2023-08-14
Added · Updated
The Central Bank of Jordan mandates that banks and mobile payment service companies implement specific identity verification controls for customers creating, reactivating, or accessing electronic channels. Providers must verify identity using at least three data pieces from distinct categories, send OTPs or use biometrics, and enforce a maximum limit of three authorized devices per account. Additionally, institutions must validate phone numbers via OTPs every 90 days, monitor for suspicious activity, and regularize their status within six months of the circular's issuance.
10/6 / 14206 27 /1 /1445 AH 14 / 8 /2023 AD
Circular to: Banks operating in the Kingdom Mobile Payment Service Companies
Subject: Mechanism for Activating Accounts on Electronic Channels
In the context of the Central Bank's regulation and development of the National Payments System to ensure the provision of safe and efficient payment, transfer, and channel systems in the Kingdom, and given the increasing use of customers for electronic channels in various fields, please confirm the necessity of implementing the following procedures and controls as a minimum:
First: When a customer creates an account on one of the electronic channels (for example, but not limited to: mobile application, internet banking, etc.) or reactivates their account on it, or in the event of recovering/changing the customer's username or recovering the customer's password through these channels, or when accessing from another device not stored in your records, you must verify the customer's identity by activating the following controls:
Request at least three pieces of information from the following data categories, ensuring that at least one piece of information is included from each category and matching it with the data registered with you:
After verifying and matching the data specified in Clause (First/1) above, send a One-Time Password (OTP) to the customer on the phone number identified in your records. If the customer has biometric features available, you may request biometric verification from the customer without the need to send a One-Time Password (OTP).
Second: When a customer changes the phone number registered with you by using one of the electronic channels, and for the purpose of verifying the customer's identity, this requires initially following the procedures stipulated in Clause (First/1) above, and then sending a One-Time Password (OTP) to the new number for the customer. Additionally, send a Short Message Service (SMS) to their old number to inform them of the change of their identified phone number with you, as well as send an email to the customer according to the email address identified in your records (if available) to inform them of the change.
Third: In the event of allowing the customer to access their account on more than one device, a One-Time Password (OTP) must be sent when accessing the account from an unidentified device with you. An SMS message must be sent to inform the customer of the attempt to access the account from another device. Additionally, you must set a maximum limit for the number of authorized devices allowed to access the account, which shall not exceed three devices, and not allow simultaneous access. You must also enable the customer to manage access for authorized devices through their account.
Fourth: You must monitor the validity of customers' phone numbers linked to their accounts and periodically verify the validity of using electronic channels through the same phone number identified with you. This is done by requiring all customers to enter a One-Time Password (OTP) at a maximum interval of (90) days when accessing their accounts on electronic channels. A grace period of up to (30) days will be determined after the (90) days have passed, during which a One-Time Password (OTP) will be sent for any login attempt by customers on their accounts before the account status becomes "inactive." Customers will then need to reactivate their accounts through the controls mentioned in Clause (First) above to reactivate the accounts.
Fifth: You must periodically review customers' login processes to their accounts on electronic channels and document the review results. This is to ensure that electronic channels are not used by non-customers and to detect any unusual usage attempts based on customer behavior and activity. Examples include (reports of repeated incorrect login attempts by customers on their accounts, reports of using electronic channels from multiple geographic locations, reports of repeated phone number changes within relatively short time periods, etc.) and taking the necessary measures.
Sixth: You are committed to regularizing your status in accordance with the provisions of this circular within a period not exceeding (6) months from the date of its issuance.
Please accept our highest respect,
The Governor Dr. Adel Al-Sharkas