Circular No. 77/2025/TT-NHNN amending and supplementing certain Articles of Circular No. 50/2024/TT-NHNN of the Governor of the State Bank of Vietnam on safety and security for the provision of online services in the banking sector.

These appendices specify the classification and confirmation of online payment transactions as well as online card payments in the Vietnamese banking system based on transaction value and risk level. Appendix 02 and 04 detail different authentication methods to be applied to each type of transaction to ensure safety and compliance with the regulations of the State Bank of Vietnam.

文号77/2025/TT-NHNN
文件类型Circular
发布机关State Bank of Vietnam
签署人Phạm Tiến Dũng — Phó Thống đốc
更新11/06/2026
发布日期31/12/2025
生效日期01/03/2025
失效日期
状态In effect
✦ 智能摘要

These appendices specify the classification and confirmation of online payment transactions as well as online card payments in the Vietnamese banking system based on transaction value and risk level. Appendix 02 and 04 detail different authentication methods to be applied to each type of transaction to ensure safety and compliance with the regulations of the State Bank of Vietnam.

适用范围

These provisions apply to all organizations providing payment services, commercial banks, credit card companies, and individual/business customers using online payment services or online cards in Vietnam.

要点

  • Appendix 02 specifies the confirmation of online payment transactions for types A, B, C, and D based on risk level.
  • Appendix 04 specifies the confirmation of online card payment transactions for types E, F, and G based on risk level.
  • Authentication methods include OTP via SMS/Voice/Email, Soft OTP/Token OTP, biometric information matching, FIDO, secure electronic signature, and EMV 3DS.
  • nhungdieuquantrongcanxemthem
  • 1. For individual customers: - The authentication method for transaction type D can confirm transaction types A, B, and C. - The authentication method for transaction type C can confirm transaction types A and B. - The authentication method for transaction type B can confirm transaction type A. 2. For organizational customers: - The authentication method for transaction type D1 can confirm transaction types A, B, and C1. - The authentication method for transaction types D2 and D3 can confirm transaction types A, B, C2, and C3. - The authentication method for transaction type C (including C1, C2, and C3) can confirm transaction types A and B. - The authentication method for transaction type B can confirm transaction type A.
  • nhungdieuquantrongcanxemthem2
  • In cases where customers are households or micro-enterprises applying simplified accounting, the classification and confirmation of transactions are similar to those for individual customers. Payment service providers must comply with information security and system safety regulations to ensure the legality of online transactions.
  • thongtinchitietvephuluc02va04
  • Appendix 02: Confirmation of online payment transactions - Transaction type A: Secret code or PIN. - Transaction type B: SMS OTP, Voice OTP, Email OTP, Matrix OTP card, basic Soft OTP/Token OTP, biometric information matching device, FIDO, secure electronic signature. - Transaction type C: OTP sent via SMS/Voice or basic Soft OTP/Token OTP combined with biometric information matching. - Transaction type D: Advanced Soft OTP/Token OTP, FIDO, secure electronic signature combined with biometric information matching. Appendix 04: Confirmation of online card payment transactions - Transaction type E: Secret code or PIN. - Transaction type F: SMS OTP, Voice OTP, Email OTP, Matrix OTP card, basic Soft OTP/Token OTP, biometric information matching device. - Transaction type G: Advanced Soft OTP/Token OTP, FIDO, secure electronic signature, EMV 3DS.

🌐 本文件的社会影响

  • These provisions contribute to enhancing the security of online transactions and online cards in Vietnam, helping to prevent fraudulent and deceptive activities.
  • The application of stronger authentication methods will increase customer confidence in the electronic payment system, promoting the development of e-commerce and online financial services in Vietnam.

❓ 常见问题

Which types of transactions do these appendices regulate?

The appendices regulate online payment transactions (A, B, C, D) and online card payment transactions (E, F, G).

What authentication methods are applied to each type of transaction?

Authentication methods include OTP via SMS/Voice/Email, Soft OTP/Token OTP, biometric information matching, FIDO, secure electronic signature, and EMV 3DS.

Can individual customers use the authentication method for transaction type D to confirm transactions types A, B, and C?

Yes, individual customers can use the authentication method for transaction type D to confirm transactions types A, B, and C.

