Biometric Authentication to Make PHL Financial Services 'Phishing-Resistant'
Key Takeaways
- •Many Philippine banks have shifted from OTPs to biometric, behavioral, adaptive, or password-less authentication to meet BSP requirements under the Anti-Financial Account Scamming Act.
- •iProov’s chief technology officer said SMS OTPs are insecure and that biometrics provide a stronger security factor.
- •The company uses Dynamic Liveness and more than 20 neural networks to detect deepfakes, manipulated imagery, and digital playback.
- •iProov processes between 1.5 million and 2 million transactions daily and monitors more than 130 criminal forums for threat intelligence.
- •The system is designed to work across skin tones, ethnicities, and older mobile handsets while keeping the login process simple for users.

Biometric authentication can make online financial services more secure against evolving cyberthreats as the Philippines continues to record growth in digital transactions, according to identity verification service provider iProov.
Many Philippine financial institutions have already replaced one-time passwords (OTPs) with stronger authentication technologies — biometric, behavioral, adaptive, or password-less solutions — to comply with Bangko Sentral ng Pilipinas (BSP) rules issued in accordance with the Anti-Financial Account Scamming Act, or Republic Act No. 12010.
Dominic Forrest, chief technology officer of iProov, called this a welcome development, noting that OTPs are “very well known” to be insecure.
“Biometrics provide a far stronger security factor than SMS OTP ever can,” Mr. Forrest told BusinessWorld in an online interview.
His remarks come as cybercriminals deploy increasingly sophisticated fraud methods, using deepfakes and generative artificial intelligence (AI) to intercept traditional authentication systems, adding pressure on banks and other financial firms to harden login and transaction checks without making services harder to use.
“The biggest challenge is that criminals will always adapt and, because they are not bound by the same regulations banks must follow, they can move faster,” Mr. Forrest said.
He described biometrics as a truly “phishing-resistant” technology because, unlike a code or token, a user cannot share their face.
Liveness checks and layered defense
To counter deepfakes, iProov uses liveness checks to confirm that a user is a “real person, right person, and present right now.” This is achieved through a process called Dynamic Liveness, in which the device screen changes colors to observe how light reflects off the user’s face. The video is then analyzed by more than 20 neural networks to detect signs of manipulated imagery or digital playback.
Mr. Forrest said the company also provides a layered defense strategy to fend off attackers. By passing every transaction through multiple AI networks, the system creates “information asymmetry,” where defenders learn from every attack while criminals receive no feedback on why they failed.
“This setup is deliberately completely unfair to the criminals. They have no data, while defenders have vast amounts of data to defend against them, making it not a fair competition and allowing the system to learn a lot while attackers get no useful feedback,” Mr. Forrest said.
iProov sees between 1.5 million and 2 million transactions daily, he said. The platform is updated regularly, similar to anti-virus software, learning from global attack patterns through a dedicated threat intelligence arm that monitors more than 130 criminal forums on the dark web and the messaging app Telegram.
Because biometric imagery is often deleted after a short period to protect privacy, iProov maintains technical metadata consisting of floating-point numbers generated by its neural networks. This data allows the company to reconstruct the state of the platform at any time and to provide regulators and banks with detailed audit trails.
Seamless and inclusive by design
For the everyday user, the goal is to make high-level security transparent. The authentication process typically requires a user to hold their face still for two to three seconds, without the need to perform complex gestures.
Mr. Forrest added that the system is designed for inclusivity, working across different skin tones and ethnicities, and even on older mobile handsets with poor connectivity.
“iProov’s job is to ‘get out of the way’ of the consumer: keep security strong, but make the process so seamless and consistent that people barely notice it’s there,” he said. — J.C.A. Gonzales