The general policy should, if you want the security to be reasonably tight, be a secret and a token of some description that together get you into the account.
So, username, password and 2fa token system like a dongle or a mobile phone (provided that the mobile phone has some sort of security on it too).
A fingerprint isn't enough. The Sci-Fi author Michael Marshall Smith, in one of his stories details why. The protagonist is a small-time criminal engaged in a less than legal but highly lucrative trade. One morning this trade goes sideways and he is forced to request a loan from a colleague. Said colleague cannot provide said loan so offers an alternative. This consists of a finger attached to a small life support device, said finger giving access to the bank account of its former owner (who was deprived of his life around the time he was deprived of his finger). The lesson is simple: fingerprints can be stolen, secrets are more difficult to steal.