Can organizational customers use the authentication method for transaction type D1 to confirm transactions types A, B, and C1?

Yes, organizational customers can use the authentication method for transaction type D1 to confirm transactions types A, B, and C1.

In the case of customers being households or micro-enterprises applying simplified accounting, what regulations must they follow?

In this case, the classification and confirmation of transactions are similar to those for individual customers.

全文

STATE BANK OF VIETNAM
VIETNAM

SOCIALIST REPUBLIC OF VIET NAM
Independence - Freedom - Happiness

Number: 77/2025/TT-NHNN

Hanoi, December 31, 2025


CIRCULAR

Amending and supplementing certain Articles of Circular No. 50/2024/TT-NHNN of the Governor of the State Bank of Vietnam on safety and security for online service provision in the banking industry
Pursuant to the Law on Information Security No. 86/2015/QH13;
Pursuant to the Cybersecurity Law No. 24/2018/QH14;

 

Pursuant to the Law on the State Bank of Vietnam No. 46/2010/QH12;

The Governor of the State Bank of Vietnam hereby promulgates this Circular amending and supplementing certain Articles of Circular No. 50/2024/TT-NHNN of the Governor of the State Bank of Vietnam on safety and security for online service provision in the banking industry.

Article 1. Amending and supplementing certain Points and Clauses of Article 1

Pursuant to the Law on Electronic Transactions No. 20/2023/QH15;

Pursuant to the Law on Credit Organizations No. 32/2024/QH15 amended and supplemented by Law No. 96/2025/QH15;

Pursuant to Decree No. 26/2025/NĐ-CP of the Government stipulating the functions, tasks, powers, and organizational structure of the State Bank of Vietnam;

At the proposal of the Director of the Department of Information Technology;

1. Supplementing Point d Clause 1 of Article 1 as follows:      

“d) Mobile money service provision activities;”

2. Amending and supplementing Clause 2 of Article 1 as follows:

“2. Scope of application

This Circular applies to credit organizations, foreign bank branches, organizations providing payment intermediary services, mobile money service providers, and credit information companies (hereinafter referred to collectively as entities).”

Article 2. Supplementing Clause 11 of Article 2

New organizational customers

are organizations newly established within twelve months or organizations newly establishing relationships with entities within twelve months and subject to risk assessment by the entity to determine the time required to apply biometric authentication or secure electronic signature methods when conducting transactions. This provision does not include:

“11. a) State agencies, public service units; b) Credit organizations, foreign bank branches;

c) Organizations listed under the Securities Law;

d) Organizations included in the Fortune Global 500 list published by Fortune Magazine in the preceding year;

e) Foreign investors who are non-residents opening settlement accounts to conduct indirect investment activities in Vietnam;

f) Other organizations selected by the entity and fully responsible for risks arising from such selection. The entity must ensure accurate verification of customer information and bear full responsibility for customer due diligence.”

Article 3. Amending and supplementing Point a Clause 3 of Article 3

“a) Applying at least one of the confirmation methods stipulated in Clauses 3, 4, 5, 7, 8, and 9 of Article 11 of this Circular when changing customer identification information.

In the case of individual customers or new organizational customers changing personal identification documents (including citizen identity cards, passports of individual customers or authorized representatives of organizational customers) or information used to register and utilize transaction confirmation methods (at least including phone number or email address or electronic signature), applying the confirmation methods stipulated in Clause 5 of Article 11 of this Circular in combination with one of the confirmation methods stipulated in Clauses 3, 4, 7, 8, and 9 of Article 11 of this Circular.”

Article 4. Amending and supplementing certain Points and Clauses of Article 7

1. Amending and supplementing Point c Clause 3 of Article 7 as follows:

“c) Evaluating and scanning to detect technical vulnerabilities and weaknesses. Assessing the ability to prevent and mitigate vulnerabilities, weaknesses, and types of attacks to meet the following minimum requirements:

(i) For web-based Online Banking applications, preventing and mitigating the ten most common vulnerabilities published by the OWASP organization (OWASP Top Ten).

(ii) For Mobile Banking applications, meeting the minimum security requirements for mobile applications published by the OWASP organization (OWASP Mobile Application Security).

(iii) The version of OWASP Top Ten or OWASP Mobile Application Security applied shall be the latest version or the closest version released within six months.”

