top of page
Search

What happens to banks when your face becomes your wallet?

A few weeks ago, Eftpos New Zealand announced the rollout of its new Verifone Victa payment terminals. On the surface, it sounds like a fairly standard technology upgrade. New terminals, better screens, Android-based technology and more capability for retailers.


Then I got to the part about biometrics.


The new terminals have been designed to support facial and palm recognition, opening up the possibility that one day we could walk into a New Zealand shop and pay without getting out a card, phone or watch. We aren't there yet. Eftpos NZ has been clear that while the hardware is capable of supporting biometric payments, the infrastructure required to make them work isn't currently available in New Zealand.


I actually find that more interesting than if they had simply announced that facial payments were launching next month, because it means we're starting to put the physical infrastructure for a different kind of payment experience into our shops before the rest of the ecosystem has caught up.


And it got me thinking about what this means for banks.


We've been slowly making the card disappear for years


I can remember when paying for something meant handing over a card, waiting for it to be swiped and signing a piece of paper. Then came chip and PIN, followed by contactless payments and digital wallets. Now I can pay with my phone or watch without thinking much about the card sitting underneath the transaction.


Online, the same thing is happening. Card numbers are increasingly being replaced by tokenised credentials, while passkeys and biometrics are beginning to replace passwords and SMS codes as ways of proving that the person making the payment is really you.


None of this has killed the card. What it has done is make the card increasingly invisible.


That's an important distinction when thinking about biometric payments.


When I use Face ID before making a payment on my phone today, my face isn't actually paying for anything. My face helps my phone establish that I'm me, and my phone then allows a token representing my card to be used.


A biometric payment terminal could remove the phone from that interaction. I could simply present myself at the checkout, have my identity authenticated and have a payment credential associated with me used to complete the transaction.


Somewhere underneath that experience there could still be a Visa or Mastercard credential and a bank account. I just wouldn't need to know about it.


That creates an interesting question for banks. If customers stop interacting with cards, even though card infrastructure continues to operate underneath their payments, are banks really in the card business anymore? Or are they increasingly in the business of managing trusted payment credentials?


Perhaps the banking app becomes the place where I manage my authority to pay


This idea isn't actually new to New Zealand. Back in 2019, Paymark, which is now Worldline New Zealand, was already exploring what facial recognition payments might look like here.


What caught my attention when I went back and read that work was the role it imagined for the banking app. Customers could potentially decide which merchants they trusted, set transaction limits and manage their biometric payment permissions through their bank.


Seven years later, that idea feels even more relevant.


I can imagine opening my banking app in the future and seeing all the different ways I've given permission for my money to be used. My Apple or Google wallet might be there alongside Click to Pay, merchants holding payment credentials for subscriptions, biometric payment services and, increasingly, AI agents I've authorised to transact on my behalf.


Rather than simply showing me my debit and credit cards, my bank could show me where my payment credentials exist, what they can do and how they can be used. I could change limits, remove access or decide that I no longer want my face associated with payments at a particular retailer.


That feels like a natural evolution of something banks have always done: helping customers control access to their money. The difference is that the mechanisms for accessing that money are becoming much more diverse.


There is another possibility, though, and this is where things get really interesting


So far I've assumed there is still a card sitting underneath the biometric transaction.


There probably will be initially. Facial or palm recognition could simply authenticate the customer, retrieve a tokenised card credential and send the transaction through the existing Visa or Mastercard network. From the customer's perspective it would feel radically different, while underneath it could still look remarkably similar to a card payment today.


But it doesn't have to stay that way.


At the same time as biometric technology is developing, New Zealand is introducing regulated open banking, including payment initiation. That creates the ability for authorised providers to initiate payments directly from a customer's bank account with their consent.


Put those two developments together and another possible future appears.


I walk into a shop, my identity is authenticated, I approve the purchase and the money moves directly from my bank account to the merchant using an account-to-account payment service.


From my perspective, the experience might feel exactly the same whether a Visa token or an account-to-account payment sits underneath it. I look at the terminal, approve $93 and leave with my groceries.


I probably don't care which payment rail moved the money. The merchant and the organisations involved in moving it almost certainly do.


That's where this becomes much more than a conversation about facial recognition.


