One-time passwords (OTPs) remain a familiar security feature for Philippine banking and fintech users, but telcos and financial institutions are looking at additional ways to spot suspicious activity before a transaction goes through.
Smart Communications, Inc. has secured GSMA Open Gateway certification for its SIM Swap and Device Swap APIs, which can give businesses network-level signals that may help detect potential account takeovers.
PLDT Enterprise said the APIs are now part of SmartSafe NetIdentity, a verification solution that allows enterprises to check whether a mobile number has recently been moved to another SIM or used on a different device.

The PLDT Enterprise office in Makati
The development could be particularly relevant to banks, digital banks, e-wallets, lending platforms and other fintech companies that rely on mobile numbers as part of customer authentication.
Adding another layer to fraud detection
OTP-based authentication has long been used to verify customers during logins, fund transfers and other sensitive transactions. But a successful OTP check does not necessarily mean the person on the other end is the legitimate account holder.
SIM-related fraud can allow criminals to take control of a victim’s mobile number and potentially receive authentication codes intended for the account owner. Device changes can also provide a useful warning signal when they occur alongside other unusual account activity.
Smart’s newly certified APIs are designed to provide businesses with those signals.
The SIM Swap API can determine whether a mobile number has recently been transferred to a different SIM. The Device Swap API, meanwhile, can identify whether a subscriber’s SIM has been placed in a different device.

IMAGE CREDIT: Pexels
For a bank or fintech platform, such information can be incorporated into its existing fraud-detection systems. A recent SIM swap, for example, could prompt the institution to require additional verification before allowing a high-value transfer or other sensitive transaction.
That approach allows OTPs to remain part of the authentication process while giving fraud teams another way to assess whether a transaction deserves closer scrutiny.
“Digital trust is built in the small moments customers experience every day — when they log in, make a payment, or access a service without worry,” said Benedict Patrick V. Alcoseba, Enterprise Core Business Management & Innovation at PLDT Enterprise.
“With SmartSafe NetIdentity, we are helping businesses strengthen protection behind these everyday interactions, using globally certified network APIs that support safer authentication without adding unnecessary friction for users.”
What it means for Philippine fintech
The additional security layer comes as financial services in the Philippines become increasingly dependent on mobile-based transactions.

Banks, e-wallets and fintech platforms routinely use mobile numbers for account registration, authentication and transaction alerts. That makes the security of the number itself an important part of protecting a digital account.
For fintech companies, the appeal of network APIs is that the information can be incorporated into existing risk engines instead of requiring customers to go through additional security steps every time they transact.
A platform could, for instance, treat a recent SIM change as one of several risk indicators. A low-risk transaction could proceed normally, while a transaction involving a recently changed SIM and an unfamiliar device could be subjected to additional checks.
The result is a risk-based approach rather than relying on a single authentication method.
Part of GSMA Open Gateway framework
The certification places Smart’s latest APIs under the GSMA Open Gateway framework, which seeks to create common standards for telecom network capabilities that developers and businesses can integrate into their applications.
Smart previously secured GSMA certification for its Number Verification and RoamStatus APIs. PLDT Enterprise said these earlier capabilities, together with the newly certified SIM Swap and Device Swap APIs, strengthen its network-powered authentication and fraud-prevention offering.

SmartSafe was introduced in November 2025 as a telco-enabled fraud management suite aimed at businesses operating in the Philippines.
For the country’s financial technology sector, the broader development points to a shift in how digital fraud is being tackled: rather than asking customers to repeatedly prove who they are, banks and fintech platforms can increasingly use behind-the-scenes signals to determine whether a transaction looks legitimate.
That could become increasingly important as fraudsters find new ways to exploit trusted authentication methods, including the mobile numbers that underpin much of the country’s digital financial ecosystem.
