Meeting NRB Security Guidelines for Transactional SMS & OTP Logging in Nepal
Nepal Rastra Bank (NRB) issued updated IT Guidelines and Cyber Security Risk Directives governing all licensed Payment Service Providers (PSPs), Payment Systems Operators (PSOs), and commercial banks. Compliance with these directives is mandatory during annual NRB IT audits.
1. Mandatory Audit Logging Attributes
According to NRB directives, all financial transaction authorization requests must record and archive tamper-evident audit logs for a minimum retention period. Required log parameters include:
- Source IP address and user-agent string
- Masked phone number (
+977-984****567) - Carrier delivery status callback timestamp (NPT/UTC)
- Unique message reference ID generated by the licensed SMS gateway
2. Dedicated NTA-Registered Alpha Headers
Financial institutions are strictly prohibited from using shared or unverified Sender IDs. All transactional headers must be registered with the Nepal Telecommunications Authority (NTA) to prevent spoofing and phishing attacks.
Related Articles
How to Ensure 99.9% OTP Delivery Rates Across NTC & Ncell Networks in Nepal
An in-depth technical analysis of mobile carrier routing in Nepal, managing Short Message Service Centers (SMSC), overcoming DND filters, and building zero-latency failover pipelines.
Securing Financial Apps in Nepal: Best Practices for 2FA and OTP Verification
A comprehensive guide for mobile wallets, online banking platforms, and fintech startups in Nepal on implementing compliant, tamper-proof OTP authentication.