Join our Newsletter — 33% off our NHI Course

Why are regulators limiting SMS OTP instead of treating it as acceptable MFA?

Because SMS OTP proves access to a phone number, not durable possession of a secure authenticator. Regulators are reacting to SIM swap, phishing and adversary-in-the-middle abuse, which make the factor easy to capture or replay. The practical result is a move toward device-bound, phishing-resistant authentication for higher-risk banking actions.

What regulators are rejecting when they narrow SMS OTP

sms otp is being treated less as a strong factor and more as a fallback signal of phone-number control. The problem is not whether it sometimes works, but whether it is resistant enough for higher-risk banking actions. In practice, regulators are pushing firms to distinguish convenience from assurance, especially where phishing-resistant authenticators are now available.

For that reason, the key comparison is between a factor that can be intercepted, forwarded, or socially engineered and one that is bound to the user’s device or cryptographic authenticator. That difference matters most when the action being protected could move money, change account settings, or alter recovery paths.

For a broader explanation of the phishing-resistant direction regulators are moving toward, see MFA Guide and Passwordless and Passkeys Guide.

Why SMS OTP fails the assurance test

SMS OTP is vulnerable because it relies on a telecom channel and a shared phone-number identity, not on a secure authenticator that is difficult to clone or replay. SIM swap, message interception, malicious forwarding, and adversary-in-the-middle phishing can all undermine the value of the code even when the user receives it promptly.

That weak assurance is why SMS OTP often remains acceptable only for low-risk recovery, step-up, or transition scenarios, if it is allowed at all. When the event being protected has a direct financial or account-takeover consequence, the factor is usually no longer good enough on its own.

Related attack paths are documented in Twilio 0ktapus breach 2022, CitrixBleed exploitation 2023, and Uber breach 2022, all of which show how OTP-style or second-factor controls can be bypassed when the surrounding trust path is weak.

What regulators want banks and platforms to use instead

The direction of travel is toward device-bound, phishing-resistant authentication for sensitive actions, especially passkeys, security keys, and strong authenticator-app flows that are resistant to relay and code capture. Regulators are not saying every login must be the same, but they are narrowing what counts as acceptable MFA when fraud impact and account recovery risk are high.

This also changes how teams should design recovery. If SMS remains anywhere in the stack, it should not be the only path that can restore access, approve a payout, or reset a primary authenticator. The safer pattern is to reserve SMS for low-assurance contingencies and keep high-impact actions tied to stronger methods.

See Workforce Identity Security Guide for the rollout logic behind phishing-resistant MFA and Passwordless and Passkeys Guide for the recovery trade-offs that matter when moving off SMS.

Risk and Threat Considerations

SMS OTP creates a concentration risk around the phone number as the de facto recovery and verification channel. If an attacker can take over the number, intercept the message, or coerce the user into sharing the code, the control collapses even though the user appears to have completed MFA.

Failure mechanism: The factor authenticates possession of a reachable phone channel, not durable possession of a secure authenticator, so SIM swap, relay phishing, and session replay can defeat it.

Impact: Account takeover, fraudulent payment approval, and recovery-path abuse become materially easier, especially when SMS is allowed to approve sensitive banking actions.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST SP 800-53 Rev 5 and OWASP ASVS set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-63 Digital Identity Guidelines SMS OTP and phishing-resistant MFA are directly governed by digital identity assurance guidance.
Recommendation — Adopt phishing-resistant authenticators for high-risk actions and limit SMS to lower-assurance use cases.
NIST SP 800-53 Rev 5 IA-2 — Identification and Authentication (Organizational Users) Higher-risk banking actions need stronger user authentication than SMS OTP provides.
Recommendation — Require stronger authenticators for privileged and high-risk access paths.
OWASP ASVS V6 — Authentication The question is fundamentally about authenticator strength and MFA assurance.
Recommendation — Enforce authentication methods that resist interception, relay and replay.
ISO/IEC 27001:2022 A.5.15 — Access control Regulated MFA decisions are an access-control policy issue for sensitive services.
Recommendation — Define which actions require stronger authentication and prohibit weak fallback factors.

Practitioner Guidance

What to verify: Treat SMS OTP as a risk-acceptance decision, not a default MFA choice. Verify whether the factor is used for login only, for step-up, or for recovery, because the acceptable level of assurance is very different in each case.

Decision rule: If the action can move funds, reset access, or create a new recovery path, require phishing-resistant authentication and do not let SMS be the sole control. If SMS remains temporarily, constrain it to lower-risk workflows and put a sunset date on it.

Practitioner takeaway: The question is not whether SMS OTP is convenient, but whether it still matches the assurance level required by the business action being protected. For regulated environments, that answer is increasingly no.