ZENTARA

AFASA Compliance: How Philippine FIs Can Strengthen MFA

Learn how Philippine banks and e-wallets can strengthen AFASA compliance with phishing-resistant MFA, FIDO2 passkeys, and device-bound authentication.

Francesco Catozzo8 min read
AFASA Compliance: How Philippine FIs Can Strengthen MFA

AFASA Compliance: How Philippine FIs Can Strengthen MFA

The Philippines' financial sector is moving towards stronger protection against account scams. The challenge is no longer just detecting fraud after a transaction occurs. It is also about preventing attackers from gaining control of customer accounts in the first place.

The Anti-Financial Account Scamming Act (AFASA) and the Bangko Sentral ng Pilipinas (BSP) rules that implement its information technology risk management requirements are pushing financial institutions to strengthen their defences against increasingly sophisticated scams.

At the centre of this effort is authentication.

Passwords and SMS OTP mechanisms have long been used to protect digital financial accounts. But phishing and social engineering can trick customers into giving attackers the information needed to bypass these controls.

For institutions evaluating MFA Philippines frameworks, the next step is to move towards authentication methods that are harder to steal and harder to reuse. This is where phishing resistant MFA, including FIDO2 passkeys and device bound authentication, plays a critical role.

What Is AFASA?

The Anti-Financial Account Scamming Act (Republic Act No. 12010) was enacted to address financial account scams and strengthen protections against cybercriminals who target financial accounts.

The law recognises the growing risks created by digital banking and electronic financial services. It also establishes mechanisms for financial institutions and authorities to detect, investigate, and respond to fraudulent transactions.

The BSP subsequently issued BSP Circular No. 1213, which amended its information technology risk management regulations to implement the IT risk management provisions of AFASA.

The circular applies across relevant BSP-supervised financial institutions and strengthens requirements around fraud management, account security, and controls for electronic products and services.

The regulatory direction is clear: financial institutions need stronger controls that can prevent, detect, and respond to financial account scams.

Why MFA Matters Under AFASA

MFA adds additional layers of verification beyond a password. The idea is simple. Even if an attacker steals a customer's password, they should still be unable to access the account without another authentication factor.

However, not all MFA methods provide the same level of protection.

An SMS OTP can help reduce the risk of password-only attacks, but it remains vulnerable to phishing, social engineering, SIM-swapping, and other techniques that trick users into revealing the code.  

This creates an important distinction:  

Standard MFA makes account takeover harder; phishing resistant MFA makes the authentication factor itself virtually impossible to steal.  

For financial institutions dealing with increasingly sophisticated scams, that difference matters

From SMS OTP to Phishing-Resistant MFA

Moving away from SMS OTP does not necessarily mean removing MFA. It means using stronger authentication factors that are designed to resist phishing.

Authentication Method

Delivery Mechanism

Vulnerability Profile

Regulatory Standing

SMS OTP

Cellular Network / SMS

Vulnerable to SIM swaps, interception bots, and phishing relays.

Being phased out for high-risk transactions.

Authenticator Apps (TOTP)

Time-based Local Generator

Resistant to SIM swaps, but vulnerable to real-time phishing relays.

Transitional control.

FIDO2 Passkeys

Hardware-bound Asymmetric Keys

Cryptographically bound to domain; immune to phishing relays.

Highly recommended standard.

What Is Device-Bound Authentication?

The concept of device bound authentication links an authentication credential directly to a specific, cryptographically verified hardware asset. Instead of relying exclusively on user memory, the system evaluates device integrity and identity. 

This reduces the risk of stolen credentials being utilized from unauthorized hardware endpoints. 

For financial institutions, device binding can be particularly useful for protecting high-risk activities such as:

  • New device registration
  • Password or credential changes
  • Adding a new beneficiary
  • Changing a registered mobile number
  • Increasing transaction limits
  • High-value transactions
  • Account recovery

BSP Circular No. 1213 specifically addresses key account changes, including updates to a customer's mobile number, email address, and registered or authenticated device. It also establishes a 24-hour Transaction Pause Period after such changes, while allowing institutions to shorten or modify the pause when strong authentication mechanisms are in place and the institution accepts the associated risk.

This creates an important opportunity for FIs to rethink how authentication is applied to sensitive account changes.

Blueprint for Phishing-Resistant MFA

Implementing stronger authentication requires more than simply replacing one login method with another.

Financial institutions should consider the entire customer authentication journey.

  1. Identify high-risk authentication events

Start by identifying where account takeover could cause the greatest harm. This includes login, device registration, account recovery, credential changes, and high-value transactions.

Not every action needs the same level of authentication. Risk-based controls can help organisations apply stronger verification where the potential impact is highest.

  1. Introduce phishing-resistant authentication

FIDO2 passkeys can provide a stronger alternative to authentication methods that rely on codes users can be tricked into revealing. The goal is to make authentication resistant to common phishing and social engineering techniques while keeping the customer experience practical.

