Skip to content
← All work
One of the UK's biggest insurersNDA-safe

How do you get people into a regulated account with the least friction and the most trust?

Registration, login and passwordless one-time links for the MyAccount experience of one of the UK's biggest insurers, plus the redesign work I took the journeys through beyond what shipped.

Project frame: One of the UK's biggest insurers: registration, login and passwordless access for MyAccount

Scope note: Every visual on this NDA-bound page is a newly drawn composite using fictional data and a neutral visual system. No image reproduces employer branding, production UI, source files, analytics, or customer records. Accessibility is demonstrated through reconstructed states; no formal product-conformance claim is made here.

Role
Senior UI Designer · UX Designer
Team
Design system team · Product · Engineering · Compliance
Year
2024 to 2025
Platform
Web · iOS · Android · FCA-regulated
Register
the hardest journey

Matching new users to an existing policy on sensitive fields, with validation that prevents errors before they happen.

Magic link
passwordless entry

One-time, time-boxed links so people get in without a password to forget or reset.

FCA
regulated by design

Compliance and data-use needs built into the flow from the first draft, not bolted on at review.

Every state
focus, error, disabled

Each field shipped as a small state machine, with accessibility structural rather than a final-pass audit.

NDA-safe abstract account-access case study covering registration, sign in, validation, secure links, and account home
01 · Context

The problem

Account access is the front door to everything a customer can self-serve, yet it is where regulated journeys quietly lose people. New customers must be matched to an existing policy using sensitive details, and a single unclear error or forgotten password sends them to a call centre instead of their account.

02 · Evidence

What shaped the direction

Where journeys actually fail

Registration, not login, is where account access breaks down. People abandon on the fields they hesitate over, like date of birth and postcode.

The support signal

Forgotten passwords are a leading driver of account-access support contact, which made passwordless more than a convenience.

Regulated constraint

As an FCA-regulated journey, wording, consent and data use had to be right, so I partnered with compliance from the first draft.

Multi-brand system

Patterns had to hold up across brands and themes, so they were designed against the design system rather than as one-offs.

03 · Process

How it came together

The brief

At one of the UK's biggest insurers I worked on MyAccount, the place customers go to manage their car, van and home cover. My focus was the way in: registration, login and passwordless one-time links, with a hand in the account home itself. Account access sounds simple. In a regulated business it is one of the highest-stakes flows there is, because the alternative to a smooth login is an expensive phone call.

Abstracted account sign-in concept with email, password and secure-link options
NDA-safe composite illustrating email, password and secure-link access. It uses fictional data and is not a production screen.

Registration is the hard part

Everyone talks about login, but registration is where account journeys actually break. A new customer is not creating an account from nothing; they are being matched to a policy that already exists, using details like surname, date of birth and postcode. Get the matching wrong and they are locked out of their own cover. So the flow keeps each step small: confirm your email first, then the details we use to find you.

Fictional registration concept showing an email field with a valid-state tick
A newly drawn composite: step one keeps the ask to a single field, with validation that confirms the moment the email is valid.

The details step is where care matters most. Date of birth and postcode are the fields people fumble, and a vague error is enough to make someone give up. The flow validates each field and speaks plainly when something is off.

Fictional registration details concept showing valid fields and an inline postcode error
An NDA-safe composite demonstrating inline, specific validation. The postcode error sits next to the field and says exactly what to fix.

Once details check out, we confirm rather than leave people wondering.

Abstracted check-your-email confirmation concept shown after registration
A reconstructed hand-off to email, with a spam-folder nudge and an obvious way to retry if nothing arrives.

Getting people in without a password

The strongest lever on account access is not a better password field; it is removing the password. The experience offers a one-time login link alongside the classic email and password, and mirrors it with password reset, so nobody hits a dead end on a small screen.

Three fictional mobile concepts for sign in, password reset and secure-link access
NDA-safe mobile composites for sign in, reset and secure link. Each is a single, calm task on a phone.

The one-time link email itself is part of the design. It has to be reassuring, unmistakably from us, and safe by default.

Fictional secure-link email concept with one primary button and an expiry note
A newly drawn email composite: one job, one button. The link is single-use, time-boxed to fifteen minutes, with a safe-to-ignore note.

The account they land in

I also had a hand in the account home. The goal is instant reassurance: what is covered, and what to do next. Everything else is secondary to that first glance.

Abstracted account home concept showing a sample policy and secondary actions
An NDA-safe account-home composite. Cover is front and centre, with secondary actions available without reproducing the employer product.

Where I took it next

The reconstructed artifacts above represent the interaction model that shipped, without reproducing employer UI. A good deal of my work ran ahead of that baseline. This is the registration flow rebuilt around one idea: reduce the moments where a real person hesitates.

A fictional redesigned registration concept with progress, positive validation and trust markers
A reconstructed redesign concept: visible progress, forgiving date input, positive validation, a plain reason for every sensitive field, and trust signals where doubt shows up.

None of that is decoration. Each change maps to a specific place people stall.

A fictional registration concept annotated with seven design principles
A newly drawn explainer of seven decisions, from progressive disclosure to errors that recover, each aimed at avoidable drop-off.

Designing every state

Regulated journeys are won or lost in the states most designs skip. I treated each input as a small state machine and specified the edges, then made accessibility structural rather than a final-pass audit.

A reconstructed input shown in default, focus, filled, valid, error and disabled states
A neutral, fictional field in every state, with visible focus, errors that use text and icon rather than colour alone, and autocomplete that speeds real people up.

Passwordless, promoted

The live product treats one-time links as a secondary option. I explored making them the default, so the safest way in is also the first one people see, with the password kept a single tap away for anyone who wants it.

A fictional passwordless-first sign-in concept with rationale and a how-it-works flow
An NDA-safe passwordless concept: lead with the link, keep the password optional, and explain the trade in plain terms.

What I would measure

Because this is account access, the numbers that matter are completion of registration, error rates on the fields people fumble, the share of logins that go passwordless, and the volume of forgotten-password support contacts. I designed the flows so those are the things that move, and worked with product, engineering and compliance so the wording and consent were right long before launch.

04 · Craft

Decision trail

  • 01Treated registration, not login, as the real problem, because that is where people drop off when details do not match or errors arrive too late.
  • 02Designed validation to confirm as people go, not just fail on submit, so mistakes are caught and fixed in place.
  • 03Pushed for passwordless one-time links as a first-class way in, since the safest path can also be the fastest.
  • 04Built every field as a full set of states, with accessibility and FCA wording in from the start rather than added at review.
05 · Result

What changed

The shipped work gave customers cleaner registration, login and passwordless access to MyAccount. The patterns I designed on top, progressive registration, positive validation, full state and accessibility coverage, and a passwordless-first login, show where I took the journeys next.

3 journeysregister, login, magic link
Passwordlessone-time link access
AA-awarestates and interactions

Confidential details are omitted. Any reconstructed visuals are labelled, and exact figures are only shown where they can be shared.

Next case study →QZee: one platform for service venues to run bookings, payments, and client admin