Panel discussion at VERIFY Philippines
24 February 2027
,
Manila

VERIFY Philippines 2027

Philippines' dedicated event on identity, fraud and digital trust

Identity, Fraud and Digital Trust
The Philippines set one of the region's most specific fraud regimes and held to its deadline. The Anti-Financial Account Scamming Act, enacted in July 2024 and implemented through three BSP circulars, required supervised institutions to stop using SMS and email one-time passwords for high-risk transactions from 25 June 2026, replacing them with biometrics, passkeys or hardware keys. The central bank confirmed it would not extend the date, and institutions now carry clearer responsibility when controls fail.

By February 2027 the sector has months of operating experience behind that change — what it did to fraud rates, to abandonment, and to the customers hardest to migrate. VERIFY Philippines convenes the identity, fraud, financial crime and payments risk leaders who lived through it, and who now carry the cost when a scam succeeds.

Senior delegates in the audience
Why VERIFY, why now
0 %
of H1 2025 cyber-fraud losses from social engineering, account takeover and identity theft
0 %
of retail payment volume was digital in 2025
0 k
crime and loss reports filed by supervised institutions in 2024
0 bn
pesos in gross cyber losses at supervised institutions in 2024
Who Will Be There
The identity, fraud and financial crime leaders building trust across the Philippine digital economy
ROLES

Heads of Fraud and Financial Crime · Heads of Identity · Heads of Trust & Safety · Chief Risk Officers · Heads of Payments Risk · Chief Compliance Officers

ORGANISATION TYPES

Universal, commercial and digital banks · E-money issuers and wallets · Payment operators · Financing and lending companies · Telecoms and digital platforms · Regulators and national infrastructure

What Makes VERIFY Unique
Built around a deadline that has already passed, and what the sector learned from it
Implementation experience, not anticipation
The authentication mandate took effect in mid-2026. By the time the summit runs, institutions have operated under it for months and can compare what worked, what broke and where fraud relocated. Sessions are built on outcomes rather than intentions.
Three pillars, one problem
A scam now moves through onboarding, authentication, payments and platforms in a single customer journey. VERIFY Philippines follows that chain end to end, through liability, autonomous transacting and collective defence, so identity, fraud and digital trust leaders tackle it as one problem.
Built across sectors, not inside one
Scams in the Philippines rarely stay inside one institution. They start on messaging apps and marketplaces, run through telecom numbers and e-wallets, and land at a bank. VERIFY Philippines puts the people who each see part of that attack in one room.
Agenda

8:15

9:05

Registration & Networking Breakfast

    9:05

    9:10

    Opening Remarks

      9:10

      9:50

      The Trust Infrastructure the Philippines Is Building: Who Pays When Trust Fails?

      The Anti-Financial Account Scamming Act and its implementing rules strengthened institutional duties around scam prevention, temporary holds, investigation and customer protection. They also created defined mechanisms for coordinated verification and account inquiry. That does not mean every fraud loss automatically shifts to the institution. This session examines where responsibility now sits when required controls fail, how privacy and secrecy exceptions operate in investigations, and where banks need other sectors to participate before the defence can work.
      • AFASA strengthened institutional duties around scam prevention and response. What has that changed about where prevention, investigation and customer-protection budgets are spent?
      • Fraud inquiries can engage statutory exceptions to secrecy and privacy rules. Where should Philippine institutions draw the operational boundary for investigations?
      • Philippine payment volumes can scale faster than manual controls. Where should institutions invest first when transaction growth starts outrunning defensive capacity?
      • Scam journeys often cross banks, telecoms and digital platforms. Who should set a common operating standard when responsibility spans several regulatory perimeters?

      9:50

      10:05

      How We Solved…

      A practical case study on a real industry challenge, the approach taken, and results achieved.

        10:05

        10:45

        Identity Assurance After the OTP: Authentication When the Text Message Is Gone

        Circular 1213 required BSP-supervised institutions to strengthen fraud management and transition away from interceptable authentication mechanisms, including SMS- and email-based OTPs, for financial and other high-risk activities by the June 2026 compliance deadline. The circular points institutions towards phishing-resistant multi-factor authentication, including biometrics, passkeys and hardware security keys, without prescribing one universal replacement. Months on, the practical question is what implementation changed in fraud, customer abandonment, recovery and support.
        • Circular 1213 requires transition away from interceptable authentication for high-risk activity. What did implementation change in fraud, abandonment and support volumes?
        • Biometric authentication serves some customers poorly. How have Philippine institutions handled worn fingerprints, older devices, accessibility requirements and failure recovery at scale?
        • Generated media is cheap enough to industrialise attacks in the Philippines. Where are liveness and deepfake controls holding, and where are attackers winning?
        • Account recovery can undo strong authentication in one step. How are Philippine institutions rebuilding recovery without recreating the vulnerability they removed elsewhere?

