2021-10-05
Added · Updated
The Hong Kong Monetary Authority issued this circular to recommend that authorized institutions adopt enhanced authentication and fraud prevention controls for Simplified Electronic Direct Debit Authorizations. The guidance mandates that payee banks implement two-factor authentication, send SMS one-time passwords, and verify customer details with payer banks to mitigate impersonation and unauthorized access risks. Additionally, the regulator advises restricting transfers to same-name accounts, setting transaction limits, and requiring payer banks to send additional notifications for subsequent debits to strengthen overall security.