From AFASA to BSP Circulars 1213 – 1215: SAVYINT Partners with Philippine Banks to Strengthen Security and Fight Digital Fraud 

From AFASA to BSP Circulars 1213–1215 Savyint Partners with Philippine Banks to Strengthen Security and Fight Digital Fraud

The rapid growth of digital banking, e-wallets, and online payments in the Philippines has led to a serious consequence – financial fraud is becoming increasingly sophisticated and more organized. Following the enactment of AFASA, the Bangko Sentral ng Pilipinas (BSP) continued to issue BSP Circulars 1213, 1214, and 1215, tightening the responsibilities of financial institutions and imposing stricter requirements for user authentication, fraud management, and data protection.  About AFASA and BSP Circulars 1213, 1214, and 1215  Officially taking effect on June 25, 2025, the Anti-Financial Account Scamming Act (Republic Act No. 12010) was enacted by the Philippine government with the following core objectives:  One of the most important requirements under AFASA is the mandatory transition of authentication methods before June 2026. OTPs sent via SMS and email will no longer be accepted for high-risk transactions. Instead, more secure methods must be implemented, such as biometric authentication, passwordless authentication, and adaptive multi-factor authentication (MFA) based on risk levels.  AFASA marks a major shift in risk management thinking: account security is no longer just a technology choice – it is now a legal obligation.  BSP Circular 1213 – Focus on Fraud Management and Strong Authentication  Among the three circulars, BSP Circular 1213 is considered the technical backbone that brings AFASA into real operational practice.  This circular requires banks and financial institutions to:  BSP Circular 1213 clearly states that traditional authentication methods are no longer sufficient. Systems must understand user behavior patterns and detect fraud at the earliest stages – during login or even before a transaction is completed.  Read more: Philippines BSP Circular No. 1213 and Compliance Solutions for Financial Institutions BSP Circular 1214 – Enabling Data Sharing for Faster Fraud Response  BSP Circular 1214 addresses a major legal bottleneck related to accessing account data during fraud investigations. Its main goal is to create a fast-response mechanism to prevent funds from being completely withdrawn before authorities can intervene.  Under this regulation:  BSP Circular 1215 – Protecting Funds During Disputes  While Circular 1213 focuses on prevention and 1214 focuses on investigation, BSP Circular 1215 addresses what happens after an incident occurs. It allows financial institutions to protect customer funds during the investigation period, preventing money from “disappearing” within minutes.  Specifically, this circular:  Together, AFASA and BSP Circulars 1213, 1214, and 1215 are reshaping the digital financial security standards in the Philippines. Financial institutions now need not only compliance documentation but also a strong technology foundation capable of detecting, preventing, and responding to fraud in real time.  AFASA & BSP 1213, 1214, 1215 – Compliant Security Solutions from SAVYINT Savyint is a leading trusted service provider, ready to deliver authentication and payment security solutions that strictly comply with security standards and regulatory requirements under AFASA, BSP Circulars 1213, 1214, and 1215 issued by the Bangko Sentral ng Pilipinas (BSP), as well as the Philippine Open Banking framework and international regulations.  Savyint’s solution ecosystem is built around four key pillars: Risk Management & Compliance, Cybersecurity & Application Protection, SCA/MFA Identity, and the FMS AI Fraud Engine. Together, these components protect the entire customer journey – from registration, login, authentication, and transaction execution to post-transaction monitoring.  SAM Auth Server  SAM Auth Server is an all-in-one strong authentication solution designed for mobile payments and digital banking.  Built on a Zero Trust architecture and integrated with a FIPS 140-3 Level 3 certified Hardware Security Module (HSM), and ready for Post-Quantum Cryptography, SAM Auth Server supports a wide range of modern authentication methods, including: Biometric authentication, Smart OTP, Push Authentication, FIDO2 / Passkeys and Context-based authentication  It enables step-up authentication when risk levels increase, ensuring maximum protection for electronic transactions.  SAM FIDO2 Identity Server  SAM FIDO2 Identity Server is a passwordless identity and authentication platform based on FIDO2/WebAuthn standards. It eliminates password storage by replacing passwords with asymmetric key-based authentication securely stored on the user’s device.As a result, the system effectively protects against common attacks such as phishing, man-in-the-middle attacks, and credential stuffing.  SAM FIDO2 Identity Server fully meets Strong Customer Authentication (SCA) requirements under PSD2/PSD3 and complies with international standards for identity and data security.  SAVYINT Fraud Prevention & Risk Management  SAVYINT Fraud Prevention & Risk Management leverages AI and Machine Learning (ML) to help banks and financial institutions detect, assess, and prevent fraud across the entire user journey – from login behavior, device characteristics, and access context to transaction data. Key capabilities include:  RASP+  RASP+ protects mobile applications directly within the runtime environment, detecting and blocking attacks while the application is running. It can detect rooted or jailbroken devices, debugging attempts, code tampering, hooking techniques, memory manipulation and emulator-based attacks.   RASP+ integrates directly into mobile applications without affecting performance, ensuring strong protection without compromising user experience.  TrustShield  TrustShield is a mobile fraud prevention platform powered by device fingerprinting, behavioral analytics, and AI. It can identify devices without relying on cookies or advertising IDs, detect emulators, rooted or jailbroken devices, identify multi-device fraud patterns, analyze in-app user behavior, generate real-time risk scores and trigger adaptive authentication directly on mobile devices.   With a multi-layered architecture and seamless integration capabilities, Savyint’s security ecosystem delivers a comprehensive fraud prevention model – protecting devices, behavior, identity, and transactions simultaneously.  All solutions comply with AFASA, BSP Circulars 1213, 1214, 1215, and international standards such as FIDO2, PSD2/PSD3, eIDAS, GDPR, and PCI DSS. This allows fast deployment on existing infrastructure while achieving the highest level of security.  Connect with Savyint’s experts today to implement and optimize your security solutions – and be fully prepared to meet AFASA and BSP requirements within just 3 months! 