        10:45

        10:50

        The Room Speaks: Morning Pulse

          10:50

          11:20

          Networking Break

            11:20

            11:35

            How We Solved…

            A practical case study on a real industry challenge, the approach taken, and results achieved.

              11:35

              12:15

              The Origination Problem: Where the Scam Begins Before the Payment Moves

              Supervised Philippine institutions filed 40,780 crime and loss reports in 2024 — and most of what they reported began somewhere they could not see: recruitment, impersonation and investment pitches on messaging apps, marketplace listings and social feeds. AFASA strengthened institutional duties and investigative mechanisms once money moves, but the approach stays invisible to the institution carrying the loss. This session asks who disrupts the pipeline before the first peso leaves the account.
              • Scam recruitment and victim contact happen on consumer platforms outside every bank's perimeter. Who disrupts the pipeline before an account is even touched?
              • AFASA strengthened investigative powers and institutional duties once funds move. What changes for institutions in the window before the first transfer?
              • Philippine telecoms hold the number that anchors wallets and authentication. Where does operator signal reach the bank before money moves?
              • Takedown speed decides how long a scam site keeps harvesting victims. How fast can institutions and providers remove infrastructure at source?

              12:15

              12:30

              How We Solved…

              A practical case study on a real industry challenge, the approach taken, and results achieved.

                12:30

                13:30

                Networking Lunch

                  13:30

                  14:10

                  Know Your Agent: When Software Becomes the Customer

                  In 2025, InstaPay and PESONet processed a combined ₱24.74 trillion as real-time and batch account-to-account payments became ordinary infrastructure. AI agents that initiate payments or act on a customer's instruction challenge controls built around a human at the keyboard. Behavioural models, authentication and transaction monitoring all assume a person is present somewhere in the journey. This session asks what changes when software transacts at machine pace and the customer never touches the screen.
                  • Behavioural models assume a human at the keyboard. What breaks in detection when an AI agent transacts at machine pace?
                  • An agent initiating a QR Ph payment never passes an authentication challenge. Where does verification move when the customer is never present?
                  • A manipulated agent could transact at scale before anyone notices. Who holds the kill-switch, and how fast does it operate?
                  • Agent identity is being defined now across banks and platforms. What standard does the institution adopt before the market fragments?

                  14:10

                  14:25

                  How We Solved…

                  A practical case study on a real industry challenge, the approach taken, and results achieved.

                    14:25

                    15:05

                    Collective Defence: Finding the Network No Institution Sees Alone

                    Supervised institutions filed 40,780 reports of crimes and losses in 2024 and recorded ₱5.82 billion in gross cyber losses. The act criminalised money muling directly, but a mule account is not a technical compromise. It is a real customer, verified correctly, behaving as instructed. Detecting one means seeing behaviour across institutions that no single institution can see on its own.
                    • Supervised institutions filed more than 40,000 crime and loss reports in 2024. Which behavioural, device and network signals identify a mule before the funds leave?
                    • Each account in a mule network looks legitimate alone. How does an institution detect the network rather than the account?
                    • The AFASA framework opened defined channels for coordination. What fraud signals can Philippine institutions exchange today, and what information still cannot move?
                    • Real-time Philippine payment rails compress recovery time almost to zero. How fast must shared fraud intelligence move before it becomes operationally useful?

                    15:05

                    15:10

                    The Room Speaks: Closing Pulse

                      15:10

                      15:15

                      Closing Remarks

                        15:15

                        16:00

                        Coffee and Networking

                          Contact Us
                          Whether attending as a delegate or exploring sponsorship, contact us to discover exciting opportunities at our upcoming events.
                          Request your invitation
                          Join senior decision-makers and industry peers for a focused programme of insights, discussion, and networking. Attendance is complimentary for qualified professionals, subject to approval.
                          Thank you! Your submission has been received!
                          Oops! Something went wrong while submitting the form.
                          Partner with Us
                          Showcase your expertise, build new relationships, and engage directly with senior decision-makers. Explore sponsorship, speaking, branding, and business development opportunities tailored to your objectives.
                          Share your insights
                          Share your experience, case study, or perspective with an audience of senior professionals. We welcome submissions from practitioners, industry leaders, and subject-matter experts with relevant insights to contribute.
                          Thank you! Your submission has been received!
                          Oops! Something went wrong while submitting the form.