
Project overview
Making card PIN management secure, self-serve, and available anytime.
I led the end-to-end design of a new mobile experience that allows customers to securely view or change their debit and credit card PIN directly within the banking app, eliminating the need to visit a branch or wait for a replacement PIN by mail.
Goals: Instead of visiting a branch or waiting for a mailed PIN, customers can securely view or change their card PIN in minutes from their mobile device.
Platform: Native mobile app (iOS and Android)
Background
Customers increasingly expect routine banking tasks to be completed from their phones. While most card management features had become digital, managing a card PIN still relied on offline channels.
Customers who forgot their PIN or simply wanted to change it, had only two options:
Visit a physical branch
Call customer support
Even after contacting customer support, a replacement PIN had to be mailed, often taking 1–2 weeks before the customer could use their card again.
This created unnecessary friction for customers and felt inconsistent with the rest of the mobile banking app.

Problem statement
Customer Pain Points
Research and customer support calls uncovered several recurring frustrations:
Forgotten PINs prevented customers from completing purchases.
Branch visits were inconvenient and often impossible outside business hours.
Waiting for mailed PINs delayed access to funds.
Business Problem
The existing experience created operational costs beyond customer frustration.
High contact centre volume
Branch operational effortU
Slow issue resolution
Poor digital self-service adoption
The bank also wanted to continue shifting routine banking tasks into digital channels while maintaining strong security standards.
User research and insights
Understanding existing behaviours
To understand where customers struggled, I reviewed:
Customer support calls
Interviews from branch advisors and tellers
Authentication requirements
Risk and fraud policies
Analytics around card management usage
Internal stakeholder feedback
Key insights
Customers expected immediate resolution
Forgetting a PIN often happened at checkout, making long recovery times particularly frustrating.
Security was expected
Customers didn't object to additional verification when accessing sensitive information; they expected it.
Mobile had become the primary banking channel
Routine banking activities were already completed on mobile, making PIN management feel like an obvious gap.
Design Challenge
How might we allow customers to securely view and change their card PIN within the mobile app while maintaining the same level of trust as existing branch and contact centre processes?
Exploration
Exploring how to display PIN
Balancing security education with usability

Security awareness and content exploration
Exploring ways to educate customers about fraud prevention while keeping the experience concise, relevant, and easy to understand without adding unnecessary cognitive load.

When should customers complete step-up verification?
Security vs. Friction?

Final Experience
The final experience required additional identity verification immediately before revealing or changing a PIN.
This balanced convenience and security.
Final Experience — View PIN

Final Experience — Change PIN

Security design decisions

Edge Cases
Reflections
This project taught me that designing secure experiences isn't about introducing more friction, it's about introducing the right friction at the moment it matters. Collaborating closely with Risk, Fraud, and Engineering helped us create an experience that felt simple for customers while meeting the bank's security requirements.