2. Amending and supplementing Point g Clause 6 of Article 7 as follows:

“g) For organizational customers, the application software must be designed to ensure that online payment transactions (excluding card payments through payment acceptance units) are carried out in at least two steps: transaction creation and approval.

In the case of individual businesses or micro-enterprises using simplified accounting systems, the transaction process is not required to separate the two steps of transaction creation and approval;”

3. Amending and supplementing Point b Clause 8 of Article 7 as follows:

“b) Online Banking application software must have a function to authenticate connections with customer organizational software to ensure safety, security, fraud prevention, and counterfeiting according to international or Vietnamese standards and regulations;”

3. Amend and supplement Point b Clause 8 Article 7 as follows:

“b) The Online Banking application software must have the function to authenticate connection with the software of organizational customers to ensure safety, security, prevent fraud and forgery according to international or Vietnamese standards or technical regulations;”.

Article 5. Amend and supplement some clauses of Article 8

1. Supplement Clause 1a following Clause 1 of Article 8 as follows:

"1a. Control the versions of the Mobile Banking application that are released:

a) At least once every three months, the unit must assess the security and safety of software applications currently allowing customers to install and use, with the aim of identifying security vulnerabilities and evaluating the risk of cybercrime intervention.

b) In cases where customers activate on new devices or reactivate the Mobile Banking application, customers must install and use the latest version or the nearest version ensuring compliance with security requirements as stipulated. The unit must have measures to prevent downgrading to lower versions in this case.

c) Upon discovering high or severe level security vulnerabilities, the unit must take measures to check, prevent transactions from being executed, or implement control measures to prevent cybercriminals from exploiting security vulnerabilities for network attacks, fraudulent transactions, and asset theft; simultaneously, the unit must promptly address, rectify, and update to the new version within the time frame specified in Clause 6 of Article 14 of this Circular."

2. Amend and supplement Clause 4 of Article 8 as follows:

"4. Implement solutions to prevent, detect, and combat unauthorized interventions into the Mobile Banking application installed on customers' mobile devices. The Mobile Banking application must automatically exit or stop operation and notify the customer of the reason if any of the following signs are detected:

a) A debugger is attached or an environment with a debugger is active; or when the application is running in a simulated/emulated environment, virtual machine, or emulated device; or operating in a mode that allows direct communication between the computer and the Android device (Android Debug Bridge);

b) The application software has been injected with external code while running, performing actions such as tracking functions being run, logging data transmitted through functions, APIs... (hooking); or the application software has been repackaged or tampered with;

c) The device has been unlocked (root/jailbreak); or the bootloader protection mechanism has been unlocked (unlock_bootloader)."

3. Amend and supplement Clause 5 of Article 8 as follows:

"5. Do not allow the function to remember access secret codes, except in cases where the confirmation method prescribed in Clause 6 of Article 11 of this Circular is applied."

Article 6. Amend and supplement some points and clauses of Article 10

1. Amend and supplement Point a of Clause 1 of Article 10 as follows:

"a) For payment transactions using a payment account or e-wallet or mobile money account or fund transfers from debit cards or prepaid cards, the unit shall classify transactions according to the transaction types specified in Appendix 01 issued together with this Circular and apply the confirmation methods prescribed in Appendix 02 issued together with this Circular, except for the provisions in Points b, c, d, and đ of this clause;"

2. Amend and supplement Point d of Clause 1 of Article 10 as follows:

"d) For transactions where the unit proactively deducts funds from a payment account, proactively deducts funds from an e-wallet, proactively deducts funds from a mobile money account, or proactively pays from the customer's card based on an agreement with the customer, there is no need to apply the transaction confirmation methods prescribed in Points a and c of Clause 1 of this Article;"

3. Amending and supplementing Clause 2 of Article 10 as follows:

"2. For automatic deduction transactions from a payment account, automatic deduction transactions from an e-wallet, automatic deduction transactions from a mobile money account, or automatic payments from the customer's card, the unit must apply at least one of the confirmation methods prescribed in Clauses 3, 4, 5, 7, 8, and 9 of Article 11 of this Circular."

