|
THE STATE BANK OF VIETNAM
--------
|
THE SOCIALIST REPUBLIC OF VIETNAM
Independence - Freedom - Happiness
---------------
|
|
No. 77/2025/TT-NHNN
|
Hanoi, December 31, 2025
|
CIRCULAR
AMENDING AND SUPPLEMENTING SOME ARTICLES OF CIRCULAR NO. 50/2024/TT-NHNN
OF THE GOVERNOR OF THE STATE BANK OF VIETNAM PROVIDING FOR SECURITY AND
CONFIDENTIALITY DURING PROVISION OF ONLINE BANKING SERVICES
Pursuant to the Law on
the State Bank of Vietnam No. 46/2010/QH12;
Pursuant to the Law on
Cyberinformation Security No. 86/2015/QH13;
Pursuant to the Law on
Cybersecurity No. 24/2018/QH14;
Pursuant to the Law on
E-Transactions No. 20/2023/QH15;
Pursuant to the Law on
Credit Institutions No. 32/2024/QH15 amended by the Law No. 96/2025/QH15;
Pursuant to the Government’s
Decree No. 26/2025/ND-CP defining the functions, tasks, powers and
organizational structure of the State Bank of Vietnam;
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
The Governor of the
State Bank of Vietnam hereby promulgates a Circular amending and supplementing
some Articles of the Circular No. 50/2024/TT-NHNN of the Governor of the State
Bank of Vietnam providing for security and confidentiality during provision of
online banking services.
Article
1. Amending and supplementing some points and clauses of Article 1
1. Point d is added to
clause 1 of Article 1 as follows:
“d) Activities of
providing mobile money services;”.
2. Clause 2 of Article 1
is amended and supplemented as follows:
“2. Regulated entities
This Circular applies to
credit institutions, foreign bank branches, intermediary payment service
providers, mobile money service providers and credit information companies
(below collectively referred to as “units”).”.
Article
2. Adding clause 11 to Article 2
“11. “new
institutional client” means an organization that has had its establishment
newly registered within a period of 12 months or an organization that has newly
established a relationship with a unit within a period of 12 months, and for
which the unit has conducted a risk assessment and determined the period of
time over which the method of biometric information matching or safe electronic
signatures needs to be applied to such client when conducting transactions.
This provision shall not apply to:
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
b) Credit institutions
and foreign bank branches;
c) Listed organizations
as prescribed by the Law on Securities;
d) Organizations on the
Fortune Global 500 list published by the Fortune magazine in the immediately
preceding year;
dd) Foreign investors
being non-residents opening checking accounts to conduct indirect investment
activities in Vietnam;
e) Other organizations
selected by the units. In this case, the units will be fully responsible for
the risks posed by their selection. The units shall ensure accurate client
verification and shall take full responsibility for client identification.”.
Article
3. Amending and supplementing point a clause 3 of Article 3
“a) Applying at least one
of the authentication forms specified in clauses 3, 4, 5, 7, 8 and 9 Article 11
of this Circular upon changing the client's identification information.
Where an individual
client or a new institutional client changes their identification documents
(including the citizen identity card, identity card, electronic identity card
or passport of the individual client or of the legal representative of the
institutional client) or information used for registration and use of
transaction authentication forms (minimally comprising telephone number or
email address or electronic signature), the authentication forms specified in
clause 5 Article 11 of this Circular shall be applied in combination with one
of the authentication forms specified in clauses 3, 4, 7, 8 and 9 Article 11 of
this Circular.”.
Article
4. Amending and supplementing some points and clauses of Article 7
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
“c) Assess and scan to
detect technical vulnerabilities and weaknesses. Assess the capacity for preventing
and combating vulnerabilities, weaknesses and attack types, satisfying at least
the following requirements:
(i) For online banking
application software provided via web platforms, it is required to prevent and
combat the 10 most common vulnerabilities published by the OWASP organization
(OWASP Top Ten).
(ii) For mobile banking
application software, it is required to satisfy at least the security and
privacy requirements for mobile applications published by the OWASP
organization (OWASP Mobile Application Security).
(iii) The applicable
version of OWASP Top Ten or OWASP Mobile Application Security shall be the
latest version or the version closest to the version issued within a period of
06 months.”.
2. Point g clause 6 of
Article 7 is amended and supplemented as follows:
“g) With regard to a
client being an organization, the application software shall be designed in
such a manner as to ensure that every online payment transaction (excluding online
card payment via payment acceptors) is conducted in at least two steps:
transaction creation and transaction approval.
For a client being a
business household or micro-enterprise applying a simple accounting regime, the
transaction is not required to be conducted by separating the two aforesaid
steps;”.