SAVYINT YEAR-END PARTY 2025 | RE:IMAGINE – REDEFINING DIGITAL TRUST FOR THE GLOBAL STAGE

Closing 2025 with pride and opening a new chapter of aspiration, Savyint gathered for its year-end party under the theme “RE:IMAGINE.” More than a celebration, this event served as a strategic milestone, declaring a bold vision to conquer the APAC and MENA markets in 2026. A Global Vision with Strong Roots With its office located in Australia, Savyint serves as a beacon of technological excellence, seamlessly connecting world-class R&D with practical, high-scale deployment. With a core team comprising top Australian and Vietnamese talent, Savyint operates a dual R&D structure in Sydney and Vietnam, supported by a robust service center in Vietnam and business centers strategically located across Hanoi, HCMC, Singapore, the Philippines, Dubai, Sydney, and the EU. The “REIMAGINE” theme signifies a major strategic pivot. It is a commitment to breaking familiar boundaries and creating distinctive value on a global scale. As Executive Chairman Steve Huang emphasised during the opening speech, amidst a rapid global digital transformation, Savyint is steadfast in mastering core technologies to meet the most stringent international standards. The 2026 Strategy focuses on Advanced Technology and Zero Trust Moving into 2026, Savyint is restructuring its strategic focus to deepen its expertise in cutting-edge domains. The group is well-positioned to take the lead in the following areas: At the heart of this strategy is the Zero Trust Framework. Savyint positions itself as a pillar of digital trust, ensuring absolute safety in payment transactions and cryptocurrency dealings, while providing a total fraud prevention mechanism. Compliance: The Competitive Edge Savyint distinguishes itself not just by technology but by rigorous adherence to global and local compliance standards. Savyint’s solutions are engineered to comply with a comprehensive matrix of regulations: This dedication ensures that Savyint acts as a secure bridge for enterprises as they navigate the complicated regulatory landscapes of APAC and MENA. Highlighting this success, SAM Enterprise Appliance was honoured as the “Product of the Year”. Already successfully deployed in major financial institutions like Agribank, BIDV, Sacombank, and Bac A Bank, this solution recently won at APICTA 2025 (the “Oscars” of Asia-Pacific ICT), affirming Savyint’s ability to compete on the international stage. Reaching the Open Seas The Year End Party 2025 concluded not just with festivities but with a unified spirit of determination. The Savyint team’s energy – from the R&D engineers to the business units – reflected a readiness to step into the “Open Seas”. With a redefined strategy, a footprint stretching from Sydney to Dubai, and a portfolio of certified, high-security solutions, Savyint Group is ready to dominate the competitive landscape of 2026, delivering uncompromised Digital Trust to the world. Highlights at the event: