The OTP Isn’t Dead Yet. But Banks Are Already Building What Comes Next

The OTP Isn’t Dead Yet. But Banks Are Already Building What Comes Next

A six-digit code arriving by SMS has become one of the most recognisable security rituals in digital banking. Customers receive it, copy it, enter it and assume the transaction is protected. Fraudsters understand the ritual just as well. Phishing pages are designed to capture codes in real time, criminals impersonate bank employees to persuade customers to reveal them, and SIM swap attacks can redirect messages altogether. The problem is increasingly not whether an OTP can prove that someone possesses a phone number. It is whether that proof tells a bank enough about who is actually approving the transaction and whether they understand what they are approving.

OTPs Solved a Different Security Problem

One-time passwords became widely adopted because they provided an additional authentication factor beyond a static password.

For years, that represented a significant improvement in digital security. Even if a criminal obtained someone’s username and password, completing a transaction could still require access to a separate code sent to the customer’s registered mobile number.

But the threat environment has changed.

Attackers increasingly target the authentication process itself. Instead of attempting to break encryption or compromise a bank’s core systems, they manipulate customers into completing legitimate security procedures on the criminal’s behalf.

A convincing phishing site can request an OTP immediately after stealing login credentials. Social engineering calls can persuade customers that a verification code is needed to stop a fraudulent transaction. SIM swapping can potentially give an attacker control of the mobile number receiving the message.

In each case, the OTP may function exactly as designed.

That is precisely the problem.

A Code Doesn’t Explain What Is Being Approved

One of the fundamental weaknesses of traditional OTP authentication is its lack of context.

A customer receives a numerical code, but the authentication experience may provide limited information about the transaction associated with it. The customer is effectively being asked to prove possession of a communication channel rather than actively review the financial action being authorised.

Banks and payment providers are beginning to rethink that interaction.

Instead of sending a code outside the banking environment, an authentication request can be delivered directly into the authenticated banking or wallet application. The customer can then see information such as the merchant, transaction amount or type of request before deciding whether to approve it.

This is the approach behind stc pay’s new in-app transaction authentication capability in Bahrain, which replaces SMS and email OTPs for applicable online card transactions with approval inside its mobile application.

The distinction looks small from a user-experience perspective. From a security perspective, it is much more significant.

The question changes from “What is your code?” to “Do you recognise and approve this transaction?”

Authentication Is Moving Into the Banking App

Banking applications are increasingly becoming trusted authentication environments in their own right.

Modern smartphones provide banks with access to security capabilities that SMS was never designed to offer. Device binding, biometrics, cryptographic credentials, behavioural signals and secure application sessions can potentially be combined to determine whether an authentication request is legitimate.

That creates an opportunity to make authentication both stronger and easier.

A customer may receive an in-app notification showing the transaction details, authenticate using their fingerprint or face, and approve the payment without copying a numerical code between applications.

The bank, meanwhile, can potentially evaluate a much richer set of signals behind the interaction.

Is this a recognised device? Is the customer’s behaviour consistent with previous sessions? Is the transaction unusual? Has the device recently changed? Does the location or transaction pattern create additional risk?

Authentication can therefore become dynamic rather than identical for every transaction.

The Future Is Risk-Based, Not Friction-Based

Bank security has historically faced an uncomfortable trade-off: adding security frequently meant adding friction.

More passwords, additional questions and extra verification steps could make an account harder to compromise, but they could also make legitimate banking more frustrating.

Risk-based authentication offers a different model.

Instead of applying exactly the same security process to every customer and transaction, banks can use contextual signals to determine the appropriate level of verification.

A routine transaction from a trusted device might require very little additional interaction. A large payment from a newly registered device could trigger stronger authentication. An unusual combination of behaviour, location and payment destination might require additional verification or human intervention.

AI will increasingly strengthen this capability by allowing banks to analyse large volumes of behavioural and transaction data in real time.

The objective is not to remove authentication. It is to make authentication proportional to risk.

That could eventually make secure banking feel less intrusive for legitimate customers while creating more obstacles for criminals.

Fraud Is Becoming a Battle for Customer Intent

This shift also reflects a deeper change in financial crime.

Many modern scams do not require criminals to technically bypass bank security. They persuade the customer to authenticate the transaction themselves.

Authorised push payment fraud is an obvious example. A customer may genuinely log into their bank, pass authentication and transfer money, but do so because a criminal has manipulated them into believing the payment is legitimate.

An OTP cannot solve that problem because the customer possesses the correct code.

Authentication systems therefore need to become better at understanding intent and context rather than simply verifying credentials.

That could mean showing clearer transaction information, introducing warnings when behaviour resembles known scam patterns, using behavioural analytics to detect unusual interactions or adding friction selectively when the risk is unusually high.

The strongest authentication system may eventually be the one that asks not only “Is this the customer?” but also “Does this transaction make sense for this customer?”

SMS Still Has Advantages Banks Cannot Ignore

None of this means OTPs will disappear quickly.

SMS remains universally accessible, familiar to customers and independent of whether someone has the latest version of a banking application installed. It can also provide an important fallback authentication channel.

Banks operating across diverse customer populations cannot assume that every customer has the same smartphone, connectivity or level of digital confidence.

Replacing OTPs therefore requires more than introducing push notifications.

Banks need resilient alternatives for customers who lose devices, change phones, travel internationally, have limited connectivity or cannot use biometric authentication. Recovery processes are particularly important because criminals frequently target account recovery as the weakest point in otherwise sophisticated security systems.

There is also a concentration consideration. Moving authentication into the mobile banking application makes that application an even more important security boundary.

Banks will need to protect it accordingly.

Authentication Is Becoming Part of Digital Banking Strategy

The move beyond OTPs should not be viewed purely as a cybersecurity project.

Authentication sits directly inside the customer experience.

Every additional verification step affects how easily customers can pay, transfer money, open products and interact with digital banking services. Poorly designed security creates abandonment and frustration. Weak security creates fraud and destroys trust.

The two objectives increasingly have to be designed together.

This is why authentication is likely to become an increasingly important part of digital banking differentiation. Customers may never choose a bank because of its authentication architecture, but they will notice when security is confusing, inconvenient or repeatedly interrupts legitimate activity.

They will notice even more when it fails.

What it means for the industry

  • OTPs will remain, but their role will diminish. SMS authentication still provides accessibility and fallback value, but banks are increasingly building richer authentication methods around trusted applications and devices.
  • Transaction context will matter more than possession of a code. Showing customers exactly what they are approving can make authentication more meaningful and potentially harder to manipulate.
  • Risk-based authentication can reduce unnecessary friction. Banks can apply stronger verification to unusual activity while allowing lower-risk interactions to remain relatively seamless.
  • Mobile banking apps are becoming security platforms. Device intelligence, biometrics and behavioural signals give banks authentication capabilities that SMS alone cannot provide.
  • Fraud prevention will increasingly focus on intent. Confirming identity is no longer sufficient when criminals can manipulate legitimate customers into authorising fraudulent transactions.
  • The replacement for OTPs will not be one technology. The future is likely to combine device security, biometrics, behavioural analytics, transaction intelligence and adaptive authentication rather than relying on another universal security step.
Notice an error or have additional information about this story? Contact the Finnoex newsroom: newsroom [at] finnoex [dot] com.

Discover more from Finnoex

Subscribe now to keep reading and get access to the full archive.

Continue reading