendor management agreement as Exhibit A
- Require monthly reporting on authentication method usage and failure rates
- Specify that agents may NOT bypass multifactor authentication even if the caller provides correct answers to knowledge-based questions
- Include contractual language making the vendor liable for losses from authentication failures
Validation Steps
Test the script before rollout:
Conduct tabletop exercises where managers pose as fraudsters with stolen card data. Agents should fail to authenticate them.
Measure baseline metrics for one month:
- Average handle time for unlock requests
- Authentication success rate
- Escalation rate to supervisors
- Customer complaints about verification friction
Deploy to a pilot group of agents for two weeks. Compare their metrics to baseline.
Review call recordings weekly during the first month. Listen for:
- Agents skipping steps under caller pressure
- Callers who hang up when multifactor authentication is mentioned
- Successful social engineering attempts
Monitor ongoing effectiveness:
- Flag accounts where authentication fails three times in 24 hours
- Track whether fraud losses decrease in the 90 days after deployment
- Survey cardholders who successfully completed authentication: did they find it reasonable?
Audit your vendor if you outsource:
Request call recordings monthly. Verify agents follow your script, not a knowledge-based question flow. FiCare's motion alleges that five other credit unions reported similar authentication problems to Fiserv. Your contract should require the vendor to disclose when other clients report security incidents.
If your processor can't or won't implement multifactor authentication in their call center, the FFIEC's 2021 guidance makes clear: you're still responsible. Consider bringing the function in-house or moving to a vendor that meets the standard.
The cost of deploying this script is a few extra seconds per call. The cost of not deploying it showed up 18 times for FiCare in a single month.





