OTPs will expire under BSP reforms
Banks must deploy stronger fraud management systems capable of detecting suspicious transactions in real time.

Banks must deploy stronger fraud management systems capable of detecting suspicious transactions in real time.


Business sentiment nosedived in July amid persistent inflationary pressures arising from the Middle East conflict, the…

NAGA CITY — Albay Gov. Noel Rosal has ordered the reactivation of barangay dengue brigades following an increase in…

BAGUIO CITY — The Baguio City government will utilize digital monitoring tools to address recurring zoning exemptions…

The Scrap Collectors and Recyclers Association of the Philippines Inc.’s support is a significant step in Meralco’s…

Manila pet owners have been urged to take extra precautions against rabies after seven people were reported to have…
Reliance on one-time passwords (OTPs) as the main security layer in Philippine digital banking is set to decline as regulators push financial institutions to adopt stronger authentication systems.
The Bangko Sentral ng Pilipinas (BSP) is requiring banks to reduce reliance on interceptable authentication mechanisms such as SMS or email OTPs, which regulators say are increasingly vulnerable to phishing, SIM-swap attacks and social engineering schemes.
The shift is part of implementing the Anti-Financial Account Scamming Act (AFASA), a law aimed at strengthening defenses against the growing number of digital financial scams.
Under the rules, banks must deploy stronger fraud management systems (FMS) capable of detecting suspicious transactions in real time. Institutions offering complex electronic financial services — or processing at least P75 million in average monthly network value — must adopt monitoring tools such as behavioral analytics, device-change detection and geolocation tracking.
June compliance deadline
BSP Deputy Governor Elmore Capule said the central bank is maintaining the June 2026 compliance deadline.
“As of now we are not extending it,” Capule said, stressing that financial institutions are expected to accelerate preparations for the new requirements.
The BSP is encouraging banks to shift toward phishing-resistant multi-factor authentication, including biometric verification and device-bound credentials.
Meanwhile, BSP General Counsel Roberto L. Figueroa said broader reforms to bank secrecy laws could further strengthen AFASA enforcement.
“Access to financial information under reasonable suspicion will significantly strengthen our ability to go after financial criminals,” Figueroa said.
The deadline for banks to comply remains on 30 June.