State Bank of Pakistan: test your mobile banking app before every launch.

SBP asks banks and microfinance banks to run a security review of every new or changed digital product, and to fix all critical, high and medium vulnerabilities before launch. Its technology risk framework adds vulnerability assessments and penetration tests, and its 2023 digital banking measures set device binding, authentication and encryption controls, with compensation duties for victims of fraud if the controls are missing. Ostorlab tests the controls in your app and the APIs behind it, on every release.

  • Static and dynamic testing of the build you ship, with no source code needed
  • Tests login, one-time codes, step-up checks and session handling with your test accounts
  • Follows the app into its APIs, even with TLS pinning
  • Risk ratings, tickets and retests, so every fix is validated before launch
Scan your own appBook a demo

Free scan of your app from the App Store or Google Play. No login required.

Who it applies to
Banks, DFIs and microfinance banks in Pakistan, and other SBP regulated entities for some texts
Key date
Digital banking security measures due by 31 December 2023 (BPRD Circular No. 04 of 2023)
Focus
Security reviews before launch, penetration testing, authentication and device binding
Main references
BPRD Circular No. 05 of 2017 and BPRD Circular No. 04 of 2023
Key dates

How the SBP rules for digital channels took shape

SBP has built its rules for technology and digital channels through circulars. The dates below are for the texts cited on this page.

  1. 22 June 2016

    Prevention against cyber attacks

    BPRD Circular No. 07 of 2016 asks banks, DFIs and microfinance banks for periodic independent assessments of their cyber security controls, including vulnerability assessments and penetration testing.

  2. 30 May 2017

    Technology governance framework

    BPRD Circular No. 05 of 2017 issues the Enterprise Technology Governance & Risk Management Framework, with compliance required by 30 June 2018.

  3. 28 November 2018

    Security of digital payments

    PSD Circular No. 09 of 2018 requires vulnerability assessment and penetration testing of alternate delivery channels, including internet and mobile banking, and an independent third-party review.

  4. 14 April 2023

    Digital banking security measures

    BPRD Circular No. 04 of 2023 sets control measures for digital banking products and services, with a plan due to SBP within 30 days and monthly progress reports.

  5. 31 December 2023

    Deadline for the measures

    Banks and microfinance banks that miss it are liable to compensate victim customers within three working days of the reporting of fraud.

  6. 16 February 2026

    Cyber Shield strategy

    SBP's Cyber Resilience Strategy for regulated entities, with milestones to be implemented in a phased manner by 2030.

What SBP asks

The SBP rules, applied to your mobile app

For each rule: what the text says, what it means for a mobile banking app, how Ostorlab helps, and what stays with your team.

  1. BPRD Circular No. 04 of 2023, Annexure A, 2(vii) and 2(viii)

    Review every new or changed digital product before launch

    What the text says

    Conduct comprehensive information security reviews of new digital products and services, and of any modification to existing ones, covering people, process and technology. Weaknesses and all critical, high and medium vulnerabilities found in those reviews must be rectified and controlled through validation before deployment to production and launch.

    Source:BPRD Circular No. 04 of 2023, Annexure A, 2(vii) and 2(viii)

    What it means for your mobile app

    Each release of the mobile app changes a digital product. It needs a security review, and every medium, high or critical finding has to be fixed and retested before the store update goes live.

    How Ostorlab helps

    Run automated scans from your CI/CD pipeline on every build. Mobile SAST analyses the APK, AAB or IPA directly, with no source code needed, and Mobile DAST runs the app. Findings are rated critical, high, medium or low, tracked as tickets in the platform or in Jira and ServiceNow, and retested once the fix ships.

    What stays with you

    The review baseline, the people and process parts of the review, and the go-live decision.

  2. BPRD Circular No. 04 of 2023, Annexure B (FAQs), Management Control 2(vii)

    Run periodic application security reviews

    What the text says

    SBP's FAQs on the 2023 measures say regulated entities must conduct periodic application security reviews, including vulnerability assessments, penetration testing and source code reviews, and address and rectify all identified vulnerabilities in a timely manner. Each entity develops its own review baseline, based on best practices and its own risk assessment.

    Source:BPRD Circular No. 04 of 2023, Annexure B (FAQs), Management Control 2(vii)

    What it means for your mobile app

    Release checks are not enough on their own. The app and its APIs also need a recurring cycle of vulnerability assessment, penetration testing and code review, with a record that the findings were fixed.

