2023-08-14
Added · Updated
The Central Bank of Jordan mandates that banks and mobile payment service companies implement specific identity verification controls for customers activating or reactivating accounts on electronic channels. These requirements include verifying at least three pieces of data across personal, account, and card categories, utilizing One-Time Passwords or biometrics, and restricting authorized device access to a maximum of three non-simultaneous devices. Institutions must also enforce periodic OTP verification every 90 days, monitor for unusual login activity, and regularize their compliance within six months of the circular's issuance.
Central Bank of Jordan
Number: 10/6/1459 Date: 27/1/1445 AH Corresponding to: 14/8/2023 AD
Circular to: Banks operating in the Kingdom Mobile Payment Service Companies
Subject: Mechanism for activating accounts on electronic channels
In the context of the Central Bank's regulation and development of the National Payments System to ensure the provision of safe and efficient payment and transfer systems and channels in the Kingdom, and given the increasing use of customers for electronic channels in various fields, I request you to confirm the necessity of implementing the following procedures and controls as a minimum:
First: When a customer creates an account on one of the electronic channels (for example, but not limited to: mobile application, internet banking, etc.) or reactivates their account on them, or in the event of recovering/changing the customer's username or recovering the customer's password through these channels, or when accessing them from a device other than those stored in your records, you must verify the customer's identity by activating the following controls:
Request at least three pieces of information from the following data categories, ensuring that at least one piece of information is included from each category and matching it with the data registered with you: a. The customer's personal data, for example, but not limited to (National ID/Passport number for non-Jordanians, date of birth, document number, document expiry date). b. Account-related data, for example, but not limited to (bank account number, International Bank Account Number (IBAN), customer's PIN code). c. Banks are committed to requesting payment card-related data, for example, but not limited to (payment card number, CVV number), followed mandatorily by the customer's PIN code. Mobile payment service companies have the option to apply this clause if cards are linked to e-wallets.
After verifying and matching the data specified in Clause (First/1) above, a One-Time Password (OTP) is sent to the customer on their phone number registered in your records. If the customer has biometric features, you may request biometrics from the customer without the need to send a One-Time Password (OTP).
Central Bank of Jordan CENTRAL BANK OF JORDAN
Second: When a customer changes their registered phone number with you by using one of the electronic channels, and for the purpose of verifying the customer's identity, this requires initially following the procedures stipulated in Clause (First/1) above, and then sending a One-Time Password (OTP) to the new number for the customer, in addition to sending a Short Message Service (SMS) to their old number to inform them of the change of their registered phone number with you, as well as sending an email to the customer according to the email registered in your records - if available - to inform them of the change.
Third: In the event of allowing the customer to access their account on more than one device, a One-Time Password (OTP) must be sent when accessing the account from an unrecognized device with you. An SMS message must be sent to inform the customer of the attempt to access the account from another device. In addition, you must set a maximum limit for the number of devices authorized to access the account so that it does not exceed three devices, and not allow simultaneous access. You must also enable the customer to manage access to authorized devices through their account.
Fourth: You must monitor the effectiveness of customers' phone numbers linked to their accounts and periodically verify the effectiveness of using electronic channels through the same phone number registered with you. This is done by obliging customers to enter a One-Time Password (OTP) at a maximum interval of (90) days when accessing their accounts on electronic channels. A grace period of up to (30) days will be determined after the (90) days have passed, during which a One-Time Password (OTP) will be sent for any login attempt by customers on their accounts before the account status becomes "inactive." Customers will then need to reactivate their accounts through the controls mentioned in Clause (First) above to reactivate the accounts.
Fifth: You must periodically review customers' login processes to their accounts on electronic channels and document the results of the review. This is to ensure that electronic channels are not used by non-customers and to detect any unusual usage attempts based on customer behavior and activity, for example, but not limited to (reports of repeated failed login attempts by customers on their accounts, reports of using electronic channels from multiple geographic locations, reports of repeated phone number changes in relatively short time periods, etc.) and taking the necessary measures.
Sixth: You are committed to regularizing your status in accordance with the provisions of this circular within a period not exceeding (6) months from the date of its issuance.
Please accept our highest regards,
The Governor Dr. Adel Al-Sharkas
Form (1/1) - 09/01