  1. Bind authentication to trusted devices

Where appropriate, authentication should be linked to trusted devices and monitored for changes. A new device should trigger additional verification, particularly when it is combined with other risky activity, such as a password reset or changes to account details.

  1. Protect account recovery

Strong authentication can be undermined by a weak account recovery process.Attackers may bypass secure login controls by exploiting customer support processes, password resets, or device replacement procedures.

Account recovery should therefore receive the same level of security attention as normal authentication.

  1. Monitor authentication and transaction activity together

Authentication data should not be viewed in isolation. A successful login from a new device followed by a password change, beneficiary addition, and unusual transfer may indicate account takeover.

Combining authentication signals with transaction monitoring can help financial institutions identify suspicious behaviour earlier.

BSP Circular No. 1213 requires relevant BSFIs to implement automated and real-time fraud monitoring and detection capabilities for disputed, suspicious, or fraudulent online transactions, with stronger requirements for institutions handling complex electronic products and high aggregate transaction values.

  1. Test the controls

Authentication controls should be regularly tested against realistic attack scenarios.

Security testing should include phishing simulations, API testing, authentication flow assessments, account takeover scenarios, and reviews of device registration and account recovery processes.

The goal is to identify whether attackers can bypass the authentication layer even when the technology appears to be working as designed.

What Philippine FIs Should Review

For banks, e-wallets, and other BSP-supervised financial institutions, moving towards phishing-resistant MFA should be part of a broader security programme.

Key areas to review include:

  • Authentication: Are customers protected by strong authentication methods that resist phishing and social engineering?
  • Device security: Can attackers register unauthorised devices or bypass device verification?
  • Account recovery: Can customer support or recovery processes be exploited to take over accounts?
  • Transaction security: Are authentication signals combined with transaction risk indicators?
  • Fraud monitoring: Can suspicious transactions be detected and blocked in real time?
  • Third-party risk: Do authentication and security controls extend to vendors and technology providers?
  • Incident response: Can the organisation quickly detect, investigate, and contain account takeover attempts?

Why Replacing SMS OTP Alone Is Not Enough

Transitioning from SMS OTP to passkeys is a major upgrade, but it cannot function as a standalone fraud strategy. Attackers target the broader account lifecycle through device compromise, social engineering, or post-authentication abuse. 

This means phishing-resistant MFA should work alongside:

  • Real-time fraud monitoring
  • Transaction risk analysis
  • Device intelligence
  • Behavioural analytics
  • Strong identity governance
  • API security
  • Secure account recovery
  • Continuous security monitoring

AFASA compliance is therefore not just an authentication project. It is a broader effort to protect the entire financial account ecosystem.

Building a Stronger AFASA Security Strategy

The shift towards phishing-resistant MFA represents a broader change in how financial institutions approach account security.

Instead of assuming that a password and SMS OTP are enough, organisations need to consider how attackers actually compromise accounts and where stronger controls can stop them.

For Philippine FIs, the priority should be to build layered protection across authentication, devices, transactions, APIs, fraud monitoring, and incident response.

Zentara helps financial institutions strengthen cybersecurity across critical digital environments, from vulnerability assessments and penetration testing to security monitoring and incident response. 

Ready to strengthen your financial institution's security posture?

Explore how Zentara can help validate your controls, uncover hidden weaknesses, and build stronger resilience against modern cyber threats.

Frequently Asked Questions

  1. What is AFASA?

AFASA, or the Anti-Financial Account Scamming Act, is Philippine legislation designed to combat financial account scams and strengthen protections for customers of banks and other financial institutions.

  1. Does AFASA require FIDO2 passkeys?

AFASA and BSP Circular No. 1213 do not specifically mandate FIDO2 passkeys. However, phishing-resistant authentication such as FIDO2 can be considered a strong technical approach for strengthening authentication and reducing the risk of phishing-based account takeover.

  1. Are SMS OTPs still secure?

SMS OTPs provide an additional layer of security, but they are vulnerable to phishing and social engineering because users can be tricked into sharing the code. Stronger phishing-resistant methods can reduce this risk.

  1. What are FIDO2 passkeys?

FIDO2 passkeys use public-key cryptography to authenticate users without requiring them to enter a password or one-time code that can be captured by attackers. The private credential remains protected on the user's device.

  1. What is device-bound authentication?

Device-bound authentication links a credential or authentication process to a specific device, helping reduce the risk of stolen credentials being reused from unauthorised devices.

  1. Is MFA enough to prevent account takeover?

No. MFA is an important layer of defence, but financial institutions also need fraud monitoring, transaction analysis, secure account recovery, device security, API protection, and continuous monitoring to address the full range of account takeover risks.

More like this, monthly.

What our teams are seeing in Indonesian threat activity and regulatory movement — written by the people running the SOC.

We use your address to send what you asked for and nothing else. No list is sold or shared. Privacy policy.

Have a security question this raised?

Our engineers answer directly — no qualification call first.