If different payment rails can eventually provide an equally frictionless experience at checkout, merchants may have more choice about how they receive payments. Banks, card schemes, payment providers and fintechs may find themselves competing in ways customers barely see.


The battle for the future of payments could increasingly happen underneath the experience rather than at the checkout.


Biometrics don't make fraud disappear


My first instinct when thinking about biometric payments was that they should be incredibly effective against fraud. A stolen card can be used by someone else; my face can't simply be handed to another person.


That's true, but only up to a point.


If it becomes harder to impersonate me during the transaction itself, criminals have an incentive to attack another part of the journey. The really valuable moment could become enrolment: the point at which an identity, biometric and payment credential are linked together.


Account takeover becomes more valuable. So does social engineering. Fraudsters may target account recovery or fallback processes when biometric authentication fails. AI-generated identities and deepfakes make strong identity verification even more important.


The question for a bank therefore becomes broader than whether a biometric match was successful. It needs confidence that the person was correctly identified in the first place, that the biometric was legitimately enrolled, that the payment credential belongs to them and that the transaction itself makes sense.


In some ways, making the checkout more secure simply pushes the difficult security work further upstream.


Then we have to talk about trust


There's something psychologically quite different about unlocking my own phone with my face and standing in front of a camera belonging to a retailer.


My phone feels personal. A checkout terminal doesn't.


That distinction matters, particularly now that New Zealand's Biometric Processing Privacy Code is in force. Biometric information deserves a high level of protection because, unlike a password, it isn't something we can simply reset when it is compromised.


For banks, merchants and payment providers, the challenge shouldn't be working out how much biometric information they can collect. It should be working out how little they actually need.


Ideally, many organisations involved in a payment would only need to know that a trusted biometric authentication had successfully occurred. They wouldn't necessarily need to possess the biometric information that made that authentication possible.


Customers also need genuine choice. Paying with your face shouldn't quietly become the easiest experience while people who don't want to provide biometric information are left navigating a slower or inferior alternative.


Technology can make biometric payments possible. Trust will determine whether people actually use them.


There's also the question of whether tapping my phone really needs fixing


This is something I keep coming back to.


Contactless payment is already incredibly convenient. Taking my phone out of my pocket and tapping it against a terminal isn't a particularly painful problem.


If the proposition for biometric payments is simply that I can save a couple of seconds by giving another organisation access to something as sensitive as my biometric identity, I'm not convinced that's enough.


Where it becomes more compelling is when several pieces of friction disappear at once.


Perhaps the checkout recognises my loyalty membership, verifies my age where necessary, knows my preferred payment method, authenticates me and completes the transaction as one consented experience. In places where people transact frequently or queues matter, that starts to create meaningful value.


It also explains why the future of biometric payments probably won't be decided by the technology alone. It will be decided by whether customers feel they're getting something genuinely useful in return.


So, are cards going away?

Yes, but not anytime soon.


Cards are remarkably successful pieces of payment infrastructure and the networks behind them solve much more than the moment when we tap a terminal.


But I do think we're heading towards a world where customers interact with the card less and less.


What fascinates me about the Eftpos NZ announcement is that it isn't happening in isolation. We're seeing tokenisation reduce our reliance on card numbers, passkeys change how we authenticate ourselves, open banking create new ways to move money, digital identity mature, and AI agents begin to raise entirely new questions about who or what can transact on our behalf.


Now biometric-capable hardware is arriving at the checkout.


When I look at all of those developments together, I wonder whether the future banking experience will be less about managing individual cards and more about managing our authority to pay.


I want to know which devices, merchants, services and AI agents can access my money. I want to know how they are allowed to authenticate me, which account they can use, how much they can spend and when their permission expires. Most importantly, I want to be able to change my mind and remove that access easily.


Banks already sit in an unusually trusted position between our identity and our money. There is an opportunity to make that position even more valuable as payments become increasingly invisible.


So while “pay with your face” makes a great headline, I don't think facial recognition is actually the most interesting part of the Eftpos NZ announcement.

For me, it's the glimpse of what comes afterwards.


If I no longer need to present a card, a phone or perhaps eventually even choose the payment rail, then the thing I present at the checkout is simply myself.


And that could change far more than the way we pay.

 
 
 

Comments


bottom of page