Skip to main content
Didit Raises $7.5M to Build the Infrastructure for Identity and Fraud
Didit
Back to blog
Blog · August 1, 2026

Asia is moving the cost of weak identity checks onto banks and platforms

Nine Asian markets rewrote their identity rules between December 2024 and January 2026. Singapore and Thailand now make institutions pay for scam losses.

By DiditUpdated
Didit Blog card on a dark navy canvas. Eyebrow reads Asia, IDV Regulation, 2026. The headline 'Nine markets made identity the law.' sits beside a dotted globe of Asia with nine lime markers.

Nine markets rewrote their identity rules between December 2024 and January 2026. Singapore and Thailand now make institutions pay for scam losses, Vietnam gates banking on a face match, and Japan retires photo-upload verification in April 2027.

The short version

01

The United Nations Office on Drugs and Crime puts the annual profits of Southeast Asia's scam compounds at just under $40 billion, run on trafficked labour from more than 50 countries.

02

Nine Asian markets rewrote their identity verification rules between December 2024 and January 2026. Most of those rules are already in force.

03

Singapore's Shared Responsibility Framework, in force since 16 December 2024, makes a bank reimburse a phishing victim when the bank skipped a prescribed anti-scam duty. Thailand went further by emergency decree in April 2025, making banks, telcos and platforms co-liable.

04

Vietnam has required a face match against the national chip-identity database for online banking access since 1 January 2025. Thailand requires facial recognition above 50,000 baht.

05

Japan has announced that photo-upload identity checks will be abolished for remote account opening from April 2027, leaving chip reading as the only route.

06

India's Digital Personal Data Protection Rules were gazetted on 14 November 2025 and bind fully from 14 May 2027, with penalties up to 250 crore rupees, about $29 million.

Southeast Asia's scam compounds earn about $40 billion a year, and the rules followed the money

The United Nations Office on Drugs and Crime estimates that scam centres operating from compounds across Southeast Asia clear just under $40 billion a year. Its 2025 assessment describes an industry staffed by hundreds of thousands of workers, many trafficked, drawn from more than 50 countries. The identity mandates that followed are a response to that scale.

The word worth holding onto is industrial. These are not individuals working alone. The UNODC describes compounds with recruitment pipelines, shift patterns and management layers, which is why the response has been regulatory rather than only criminal: a compound can be raided, but the bank account and the phone number it used are what let it reach a victim.

INTERPOL's Global Financial Fraud Threat Assessment, published in March 2026, counted Asia-Pacific fraud alerts up 47% in a single year, and found that schemes using artificial intelligence were roughly 4.5 times more profitable than those without. Its Secretary General put the shift plainly.

We are witnessing the industrialization of fraud.

— Valdecy Urquiza, Secretary General, INTERPOL. Global Financial Fraud Threat Assessment, March 2026

Two cases show what that industrialisation looks like at the point of contact. Hong Kong police briefed a video-conference fraud in February 2024 in which every participant except the victim was a deepfake, costing HK$200 million. Singapore police traced a S$4.9 million loss to a deepfake of the Prime Minister. Both were briefed publicly by police, and both turn on the same weakness: a person on a screen was accepted as identification.

That is the proportionality question running under every rule in this post. Identity checks are being attached to more and more everyday actions, and each time the open question is whether the harm justifies the friction. In Asia the harm is unusually well measured, which is part of why the answer has come back the way it has.

Nine markets rewrote their identity rules in fourteen months

Between 16 December 2024 and 22 January 2026, nine Asian markets changed the rules governing how businesses verify identity: Singapore, Vietnam, India, Thailand, Malaysia, the Philippines, Japan, South Korea and Indonesia. Most of those changes are already in force. The remaining deadlines run to 14 May 2027.

The sequence matters more than the count. Singapore moved first on liability, Vietnam moved first on access, and Japan is moving first on method. Each is a different lever aimed at the same failure, and the later movers have been able to watch the earlier ones.

Regulators elsewhere are running the same play on different timelines. The European Union's Anti-Money Laundering Regulation attaches ongoing monitoring duties to existing customers rather than only to onboarding, and Australia is pulling whole professions into an identity regime for the first time.

