For years, one of the most familiar steps in Philippine digital banking was waiting for a six-digit code to arrive by text. Whether transferring money, paying a bill or confirming an online purchase, the SMS one-time password became almost synonymous with transaction security.
That system is now being pushed out of the country’s highest-risk financial transactions.
Beginning June 25, covered banks and e-wallet operators were required to move away from SMS- and email-based OTPs for high-risk transactions under BSP Circular No. 1213. The rules favor stronger authentication methods including biometrics, behavioral authentication, adaptive authentication and passwordless technologies.

The change does not mean the SMS OTP has completely disappeared. Banks may still use it in certain circumstances, including verifying ownership of a registered mobile number. But for Filipinos accustomed to treating a texted code as the final security checkpoint before money leaves an account, the direction is clear.
Increasingly, the phone itself, the customer’s biometrics and the bank’s assessment of a transaction are becoming part of the authentication system.
Why banks are moving beyond SMS OTPs
SMS OTPs added an important security layer because stealing someone’s username and password was no longer enough to complete certain transactions.
The weakness is that the OTP itself can still be stolen.
A phishing website can ask a victim to enter the code. A scammer posing as a bank employee can persuade someone to read it aloud. SIM-swap fraud can allow an attacker to receive messages intended for somebody else.

The BSP’s proposed additional guidance on server-side biometric authentication explicitly describes SMS and email OTPs as “interceptable authentication” and points to the risks of SIM swaps, phishing and related attacks.
The difference between the old and new approaches is significant.
An SMS OTP largely asks whether the customer possesses a temporary code sent to a registered number. Newer authentication systems can consider whether the customer is using a recognized device, whether a fingerprint or face matches, and whether the transaction resembles the customer’s normal behavior.
Stealing one piece of information therefore becomes less useful to an attacker.
Your phone is becoming part of your bank account
Filipino customers are already seeing versions of this approach.
BPI’s Mobile Key allows customers to authorize transactions using a Mobile Key PIN, fingerprint or Face ID on a designated device. In July 2025, BPI also removed SMS OTP verification for web browser logins among customers with Mobile Key-enabled devices, replacing it with an app notification or QR verification.
Metrobank’s AppKey similarly allows customers to verify transactions through fingerprint or facial recognition. Metrobank says AppKey is used to authenticate transactions across its app and online banking and replaces the usual SMS OTP for certain online credit card transactions.
China Bank has taken another route. Effective June 25, passkeys became the authentication method for transactions on the My CBC mobile app, replacing SMS OTPs for supported devices. Customers authenticate using their fingerprint, facial recognition or device PIN instead.
For everyday banking, these changes can actually remove friction. Instead of waiting for a message, memorizing six digits and returning to the banking app before the code expires, customers can approve a transaction with a fingerprint, face scan or in-app prompt.
The bigger challenge appears when the trusted device is no longer available.
Losing your phone could become a bigger banking problem
Device binding makes account takeover harder because knowing a username and password may no longer be enough. The transaction also has to come from, or be approved through, a device that the bank already recognizes.
That makes a customer’s registered smartphone much more important.
The BSP’s rules require financial institutions to apply additional safeguards following important account changes. These include controls around changes to registered devices and credentials, with a transaction pause period among the mechanisms prescribed to reduce the risk of account takeover.

Banks already apply similar waiting periods. Metrobank’s AppKey, for example, becomes active 24 hours after enrollment. BPI’s Mobile Key can also only be active on one primary device at a time.
These controls are useful when someone is trying to hijack an account. They can become inconvenient when the legitimate customer has simply lost a phone, broken it or upgraded to another device.
The stronger the connection between an account and a specific device becomes, the more important a bank’s recovery process becomes as well.
Stronger security could leave some customers behind
This is where the shift becomes more than a cybersecurity upgrade.
In its February 2026 exposure draft on server-side biometrics, the BSP specifically raised inclusivity and accessibility as considerations for financial institutions.

The central bank cited elderly users with worn or damaged fingerprints, persons with disabilities who may not have suitable biometric templates and marginalized customers without access to devices capable of supporting certain authentication technologies. It also proposed secure fallback methods when biometric authentication does not work.
Device requirements can create another dividing line.
China Bank, for example, says its passkey implementation requires at least iOS 16 on an iPhone or Android 12 on supported Android devices. Customers on incompatible phones can continue using other authentication methods rather than enrolling in passkeys.
A customer with a recent smartphone, reliable internet and functioning biometrics may barely notice the transition. Someone using an older handset or dealing with device compatibility problems may have a very different experience.
The challenge for banks is therefore not simply to make authentication stronger. They have to do so without making legitimate customers unnecessarily difficult to authenticate.
Your bank may decide when you need more verification
Another part of the transition will happen largely in the background.
The BSP requires stronger fraud-management systems capable of monitoring transactions for suspicious activity. Among the controls identified are transaction velocity checks, geolocation monitoring, device fingerprinting and behavioral anomaly detection.
This enables something closer to risk-based authentication.
A familiar transaction made from the customer’s usual phone may require relatively little additional friction. A large transfer made shortly after a credential change, from an unfamiliar device or under unusual circumstances could be treated as higher risk and subjected to additional verification.
Security can therefore become less visible when a transaction looks normal and more aggressive when the system sees something unusual.
The next challenge is account recovery
Moving away from SMS OTPs does not make scams disappear.
Fraudsters can still deceive customers into approving legitimate-looking requests. Phones can still be stolen. Biometrics can fail. People will still forget passwords and replace devices.
The real test of the new authentication system will therefore come not only when everything works, but when it does not.
A good security system should make it extremely difficult for a criminal to take control of an account while still giving the legitimate owner a practical way to recover access. Those two goals can pull in opposite directions.
For many Filipino customers, the end result could be easier banking: fewer codes to type, faster approvals and stronger protection against phishing and SIM-swap attacks.
For others, particularly those using older devices or recovering an account after losing a phone, stronger authentication could introduce new hurdles.
The OTP is not completely dead. But its position as the default proof that the person holding a phone number is really the person authorizing a financial transaction is clearly fading.
What replaces it may ultimately be both safer and easier for most customers. The harder question is whether Philippine banks can make that security work just as well for the people who do not have the newest phone, perfect connectivity or a trusted device available when they need their money most.
