Diaryo
4notify Philippines · Official Gazette
OFFICIAL · BSP · InstaPay · PESONet · QR Ph
Diaryo No
DRY-PH-001
Date
2026-05-27
Status
In force
Category
Banking and payments

Strong customer authentication for BDO, BPI, Metrobank, Landbank and UnionBank: OTP delivery on InstaPay, PESONet and QR Ph

The Bangko Sentral ng Pilipinas (BSP) runs the National Retail Payment System; InstaPay clears in real time, PESONet clears in batches, and QR Ph is the unified QR standard. Every banking-app login and every fund transfer asks for a one-time PIN. 4notify delivers OTPs with P50 under 4 seconds across Globe, Smart and DITO over direct tier-1 routes, so the code arrives well inside the 60-second window.

SMSPushEmail
Preamble

Whereas, pursuant to the provisions of Republic Act No. 7653 (The New Central Bank Act, as amended by RA 11211) and BSP Circular 1140 (National Retail Payment System), the present Diaryo is issued on the delivery of strong customer authentication OTPs over the Philippine mobile networks.

Statutory basis
RA 7653 / RA 11211 — The New Central Bank Act

Statutory basis of the BSP and its mandate over the national payments system.

BSP Circular 1140 — National Retail Payment System

Framework for InstaPay, PESONet and QR Ph as the country's real-time payment rails.

RA 8791 — General Banking Law of 2000

Duty of supervised entities to apply multi-factor authentication on electronic channels.

Implementation
01

NTC accreditation + direct tier-1 routing

4notify is accredited with the NTC as a content provider and holds direct tier-1 routes with Globe, Smart and DITO for authentication traffic.

02

OTP generated inside the bank's HSM

The one-time PIN is generated inside the bank's hardware security module; 4notify only receives the hash plus the mobile number.

03

60-second window with a fallback chain

SMS clears under 60 seconds; on a failed delivery report the chain falls through to push and then to email. No grey-route delays.

04

Five-year audit custody

Each delivery is signed and retained for five years, in line with BSP and AMLA reporting requirements.

Delivery envelope
json
{
  "event": "bank.instapay.otp",
  "bank_id": "PH-BDO",
  "transaction_id": "TX-2026-05-27-948210",
  "amount": 12500.00,
  "currency": "PHP",
  "rail": "instapay",
  "delivery": {
    "channel": "sms",
    "fallback": ["push", "email"],
    "window_seconds": 60,
    "template": "instapay_otp_ph_v3"
  },
  "audit_signature": "https://4notify.net/sig/bank/948210"
}
Sample message
SMS

BDO: your code to confirm InstaPay transfer of PHP 12,500 to J. Reyes is 482193. Valid for 5 minutes. Do not share it with anyone.

Compliance checklist
  • NTC content-provider accreditation current
  • Direct tier-1 routing with Globe, Smart and DITO active
  • OTP P50 ≤ 4 seconds measured quarterly
  • Five-year audit custody documented for AMLA reviews
The 4notify difference

4notify is the only A2P provider with simultaneous direct tier-1 routing on Globe, Smart and DITO and a signed five-year audit trail for strong customer authentication aligned with BSP Circular 1140 and the AMLA.

Frequently asked questions
Does 4notify deliver direct to Philippine banks or through an aggregator?

Direct tier-1 connectivity with Globe, Smart and DITO. No grey-route aggregation for authentication traffic.

Do push notifications count as a second factor?

Yes — an app-bound push is a recognised possession factor. But because the app does not guarantee a durable medium, we always pair it with SMS or email.

Issued
4notify Operations Department
2026-05-27 · DRY-PH-001

Start free

14 days, no card. English-speaking support on weekdays.

Other entries in this issue