From
Ideem— device-bound passkeys and A2A payment authentication for banks, fintechs, and payment platforms.
If you only watched the headlines, you would think Singapore's authentication transformation began in July 2024, when MAS and the Association of Banks in Singapore announced that major retail banks would phase out SMS OTPs for digital token users within three months. It did not. It began earlier — in the deliberate, almost understated language of MAS Notice 655 on Cyber Hygiene, and the Technology Risk Management Guidelines that surround it.
That document and its successor, Notice FSM-N06, are the quiet authentication mandate. They never made the front page. They reshaped APAC anyway. For practitioners deploying authentication into Singapore-licensed banks, or into any of the APAC jurisdictions that have started borrowing the Singapore template, the Notice 655 lineage is the regulatory throughline you cannot afford to misread.
MAS Notice 655 applied to all banks in Singapore. Its scope was deliberately broad: securing administrative accounts, applying security patching, establishing baseline security standards, deploying network security devices, implementing anti-malware measures, and — the line that matters most for this conversation — strengthening user authentication.
The authentication clause was the one that did the heavy lifting. Notice 655 required multi-factor authentication on every administrative account in respect of any operating system, database, application, security appliance, or network device that is a critical system. It also required MFA on every account on any system used to access customer information through the internet. In plain language: if your system touches customer data over the public internet, single-factor authentication is not an option.
That clause, written in the language of cyber hygiene rather than the language of identity, is what set the floor. Notice 655 was cancelled with effect from May 10, 2024, and replaced by Notice FSM-N06. The replacement notice carries the same requirements forward into the current rulebook with the same scope — full banks, wholesale banks, and the licensed entities that sit alongside them. The MFA mandate on administrative accounts and internet-facing customer systems remains intact.
Read alongside the MAS Technology Risk Management Guidelines, which were revised in January 2021 and have been progressively reinforced since, the picture is sharper still. The TRM Guidelines call out that financial institutions should "adopt robust user authorization and authentication based on the criticality of IT assets" — with explicit reference to step-up authentication and phishing-resistant authenticators. The combination of the cyber hygiene notice and the TRM Guidelines is what gives MAS its quiet mandate. Banks know what they need to do. The guidance is written.
The clearest way to see Notice 655's influence is to trace what Singapore banks have actually done over the last two years.
In July 2024, MAS and ABS announced the phase-out of SMS OTP for bank account login by customers who have activated their digital token on their mobile device. The phase-out was framed as a phishing protection measure — scammers had become sophisticated enough to spoof bank login pages and harvest OTPs at scale — but the regulatory authority for the move was already present in the Notice 655 and TRM Guidelines combination. The MFA requirement had always been there. What changed in 2024 was the recognition that SMS OTP could no longer credibly satisfy it for retail flows.
In December 2024, the Shared Responsibility Framework took effect. Jointly administered by MAS and the Infocomm Media Development Authority, the SRF assigns duties to financial institutions and telcos to mitigate phishing scams — and requires payouts to affected scam victims when those duties are breached. The framework introduced a new FI duty to perform real-time fraud surveillance directed at detecting unauthorized transactions in a phishing scam that result in account draining. The authentication layer is where that surveillance lives.
In October 2025, ABS rolled out enhanced safeguards across Singapore's domestic systemically important banks. Accounts with balances of at least S$50,000 are now protected by a threshold safeguard that kicks in when a transaction, combined with the prior 24 hours of withdrawals, would move more than 50% of the account balance out. Digital token users now receive in-app push notifications for acknowledgment when banks make outbound calls. Scam losses in Singapore declined 12.6% year-on-year in the first half of 2025, and case counts dropped 26%. The authentication architecture is doing real work.
None of these initiatives reads, in isolation, as an authentication mandate. Taken together, they are exactly that. The MAS approach is to set the floor in the cyber hygiene notice, reinforce it in the TRM Guidelines, and then let the industry — under regulator coordination — build the customer-facing controls that satisfy the floor.
From the customer success side of the table, the Singapore deployment pattern reads cleanly. The teams we work with in APAC are running three workstreams in parallel.
The first is the digital token transition for retail login. The phase-out of SMS OTP for digital token users created an installed base of customers who now authenticate to their bank app via on-device cryptography rather than a text message. That installed base is the foundation a passkey program is built on top of — the device binding, the biometric user verification, the relying party origin check are all already there in some form.
The second is high-value transaction step-up. Singapore's regulatory architecture, especially after the SRF and the October 2025 safeguards, treats high-value transactions as a distinct authentication moment. A login that produces a session is not the same artifact as a transaction that moves S$100,000. The bank's authentication layer needs to express both — and produce audit evidence that the right control was applied to the right moment.
