UAE banks race to replace OTPs as new fraud rules take effect
Rob Woods from LexisNexis Risk Solutions: UAE banks must rethink fraud prevention in the social-engineering era
11 March, 2026
TT
16
New regulations from the Central Bank of the UAE (CBUAE), set to take effect by the end of March 2026, are forcing financial institutions to rethink how they authenticate customers and detect scams in real time.
At the centre of the shift is the planned elimination of SMS and email-based one-time passwords (OTPs), long considered the default layer of authentication across digital banking platforms. According to Rob Woods, senior director, fraud and identity at LexisNexis Risk Solutions, the move reflects a recognition that these methods no longer offer sufficient protection.
“One-time passwords delivered via either email or SMS have long been considered weak and open to exploitation by fraudsters, yet they became the default authenticator method mainly because they’re relatively easy, quick and widely available,” Woods says.
The problem lies in how easily those channels can be compromised. “They are considered weak because it’s fairly easy for a fraudster to gain access to an email account or do a SIM swap and intercept the OTP,” he explains. In contrast, mobile-based authentication tied directly to banking applications offers stronger security and lower operational cost.
“Mobile apps are the obvious alternative, offering more secure, cheaper authentication via the banking/payment app/wallet and that’s why the CBUAE is leading the way globally to push for this change, to protect consumers.”

The rise of social engineering
The regulatory shift comes at a time when impersonation scams and social engineering attacks are surging across the region. Rather than hacking systems directly, fraudsters increasingly manipulate victims into authorising fraudulent transactions themselves.
“Scams are all about manipulating the victim to participate in the fraud and unknowingly authorise the fraudulent payment themselves,” Woods says.
In many cases, the victim believes they are protecting their account or making an urgent investment. Because the real customer is logging in and entering credentials, traditional security checks often fail to detect malicious intent.
“By persuading the customer to make the payment, the fraudster is effectively bypassing all of the checks and security in place,” Woods explains. “It’s the genuine customer logging in, authenticating themselves, entering the OTPs and navigating through the app.”
That dynamic makes prevention significantly more complex. Detection must occur before the payment is authorised, not after. Advances in behavioural analytics and contextual risk intelligence are increasingly becoming the key tools for identifying suspicious activity early.
“Only with the more recent developments in behavioural analytics and contextual risk intelligence can the malicious intent be surfaced earlier and the payment stopped.”
Detecting scams in real time
The new CBUAE rules also encourage banks to deploy capabilities such as active call detection and screen-sharing detection—technologies designed to identify common patterns associated with social engineering attacks.
“Active Call is a means of detecting whether the customer is on a live phone call whilst they are logging into their banking app or making a payment,” Woods explains.
This matters because many impersonation scams involve criminals coaching victims through transactions step by step during a phone call. The presence of an active call during a sensitive banking interaction can therefore serve as a powerful risk signal.
Screen-sharing detection offers another layer of defence. “Screen sharing is typically not something used in genuine banking sessions and is therefore, again, a reliable indicator of risk,” Woods notes.
Together, these signals allow financial institutions to detect fraud scenarios that traditional authentication methods would miss.
Beyond device verification and authentication tokens, banks are increasingly turning to behavioural biometrics to differentiate legitimate users from fraudsters.
“Behavioural Intelligence like BehavioSec is a valuable tool in helping to spot the difference between genuine customer behaviour and manipulated behaviour, imposters or automated BOTs,” Woods says.
Behavioural biometrics analyse how users interact with their devices—their typing patterns, navigation habits, and interaction signals. Once a baseline profile is established, deviations from that pattern can indicate compromised accounts or malicious activity.
“By pre-determining the typical patterns of how a genuine individual interacts with their device through the signals it produces, variances in that behaviour can help to detect when an account might be compromised.”
This approach moves fraud prevention beyond static credentials toward continuous verification.
While larger banks have already begun investing heavily in advanced fraud prevention frameworks, smaller financial institutions may face greater challenges as the March deadline approaches.
“Smaller organisations may have smaller fraud prevention teams and budgets to deploy fraud controls and smaller operations teams managing customer fraud cases,” Woods says.
However, he notes that smaller institutions also have an advantage: agility. With the right technology partners, they can implement integrated fraud prevention systems relatively quickly.
“If they invest in an enterprise fraud prevention provider who can deliver a one-stop shop of intelligence, prevention and authentication capabilities, the smaller, more agile financial institution may be able to deliver a robust fraud control framework more quickly.”
Technology alone will not solve the problem. As fraudsters increasingly target younger users through social media phishing campaigns and romance scams, customer awareness is becoming just as important as technical defences.
“Customer education needs to be engaging and targeted via multiple channels and access points to hit all possible demographics,” Woods says.
Traditional approaches—such as information pages buried deep within websites—are no longer effective. Instead, banks must engage customers through campaigns, social media and other channels that mirror how fraudsters reach their victims.
“A customer education page buried deep in a website is no longer enough,” he adds.
Balancing security with customer experience
As banks transition toward biometric and risk-based authentication, maintaining seamless user experience remains a major challenge.
“Customer experience sits at the heart of any financial institution’s transformation programme, but it must be balanced with strong fraud controls,” Woods explains.
The difficulty lies in coordinating fraud detection across multiple customer touchpoints—from mobile apps and telephony systems to branch networks and payment terminals.
“How to pool, aggregate and coordinate intelligence across all of these touch points to make intelligent customer centric but secure risk decisions is not easy,” he says.
Ultimately, the institutions that treat fraud prevention as a strategic capability rather than a compliance exercise may gain a significant competitive edge.
“Trust is perhaps the most valuable commodity for customers,” Woods says.
Financial institutions that protect customers effectively—and support them if fraud occurs—tend to build stronger, longer-lasting relationships.
“Across the globe, we have seen organisations that are best at supporting and protecting their customers, are the ones that thrive,” Woods explains. “Those that compromise on safety, lose customers and suffer from issues with regulators.”
As digital banking becomes the norm across the UAE and the wider Middle East, the battle against fraud is shifting from passwords and codes to behavioural intelligence, risk signals, and ecosystem-wide coordination.
For banks navigating the next phase of digital transformation, security may no longer be just a defensive necessity. It could become a defining pillar of customer trust—and long-term competitiveness.

























