The bank was facing:
The compliance team had specifically flagged the visual similarity between promotional push notifications and genuine security alerts as a real risk -- not just a marketing effectiveness problem, but a customer trust and potential fraud-vector concern that needed to be addressed structurally, not just through better copywriting. Marketing and product teams had historically operated with separate messaging priorities and no shared review process, meaning promotional campaigns could ship without anyone systematically checking them against the security-alert visual standard.
We designed and implemented a disciplined, channel-differentiated Braze messaging program, built specifically around the security-versus-marketing distinction the compliance team had identified as a genuine risk:
The compliance team was involved throughout this engagement, not just at final review -- the visual distinction between security and promotional content was designed collaboratively with their input from the start, ensuring the solution addressed their actual concern rather than a marketing team's interpretation of it. This collaboration also shaped the frequency capping policy, since compliance specifically wanted assurance that security-relevant communication would never be suppressed or delayed by a promotional frequency cap, which is why that exemption was built in explicitly rather than left to a shared, undifferentiated cap.
Getting the personalization work right required deeper access to account context than the marketing team had previously worked with, which meant coordinating closely with the data and security teams on exactly what account information could appropriately inform messaging content, and through what approved data pathway. This wasn't a purely technical integration question -- it involved genuine conversations about what customers would find helpfully relevant versus uncomfortably invasive, given the sensitivity of financial account data specifically. The team ultimately settled on using aggregate spending pattern categories and product usage signals, deliberately avoiding anything that referenced specific transaction details in message content, balancing personalization value against genuine privacy comfort.
Within four months of implementation, with the new review process embedded and both the security-alert and promotional treatments fully rolled out across the entire customer base:
The core design principle underlying this engagement was that customers needed to be able to recognize a genuine security alert instantly, without needing to read the content carefully to determine whether it was legitimate. This meant the visual treatment -- format, color, urgency framing -- for security alerts needed to be completely consistent and completely distinct from anything used for promotional content, with zero exceptions. Even a single promotional campaign accidentally using a similar visual treatment would have undermined the entire trust-building premise. This discipline required genuine coordination between marketing and compliance teams who hadn't previously had a structured process for reviewing campaign formats against this specific risk, and establishing that review step was itself a meaningful organizational outcome of the engagement, independent of the messaging metrics themselves.
It might seem counterintuitive that reducing overall message frequency improved promotional engagement rates, but this reflects a pattern seen across financial services messaging specifically: banking customers are generally more sensitive to message frequency than typical e-commerce or media audiences, given the genuinely higher stakes associated with anything appearing to come from their bank. By capping frequency and ensuring every promotional message that did get sent was genuinely relevant and well-personalized, the bank's customers began engaging with a smaller volume of higher-quality messages rather than tuning out a larger volume of generic ones. This validated the frequency capping investment not just as a customer experience improvement, but as a genuine driver of better marketing performance in its own right.
Perhaps the most durable outcome of this engagement wasn't any single campaign or message format, but the review process established between marketing and compliance for evaluating new campaigns against the security-versus-promotional visual standard before launch. Prior to this engagement, no such structured review existed -- campaigns shipped based on marketing team judgment alone, with compliance typically only becoming aware of a campaign after it was already live, if at all. Establishing a lightweight but genuinely enforced pre-launch review checkpoint meant this specific risk category couldn't quietly re-emerge as new campaigns launched after the initial engagement ended. A year later, this review step remained a standard part of the bank's campaign launch process, confirming it had genuinely become institutional practice rather than a one-time consulting recommendation that faded once direct oversight ended.
Roughly two months into the engagement, before the new review process was fully embedded, a promotional campaign was drafted using a layout closer to the security-alert treatment than the new standard allowed -- an honest oversight from a team member not yet fully versed in the new distinction. Because the review checkpoint was already in place by that point, the campaign was caught and revised before launch rather than reaching customers. This incident, while minor and successfully caught, became a genuinely useful case study internally for why the review step mattered -- reinforcing buy-in from marketing team members who had initially viewed the additional review step as a bureaucratic slowdown rather than a genuine safeguard.
Most messaging engagements measure success primarily through engagement and conversion metrics, but this project specifically tracked a less common metric: unprompted customer feedback mentioning trust or confidence in the app's communications, gathered through the bank's existing customer feedback channels and support ticket tagging. Before the engagement, a meaningful share of support interactions included some variation of "I wasn't sure if that notification was really from you" -- a genuine trust signal that standard engagement metrics wouldn't have captured directly. Tracking this specific feedback category, rather than relying solely on click-through and opt-in rates, gave the bank's leadership a more complete picture of whether the underlying trust problem the compliance team had originally flagged was actually being resolved, not just whether messaging performance numbers were improving.
The broader lesson the bank's leadership took from this engagement was that disciplined messaging architecture and genuine marketing performance aren't in tension with each other in a regulated environment -- they're mutually reinforcing when designed together deliberately from the start, rather than treated as competing priorities to be traded off against one another after the fact.
Our team of experts is here to help you achieve measurable, lasting results.