The UAE is tightening digital banking security standards, with regulators pushing banks to replace traditional authentication methods with more advanced, fraud-resistant technologies.
UAE banks are moving decisively away from SMS and email-based one-time passwords, adopting biometric logins and intelligent fraud detection as part of a wider regulatory push led by the Central Bank of the UAE.
Under updated digital security requirements, licensed financial institutions are expected to discontinue SMS and email OTPs by the end of next month. In their place, banks are rolling out app-based transaction approvals, biometric authentication, and risk-based security controls designed to better protect customers against fraud.
The change marks a significant milestone in the UAE’s 2026 financial sector agenda, which places strong emphasis on artificial intelligence governance, fraud prevention, and operational resilience across banks and financial services providers.
App-based authentication becomes the new standard
With the new framework in effect, customers will increasingly approve transactions directly within their mobile banking applications. These approvals are typically secured using fingerprint recognition, facial authentication, or secure in-app PINs, reducing reliance on externally delivered verification codes.
A spokesperson from a Dubai-based bank confirmed that SMS and email OTPs are being phased out in line with Central Bank guidance, with customers now encouraged to authenticate transactions through their bank’s official mobile app.
This approach not only streamlines the customer experience but also mitigates risks associated with SIM-swap fraud, phishing attacks, and intercepted messages — vulnerabilities that have become more prominent as digital banking adoption has grown.
What this means for customers
The transition affects everyday banking activities, including online purchases, fund transfers, and card-based payments — areas that have traditionally depended on six-digit codes sent via text or email.
While customers may notice changes in how transactions are approved, banks say the shift ultimately delivers stronger protection and aligns the UAE with global best practices in digital banking security.
As financial institutions continue to modernise their authentication frameworks, biometric and app-based approvals are set to become the default layer of trust in the UAE’s digital banking ecosystem.
Key takeaways
- UAE banks are phasing out SMS and email OTPs
- Authentication is shifting toward biometric and app-based approvals
- The move strengthens protection against fraud and phishing attacks
- Regulators are driving higher security standards across banking
- Digital trust is becoming central to customer experience and safety