The third is provider governance. MAS's third-party risk expectations, including in the TRM Guidelines, mean that the identity providers and authentication vendors a bank chooses are themselves subject to scrutiny. Examiners are increasingly asking how a bank vets its authenticator providers, how it monitors the FIDO Metadata Service, and how it handles a provider whose attestation posture changes. Banks that cannot answer those questions cleanly are the ones losing time in examinations.
The Singapore template does not stay in Singapore. The same architecture — cyber hygiene baseline plus TRM Guidelines plus industry coordination — is now visible in three of Singapore's most important regional neighbors.
In the Philippines, BSP Circular 1213, issued in June 2025, requires banks and financial institutions to phase out SMS- or email-based OTPs and adopt strong, phishing-resistant authentication methods such as passwordless logins, biometrics, or FIDO-compliant passkeys by June 2026. The language — phishing-resistant, FIDO-compliant — is the Singapore vocabulary, exported.
In Malaysia, Bank Negara Malaysia's updated Risk Management in Technology (RMiT) policy came into effect on November 28, 2025, tightening the technology risk expectations on Malaysian financial institutions. The same month, BNM released a draft proposing regulatory requirements for open finance — consent-driven sharing of customer information across the financial sector — that will sit alongside RMiT in the bank technology risk architecture.
In Hong Kong, HKMA has been progressively reinforcing its supervisory framework for banking technology, including the work on stablecoins and the joint HKMA-SFC guidance on staking services issued in April 2025. The authentication implications of that framework rhyme with the Singapore approach more than they do with any other reference model.
The FIDO Alliance's choice to bring the Authenticate APAC 2026 conference to Singapore in June 2026 is not accidental. The region has gained influence on the global cybersecurity conversation, and Singapore is the regulatory anchor that other APAC jurisdictions are increasingly calibrating against.
For institutions licensed by MAS — or by any APAC regulator that has been watching Singapore — the practical work for 2026 reads in three pieces.
Map your current authentication estate against the FSM-N06 floor and the TRM Guidelines. Every administrative account, every system that touches customer information over the internet, every high-value transaction flow needs a documented authentication control. The examination conversation is increasingly granular. Inventory beats improvisation.
Build the SRF surveillance and step-up architecture as one program. The Shared Responsibility Framework's real-time fraud surveillance duty and the October 2025 high-balance safeguards both depend on the authentication layer being a first-class signal. If your authentication telemetry is siloed from your fraud telemetry, the program is harder than it needs to be. Treat them as the same surface.
Make your provider governance auditable. The FIDO Metadata Service, attestation posture, AAGUID handling, and policy controls on which authenticators the bank accepts are all going to surface in regulator conversations. Banks that have a clean answer to "how do you vet and monitor your authenticator providers" are positioned. Banks that don't are going to be writing remediation plans.
Ideem's Passkeys+ was built for the regulatory environment that the Notice 655 lineage has produced — in Singapore, and now across APAC. The platform integrates with the bank's existing identity stack (Okta, ForgeRock, Ping, or a homegrown IdP), produces audit-grade evidence of every authentication decision, and supports the policy controls MAS and its regional peers are converging on: phishing resistance by default, step-up to device-bound credentials for high-value flows, and provider-level governance driven by the FIDO Metadata Service.
Because Passkeys+ is provider-agnostic across the passkey ecosystem — Apple, Google, Microsoft, the major password managers, and hardware security keys — APAC banks can support the consumer authenticators their customers actually use today while retaining the trust-tier machinery the regulator expects. Synced credentials work for retail login. Device-bound credentials gate high-value transactions. The policy lives at the authentication layer, not buried in custom application code, and the evidence is ready when the examiner asks.
The MAS approach to authentication has always been deliberate and quietly insistent. Notice 655 set the floor. FSM-N06 carries it forward. The TRM Guidelines reinforce it. The Shared Responsibility Framework operationalizes it. The 2025 ABS safeguards extend it. And the APAC regulators that have been watching are now writing their own versions. Banks that build their 2026 program around the Singapore template — rather than waiting for their local regulator to publish the version they should have anticipated — will be the ones examiners cite as the model. That is the work worth doing this quarter.
Most orgs running OTP-based MFA have 3–4 exploitable gaps they don’t know about. Our Authentication Assessment takes 2 minutes and shows you exactly where you stand — plus a phased migration roadmap.
Take the Assessment →Built by Ideem
Device-bound passkeys and A2A payment authentication. One SDK. No OTPs, no redirects.
Our 2-minute assessment scores your authentication setup and shows you exactly where the improvements are.
See Your Score →