DateWhat changedStatus
16 Dec 2024Singapore, Shared Responsibility Framework Banks and telcos reimburse phishing victims where they breached a prescribed anti-scam duty. Issued by the Monetary Authority of Singapore and the Infocomm Media Development Authority.In force
1 Jan 2025Vietnam, biometrics gate online banking No online banking access without a face match against the national chip-identity database.In force
21 Feb 2025Philippines exits the FATF grey list All 18 action items cleared after four years under increased monitoring.Done
13 Apr 2025Thailand, co-liability by emergency decree Banks, telcos, wallet providers and platforms share scam losses unless they show they met prescribed standards.In force
1 Jun 2025Malaysia, data protection officers and 72-hour breach notice Final phase of the Personal Data Protection (Amendment) Act 2024, Act A1727.In force
1 Jul 2025Singapore, Protection from Scams Act Police may restrict the bank accounts of people assessed to be about to transfer money to a scammer.In force
14 Nov 2025India, Digital Personal Data Protection Rules gazetted Phased duties begin an 18-month run to full force.In force
1 Jan 2026Vietnam, Personal Data Protection Law 91/2025 Unverified accounts are suspended from online transactions.In force
22 Jan 2026South Korea, AI Basic Act Reported as Asia's first comprehensive artificial intelligence statute; deepfakes must carry clearly recognisable labels.In force
31 Dec 2026Singapore, NRIC authentication ban Private organisations must stop using national registration numbers to authenticate customers.Ahead
1 Apr 2027Japan, chip-only remote identity checks Photo-upload and mail-based verification abolished for remote account opening. Announced; the amendment was before the Diet at the time of writing.Ahead
14 May 2027India, DPDP Act at full force Breach notices, children's age checks and Significant Data Fiduciary audits bind. Penalties to 250 crore rupees.Ahead

Singapore made banks and telcos pay when they skip a required control

Singapore's Shared Responsibility Framework has been in force since 16 December 2024. Issued by the Monetary Authority of Singapore, it sets specific anti-scam duties for banks and telecommunications operators, and assigns the loss to whichever party missed one. It is a loss-sharing regime rather than a fine, and the bank is assessed first.

The duties are concrete rather than principles-based: a cooling-off period after a high-risk change, real-time alerts on outgoing transfers, a kill switch the customer can use to freeze an account. A bank that skipped one of these reimburses the phishing victim. If the bank met its duties, the telco is assessed against its own list. The victim bears the loss only where both institutions complied.

That ordering is the whole design. It prices weak verification in reimbursements rather than penalties, which means the cost lands whether or not a regulator opens a case.

Thailand went further. Its amended emergency decree of 13 April 2025 makes banks, telcos, wallet providers and online platforms co-liable for scam losses unless they can show they complied with prescribed standards. The Philippines criminalised money muling and gave its central bank hold powers over disputed funds.

Singapore's own figures for the first full year under the framework, published by the Singapore Police Force, record scam losses falling from S$1.11 billion in 2024 to S$913 million in 2025, and cases from about 51,500 to 37,300. The Singapore Police Force reports this as the first annual decline in scam cases on record. It does not attribute the fall to any single measure, and neither does this post: the framework, the Protection from Scams Act and a public awareness campaign all ran in the same period.

Reported scam losses, first full year of the framework — Source: Singapore Police Force, Annual Scams and Cybercrime Brief 2025

PeriodReported figure
20241.11 S$bn
2025913 S$m

Cases fell from about 51,500 to 37,300 over the same period, which the Singapore Police Force reports as the first annual decline on record. The force does not attribute the fall to any single measure.

Vietnam made a face match the condition for using a bank account at all

Vietnam has required a face match against the national chip-identity database for online banking access since 1 January 2025, following a rule from 1 July 2024 that applied to transfers above 10 million dong, roughly $400. From 1 January 2026, accounts without verified biometrics are suspended from online transactions entirely.

This is a different lever from Singapore's. Singapore prices the failure after the fact; Vietnam removes access before it. An account that never matched a chip-identity or VNeID profile does not transact online, whatever its balance.

Vietnamese state media reported that around 86 million accounts were deactivated by September 2025 for failing biometric verification, covering dormant, duplicate and suspected mule accounts. That figure is reported rather than published by the State Bank of Vietnam in a release retrieved for this post, and it should be treated as an order of magnitude rather than an audited count.

The State Bank of Vietnam's own measurement of the first mandate, as reported in Vietnamese state media for August 2024 against the January to July monthly average, put fraud losses down roughly 50% and the number of accounts receiving fraudulent funds down roughly 72%. It is the clearest before-and-after figure any regulator in the region has offered, and it rests on a single source.

