Philippines Philippines SIM registration cyberlibel NPC

The Philippines Just Shifted Bank Fraud Liability to Force Biometric Logins — And Left Its Own Privacy Regulator on the Sidelines

BSP's June 25 OTP ban fixes a real fraud problem but centralizes biometric data at scale without the NPC oversight the same law implies it needs.

The OTP Phase-Out, By the Numbers People of Internet Research · Philippines June 25, 2026 Deadline that took effect BSP Circular 1213's OTP ban for hi… ₱75M Monthly volume threshold Institutions above this average mo… ₱10M Max fine for non-compliance AFASA's administrative penalty cei… ~70,000 Fraud complaints logged in 2024 Cited as part of the case for repl… peopleofinternet.com
The OTP Phase-Out, By the Numbers People of Internet Research · Philippines June 25, 2026 Deadline that took effect ₱75M Monthly volume threshold ₱10M Max fine for non-compliance ~70,000 Fraud complaints logged in 2024 peopleofinternet.com

Key Takeaways

The Deadline That Just Passed

On June 25, 2026, Bangko Sentral ng Pilipinas Circular No. 1213 took full effect, barring SMS- and email-based one-time passwords for "high-risk" transactions at every covered bank, digital bank, e-money issuer, and payment operator averaging more than ₱75 million a month in online transaction volume. Login enrollment, adding a new payee, large transfers, and changes to registered contact details now require biometric, behavioral, or passwordless authentication instead of a six-digit code sent over a SIM. OTPs survive only for confirming a mobile number belongs to the account holder — not for authorizing money movement.

The circular implements the IT risk-management provisions of Republic Act No. 12010, the Anti-Financial Account Scamming Act (AFASA), which President Marcos signed on July 20, 2024. AFASA's real lever isn't the authentication mandate itself — it's liability. Banks that fail to deploy "adequate risk management systems and controls" must now reimburse scam victims directly, and conviction of the scammer is not a prerequisite. Banks the BSP certifies as compliant are shielded from that liability. Non-compliant juridical persons face administrative fines of up to ₱10 million. That is why an obscure IT-risk circular is reshaping login screens for tens of millions of Filipino banking customers: the cost of an SMS OTP got attached to the cost of the fraud it fails to stop.

The Case the BSP Is Making

The regulator's logic deserves a fair hearing before any pushback. SMS OTPs are interceptable by design — SIM-swap fraud, in which a scammer social-engineers a telco into porting a victim's number to a new SIM, then harvests the OTP to drain the linked account, has become one of the most common account-takeover vectors in Philippine digital banking. Biometric Update reported that fraud complaints hit roughly 70,000 in 2024 alone, and industry analysts have flagged that AI-assisted social engineering is now targeting ordinary retail users, not just high-net-worth accounts. A code sent over a network the customer doesn't control is a weaker credential than a biometric check performed against a server-side template the customer can't lose or have SIM-swapped away. Pairing that authentication upgrade with a liability shift — the bank eats the loss if its controls are inadequate — is a coherent, evidence-based response to a genuine and growing harm. This is not regulation for its own sake.

Where the Design Gets Ahead of Itself

The gap is oversight of what replaces the OTP. Biometric authentication under Circular 1213 relies on centralized templates held by the bank — fingerprint, face, or voice data converted to encrypted mathematical representations and matched server-side. The BSP's own guidance, per Biometric Update's reporting, concedes that "centralized biometric databases introduce privacy, cybersecurity and operational risks." That's an unusually candid admission for a rule that just made biometric enrollment mandatory for high-risk banking activity nationwide.

The Philippines' own privacy regulator has already litigated exactly this risk, in a different context. On October 8, 2025, the National Privacy Commission issued a cease-and-desist order against Tools for Humanity, the company behind Worldcoin's iris-scanning World App, for collecting biometric data from Filipinos without adequately informed, freely given consent. NPC Deputy Commissioner Belarmino's reasoning was blunt: biometric data is a "unique and permanent identifier," and unlike a password, an iris scan or fingerprint template that leaks cannot be reset. The commission called the resulting exposure a "serious and lifelong risk."

That is precisely the risk profile Circular 1213 now asks banks to manage — at a scale far larger than one crypto ID startup's user base — yet neither the BSP nor the NPC has published a joint framework governing retention limits, breach-notification timelines, or third-party audit standards for the biometric templates banks are about to accumulate. AFASA gives the BSP authority over fraud controls; it does not relieve the NPC of jurisdiction over how the underlying biometric data is processed under the Data Privacy Act of 2012. Regulatory silence on that seam is not a reason to delay the OTP phase-out — SIM-swap fraud is a live problem today — but it is a reason to publish the coordination framework before, not after, a bank's biometric database is the one that leaks.

A Narrower, Better Version of This Rule

The fix is not to soften the liability shift, which correctly makes banks internalize the cost of weak controls. It is to pair it with three things Circular 1213 currently leaves implicit: an explicit NPC audit and breach-notification regime for bank-held biometric templates, modeled on the standard the NPC already applied to Tools for Humanity; a preserved non-biometric fallback (hardware token or passwordless credential) for customers whose devices can't support biometric capture, so financial inclusion doesn't erode as a side effect of fraud prevention; and phased enforcement timelines for smaller cooperative and rural banks below the ₱75-million threshold, since fraud predictably migrates to whichever institution has the weakest controls — a dynamic Vietnam's rollout of similar rules has already demonstrated. AFASA's liability incentive is sound policy. Making sure the data it now requires banks to collect is governed as carefully as the fraud it prevents is the piece still missing.

Sources & Citations

  1. BSP Circular No. 1213 (2025)
  2. Republic Act No. 12010 (AFASA), LawPhil
  3. GMA News — OTP deadline takes effect
  4. GMA News — NPC cease-and-desist order on Tools for Humanity
  5. Biometric Update — Philippines biometric security shift
  6. Tech Pilipinas — BSP OTP order details