The State Bank of Pakistan (SBP) has introduced new measures to strengthen the security of digital financial transactions across mobile apps and internet banking portals. Banks and microfinance banks (MFBs) must replace SMS-based one-time passwords (OTPs) with Transaction PINs (TPINs) or Financial PINs (FPINs) by January 1, 2025.
In addition, SBP has directed banks to offer free transaction alerts through push notifications, in-app notifications, and email alerts instead of relying on SMS. This initiative aims to provide greater convenience and reduce vulnerabilities associated with SMS-based authentication, which fraudsters often exploit.
Enhanced Notification System
SBP has mandated that banks keep in-app and push notifications permanently enabled on mobile banking apps. Financial institutions must also maintain detailed logs of transaction alerts and provide them during dispute resolution or customer claims.
“The notifications on mobile apps must remain active at all times, ensuring customers are informed about their transactions. Banks must also preserve detailed logs to address disputes or fraud cases,” the SBP circular emphasized.
Standardized Alerts and Consumer Protection
The regulator has introduced uniform templates for transaction notifications, replacing earlier guidelines from May 2018. Banks and MFBs are also held accountable for reimbursing customers in cases of fraud or unauthorized transactions under the liability framework established in 2023.
Implementation Timeline
The updated guidelines will take effect on January 1, 2025, giving financial institutions ample time to comply with these changes. This directive reflects SBP’s commitment to enhancing cybersecurity and safeguarding consumers as digital banking evolves.