Thailand gates mobile transfers above 50,000 baht on facial recognition. Across the region's privacy statutes, in Vietnam, Indonesia, Thailand and Malaysia, biometric data is now sensitive by law, which means the same rules that require a face match also constrain how it is stored.

Japan is retiring an entire verification method rather than tightening it

Japan has announced that from 1 April 2027, photo-upload and mail-based identity checks will no longer be accepted for opening an account remotely. Only reading the integrated circuit chip in a My Number card or equivalent credential will qualify. The amendment was before the Diet at the time of writing, so the date is announced rather than settled.

The distinction is worth stating plainly, because it is the one most likely to break an existing onboarding flow. Every other rule in this post asks for a stronger check. Japan is removing a method: the selfie-plus-document upload that most remote onboarding in the region is built on stops being a lawful route, regardless of how well it is implemented.

Chip reading is a different technical path. It requires the customer's device to read a contactless chip and validate the signature on the data it returns, which is what makes the credential hard to forge. Japan's Digital Agency publishes the My Number card holding rate, which sat around 80% of the population, so the credential base exists.

Singapore is making a narrower version of the same move. From 31 December 2026, private organisations must stop using national registration identity card numbers to authenticate customers. The number remains an identifier; it stops being a password. Anyone who has used the last four digits of an identification number as a security question is inside the scope of that change.

The obligations differ by dimension, not by country

Across nine Asian markets that rewrote identity rules between December 2024 and January 2026, no single country is strictest on everything. Vietnam is tightest on biometric access, Singapore on authentication method, India on audit and penalty, Malaysia and Thailand on breach clocks. One programme built to the strictest constraint in each dimension satisfies all nine.

The table below is the practical output of that. Confirm specifics with local counsel before relying on any single row: several of these instruments have implementing regulations still pending.

MarketCore instrumentAuthorityKey date
IndiaDPDP Act 2023 and Rules 2025Data Protection Board of IndiaFull force 14 May 2027
SingaporePDPA 2012, Shared Responsibility Framework, Protection from Scams ActPDPC, MAS, IMDANRIC authentication ban 31 Dec 2026
VietnamPersonal Data Protection Law 91/2025Ministry of Public SecurityIn force 1 Jan 2026
ThailandPDPA 2019 and technology-crime emergency decreePDPC, Bank of ThailandCo-liability since 13 Apr 2025
MalaysiaPDPA as amended by Act A1727Personal Data Protection CommissionerAll phases in force 1 Jun 2025
PhilippinesData Privacy Act 2012, AFASA 2024NPC, Bangko Sentral ng PilipinasGrey-list exit 21 Feb 2025
JapanAPPI, amendment before the DietPPC, Financial Services AgencyChip-only checks announced for 1 Apr 2027
South KoreaPIPA, AI Basic ActPIPC, Financial Services CommissionAI Basic Act in force 22 Jan 2026
IndonesiaPDP Law 27/2022Authority pendingImplementing regulation expected

State identity systems are the other half of the picture. Aadhaar passed 150 billion cumulative authentications in April 2025 and runs roughly 2.3 billion checks a month. The Philippines went furthest on acceptance: the central bank directed every supervised institution to accept the national identity card in any format, with no supplementary documents required. Where a state rail reaches most of the population, regulators start treating it as the default credential rather than one option among several.

Key takeaways

  • The driver is measured, not assumed. The UNODC puts Southeast Asia's scam economy at just under $40 billion a year. INTERPOL counted Asia-Pacific fraud alerts up 47% in a year.
  • Liability moved before the technology did. Singapore's loss-sharing framework and Thailand's co-liability decree price weak verification in reimbursements rather than fines. The cost lands without an enforcement case.
  • Vietnam removed access rather than pricing failure. Since 1 January 2025 an account without a verified face match against the chip-identity database does not bank online. From January 2026 unverified accounts are suspended.
  • Japan is deleting a method, not raising a bar. From April 2027, as announced, photo-upload verification stops being a lawful route for remote account opening. Chip reading becomes the only path.
  • The strictest constraint in each dimension is the build target. No single market is strictest on everything. One programme built to the tightest rule per dimension covers all nine.

Using Didit for Asia's verification mandates

Three of the changes in this post are checks rather than policies, and those are the ones a verification provider can carry. Japan's move to chip-only remote identity checks from April 2027 is a reading problem: NFC Reading at $0.15 per check reads the chip in a My Number card or equivalent credential and validates the signature on what it returns, which is the step that replaces the photo upload Japan is retiring. Vietnam's face match against the national chip-identity database and Thailand's facial recognition above 50,000 baht are the same shape: ID Verification at $0.15 per check, Face Match (1:1) at $0.05 per check and Passive Liveness at $0.10 per check. South Korea's Travel Rule threshold is scheduled to disappear in August 2026, which would make identity data travel with every crypto transfer regardless of size, and that is what Travel Rule at $0.02 per transaction covers. Current module prices are listed on the pricing page.

