GR-6.3.13

Islamic retail bank licensees must adopt security measures that meet the following requirements for payment transactions:

(a) the authentication code generated must be specific to the amount of the payment transaction and the payee agreed to by the payer when initiating the transaction;
(b) the authentication code accepted by the licensee maintaining customer account corresponds to the original specific amount of the payment transaction and to the payee agreed to by the payer;
(c) a SMS message must be sent to the customer (or through alternative means of communication for legal persons) upon accessing the online portal or application and when a transaction is initiated; and
(d) any change to the amount or the payee must result in the invalidation of the authentication code generated.
Amended: September 2024
Amended: July 2021
Added: April 2019