NEWS | For years, a bank could point to a customer's own mistake, like reading a text code to a stranger, to avoid refunding stolen money. That defense just got harder to use. A compliance deadline tied to the country's Anti Financial Account Scamming Act passed in late June, and regulators say banks that missed it now carry the risk of covering customer losses themselves.
The law, AFASA, was signed in 2024 and gave banks and e wallets until June 25 this year to overhaul how they verify transactions. Text and email based one time passwords are being phased out for high value transfers, replaced by biometric checks and stronger verification. The Bangko Sentral ng Pilipinas oversees the rollout and has logged over 500 scam related cases filed with police in the past year.
What changes now is where blame lands. Banks that upgraded in time get legal protection if a scam still slips through. Those that did not could be ordered to fully repay a victim, even if the bank never touched the stolen funds. Regulators say blaming a customer for entering a code no longer works for institutions that failed to modernize on time.
BMN's view is that this marks a clear shift in how digital fraud liability gets handled in the region, moving the burden toward the institutions holding the money rather than the people who lost it. Consumer groups welcomed the change but urge banks to move fast, warning slow compliance could leave gaps scammers exploit quickly.
If your bank still leans on a text message to confirm your transfers, would you trust it with your next paycheck?
Your picture beside a comment comes from Gravatar, matched to the email you signed in with. Set one there and it appears here; without one you get your initials. How we handle this