Skip to main content
Security June 5, 2026 15 min read

Meeting NRB Security Guidelines for Transactional SMS & OTP Logging in Nepal

N
NepalOTP Compliance Desk

Nepal Rastra Bank (NRB) issued updated IT Guidelines and Cyber Security Risk Directives governing all licensed Payment Service Providers (PSPs), Payment Systems Operators (PSOs), and commercial banks. Compliance with these directives is mandatory during annual NRB IT audits.

1. Mandatory Audit Logging Attributes

According to NRB directives, all financial transaction authorization requests must record and archive tamper-evident audit logs for a minimum retention period. Required log parameters include:

  • Source IP address and user-agent string
  • Masked phone number (+977-984****567)
  • Carrier delivery status callback timestamp (NPT/UTC)
  • Unique message reference ID generated by the licensed SMS gateway

2. Dedicated NTA-Registered Alpha Headers

Financial institutions are strictly prohibited from using shared or unverified Sender IDs. All transactional headers must be registered with the Nepal Telecommunications Authority (NTA) to prevent spoofing and phishing attacks.