A user goes to send $2,000 to their landlord. They pick the wrong saved payee, a contractor with a similar name, tap through the confirm screen on autopilot, and the money is gone. Not “pending.” Gone. The support ticket lands an hour later, and now your team is negotiating with a stranger to send it back.
This is the part of fintech that never shows up in the demo. The happy path looks clean. The problem is that money moves in one direction and does not politely return, and a huge share of fintech UX work is about the handful of screens where a single tap has consequences nobody can take back. Get those right and users trust you with bigger balances. Get them wrong and one bad transfer teaches them to be afraid of your product.
Why fintech breaks the “just add a confirm dialog” habit
Most software treats destructive actions as an edge case. Fintech makes them the main event. Sending money, executing a trade, closing an account, moving funds between rails: these are the reasons the product exists, and most of them cannot be cleanly undone.
The reflex is to drop a confirmation dialog in front of each one and call it safe. It isn’t. People send money often, they get used to the confirm step, and they start tapping through it without reading. Nielsen Norman Group made this exact point looking at the Hawaii false missile alert: when every action has the same confirmation screen, the screen stops registering. It becomes a speed bump people learn to roll over. A confirm dialog that everyone ignores is not error prevention, it’s the appearance of it.
So the real work splits three ways. Stop the wrong action before it starts. Make the confirmation carry real weight when the stakes are high. And build a recovery window even for things you were told are final.
Stop the slip before it starts
Most costly transfers are not reckless decisions. They’re slips: the user meant to do something reasonable and tapped the wrong thing while half paying attention. NN/g’s write-up on unconscious slips is blunt about where the blame sits. If the interface made the error easy, that’s a design problem, not a user problem.
In money movement, a few things prevent the slip cheaply. Show the payee’s full identity at the moment of action, not just a name: last four digits, a photo or logo, the last time they were paid. “Wrong name that looks right” is the single most common expensive slip, and a bit of surrounding detail kills most of it. Keep dangerous and routine actions visually and physically apart, so “Send to new recipient” never sits one pixel away from “Send to your usual account.” And use the amount itself as a signal. A $20 coffee split and a $20,000 wire should not feel like the same interaction.
Make the confirmation mean something
When an action really is irreversible and large, the confirm step has to break the user’s autopilot on purpose. The goal is not more friction everywhere. It’s sharp friction exactly where the stakes justify it, which is the same idea behind the reversibility-and-blast-radius thinking we laid out for human oversight of AI agents.
Practical ways to make a confirmation land:
Restate the specifics, not a generic warning. “Send $20,000 to Acme LLC, account ending 4417. This can’t be undone.” A user can catch a wrong number in a sentence like that. “Are you sure?” gives them nothing to check.
Raise the effort to match the stakes. For a first-time large transfer, ask the person to type the amount or the last digits of the account, or re-authenticate. NN/g notes that banks use this deliberately, not for security but to signal that this action is different from the hundred routine ones before it.
Show the point of no return plainly. Tell people, in plain words, what is reversible and what is not. “You can cancel this until 5pm today” is a completely different promise than “This sends immediately,” and users deserve to know which one they’re looking at before they commit.
Design the undo you were told you can’t have
Teams say money movement can’t be undone, then design as if that closes the conversation. Often it doesn’t. You can engineer a recovery window even when the final settlement is irreversible.
A short cancellation delay is the strongest tool you have. Hold outgoing transfers for a few seconds or minutes with a visible “Cancel” affordance, the way email clients added “Undo send.” Most people who catch a mistake catch it within seconds, and that tiny buffer turns a support crisis into a non-event. For higher-risk actions, a pending state with a scheduled execution gives an even longer safety net. And when something truly cannot be reversed by the system, plan the human recovery path in advance: a clear reclaim flow, a prewritten path for support, a way to flag the transaction fast. The Hawaii case failed at exactly this point, because nobody had built the “never mind” message before they needed it.
A real example: turning an AI stock pick into a trade
We hit this head-on designing Buzz Bunny, an AI app we built for a client that surfaces smart stock recommendations. The risky moment there isn’t the recommendation. It’s when someone acts on it. The AI suggests a position, the user taps, and now real money is exposed to a market that no undo button controls.
The tempting design drops a “Buy” button straight onto the recommendation card. It looks frictionless and it quietly merges two very different decisions, reading a suggestion and committing capital, into a single thumb movement. The principle we designed around was to pull those apart. Looking at a pick and acting on it are separate steps, and the acting step spells out what’s about to happen in plain numbers: the ticker, the amount, the fact that it executes at market and can’t be walked back. The recommendation stays fast to browse. The trade asks for one deliberate beat more. That’s the whole idea of this article, applied to a product where the irreversible action is the entire point.
A quick way to decide how much friction
You can’t wrap every action in ceremony, so sort them along two lines: how reversible the action is, and how much is at stake in money or accounts touched. That gives you a simple map.
- Reversible, small (move money between your own accounts): let it fly, offer a quiet undo.
- Reversible, large (scheduled payment you can still cancel): confirm with specifics, show the cancel window clearly.
- Irreversible, small (a few dollars to a known contact): one clean confirm is plenty.
- Irreversible, large (a wire to a brand-new payee): full stop. Restated details, raised effort, a hold window, and an obvious recovery path.
Almost every painful money-movement story lives in that last box while the interface treated it like the first. Naming the quadrant honestly is most of the fix.
What to measure
Two numbers tell you whether this is working. Reversal and dispute rate: how often users try to claw back or contest a transfer they already sent. If it’s climbing, your prevention and confirmation steps are not doing their job. And confirmation abandon rate on high-value actions: how often people stop at the final step and back out. A low number sounds great, but if it’s basically zero on large transfers, users are almost certainly rubber-stamping, and you’ve built a confirmation nobody reads. You want people to pause on the big ones. That pause is the feature.
Money movement is where a fintech product earns trust or quietly loses it. Users forgive a clunky dashboard. They do not forgive losing $2,000 because a screen let them tap through a mistake. Designing for the actions people can’t take back is not a polish task you get to later. It’s the core of whether they’ll move real money through you at all.
If you’re building a fintech product and the money-movement flows are getting more complex than the “add a confirm dialog” approach can carry, and you’re weighing whether to solve it in-house or bring in a partner who has shipped this kind of high-stakes product UX in Fintech and Cloud, talk to delbueno™ Studio. It costs less to design the irreversible moments well than to run damage control after one goes wrong.





