AS the deadline for phasing out one-time passwords (OTPs) lapsed a month ago, banks are now liable to pay the amount lost by a depositor if victimized by hijacking the user’s one-time password (OTP), according to the chief legal counsel of the Bangko Sentral ng Pilipinas (BSP).
‘I’m sure you’ve heard that OTP alone is no longer allowed. There should be something more than that, especially for complex and high-value transactions,’ BSP General Counsel Roberto L. Figueroa told reporters on the sidelines of the Ceremonial Signing of Information Sharing Agreement between the BSP and the Department of Justice (DOJ) last Wednesday.
‘So if that’s the reason why the victim got scammed, and the bank, if it’s a high-value complex transaction [that] merely relied on the use of OTP by the customer, we all know that that’s not a sufficient defense on the part of the bank,’ Figueroa added.
He said the deadline was last June 25 so it is expected that all of the banks have already complied with the central bank’s circular.
‘If, let’s say, a depositor or a client of a bank gets victimized, and the reason for that is because of their failure to comply with the requirements of the Afasa [Anti-Financial Account Scamming Act], then the bank will suffer the consequence of that non-compliance,’ Figueroa said.
The central bank’s primary lawyer said that the consequence could include ‘complete full restitution,’ meaning whatever is the amount lost by the victim or by the depositor, even if the bank is not the scammer, the bank will now be ordered to pay the depositor or the customer the amount that was lost.
‘You cannot anymore use the defense that it’s the customer who entered the OTP,’ Figueroa said.
The BSP’s chief legal officer further noted that under the Afasa, it is clear that banks should have a ‘robust fraud management system,’ and that banks are now required to have a multi-factor authentication.
‘It’s not just one; in this case OTP. So with the deadline having passed, that means the victims of the scam or fraud can now use all these provisions of Afasa against the bank. A bank can no longer claim that it’s the fault of the client,’ added Figueroa.
Last year, the central bank required BSP-supervised financial institutions (BSFIs) to replace on or before June 25, 2026, SMS-based and email-based one-time password (OTP) with stronger technology. The latter includes biometric, behavioral, adaptive, or passwordless solutions, cited under BSP Circular 1213, issued in May 2025.
The circular covers banks and e-wallet operators that average more than P75 million of online transactions per month. That stipulation includes most universal and commercial banks, all digital banks, and some cooperative, thrift, and rural banks, the BSP noted.
These BSFIs are required to apply the stronger technology to transactions deemed as high-risk.
The circular, likewise, requires covered BSFIs to strengthen their fraud management systems to better detect and prevent unauthorized transactions.
‘These systems must be capable of flagging unusual or suspicious activities, including unusually rapid transactions and those involving new recipients or unrecognized devices,’ the central bank pointed out.