3. Point b clause 8 of
Article 7 is amended and supplemented as follows:
“b) Online banking
application software must have the function of authenticating the connection
with the institutional client’s software to ensure safety and confidentiality
and prevent fraud and forgery in accordance with international or Vietnamese
standards and technical regulations;”
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
1. Clause 1a is added
after clause 1 of Article 8 as follows:
“1a. Control of
released installation versions of the Mobile Banking application software:
a) Once every 03 months,
a unit shall assess the safety and confidentiality of application software versions
which clients are permitted to install and use in order to identify security
vulnerabilities and assess the possibility of interference by cybercriminals.
b) Where a client
activates the mobile banking application on a new device or reactivates the
application, the client must install and use the latest version or the nearest
version that satisfies safety and confidentiality requirements as per
regulations. The unit must seek control solutions for not permitting the
downgrading to lower versions for use in this case.
c) Upon detecting
security vulnerabilities assessed at a high or critical level, the unit shall
implement measures to inspect, prevent the conduct of transactions or apply
control measures in order to prevent criminals from taking advantage of
security vulnerabilities to conduct cyberattacks, perform fraudulent
transactions and appropriate property; concurrently, the unit shall handle and
fix the vulnerabilities and update the latest version without delay within the
time limit prescribed in clause 6 Article 14 of this Circular.”.
2. Clause 4 of Article 8
is amended and supplemented as follows:
“4. Solutions must be
adopted to prevent, combat and detect unauthorized interference in the mobile
banking application installed on clients’ mobile devices. The Mobile Banking
application must automatically exit or stop and notify the client of the reason
if detecting one of the following signs:
a) A debugger is attached
or a debugging environment is active; or when the application is running in an emulator/virtual
machine/emulated device environment; or operating in a mode allowing a computer
to directly communicate with an Android device (Android Debug Bridge);
b) The application
software is injected with external code while running, performing acts such as
monitoring executed functions, recording logs of data transmitted through
functions, APIs, etc. (hook); or the application software is interfered with or
subjected to repacking;
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
3. Clause 5 of Article 8
is amended and supplemented as follows:
“5. The password-saving
feature is not permitted, except where the authentication form prescribed
in clause 6 Article 11 of this Circular is applied.”.
Article
6. Amending and supplementing some points and clauses of Article 10
1. Point a clause 1 of
Article 10 is amended and supplemented as follows:
“a) For payment
transactions using checking accounts or e-wallets or mobile money accounts or
money transfer transactions from debit cards or identified prepaid cards, the
unit shall classify transactions by their type specified in the Appendix 01 to
this Circular and apply the authentication form specified in the Appendix 02 to
this Circular, except for the regulations set out under points b, c, d and dd
of this clause;”.
2. Point d clause 1 of
Article 10 is amended and supplemented as follows:
“d) For transactions in
which the unit automatically debits checking accounts, automatically debits
e-wallets, automatically debits mobile money accounts or automatically makes
payments from the clients’ cards as agreed upon with clients, the transaction
authentication specified in points a and c clause 1 of this Article is not
required;”.
3. Clause 2 of Article 10
is amended and supplemented as follows:
“2. For services
registered for automatic payments from checking accounts, e-wallets, mobile
money accounts and cards of clients, the unit must apply at least one of the
authentication forms specified in clauses 3, 4, 5, 7, 8 and 9 Article 11 of
this Circular.”.
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
1. Point c clause 5 of
Article 11 is amended and supplemented as follows:
“c) The Presentation
Attack Detection - PAD prescribed in point a of this clause which is deployed
by the unit itself or provided by a third party must be certified by a
biometric organization/laboratory accredited by the FIDO Alliance or
certified by a certification body licensed to certify conformity with international
standards (ISO) and satisfaction of ISO 30107 Level 2 or an equivalent level.
The certification body must be accredited by an accreditation body that is a
signatory to the Multilateral Recognition Arrangement of the International
Accreditation Forum (IAF MLA).”
2. Clause 8 of Article 11
is amended and supplemented as follows:
“8. PGP (Pretty
Good Privacy) authentication is a form of authentication according to
the standard for transaction authentication using asymmetric key algorithms
(including private keys used to generate digital signatures, and public keys
used to validate digital signatures) issued by the IETF (Internet Engineering
Task Force). PGP authentication must meet the following requirements:
a) The client’s public
key is registered with the unit, securely stored at the unit, and linked to the
client’s e-transaction account;
b) Method are in place to
ensure verification of the identity of the key holder, security mechanisms and
key revocation mechanisms;
c) There is an agreement
on the legal liability of the unit and the client relating to the authenticity,
integrity and non-repudiation of transaction files signed using this method.”.
