
From Monday, 6 January 2026, major UAE banks will switch off SMS one-time passwords (OTPs) for e-commerce and digital-banking transactions, completing a security overhaul mandated by the Central Bank of the UAE. Instead, customers must approve payments inside their banking apps using fingerprint or facial recognition, or a secure Smart Pass PIN.
For expatriate staff and frequent travellers, the change is more than a cyber-security footnote. SMS codes often fail on overseas roaming networks, leading to blocked corporate card transactions at hotels and client dinners. The move to app-based authentication removes that pain point, provided users enable push notifications before departure.
Banks have spent the past month sending “last-call” emails urging customers to: 1) update to the latest app version; 2) register biometrics; and 3) switch on notifications. Those who fail to comply risk declined online payments until they complete the new set-up. Employers should circulate step-by-step guides, particularly for blue-collar staff who may rely on pay-day remittances via digital wallets.
The Central Bank’s Notice 2025/3057 gives financial institutions until March 2026 to phase out SMS and email OTPs entirely, but most local lenders accelerated timelines after a 38 % spike in SIM-swap and phishing fraud last year. Industry analysts say the UAE will become one of the first jurisdictions to rely almost exclusively on biometric, app-based approvals for retail payments, leapfrogging many European markets.
Corporate mobility teams should update travel-expense policies to reflect the new authentication flow and remind employees that temporary roaming-SIM solutions (often purchased on arrival) will no longer be needed solely to receive banking codes.
For expatriate staff and frequent travellers, the change is more than a cyber-security footnote. SMS codes often fail on overseas roaming networks, leading to blocked corporate card transactions at hotels and client dinners. The move to app-based authentication removes that pain point, provided users enable push notifications before departure.
Banks have spent the past month sending “last-call” emails urging customers to: 1) update to the latest app version; 2) register biometrics; and 3) switch on notifications. Those who fail to comply risk declined online payments until they complete the new set-up. Employers should circulate step-by-step guides, particularly for blue-collar staff who may rely on pay-day remittances via digital wallets.
The Central Bank’s Notice 2025/3057 gives financial institutions until March 2026 to phase out SMS and email OTPs entirely, but most local lenders accelerated timelines after a 38 % spike in SIM-swap and phishing fraud last year. Industry analysts say the UAE will become one of the first jurisdictions to rely almost exclusively on biometric, app-based approvals for retail payments, leapfrogging many European markets.
Corporate mobility teams should update travel-expense policies to reflect the new authentication flow and remind employees that temporary roaming-SIM solutions (often purchased on arrival) will no longer be needed solely to receive banking codes.
Source: Times of India