A modern digital interface representing secure user authentication and sensitive data access monitoring.

Strong Customer Authentication and Compliance in Finland: The Evolution of Digital Identity

Providing security and seamless digital access to software environments is a top priority for modern enterprise organizations in the Nordic countries. Strong Customer Authentication (SCA) has historically been viewed as a complex technical hurdle. However, the deployment of unified frameworks has shifted the landscape completely.

This guide reviews the current state of customer authentication frameworks in Finland, including the Finnish Trust Network (FTN) and Mobiilivarmenne, and maps out how organizations can leverage these protocols to strengthen their security profiles and maintain rigorous compliance monitoring.

The Historical Friction of Strong Customer Authentication

Strong customer authentication has not always been seamless. For years, organizations and citizen-facing digital platforms struggled with archaic authentication architecture. Early government initiatives attempted to deploy strong, cryptography-based authentication methods embedded directly inside physical national ID cards.

The primary bottleneck was the user experience. The setup required physical card readers attached to desktop computers, a methodology completely misaligned with the rapid shift toward cloud environments and modern mobile devices. Even updated ID cards utilizing Near Field Communication (NFC) chips have failed to capture significant mainstream adoption for commercial digital transactions.

The Historical Friction of Strong Customer Authentication

To resolve the fragmentation of digital identity frameworks, the Finnish Transport and Communications Agency (Traficom) oversaw the implementation of the Finnish Trust Network (FTN).

The goal of the FTN was to replace a decentralized, inefficient scheme with a highly regulated identity broker model. Rather than forcing every digital service to conclude separate contracts with individual identity providers, the network introduced authorized authentication brokers. Today, the framework acts as a highly successful model for secure electronic identification across Europe, streamlining user onboarding while meeting stringent data security requirements.

Understanding the Transition From TUPAS to FTN

To understand the value of the modern framework, it is helpful to contrast it with the legacy Tupas system that preceded it. For nearly two decades, commercial banking institutions held an absolute monopoly over strong authentication methods in Finland. Because banks lacked real market competition in the identity space, several operational challenges emerged:

  • Prohibitive Transaction Pricing: Authentication costs were high and based entirely on transaction volume. For medium-sized organizations or growing SaaS platforms, the recurring authentication fees frequently outpaced the revenue generated by the digital service itself.

  • Outdated Security Tokens: Technical development stagnated. Many banks continued to rely on physical, paper-printed One-Time Password (OTP) lists long after modern multi-factor authentication (MFA) parameters became standard elsewhere.

  • Regulatory Interception: The arrival of the European Payment Services Directive (PSD2) forced a structural transformation. Regulatory pressure broke apart the banking monopoly, introducing cost caps on transaction expenses and standardizing protocols under open standards like OpenID Connect (OIDC).

The Role of Mobiilivarmenne in Modern Authentication

The primary alternative to traditional bank-issued electronic identities is Mobiilivarmenne (Mobile Certificate). Developed in collaboration between Finland’s major telecommunications operators (DNA, Elisa, and Telia), Mobiilivarmenne acts as a secure digital ID card directly linked to the user’s mobile subscription.

Technically, Mobiilivarmenne utilizes a Public Key Infrastructure (PKI) certificate securely embedded inside the physical SIM card or eSIM architecture of a mobile device. Authentication procedures are processed via the GSM signaling channel (the SIM Toolkit application layer) rather than the standard public internet.

Because the verification runs entirely at the SIM layer, it works reliably on both smartphones and basic mobile hardware. The service provider needs only the user’s phone number to initiate a secure multi-factor challenge, completely bypassing the need for separate integrations with individual telecommunication databases.

💡 Security & Compliance Note: Implementing strong front-end authentication like FTN or Mobiilivarmenne ensures that only authorized entities access your network. However, true corporate protection requires continuous visibility after the login event.

To achieve absolute audit trails and audit readiness, organizations must pair identity federation with robust log management. Discover how our expert allows technical teams to ingest authentication records, track system configurations, and deploy real-time alerts to mitigate security risks through a case study here.