3. Clause 9 of Article 11
is amended and supplemented as follows:
“9. Secure e-signature
authentication is a form of authentication based on e-signature which may be a
digital signature or a foreign e-signature recognized in Vietnam in accordance
with the law on e-signatures.”.
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
“Article 21. Responsibilities
of units affiliated to SBV
1. The Information
Technology Department shall carry out monitoring and inspection, and cooperate
with related units to resolve difficulties arising from implementation of this
Circular.
2. The State Bank Inspectorate
shall inspect and examine the implementation of this Circular and handle
violations in accordance with law.
3. Regional SBV branches
shall inspect and supervise the implementation of this Circular by credit
institutions, foreign bank branches and intermediary payment service providers
within areas under their management and handle violations in accordance with
law.”.
Article
9. Adding Clause 1a after clause 1 of Article 23
“1a. For services
registered for automatic payments from mobile money accounts that are conducted
before the effective date of this Circular shall continue to be rendered until
the expiry of the signed agreements; in case the agreements do not specify an
expiry date, they shall continue to be implemented until December 31, 2026. The
amendment, supplementation or extension of such agreements must comply with
clause 2 Article 10 of this Circular.”.
Article
10. Amending and supplementing Appendices to Article 50/2024/TT-NHNN
Appendices No. 01, 02 and
04 promulgated together with Circular No. 50/2024/TT-NHNN are replaced with
Appendices No. 01, 02 and 04 to this Circular.
Article
11. Responsibility for organizing implementation
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Article
12. Implementation clause
1. This Circular comes
into force from March 01, 2026, except for the cases prescribed in clauses 2
and 3 of this Article.
2. For units providing
online payment services to both individual and organizational clients, the
provisions set forth in Article 3 and Article 10 of this Circular shall be
applied from July 01, 2026.
3. For units providing
online payment services only to institutional clients (not providing services
to individual clients), the provisions set forth in Article 3 and Article 10 of
this Circular shall be applied from October 01, 2026./.
PP. THE GOVERNOR
THE DEPUTY GOVERNOR
Pham Tien Dung
APPENDIX 01
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
No.
Description
Category A
Category B
Category C
Category D
I
Individual client
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
1
Group I.1:
- Money transfer
between checking accounts, debit cards, identified prepaid cards (hereinafter
referred to as “cards”) of a client in a payment service provider.
- Money transfer
between e-wallets of a client in an intermediary payment service provider.
All transactions.
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
2
Group I.2:
- Lawful payment
transactions for goods and services provided by payment service providers, intermediary
payment service providers and mobile money service providers or selected,
appraised, supervised and managed by payment service providers, intermediary
payment service providers and mobile money service providers
Any transaction that
satisfies the following condition:
G + T ≤ VND 5 million.
Any transaction that
satisfies the following conditions:
(i) G + T > VND 5
million.
(ii) G + T ≤ VND 100
million.
Any transaction that
satisfies the following conditions:
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
(ii) G + T ≤ VND 1.5
billion.
Any transaction that
satisfies the following condition:
G + T > VND 1.5
billion.
3
Group I.3:
- Money transfer
between checking accounts, cards, e-wallets, mobile money accounts of
different account holders, card holders, e-wallet owners and mobile money
account holders.
- Money transfer
between accounts, cards, e-wallets and mobile money accounts opened at
different payment service providers, card issuers, intermediary payment
service providers and mobile money service providers.
- E-wallet cash-in from
e-wallet owner’s bank account or card at a linked bank1.
- E-wallet cash-out to
e-wallet owner’s checking account or card at a linked bank.
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
(i) G ≤ VND 10 million.
(ii) G + Tksth
≤ VND 20 million.
Any transaction (except
cash-in or cash-out between an e-wallet and checking account or card of an e-wallet
owner at the linked bank in accordance with law) that satisfies the following
conditions:
(i) G ≤ VND 10 million.
(ii) G + Tksth
≤ VND 20 million.
Any transaction that
falls into one of the following cases:
1. Case 1: Any
transaction that satisfies the following conditions:
(i) G ≤ VND 10 million.
(ii) G + Tksth
> VND 20 million.
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
2. Case 2: Any
transaction that satisfies the following conditions:
(i) G > VND 10
million.
(ii) G ≤ VND 500
million.
(iii) G + T ≤ VND 1.5 billion.
Any transaction that
falls into one of the following cases:
1. Case 1: Any
transaction that satisfies the following conditions:
(i) G ≤ VND 10 million.
(ii) G + Tksth
> VND 20 million.
