infinix x yugatech

BSP sets June 30 deadline for banks to move beyond SMS OTPs

Listen to article

Bangko Sentral ng Pilipinas has set June 30, 2026 as the deadline for banks to strengthen authentication systems and reduce reliance on SMS one-time passwords (OTPs).

The reform is part of the implementation of the Anti-Financial Account Scamming Act (AFASA), which aims to combat phishing, SIM-swap attacks, and other forms of digital financial fraud.

Under the proposed regulations, banks will be required to adopt stronger authentication methods, particularly for high-value online transactions and sensitive account changes. These may include biometric authentication, device-based credentials, and other phishing-resistant multi-factor verification systems.

According to BSP Deputy Governor Elmore Capule, the June 2026 compliance deadline will remain in place.

“As of now we are not extending it,” Capule said, emphasizing that financial institutions must accelerate preparations for the new security requirements.

In addition to stronger authentication, banks must also deploy fraud management systems capable of detecting suspicious transactions in real time. These systems may include behavioral analytics, device-change detection, and geolocation monitoring.

The rules will apply particularly to financial institutions offering complex electronic financial services or those processing at least PHP 75 million in average monthly transaction value.

The BSP is encouraging banks to move toward server-side biometric verification, where identity checks using fingerprints or facial recognition are validated through secure bank servers rather than relying solely on a user’s device.

Meanwhile, BSP General Counsel Roberto L. Figueroa said broader reforms to bank secrecy laws could further strengthen efforts to combat financial scams.

While OTPs may still be used in certain cases such as verifying mobile number ownership, the central bank said banks must gradually shift toward stronger authentication methods before the June 30 compliance deadline.

Frequently Asked Questions

What is the deadline for banks to stop using SMS OTPs?
The BSP set June 30, 2026 as the deadline for banks to strengthen authentication systems and reduce reliance on SMS OTPs.
What stronger authentication methods must banks adopt?
Banks must adopt biometric authentication, device-based credentials, and other phishing-resistant multi-factor verification systems.
Which financial institutions are affected by the new rules?
The rules apply to institutions offering complex electronic financial services or processing at least PHP 75 million in average monthly transaction value.
React to this article:
Written by
Anton Gabriel

Anton Gabriel

Senior Writer

Anton is into technology and gaming, with a growing interest in creative, tech-driven projects. He enjoys writing, editing, and experimenting with new tools, always learning and improving as he goes. Curious by nature, he likes building ideas, testing things out, and seeing where they lead.

View all posts by Anton Gabriel →

0 Comments

Leave a Reply

Loading next article...