Nowadays, fintech becomes the key technology of the mobile banking and payments. Financial market is
moved to fintech-based non-face-to-face trade/payment from traditional face-to-face process in Korea. Core
of this transition is the smartphones, which have several sensitive sensors for personal identifications such
as fingerprint and iris recognition sensors. But it has some originated security risks by data path attacks,
for instance, hacking and pharming. Multi-level certification and security systems are applied to avoid these
threats effectively, while these protections can be cause of some inconvenience for non-face-to-face
certifications and financing processes. In this paper, I confirmed that it have sensible differences correspond
with the data connection paths such as WiFi networks and mobile communication networks of the smartphones, and I propose a gradual certification method which alleviates the inconvenience by risk-level
definitions of the data-paths.