(iii) G + T > VND
1.5 billion.
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
(i) G > VND 10
million.
(ii) G ≤ VND 500
million.
(iii) G + T > VND
1.5 billion.
3. Case 3: Any
transaction that satisfies the following condition:
G > VND 500 million.
4
Group I.4:
Outbound interbank
transfer2.
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Any transaction that
satisfies the following conditions:
(i) G ≤ VND 200
million.
(ii) G + T ≤ VND 1
billion.
Any transaction that
falls into one of the following cases:
1. Case 1: Any
transaction that satisfies the following conditions:
(i) G ≤ VND 200 million.
(ii) G + T > VND 1
billion.
2. Case 2: Any
transaction that satisfies the following condition:
G >
VND 200 million.
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Institutional client3
1
Group II.1:
Money transfer between
checking accounts or e-wallets of the same client in a payment service
provider or intermediary payment service provider.
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
2
Group II.2:
- Money transfer
between checking accounts and e-wallets of different account holders and
e-wallet owners.
- Money transfer between
accounts, e-wallets opened different at payment service providers and
intermediary payment service providers.
- Lawful payment
transactions for goods and services provided by payment service providers and
intermediary payment service providers or at payment acceptors selected,
appraised, supervised and managed by payment service providers and
intermediary payment service providers.
- E-wallet cash-in from
e-wallet owner’s bank account or card at a linked bank1.
- E-wallet cash-out to
e-wallet owner’s checking account or card at a linked bank.
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
I. Category C1:
Any transaction of a
new institutional client that falls into one of the following cases:
1. Case 1: Any
transaction that satisfies the following conditions:
(i) G > VND 50
million.
(ii) G ≤ VND 1 billion.
(iii) G + T ≤ VND 10
billion.
2. Case 2: Any
transaction that satisfies the following conditions:
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
(ii) G + Tksth
> VND 100 million.
(iii) G + T ≤ VND 10
billion.
II. Category C2:
1. Case 1: Any
transaction of a new institutional client that satisfies one of the following
conditions:
(i) G ≤ VND 50 million.
(ii) G + Tksth
≤ VND 100 million.
2. Case 2: Any
transaction of other entity that satisfies the following conditions:
(i) G ≤ VND 1 billion.
(ii) G + T ≤ VND 10
billion.
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Any transaction of a
new institutional client that falls into one of the following cases:
1. Case 1: Any
transaction that satisfies the following conditions:
(i) G > VND 50
million.
(ii) G ≤ VND 1 billion.
(iii) G + T > VND 10
billion.
2. Case 2: Any
transaction that satisfies the following conditions:
(i) G ≤ VND 50 million.
(ii) G + Tksth
> VND 100 million.
(iii) G + T > VND 10
billion.
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
G > VND 1 billion.
II. Category D2:
Any transaction of
other entity that falls into one of the following cases:
1. Case 1: Any
transaction that satisfies the following conditions:
(i) G ≤ VND 1 billion.
(ii) G + T > VND 10
billion.
2. Case 2: Any transaction
that satisfies the following condition:
G > VND 1 billion.
3
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Outbound interbank
transfer2.
Category C3:
Any transaction that
satisfies the following conditions:
(i) G ≤ VND 500
million.
(ii) G + T ≤ VND 5
billion.
Category D3:
Any transaction that
falls into one of the following cases:
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
(i) G ≤ VND 500
million.
(ii) G + T > VND 5
billion.
2. Case 2: Any
transaction that satisfies the following condition:
G > VND 500 million.
Notes:
G: Value of the
transaction.
Tksth: Total
value of Category A, Category B and Category C2 (for a new institutional
client) transactions of each category of transactions performed on a checking
account or a card (including e-wallet cash-in from checking account or card
of the e-wallet owner at the linked bank when conducted on the e-wallet
application) or an e-wallet (excluding the deposit of cash in that
e-wallet from checking account or card of the e-wallet owner at the linked bank
when conducted on the e-wallet application) or a mobile money account of a
client at a payment service provider or intermediary payment service provider
or mobile money service provider, excluding checking account auto-debit,
e-wallet auto-debit, mobile money account auto-debit and card auto-debit
transactions. Tksth shall be zero (0) at the beginning of the day or
immediately after the client has a transaction in the day which is
authenticated by an authentication method for Category C or Category D transactions
(for an individual client) or Category C1 or Category D1 transactions (for a
new institutional client).
