TL;DR: The Central Bank of the UAE now prohibits banks from relying on SMS OTP, email OTP, or static passwords alone for financial transactions and account provisioning, and it requires stronger authentication, real-time fraud detection, and step-up controls for high-risk actions, according to OneSpan. The practical shift is that authentication, transaction risk scoring, and session security now have to operate as one governance model, not separate controls.
Editorial analysis by NHI Mgmt Group, based on content published by OneSpan: “Central Bank of UAE boosts consumer protection against fraud”.
Key questions
Q: What breaks when banks rely on SMS OTP as the only transaction authentication method?
A: Banks expose themselves to account takeover and transaction fraud because a stolen or relayed OTP proves only that a code was received, not that the session, device, or transaction is trustworthy.
Q: Why do weak authentication methods create fraud risk in digital banking?
A: Weak methods create fraud risk because they authenticate a session without proving that the person, device, and transaction are still trustworthy.
Q: What are the signs that banking authentication controls are failing?
A: Warning signs include repeated OTP dependence, limited use of step-up for high-risk actions, suspicious session behaviour, and fraud patterns that appear after login rather than before it.
Practitioner guidance
- Replace OTP-only transaction approval Remove SMS OTP, email OTP, and static passwords as sole factors for financial transactions and account provisioning, then re-map each banking journey to stronger verification paths.
- Bind step-up to risky actions Trigger stronger authentication for limit changes, card parameter changes, security parameter updates, payment initiation, personal-data edits, and new card requests.
- Treat mobile sessions as monitored control points Suspend app sessions when screen sharing, malware, remote access tools, or active calls are detected, and feed those signals into fraud decisioning.
Bottom line: The CBUAE notice redefines weak OTP-only access as an unacceptable banking control for transactions and account provisioning.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Weak OTP is now a governance failure, not just an authentication weakness. The CBUAE notice treats SMS OTP, email OTP, and static passwords as insufficient when they stand alone for financial transactions and account provisioning. That is a structural change in control expectation because the issue is not simply factor strength, but whether the bank can still trust an action once it leaves the login screen. The practical conclusion is that consumer banking identity governance now has to model authentication as part of transaction risk.
A few things that frame the scale:
- Nearly 60% of companies reported that fraud losses were still increasing in 2025.
A question worth separating out:
Q: How should banks respond when a digital banking session becomes high risk?
A: Banks should move from passive authentication to active session governance. That means stopping or declining suspicious transactions, suspending risky mobile sessions, requiring stronger verification for sensitive changes, and ensuring fraud signals feed directly into approval decisions before the action completes.
👉 Read our full editorial: CBUAE authentication rules push banks beyond weak OTP methods