Consumer, MSME finance providers must adopt OTP verification within two months: FRA

Daily News Egypt
3 Min Read
Islam Azzam, Chairperson of the Financial Regulatory Authority (FRA)

Financial Regulatory Authority (FRA) Chairperson Islam Azzam has issued a decision requiring companies and entities licensed to provide consumer finance and financing for medium, small, and micro enterprises to implement, within two months, FRA Board of Directors Decision No. 133 of 2026, issued last July.

The decision requires finance providers to send customers a one-time password (OTP) when entering into financing agreements and when the financing is used, while maintaining a record of the OTP.

The measure comes as part of the FRA’s efforts to accelerate the implementation of regulatory rules aimed at strengthening procedures for verifying the accuracy of customer data in consumer finance and financing for medium, small, and micro enterprises.

Under the decision, companies and entities providing consumer finance and financing for medium, small, and micro enterprises must complete the technical and regulatory measures necessary to implement the new requirements stipulated in Decision No. 133 of 2026 concerning the sending of OTPs within a maximum period of two months.

The rules require all consumer finance companies, as well as companies, associations, and institutions financing medium, small, and micro enterprises, to send an OTP to customers when entering into financing contracts. The OTP must be sent to the mobile phone number verified for each customer. An OTP must also be sent when customers use the financing, with the finance provider required to maintain a record of the verification code.

Azzam said adding OTPs to the customer identity verification system would contribute to the early detection of harmful practices and manipulation in attempts to obtain financing for consumer or productive purposes.

It would also help combat identity theft and the submission of incorrect personal data, thereby protecting the rights of individuals acting in good faith and preventing adverse effects on their creditworthiness.

Azzam said the regulatory rules established by the FRA for verifying the accuracy of customer data across all non-banking financial activities require companies under the authority’s supervision that conduct their activities using financial technology, as well as fintech-related outsourcing service companies, to verify customer data against national identification records and mobile phone ownership records.

Companies are also required to check whether customers are included on money laundering or asset-disposal restriction lists, pursuant to FRA Board of Directors Decision No. 186 of 2024 and its amendments, most recently Decision No. 133 of 2026, issued last July.

Share This Article