UAE banking explained: How online payment verification works without SMS OTPs
Dubai: UAE banks are moving away from traditional SMS and email-based One-Time Passwords (OTPs) , with secure in-app approvals and biometric verification becoming the preferred way to authenticate online payments. The shift followed guidelines from the Central Bank of the UAE (CBUAE) , which required banks to phase out traditional authentication methods by March 31, 2026 . Many UAE banks began…
UAE banks are increasingly relying on in-app approvals and biometric verification for online payments, instead of traditional SMS and email-based OTPs. This change came after the Central Bank of the UAE (CBUAE) mandated banks to phase out old authentication methods by March 31, 2026. Many banks began implementing these new systems in 2025, while others are still introducing them.
When making an online purchase, you might no longer receive an SMS with a one-time password. Instead, you may need to approve the transaction through your bank’s official mobile app. Upon entering your card details, a payment screen may prompt you to confirm the transaction via the app. You might find the payment awaiting approval in sections like ‘Activities’ or ‘Pending Transactions’ within the app. Depending on the bank, you may need to access an ‘Approve Transaction’ option after opening the payment.
Biometric verification, such as fingerprint or facial recognition, is commonly used in UAE banking apps to confirm transactions. If you haven’t registered your biometrics, you may first need to set this up in the app. Some banks may also require a digital PIN or other security feature before you can use in-app transaction approvals. For instance, Dubai Islamic Bank (DIB) currently offers customers the choice between an SMS OTP or in-app approval using either facial recognition or fingerprint authentication.
Once you approve a payment in your bank’s app, you’ll be asked to verify your identity using your registered biometric or security PIN. After authentication, the transaction is authorized without needing an SMS OTP. However, the exact process may vary between banks. Some might require biometric registration, while others may use a Smart Pass PIN or additional security steps.
Customers should follow their bank’s instructions displayed in the official mobile app or contact the bank if unsure about activating or using the new authentication method. SMS and email OTPs are being replaced as they are more susceptible to interception and fraud. Techniques like SIM swapping and phishing attacks can compromise these OTPs.
In-app authentication and biometric verification are designed to offer stronger security by keeping the approval process within the bank’s secure mobile application. The UAE Central Bank has also banned the use of WhatsApp and other messaging apps for financial customer communications and is piloting facial and palm biometric payments as part of its anti-fraud security measures.
Written by urgent.news from Gulf News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.