Article 7. Amend and supplement some points and clauses of Article 11

1. Amend and supplement point c, Clause 5 of Article 11 as follows:

“c) The Presentation Attack Detection (PAD) solution for biometric information of living entities, as provided in point a of this clause, when implemented by the unit itself or provided by a third party must be certified by an organization/laboratory recognized by the FIDO Alliance or by a Certification Body authorized to confirm compliance with international standards (ISO), meeting ISO 30107 Level 2 or equivalent. The Certification Body must be accredited by an Accreditation Body participating in the International Accreditation Forum’s Multilateral Recognition Arrangement (IAF MLA).”

2. Amend and supplement Clause 8 of Article 11 as follows:

“8. Pretty Good Privacy (PGP) confirmation method is a confirmation method according to the standard on security and authentication using asymmetric encryption algorithms (including a private key and a public key, where the private key is used for digital signing and the public key is used for verifying digital signatures) issued by the Internet Engineering Task Force (IETF). The PGP confirmation method must meet the following requirements:

a) The customer's public key must be registered with the unit, securely stored at the unit, and linked to the customer's electronic transaction account;

b) There must be a mechanism to verify the identity of the subject associated with the key, a security system, and a key revocation process;

c) There must be an agreement regarding the legal responsibility of the unit and the customer concerning the authenticity, integrity, and non-repudiation of transaction files signed through this method.”

3. Amend and supplement Clause 9 of Article 11 as follows:

“9. A secure electronic signature confirmation method is a confirmation method using an electronic signature, wherein the electronic signature is either a digital signature or a foreign electronic signature recognized in Vietnam in accordance with the law on electronic signatures.”

Article 8. Amend and supplement Article 21

Article 21. Responsibilities of Units under the State Bank

1. The Department of Information Technology shall be responsible for monitoring, inspecting, and coordinating with relevant units to address any issues arising during the implementation of this Circular.

2. The State Bank of Vietnam Inspectorate shall be responsible for inspecting and supervising the enforcement of this Circular and handling violations in accordance with the provisions of the law.

3. The State Bank of Vietnam branch in the region shall be responsible for inspecting and supervising the implementation of this Circular at credit institutions, branches of foreign banks, and service providers of payment intermediation within its jurisdiction and handling violations in accordance with the provisions of the law.”

Article 9. Supplement Clause 1a after Clause 1 of Article 23

“1a. Automatic debit transactions from mobile money accounts that were initiated before the effective date of this Circular may continue until the expiration of the agreed term; if the agreement does not specify a term, they may continue until December 31, 2026. Any amendment, supplementation, or extension of the agreement must comply with the provisions of Clause 2 of Article 10 of this Circular.”

Article 10. Amend and supplement the Appendix attached to Circular No. 50/2024/TT-NHNN

Replace Appendix No. 01, 02, 04 issued together with Circular No. 50/2024/TT-NHNN with Appendix No. 01, 02, 04 appended to this Circular.

Article 11. Responsibility for implementation

The heads of units under the State Bank of Vietnam, credit organizations, foreign bank branches, service providers of payment intermediary services, mobile money service providers, and credit information companies shall be responsible for organizing the implementation of this Circular.

Article 12. Provisions on Implementation

1. This Circular shall take effect from March 1, 2026, except for the cases stipulated in Clauses 2 and 3 of this Article.

2. For units providing online payment services to both individual and organizational customers, the application of the provisions of Articles 3 and 10 of this Circular shall commence from July 1, 2026.

3. For units that only provide online payment services to organizational customers (and do not provide services to individual customers), the application of the provisions of Articles 3 and 10 of this Circular shall commence from October 1, 2026.

 

Place of Receipt:
- As per Article 11;

- Leadership of the State Bank of Vietnam;

- The Government Office;

- Ministry of Justice (for verification);

- Central Bank of Vietnam's Official Website;

- Official Gazette;

- To be filed at VT, CNTT.

GOVERNOR
DEPUTY GOVERNOR 

(Signed)

Pham Tien Dung

 

 

 

APPENDIX 01
CLASSIFICATION OF ONLINE PAYMENT TRANSACTIONS

(Annexed to Circular No.        /2025/TT-NHNN dated       the      year 2025 of the Governor of the State Bank of Vietnam)

 

Serial number

Type of transaction

Transaction type A

Transaction type B

Transaction type C

Transaction type D

I

Individual customer

 

 

 

 

1

Group I.1:

- Transfer between payment accounts, debit cards, prepaid cards (hereinafter referred to collectively as cards) of one customer within a payment service provider organization.