Real-World Example: Fraud Detection with Splunk

Case Study CTA

See Splunk in action

Read the full case study to see how we utilized Splunk to deliver measurable impact.

Read the case study

The Strategic Balance: Government Guidelines vs. Free Market Implementations

Technical leaders often debate whether digital authentication infrastructure should be entirely built, owned, and operated by state IT agencies.

Real-world deployment patterns suggest otherwise. Governments are structurally slow to adapt to accelerating software frameworks, frequently rendering state-built tools deprecated before achieving mass adoption. The success of the FTN demonstrates that the optimal role of government regulation is to establish the compliance baselines, security rules, and architectural standards, while allowing the commercial market to develop efficient, user-friendly identification brokers.

Business Advantages: Transforming Authentication into a Security Asset

Integrating your enterprise applications with a regulated identity broker framework delivers immediate operational benefits:

  1. Mitigation of Unauthorized Access: By sourcing verified demographic data directly from verified identity registries, you completely remove the need to provision, manage, and secure internal password databases. This radically drops the risk of identity leaks and corporate fraud.

  2. Granular Sensitive Data Access Monitoring: In high-consequence sectors like finance, healthcare, and the public sector, tracking who logged in is legally mandatory. Identity federation passes rich, verified user attributes into your data layers, providing ironclad reference points for unauthorized access detection.

  3. Improved Conversion and Frictionless UX: Forcing users to remember complex, unique password strings routinely drives customers away. Utilizing familiar, trusted methods like bank logins or mobile certificates lowers onboarding friction and drives higher engagement.

Optimizing Recurring Authentication Expenses

While federated identity tokens significantly improve your risk posture, high-traffic applications can accumulate substantial transaction fees if an authentication event is triggered on every single page interaction.

The optimal architectural strategy is to leverage strong customer authentication periodically, such as during initial registration, password resets, or when accessing highly confidential sub-modules, while relying on secure session tokens and local basic authentication parameters for routine mid-session workflows.

Conclusion: Building a Defensible Digital Environment

Strong customer authentication is no longer a localized technical complication; it is the baseline for modern corporate risk management. However, verifying the identity of an incoming user is only the first step. To completely secure complex IT environments, identity verification must be paired with comprehensive system monitoring.

Whether you need to integrate advanced identity protocols into a custom application or optimize your security logging architectures to track data movement, we are here to support your engineering goals.

Ready to elevate your security monitoring infrastructure? Contact our expert technology team today to evaluate your current system visibility and logging frameworks.

About the Author

Kari Laalo is a highly skilled CIAM specialist with extensive engineering experience across budget-funded public sector agencies, national security infrastructures, and corporate financial services. Specializing in Identity & Access Management (IAM), Authentication and Authorization Infrastructures (AAI), and critical networking environments, Kari focuses on translating complex security principles into dependable digital outcomes.

Observability Playbook

WeAre’s Observability Playbook is a practical guide for IT, DevOps, platform, and business teams that want to understand how observability helps improve visibility, reduce downtime, and connect technical performance to business outcomes. It explains how logs, metrics, and traces work together, why observability matters in modern distributed environments, how mature observability practices companies have, and how organisations can move step by step from reactive troubleshooting toward faster incident response, shared visibility, and stronger operational trust.

About WeAre Solutions Oy

WeAre Solutions Oy is a Finnish observability-focused consultancy and a leading Splunk Elite Partner in the Nordics. We specialize in observability and monitoring (using Splunk), Atlassian services (Jira), and software development. Founded in 2016 and headquartered in Helsinki, our mission is to turn observability into a competitive advantage for organizations. We work with organizations that need more than just tooling. They need a partner who understands how to connect technical visibility with business value.

Our experience includes supporting regulated and business-critical environments, where reliability, clarity, and long-term maintainability matter. We combine consulting, implementation, optimization, and managed services into one seamless model, helping our customers move from fragmented visibility to stronger operational control with confidence.

At WeAre, we help organizations assess their Splunk environments, identify improvement opportunities, and align performance with real business needs. You can start with an observability assessment to understand your current state, or contact our team for a free consultation.

Facebook
Twitter
LinkedIn