Local banks are now legally required to reimburse victims of unauthorized online transactions following the expiration of a grace period to deploy mandated fraud management systems.
If a depositor suffers from unauthorized transactions due to the bank’s non-compliance with AFASA, the bank is liable for full restitution, as stated by BSP General Counsel Roberto Figuera. He emphasized that banks cannot use the customer’s entry of OTP as a defense if they solely depend on OTP for security.
Banks Need to Prevent Compromised OTPs
Under the Anti-Financial Account Scamming Act (AFASA), financial institutions were given until June 2026 to upgrade their security infrastructure. With this deadline passed, the burden of security failures now falls on the banks rather than the depositors.

Figueroa emphasized that lenders can no longer deflect responsibility by blaming customers for compromised One-Time Passwords (OTPs).
Additionally, AFASA empowers banks to instantly freeze suspected irregular transactions without awaiting a court order. The Philippine National Police has reportedly filed over 500 scam-related complaints since the law took effect.
For more local and Tech news, click HERE.
Started his freelancing adventure in 2018 and began doing freelance Audio Engineering work and then started freelance writing a few years later.
Currently he writes for Gadget Pilipinas and Grit.PH.
He is also a musician, foody, gamer, and PC enthusiast.