- Transfer between e-wallets of one customer within a payment intermediary service provider organization.

All transactions.

 

 

 

 

 

 

 

2

Group I.2:

- Legal transactions of purchasing goods and services provided by payment service providers, payment intermediaries, mobile money service providers, or at acceptance units selected, evaluated, monitored, and managed by these service providers.

Transactions meeting the condition:

G + T ≤ 5 million VND.

 

 

Transactions meeting the conditions:

(i) G + T > 5 million VND.

(ii) G + T ≤ 100 million VND.

Transactions meeting the conditions:

(i) G + T > 100 million VND.

(ii) G + T ≤ 1.5 billion VND.

Transactions meeting the condition:

G + T > 1.5 billion VND.

3

Group I.3:

- Transfer between different customers' payment accounts, cards, e-wallets, mobile money accounts.

- Transfer between payment accounts, cards, e-wallets, mobile money accounts opened at different payment service provider organizations, card issuers, payment intermediary service providers, and mobile money service providers.

- Transfer from a bank account or card of the e-wallet owner to the e-wallet at a linked bank.1.

- Withdrawal from an e-wallet to a bank account or card of the e-wallet owner at a linked bank.

Money transfer and withdrawal transactions between e-wallets and bank accounts or cards of the e-wallet owner at a linked bank in accordance with the law meet the following conditions:

(i) G ≤ 10 million VND.

(ii) G + Tksth ≤ 20 million VND.

Transactions (excluding money transfer and withdrawal transactions between e-wallets and bank accounts or cards of the e-wallet owner at a linked bank in accordance with the law) meet the following conditions:

(i) G ≤ 10 million VND.

(ii) G + Tksth ≤ 20 million VND.

Transactions meet one of the following cases:

1. Case 1: Transactions meeting the conditions:

(i) G ≤ 10 million VND.

(ii) G + Tksth > 20 million VND.

(iii) G + T ≤ 1.5 billion VND.

 

2. Case 2: Transactions meeting the conditions:

(i) G > 10 million VND.

(ii) G ≤ 500 million VND.

(iii) G + T ≤ 1.5 billion VND.

Transactions meet one of the following cases:

1. Case 1: Transactions meeting the conditions:

(i) G ≤ 10 million VND.

(ii) G + Tksth > 20 million VND.

(iii) G + T > 1.5 billion VND.

 

2. Case 2: Transactions meeting the conditions:

(i) G > 10 million VND.

(ii) G ≤ 500 million VND.

(iii) G + T > 1.5 billion VND.

 

3. Case 3: Transactions meeting the condition:

G > 500 million VND.

4

Group I.4:

International interbank transfers2.

 

 

Transactions meeting the conditions:

(i) G ≤ 200 million VND.

(ii) G + T ≤ 1 billion VND.

Transactions meet one of the following cases:

1. Case 1: Transactions meeting the conditions:

(i) G ≤ 200 million VND.

(ii) G + T > 1 billion VND.

2. Case 2: Transactions meeting the condition:

G > 200 million VND.

II

Organizational customer3

 

 

 

 

1

Group II.1:

Transfer between payment accounts or e-wallets of the same customer within a payment service provider organization or a payment intermediary service provider organization.

 

All transactions.

 

 

2

Group II.2:

- Transfer between different customers' payment accounts, e-wallets.

- Transfer between payment accounts, e-wallets opened at different payment service provider organizations, payment intermediary service providers.

- Legal transactions of purchasing goods and services provided by payment service providers, payment intermediaries, or at acceptance units selected, evaluated, monitored, and managed by these service providers.

- Transfer from a bank account or card of the e-wallet owner to the e-wallet at a linked bank.1.

- Withdrawal from an e-wallet to a bank account or card of the e-wallet owner at a linked bank.

- Transfer to a mobile money account.

 

 

 

I. Type C1:

Transactions of new organizational customers meeting one of the following cases:

 

1. Case 1: Transactions meeting the conditions:

(i) G > 50 million VND.

(ii) G ≤ 1 billion VND.

