← All updates

UAE REGULATORY UPDATE · BANKING / AML

Central Bank of the UAE: SMS and email one-time passcodes withdrawn in favour of in-app and biometric authentication

The Central Bank of the UAE has required licensed financial institutions to withdraw one-time passcodes sent by SMS and email by 31 March 2026, replacing them with biometric verification and in-app approval. Account holders whose UAE mobile number is no longer active, or who never configured the banking app, may find they have no way to authorise a transfer.

What happened

The Central Bank of the UAE (CBUAE), the federal regulator for banks and payment institutions, has directed banks, finance companies, exchange houses, insurers and payment service providers to withdraw authentication by one-time passcode (OTP) sent via SMS and email by 31 March 2026. An OTP is the single-use code that has until now been delivered to a mobile number or mailbox to confirm a transaction. From 6 January 2026 the major UAE banks had already disabled SMS OTPs for online card payments and digital banking. The replacement methods are biometric verification, approval within the bank's own application, and soft tokens generated on a registered device.

What changes in practice

Authorisation no longer travels through a message that can be received on any handset in any country. It runs through a specific enrolled device with the bank's application installed and biometrics configured. Account holders who relied on SMS precisely because they had never activated the app now have no second factor and therefore no means of releasing a payment. Restoring access from outside the UAE is not immediate: several banks require either attendance at a branch or verification against a UAE mobile number that is still live — the same number that is often the one that has lapsed.

Who it applies to

All holders of accounts at UAE-licensed institutions, both individuals and corporate entities. The practical difficulty concentrates on non-resident directors and shareholders who operate a UAE account remotely, on account holders who allowed the UAE SIM card to expire after the relationship was opened, and on companies where the authorised signatory is based abroad while the enrolled device sits with someone else. Corporate accounts with multiple signatories should assume that each signatory needs to be checked separately.

The exposure

The exposure is one of timing rather than principle. Entities with a financial year ended 31 December 2025 must file and pay corporate tax by 30 September 2026, and the payment leaves the same account. Discovering in that week that a transfer cannot be authorised means missing a deadline that carries monthly penalties, for a reason that has nothing to do with tax. Reinstating authentication credentials from abroad typically takes days rather than hours, and in a number of cases cannot be completed remotely at all.

What to do now

Run three checks now rather than in September. First, confirm that the UAE mobile number registered against the account is still active and able to receive messages. Second, confirm that the bank's application is installed on the handset actually in use, with biometric access working. Third, execute a genuine low-value transaction to verify that authorisation completes end to end — a successful login is not the same as a successful payment authorisation. Where any of the three fails, open the update request immediately, since remediation takes time and, in several institutions, a branch visit. For corporate accounts, repeat the test for every authorised signatory.

Sources

Published 18 August 2026 on the basis of public sources and official United Arab Emirates instruments. This is not legal or tax advice. Verify your position with a qualified professional before acting.