What this does not cover is the part that decides who pays. Singapore's Shared Responsibility Framework assigns loss on whether a bank ran a cooling-off period, sent a real-time alert and offered a kill switch. Those are controls inside your own product and operations, and no verification vendor performs them for you. Nor does Didit designate your Significant Data Fiduciary status under India's DPDP Act, run your data protection impact assessments, notify a regulator of a breach, or decide the legal basis on which you hold a customer's biometric data. Verification helps you meet the identity requirements described here; the obligations stay with your institution.

Common questions

Do banks have to reimburse scam victims in Singapore?

Under the Shared Responsibility Framework, in force since 16 December 2024, a bank that breached a prescribed anti-scam duty reimburses the victim of a defined phishing scam. Telcos are assessed next. The victim bears the loss only where both the bank and the telco met their duties.

When does India's Digital Personal Data Protection Act take full effect?

14 May 2027. The Digital Personal Data Protection Rules were gazetted on 14 November 2025 with phased duties: consent managers register from November 2026, and breach notification, children's age verification and Significant Data Fiduciary audits bind from May 2027. Penalties reach 250 crore rupees, about 29 million US dollars.

Is biometric verification mandatory for banking in Asia?

In a growing number of markets. Vietnam has required a face match against the national chip-identity database for online banking access since 1 January 2025. Thailand requires facial recognition for mobile transfers above 50,000 baht. Japan has announced that only chip-based identity will be accepted for remote account opening from April 2027.

Which Asian countries are on the FATF grey list?

As of the Financial Action Task Force statement of June 2026, Vietnam, Laos, Nepal and Papua New Guinea are under increased monitoring. Myanmar is subject to a call for action. The Philippines exited the grey list on 21 February 2025 after clearing all 18 action items.

What is a Significant Data Fiduciary under India's DPDP Act?

A class of large data processors designated by the Indian government under the Digital Personal Data Protection Act. A Significant Data Fiduciary must run annual data protection impact assessments and audits, carry out algorithmic due diligence, and observe cross-border transfer restrictions. These duties bind from 14 May 2027.

Related reading

Sources

  1. Inflection Point: transnational organized crime and scam centres in Southeast Asia — UN Office on Drugs and Crime · 2025
  2. Global Financial Fraud Threat Assessment 2026 — INTERPOL · March 2026
  3. Guidelines on Shared Responsibility Framework — Monetary Authority of Singapore · in force 16 December 2024
  4. Commencement of the Protection from Scams Act — Ministry of Home Affairs, Singapore · 1 July 2025
  5. Annual Scams and Cybercrime Brief 2025 — Singapore Police Force · 2026
  6. Digital Personal Data Protection Rules, 2025 — Press Information Bureau, Government of India · gazetted 14 November 2025
  7. Aadhaar crosses 150 billion cumulative authentications — Press Information Bureau, Government of India · April 2025
  8. Cashless payment requires biometric data updating from January 1, 2025 — Vietnam Government Portal · December 2024
  9. Thailand: amended emergency decree tightens measures against technology crimes — Library of Congress, Global Legal Monitor · September 2025
  10. Personal Data Protection (Amendment) Act 2024, Act A1727 — Personal Data Protection Commissioner, Malaysia · 2024
  11. All formats of the national ID accepted in financial transactions — PhilSys and Bangko Sentral ng Pilipinas · 2025
  12. Philippines exit from the FATF grey list — Presidential Communications Office, Philippines · 21 February 2025
  13. My Number card penetration rate dashboard — Digital Agency, Japan · 2026
  14. Hong Kong police crime statistics 2025 — Hong Kong SAR Government · February 2026
  15. Jurisdictions under increased monitoring, June 2026 — Financial Action Task Force · June 2026

Who wrote this

Tuan Nguyen — Growth · Didit

Writes about identity verification, fraud and compliance at Didit.

Last reviewed 29 Jul 2026 against the sources above

Infrastructure for identity and fraud.

One API for KYC, KYB, Transaction Monitoring, and Wallet Screening. Integrate in 5 minutes.

Ask an AI to summarise this page