Industry

Banking

Company

Millennium BCP

Date

oct 2025

Designing a financial control feature for Portugal's largest private bank

Case Study:
Limit Management

When EU regulation required banks to give customers control over their transfer limits, Millennium BCP had a problem: transfer limits were invisible to users, and 13,000+ customers a year were hitting silent blocks with no explanation.


As the Product Designer on this feature, I led the UX across the full journey, from scope definition and usability testing to high-fidelity prototypes and hand-off in 6 months.

Post-launch, 79% of users completed a transfer within 24 hours of adjusting their limit.

Where did this project come from?

  1. Regulatory Trigger

    EU Regulation 2024/886 mandated that all banks enable
    customers to set maximum limits for national and international instant transfers, per day and per transaction, across all channels (effective October 9, 2025).


  2. Security Gap
    Millennium had limit management only for cards.
    For transfers, limits were invisible - users had no way to see, understand, or control them.

  3. Technical Limits

    Two hard technical limits existed silently: transfers above 12,500€ triggered a mandatory validation call, and transfers above 50,000€ were blocked entirely.

Problems to solve

How might we give Millennium customers personalised control over their
transfer limits, satisfying EU regulation, reducing fraud exposure, and building financial confidence?

Desk Research

There were already 2 flows with limit related components:

  • Credit cards limit change

  • Create MB Net cards


These flows already contained a limit input component, giving us a reference point for interaction patterns our users were already familiar with inside the app.


💡 MB Net cards are temporary virtual cards created by the user for online purchases.

Benchmark key findings

  1. Security framing matters

    Revolut's Wealth Protection is the strongest example in the market - biometric gates, street mode, trusted merchants.


  2. Day + per-transfer is the expected model
    Nubank and Itaú both use dual limit models. Nubank goes further with a day/night split (a reflection of a Brazilian market that consistently leads in financial security). Relevant for our future security hub, but out of scope for Phase 1.

  3. Education reduces friction and support calls

    Itaú's inline FAQs reduce confusion about the 24h delay on increases.


With benchmark insights in hand I worked with the PM and team to map the AS IS state, align on what was technically and legally required for the MVP, and define what we would leave for Phase 2:

Must have (MVP):

Manage instant transfer limits ·
choose per-day or per-transaction · map overlimit cases


Nice to have:

Suggested values · inline FAQs


Phase 2:

Card limits · withdrawal limits · MBWay limits · Security Hub

High Fidelity Prototype

With everything defined and the data we had, we wanted to find out early whether users would actually understand what we were proposing.

So we moved straight to prototyping and took it directly to a usability test.


🎨 Since we have an established Design System, we skipped low-fidelity wireframes and went directly to medium / high fidelity.

Tests results

The test was planned and facilitated by a UX Researcher.

As the designer, I was present as an observer.

Suggestions

  1. Copy review

    Revise copy on several screens - particularly around the per-transfer limit and the authentication steps, where users showed confusion.


  2. Double authentication
    Reconsider whether double authentication makes sense in the current flow model. If kept, differentiate the credential types visually to set user expectations.

  3. Switch component

    Review the per-day vs. per-transfer toggle - both the component type (switch vs. segmented selector) and the input label on the define-limit screen.


📝 I also had access to the ux research notes, observations that helped iteration decisions.

Next phases

We're currently exploring how the main screen will evolve as more limit types are added: withdrawals, payments, and online purchases.

The architecture was designed from the start to be scalable, so adding new limit types doesn't require rebuilding the screen, just extending it.

Security hub

Limit management was our MVP for a bigger vision: bringing all security features currently across the app into one single, cohesive hub.

In October 2025, I facilitated a workshop with the security and design teams across these touchpoints. The session covered context and benchmark, stakeholder mapping, pain points and gaps, How Might We reframing, an impact vs. effort prioritisation matrix, and first ideation.

The output was a understanding of what the hub needs to solve and a prioritised list of opportunities to take forward.

This is still in early exploration and wireframing phase.

Metrics after launch:
the first 6 weeks of data

Continue monitoring...

  • Fraud & Security impact
    Compare fraud incident volume in the 6 months before and after launch. Fewer fraud incidents means fewer reimbursements and less operational cost for the bank.

    Hypothesis: users with active limits have fewer fraud incidents.


  • Call centre impact

    Track calls related to transfer blocks and limit questions before and after launch. If users can understand, set, and manage their own limits in the app, they don't need to call - costs reduced.

    Hypothesis: fewer calls about 'why was my transfer blocked'.



    📈 Why these metrics matter for the security hub?
    If we can show that limit management reduced fraud, cut call centre costs, and migrated branch transactions to digital, that's the business case for construct the full security hub. The data we collect now is the foundation for that feature.


🖤

Create a free website with Framer, the website builder loved by startups, designers and agencies.