The Bangko Sentral ng Pilipinas (BSP) is directing supervised financial institutions to phase out interceptable authentication methods, such as SMS and email one-time passwords, for high-risk transactions and move on to server-side biometrics authentication.
The Anti-Financial Account Scamming Act, which works under the BSP, officially recognises that the security biometrics authentication acts as a robust alternative to the older methods.
Server-side biometrics validate a customer’s identity against centrally stored templates, reducing vulnerabilities like account takeovers or device compromises.
However, the BSP warned that centralising this data creates a high-value target for cyber threats.
Consequently, institutions must enforce strict minimum controls, including encrypting biometric templates rather than storing raw images, alongside continuous liveness and deepfake detection.
Financial firms must also apply multi-layered security, meaning biometrics should not be the sole line of defence against fraudulent activity.
The regulatory body clarified that institutions failing to maintain adequate risk management systems will be held liable to reimburse customers for funds lost to scams.
Conversely, those compliant with these strict authentication standards will not bear liability for specific cybercrime offences.
Featured image: Edited by Fintech News Philippines based on an image by via Freepik.
The post BSP Mandates Server-Side Biometrics for High-Risk Banking Transactions appeared first on Fintech News Philippines.


