Bangko Sentral ng Pilipinas (BSP)
Driven by the need to enhance the security of digital transactions and to help protect customers’ interests, the Bangko Sentral ng Pilipinas (BSP) has released Circular No. 1213, establishing updated guidelines to adopt a robust Fraud Management System (FMS) capable of rapidly detecting, preventing, blocking disputed, suspicious, or other fraudulent transactions, including new and evolving fraud schemes.
In this circular, the BSP strongly encourages financial institutions to move away from SMS-based one-time passwords (OTPs) in favor of more secure, modern authentication methods. Although not explicitly banned, SMS OTPs are now considered insufficient on their own due to vulnerabilities such as interception and social engineering attacks. This aligns with long-standing concerns from global standards bodies, including the National Institute of Standards and Technology (NIST), which deprecated SMS-based OTPs as early as 2016.
According to 1Kosmos, this regulatory shift opens the door for stronger identity-proofing and access-control solutions such as biometric authentication, multi-factor authentication (MFA), and passwordless login methods. These technologies represent a forward-looking approach designed to strengthen security while enhancing the overall customer experience. The BSP’s updated framework is intended to not only reinforce trust in digital banking, but also ensure regulatory compliance and foster innovation without compromising risk management.
1Kosmos is well-positioned to help financial institutions meet these evolving requirements. With its privacy-by-design platform, 1Kosmos delivers verified identity assurance, enables users to control their personally identifiable information (PII), and supports seamless, secure, and passwordless access to digital services. It also acts as a universal authenticator for legacy applications and provides built-in multi-factor authentication, used millions of times daily across enterprises, financial institutions, and government entities worldwide.
Notably, the BSP’s new guidelines apply in full to institutions handling over ₱75 million in monthly digital transactions or those offering more complex digital services.
These entities are now expected to adopt real-time, risk-based fraud detection systems, including:
For smaller or less complex institutions such as thrift and rural banks, the BSP allows a tiered approach to implementation, proportionate to their operational scale and risk exposure.
In addition to regulatory expectations, these measures align with the broader provisions of the Anti-Financial Account Scamming Act (AFASA), which holds financial institutions accountable for safeguarding customer accounts. Failing to adopt appropriate authentication and fraud controls could result in administrative or civil penalties, especially in cases of avoidable customer loss.
By implementing secure, user-centric technologies like those provided by 1Kosmos, institutions can not only comply with BSP Circular No. 1213 but also significantly reduce fraud, increase customer satisfaction, and strengthen their digital trust posture.
The BSP’s updated framework, as detailed in Appendix 79/Q-66, outlines specific guidance on the adoption of multi-factor authentication (MFA) across digital financial services. Institutions offering complex digital products or processing high volumes of online transactions are now expected to implement robust authentication protocols to maintain the integrity of customer-initiated activities.
These mechanisms reflect the BSP’s risk-based approach to digital security, prioritizing solutions that are both user-centric and resilient against fraud. Institutions adopting such technologies will not only enhance customer protection but also future proof their digital platforms in compliance with the latest regulatory standards.
The 1Kosmos platform is well-positioned to address the BSP’s guidelines on alternative authentication mechanisms for digital payment transactions. Below is a detailed summary.
The 1Kosmos platform exhibits flexibility which allows service providers and their users to choose the authentication method that best suits their needs, thereby increasing the adoption of digital payments while maintaining high security standards with minimal friction to the user experience.
The platform is attested for Authentication Assurance Level 1, 2, and 3 as per NIST 800-63 standards. This allows 1Kosmos to enforce multiple factors of authentication via various authentication methods in a single platform.
It also leverages adaptive authentication to adjust the required factors based on risk signals, ensures secure transmission and storage of authentication data, and provides convenient user management and recovery options. This approach helps to protect against unauthorized access while maintaining a user-friendly experience.
1Kosmos customers are able to leverage this in multiple ways, for example, by a global banking customer.
The BSP circular recommends a risk-based approach to determine the appropriate AFA for a transaction. The 1Kosmos platform continuously assesses risk levels associated with each transaction or login attempt based on several factors such as user behavior, device, location, and time.
This dynamic assessment allows the system to adjust authentication requirements in real-time. The system collects and analyzes risk signals, which might include unusual login locations, changes in user behavior, high-value transactions, or access attempts from unfamiliar devices.
Based on the risk assessment, 1Kosmos adapts the authentication process. For elevated risk/ high value activities, it might require additional verification steps, such as biometric authentication, multifactor authentication (MFA), or additional
identity proofs. For low-risk activities, it may streamline the process with fewer steps.
As an example, a 1Kosmos banking customer leverages Facial Liveness authentication to authenticate digital payments, proving they are a real person.
The BSP circular requires explicit customer consent before implementing any new authentication method and provides the option for customers to deregister from any method.
The 1Kosmos platform ensures compliance with this requirement by:
The BSP guidelines mandates near real-time alerts for all eligible digital payment transactions. The 1Kosmos platform supports this requirement by:
Additionally, 1Kosmos platform architecture has privacy-by-design built in which emphasizes the protection of personal data, ensuring data privacy, security, and minimizing data breaches. The 1Kosmos solution can significantly aid in compliance
with this act by offering more secure and user-friendly ways to verify identity without traditional passwords, which are a common point of vulnerability. Specifically, the following benefits accrue on its implementation:
Enhanced Security: Passwords are susceptible to breaches, phishing, and other attacks. The diverse and flexible methods (e.g., biometrics, device-based authentication, and one-time codes) offered by 1Kosmos reduce the risk of unauthorized access, aligning with local privacy requirements for strong data protection.
Data Minimization: The Data Privacy Act of 2012 encourages minimizing data collected, used, and retained. Passwordless systems often reduce or eliminate the need to store password data, which reduces the volume of sensitive information the organization must protect.
Compliance: Adhering to industry standards and certifications such as the NIST 800-63-3 identity proofing and access management, FIDO2 for passwordless authentication and iBeta for biometric authentication.
Privacy by Design: The state-of-the-art approach of 1Kosmos solution aligns with the compliance requirement for ‘’privacy by design.’’ This approach inherently reduces the data footprint and enhances user security, which is built into the authentication mechanism from the start.
Improved User Control and Transparency: The reliable mechanisms, particularly those that use biometrics or device-based factors, help comply with the Data Privacy Act of 2012 emphasis on user rights by giving individuals more control over their data (e.g., biometric data stored locally on their device rather than a central server).
Reduced Risk of Data Breaches: With fewer stored passwords, the organization’s risk of exposure from data breaches decreases, which helps in meeting the Data Privacy Act of 2012 requirements for data security and breach reporting standards.
The 1Kosmos platform is well-equipped to address the BSP’s guidelines on alternative authentication mechanisms for digital payment transactions. By offering robust, dynamic, and diverse authentication methods, 1Kosmos enhances security while maintaining user convenience. The platform’s risk-based approach, customer consent mechanisms, and real-time transaction alerts further align with the BSP’s requirements. Additionally, 1Kosmos’ commitment to compliance and standardization ensures that its solutions are secure, interoperable, and reliable, making it an ideal choice for issuers looking to meet the BSP’s guidelines.