(iii) G + T ≤ 10 billion VND.

2. Case 2: Transactions meeting the conditions:

(i) G ≤ 50 million VND.

(ii) G + Tksth > 100 million VND.

(iii) G + T ≤ 10 billion VND.

 

II. Type C2:

1. Case 1: Transactions of new organizational customers meeting the conditions:

(i) G ≤ 50 million VND.

(ii) G + Tksth ≤ 100 million VND.

2. Case 2: Transactions of other entities meeting the conditions:

(i) G ≤ 1 billion VND.

(ii) G + T ≤ 10 billion VND.

I. Type D1:

Transactions of new organizational customers meeting one of the following cases:

 

1. Case 1: Transactions meeting the conditions:

(i) G > 50 million VND.

(ii) G ≤ 1 billion VND.

(iii) G + T > 10 billion VND.

2. Case 2: Transactions meeting the conditions:

(i) G ≤ 50 million VND.

(ii) G + Tksth > 100 million VND.

(iii) G + T > 10 billion VND.

 

3. Case 3: Transactions meeting the condition:

G > 1 billion VND.

 

II. Type D2:

Transactions of other entities meeting one of the following cases:

1. Case 1: Transactions meeting the conditions:

(i) G ≤ 1 billion VND.

(ii) G + T > 10 billion VND.

2. Case 2: Transactions meeting the condition:

G > 1 billion VND.

 

3

Group II.3:

International interbank transfers2.

 

 

Type C3:

Transactions meeting the conditions:

(i) G ≤ 500 million VND.

(ii) G + T ≤ 5 billion VND.

Type D3:

Transactions meet one of the following cases:

1. Case 1: Transactions meeting the conditions:

(i) G ≤ 500 million VND.

(ii) G + T > 5 billion VND.

2. Case 2: Transactions meeting the condition:

G > 500 million VND.

 

Note:

G: Value of the transaction.

d.1. Amount of taxable income in Vietnam:ksth: Total value of transaction types A, B, and C2 (for new organizational customers) of each transaction type group already executed by a payment account or a card (including money transfers into an e-wallet from a payment account or card of the e-wallet owner at a linked bank when performed through the e-wallet application) or an e-wallet (excluding money transfers into the same e-wallet from a payment account or card of the e-wallet owner at a linked bank when performed through the e-wallet applicationor a mobile money account of the customer at a payment service provider organization or a payment intermediary service provider organization or a mobile money service provider organization, excluding active debit transactions from the payment account, active debit transactions from the e-wallet, active debit transactions from the mobile money account, and active payments from the card.ksth shall be valued at 0 at the beginning of the day or immediately after the customer has initiated a transaction using confirmation for transaction type C or type D (for individual customers) or transaction type C1 or D1 (for new organizational customers) during the day.

T: The total value of transactions of each transaction type group carried out on that day (of a payment account or a card (including fund transfer transactions to an e-wallet from a payment account or card of the e-wallet owner at a linked bank when conducted through the e-wallet application) or an e-wallet (excluding fund transfer transactions into the same e-wallet from a payment account or card of the e-wallet owner at a linked bank when conducted through the e-wallet application) or a mobile money account) of the customer at a payment service provider organization or a payment intermediary service provider organization or a mobile money service provider organization), excluding active debit transactions from the payment account, active debit transactions from the e-wallet, active debit transactions from the mobile money account, and active payments from the card.

(1) For fund transfer transactions to an e-wallet from a payment account/card of the e-wallet owner at a linked bank, the transaction classification is based on the payment account or card linked with the e-wallet.

(2) The conversion limit according to the exchange rate at the time of transaction execution.

(3) In cases where the customer is a household business or a micro-enterprise applying simplified accounting procedures, the transaction classification is similar to that of individual customers.

 

 

APPENDIX 02
TRANSACTION CONFIRMATION FOR ONLINE PAYMENTS

(Annexed to Circular No.      /2025/TT-NHNN dated     the    2025

of the Governor of the State Bank of Vietnam)

 

Serial number

Transaction

Minimum transaction confirmation methods for online payments

Individual customer

Organizational customer

1

Transaction type A

- Secret code or PIN (if already confirmed at the login step, it is not mandatory to confirm at the transaction execution step).

