BSP tightens digital banking authentication rules
Users of digital banking services in the Philippines are set to receive stronger protection against fraud and unauthorized account access as Bangko Sentral ng Pilipinas-supervised financial institutions implement more secure authentication measures.
The BSP said covered financial institutions must replace SMS- and email-based one-time passwords with stronger authentication technologies on or before June 25, 2026.
The requirement is provided under BSP Circular No. 1213, which was issued in May 2025.
The stronger authentication tools include biometric, behavioral, adaptive, or passwordless solutions.
Biometric authentication covers the use of fingerprint scanning, facial recognition, and voice recognition.
Behavioral authentication tracks user patterns such as typing speed, mouse movements, or device movements.
Adaptive authentication adjusts the verification process based on the user’s context, including location, device, and behavior.
Passwordless authentication may use biometrics, hardware tokens, and cryptographic keys.
The circular applies to banks and e-wallet operators that average more than PHP 75 million in online transactions per month.
Covered institutions include most universal and commercial banks, all digital banks, and some cooperative, thrift, and rural banks.
The BSP said many covered institutions are already implementing the enhancements ahead of the deadline.
“The BSP is equally dedicated to promoting innovation in financial services as to protecting customers from new forms of fraud, including technology-enabled fraud. We are pleased that banks and e-wallet operators are stepping up on both fronts,” said BSP Deputy Governor Lyn I. Javier.
Covered institutions are required to apply stronger authentication technologies to transactions they classify as high-risk.
Risk assessment will be based on factors such as payee profile, transaction value, customer behavior patterns, and the nature of the product or service.
High-risk activities may include enrollment in digital banking, transfers to third parties, online remittances, card payments, account maintenance, and changes to mobile numbers, email addresses, login credentials, or devices.
For transactions assessed as lower risk, supervised financial institutions may continue using less stringent authentication methods, such as OTPs sent through SMS.
Lower-risk transactions may include payments to pre-registered recipients and account inquiries.
The BSP said institutions not covered by the circular are not required to shift to stronger verification tools within the same transition period.
However, non-covered institutions must regularly assess risks associated with their products and services to determine appropriate fraud prevention measures.
The circular also directs covered institutions to strengthen their fraud management systems to better detect and prevent unauthorized transactions.
These systems must be capable of flagging unusual or suspicious activities, including unusually rapid transactions and transactions involving new recipients or unrecognized devices.
The BSP said the measure forms part of its broader push to promote a safe, secure, and resilient digital payments ecosystem while supporting the continued growth of digital financial services.
Comments (0)
LEAVE A REPLY
No comments yet
Be the first to share your thoughts!
Related Articles

DOE, ERC back removal of system loss charges
MANILA — The Department of Energy and the Energy Regulatory Commission backed President Ferdinand R. Marcos Jr.’s call to remove system loss charges from electricity bills, while stressing that the proposed reform must preserve reliable service and the financial viability of power distributors. Removing the charge could reduce monthly expenses for households and operating costs