T: Total value of each
category of transactions performed in a day (on a checking account or a card
(including e-wallet cash-in from checking account or card of the e-wallet owner
at the linked bank when conducted on the e-wallet application) or an e-wallet
(excluding the deposit of cash in that e-wallet from checking account or card
of the e-wallet owner at the linked bank when conducted on the e-wallet
application) or a mobile money account) of a client at a payment service
provider or intermediary payment service provider or mobile money service
provider), excluding checking account auto-debit, e-wallet auto-debit, mobile
money account auto-debit and card auto-debit transactions.
(1) In case of e-wallet
cash-in from the e-wallet owner's checking account/card at a linked bank, the
transaction classification shall rely on the checking account/card linked to
the e-wallet.
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
(3) In case the client is
a business household or a micro-enterprise applying a simple accounting regime,
transactions of such business household or micro-enterprise are classified
similarly to transactions of an individual client.
APPENDIX 02
ONLINE PAYMENT TRANSACTION
AUTHENTICATION
(Enclosed with the Circular No. 77/2025/TT-NHNN dated December 31, 2025 of
the Governor of the State Bank of Vietnam)
No.
Transaction
Minimum online payment transaction authentication form
Individual client
Institutional client
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Category A transaction
- Password or PIN (if
authenticated at the login step, authentication is not required at the
transaction step).
- Password or PIN (if
authenticated at the login step, authentication is not required at the
transaction step).
2
Category B transaction
- SMS OTP or Voice OTP
or Email OTP;
- Or OTP Matrix Card;
- Or basic or advanced
Soft OTP/ Token OTP;
- Or two-channel;
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
- Or FIDO;
- Or secure
e-signatures.
- SMS OTP or Voice OTP
or Email OTP;
- Or OTP Matrix Card;
- Or matching the
device-based biometric information of the legal representative or the
individual authorized by the legal representative (if any).
3
Category C transaction
- OTP sent via
SMS/Voice or basic Soft OTP/Token OTP.
- And biometric
authentication.
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
- Matching the
biometric information of the legal representative in combination with basic
Soft OTP/Token OTP or two channel.
2. Category C2 and C3
transactions:
- Basic Soft OTP/Token
OTP;
- Or two-channel.
4
Category D transaction
- Advanced Soft
OTP/Token OTP or FIDO or secure e-signatures,
- And biometric
authentication.
1. Category D1 transaction:
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
- Or secure
e-signatures integrated with e-identification account of the institution.
2. Category D2 and D3
transactions:
- Advanced Soft
OTP/Token OTP;
- Or FIDO;
- Or secure
e-signatures.
Notes:
- Details about
authentication forms are specified in Article 11 of this Circular.
- For an individual
client:
+ Category D
transaction authentication form may be used to authenticate Category A, B and C
transactions.
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
+ Category B
transaction authentication form may be used to authenticate Category A transactions.
- For an institutional
client:
+ Category D1
transaction authentication form may be used to authenticate Category A, B and
C1 transactions.
+ Category D2 and D3
transaction authentication form may be used to authenticate Category A, B, C2
and C3 transactions.
+ Category C
(including C1, C2 and C3) transactions authentication form may be used to
authenticate Category A and B transactions.
+ Category B
transaction authentication form may be used to authenticate Category A
transactions.
- In case the client is a
business household or a micro-enterprise applying a simple accounting regime,
the transaction authentication form to be applied is similar to that applied to
an individual client. Regarding the form of biometric authentication and the
form of device-based biometric authentication, the biometric information used
for comparison is that of the legal representative or the individual authorized
by the legal representative (if any).
(1) In case the client
has signed into the Online Banking app using device-based biometric
authentication, this biometric authentication shall not be used during
transactions in the same sign-in session.
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
ONLINE CARD PAYMENT
TRANSACTION AUTHENTICATION
(Enclosed with the Circular No. 77/2025/TT-NHNN dated December 31, 2025 of
the Governor of the State Bank of Vietnam)
No.
Transaction
Minimum online card payment transaction authentication
form
1
Category E transaction
Password or PIN (if
authenticated at the login step, authentication is not required at the
transaction step).
2
Category F transaction
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
- Or OTP Matrix Card;
- Or Basic Soft OTP/
Token OTP;
- Or device-based
biometric authentication;
- Or two-channel.
3
Category G transaction
- Advanced Soft OTP/ Token
OTP;
- Or FIDO;
- Or secure
e-signatures;
...
...
...
Hãy đăng nhập hoặc đăng ký Thành viên
Pro tại đây để xem toàn bộ văn bản tiếng Anh.
Notes:
- Details about
authentication forms are specified in Article 11 of this Circular.
- Category G transaction
authentication form may be used to authenticate Category E and F transactions.
- Category F transaction
authentication form may be used to authenticate Category E transactions.