The UAE Central Bank has announced a significant policy shift, mandating that financial institutions refund losses incurred from fraud related to SMS One-Time Password (OTP) scams. This directive extends to all banks, insurance companies, and financial services licensed by the regulator, emphasizing the necessity for advanced security measures to protect customer transactions.
Immediate Notification and Refund Protocol
According to the Central Bank, victims of fraud must promptly alert their financial institution to ensure swift action. Should an investigation reveal that the fraud stemmed from the misuse of an SMS OTP, the institution is obliged to reimburse the full amount once the report’s validity is confirmed. This policy specifically targets cases involving OTPs sent via SMS, highlighting an increased vulnerability in this method of authentication.
Transition to Enhanced Security Measures
The directive is part of a broader initiative to phase out SMS or email-based OTPs by July 2025, transitioning to more secure authentication protocols integrated within banking apps. This change responds to a surge in cyber fraud incidents where perpetrators exploit SMS-delivered codes to infiltrate accounts and execute unauthorized transactions.
Under the new system, customers will confirm transactions through their bank’s mobile app using biometric methods such as fingerprint and facial recognition, or secure in-app access codes. This transition aims to bolster the digital infrastructure of the financial sector, ensuring the security of electronic banking services and fostering greater customer trust in digital platforms.
Guidelines for Fraud Prevention
The Central Bank has issued guidelines urging customers to authenticate transaction details thoroughly before approval, such as verifying the merchant’s name and transaction amount. If fraud is suspected, customers should immediately request a freeze on their bank card through official channels, adjust spending limits or security settings as necessary, and obtain a reference number for tracking complaint progress.
In instances where a complaint is not upheld, the financial institution must provide a clear explanation. Customers can then escalate unresolved issues to the Banking and Insurance Disputes Resolution Unit, known as Sanadak, for further mediation.
Commitment to Customer Security
The Central Bank emphasized its commitment to protecting customers, asserting that the safety of clients in the UAE remains a top priority. Banks have been advised to ensure that customers update their mobile applications and activate secure in-app authentication features to prevent potential fraud.
This new mandate represents a pivotal step in the UAE’s efforts to enhance financial security and illustrates a broader dedication to safeguarding consumer interests in an increasingly digital economy. As the transition progresses, both financial institutions and customers are encouraged to embrace these new security measures, ensuring a safer banking environment for all.