- Secret code or PIN (if already confirmed at the login step, it is not mandatory to confirm at the transaction execution step).

2

Transaction type B

- SMS OTP or Voice OTP or Email OTP;

- Or Matrix OTP Card;

- Or Soft OTP/ Token OTP basic typeor advanced type;

- Or forms channel;

- Central agencies of political-social organizations;or matching biometric information generated equipment(1);

- or FIDO;

- Central agencies of political-social organizations;or secure digital signature.

- SMS OTP or Voice OTP or Email OTP;

- Or Matrix OTP Card;

- Central agencies of political-social organizations;or matching biometric information generated equipment(1) of the authorized representative or an individual authorized by the authorized representative - Column (7): Land area in land allocation decisions, lease decisions, or documents of the competent authority or actual land area managed and used (applicable to assets that are buildings and land)..

 

3

Transaction type C

- SMS/Voice OTP or Soft OTP/Token OTP basic type or two channels.

- And matching biometric information generated.

1. Transaction Type C1:

- Kmatching biometric information generated of the authorized representative, combined with Soft OTP/Token OTP basic type or two channels.

2. Transaction Types C2, C3:

- Soft OTP/Token OTP basic type;

- Or two channels.

4

Transaction type D

- Soft OTP/Token OTP advanced type hor FIDOor secure digital signature,

- And matching biometric information generated.

1. Transaction Type D1:

- Kmatching biometric information generated of the authorized representative, combined with Soft OTP/Token OTP advanced type or FIDO or secure digital signature.

- Or csecure digital signature integrated with the electronic identity account of the organization.

 

2. Transaction Types D2, D3:

- Soft OTP/Token OTP advanced type;

- Or FIDO;

- Or secure digital signature.

Note:

- The specific forms of confirmation are detailed in Article 11 of this Circular.

- For individual customers:

+ Confirmation method for transaction type D can also confirm transaction types A, B, and C.

+ Confirmation method for transaction type C can also confirm transaction types A and B.

+ Confirmation method for transaction type B can also confirm transaction type A.

- For organizational customers:

+ Confirmation method for transaction type D1 can also confirm transaction types A, B, and C1.

+ Confirmation method for transaction types D2 and D3 can also confirm transaction types A, B, C2, and C3.

+ Confirmation method for transaction type C (including C1, C2, and C3) can also confirm transaction types A and B.

+ Confirmation method for transaction type B can also confirm transaction type A.

- In cases where the customer is a household business or a micro-enterprise applying simplified accounting procedures, the transaction confirmation method is similar to that of individual customers. Specifically, for biometric authentication and matching biometric information biometric device information, the biometric information used for comparison and verification is ) If the customer has logged into the Online Banking application using biometric device authentication, this verification method is not applied for transactions within the same login session. matching biometric information TRANSACTION CONFIRMATION FOR ONLINE CARD PAYMENTS of the authorized representative or an individual authorized by the authorized representative - Column (7): Land area in land allocation decisions, lease decisions, or documents of the competent authority or actual land area managed and used (applicable to assets that are buildings and land)..

(1Minimum transaction confirmation methods for online card payments

 

 

ANNEX 04
Transaction Type E

(Annexed to Circular No.      /2025/TT-NHNN dated     the    2025

of the Governor of the State Bank of Vietnam)

Serial number

Transaction

Secret code or PIN (if already confirmed at the login step, it is not mandatory to confirm at the transaction execution step).

1

Transaction Type F

- SMS OTP or Voice OTP or Email OTP

2

Soft OTP

Token OTP basic type;

- Or Matrix OTP Card;

- Or device;/ Transaction Type G;

- Central agencies of political-social organizations;or matching biometric information generated Or FIDO

- Or two channels.

3

- Or secure digital signature;

device;/Token OTP advanced type;

- - Or EMV 3DS.;

The confirmation method for transaction type G can also confirm transaction type E and F.

The confirmation method for transaction type F can also confirm transaction type E.

Note:

- The specific forms of confirmation are detailed in Article 11 of this Circular.

- The transaction confirmation form for type G transactions may confirm type E and F transactions.

- The transaction confirmation form for type F transactions may confirm type E transactions.

 

 

 

原始文件(PDF)

在新标签页打开PDF ↗