    How Ostorlab helps

    Fast scans usually finish in 1 to 5 minutes and full scans in 15 to 45 minutes, so they fit every release. An AI-agent pentest goes deeper, typically in a few hours, with a working exploit you can replay for each AI-agent finding, for critical changes and your periodic deep tests.

    What stays with you

    Source code reviews of your backend, the review schedule and the baseline itself.

  3. Enterprise Technology Governance & Risk Management Framework, 2.7

    Keep a testing program with vulnerability assessments and penetration tests

    What the text says

    Establish a comprehensive testing program to validate the effectiveness of the information security environment on a regular basis. Depending on the complexity of operations, use vulnerability assessments followed by a validation test that the gaps were filled, scenario-based testing, periodic penetration tests, with tests of internal systems at the time of major updates and deployments, and an independent quality assurance function that tests in-house developments for vulnerabilities. The policy sets how often each test runs.

    Source:Enterprise Technology Governance & Risk Management Framework, 2.7

    What it means for your mobile app

    Your policy defines how often the app is tested. A major release of the app or its backend is a natural trigger for a penetration test, and each assessment needs a follow-up test that proves the gaps are closed.

    How Ostorlab helps

    Your security or second-line team runs the tests and owns the results. Each finding comes with a risk rating, reproduction steps, request and response logs and screenshots, and retesting confirms whether the underlying issue is resolved.

    What stays with you

    Scenario-based and recovery testing, the testing policy and its periodicity.

  4. BPRD Circular No. 07 of 2016; PSD Circular No. 09 of 2018

    Have your cyber controls assessed independently

    What the text says

    Banks, DFIs and microfinance banks must ensure periodic independent assessments of the adequacy and effectiveness of their cyber security controls. These may include vulnerability assessments and penetration testing by officials independent of the area under review, or by external parties with sufficient IT security experience where internal teams lack the expertise. In 2018, SBP also required internal vulnerability assessment and penetration testing, and an independent third-party review, of alternate delivery channels, including internet and mobile banking.

    Source:BPRD Circular No. 07 of 2016; PSD Circular No. 09 of 2018

    What it means for your mobile app

    The people who test the app should be independent of the team that builds it. For mobile banking, SBP has already asked for both internal testing and a third-party review.

    How Ostorlab helps

    Ostorlab tests the build your customers download and the APIs it calls. Your security or second-line team runs the tests and owns the results, separately from the developers.

    What stays with you

    Deciding whether a test meets the independence expectation, and engaging external assessors.

  5. Regulations for the Security of Internet Banking, 1 and 2.2.1; BPRD Circular No. 04 of 2023, Annexure A, 3-I(iv)

    Authenticate with at least two factors, and control sessions

    What the text says

    Banks must authenticate internet banking customers with at least two-factor authentication, such as a password and a one-time token, and add layered security for high-value transactions. Authentication controls take into account failed log-in attempts, password change frequency, session time-outs and re-authentication based on predefined criteria. The regulations apply whatever access device the customer uses, and SBP's 2023 measures add that one-time passwords must be of reasonable length with appropriate validity.

    Source:Regulations for the Security of Internet Banking, 1 and 2.2.1; BPRD Circular No. 04 of 2023, Annexure A, 3-I(iv)

    What it means for your mobile app

    Lockout after failed attempts, session expiry, re-authentication for high-value transfers and one-time password lifetime are all testable settings in the app and its backend.

    How Ostorlab helps

    Ostorlab logs in with your test accounts, completes SMS, email or TOTP one-time codes, and tests login and logout, token refresh, timeouts, session invalidation and MFA enforcement, including step-up flows.

    What stays with you

    Choosing the factors and the policy values, such as lockout thresholds and one-time password validity.

  6. BPRD Circular No. 04 of 2023, Annexure A, 3-A(iii), (v), (vi), (viii) and (ix)

    Bind devices and protect credential resets

    What the text says

    Register customer devices through device fingerprinting or device binding, and notify the customer immediately of any new device. Credential resets may only be performed from the registered device, with one-time password auto-fetch or auto-fill and sender binding that restricts manual entry. A 2-hour cooling-off period applies before the mobile app is activated for newly registered customers, and before key account changes such as device, mobile number, email, transaction limits and password reset. Sign-up must not confirm that an account exists before the process is complete.

    Source:BPRD Circular No. 04 of 2023, Annexure A, 3-A(iii), (v), (vi), (viii) and (ix)

    What it means for your mobile app

    These controls have to hold in the backend, not only in the app screens. A request sent straight to the API should hit the same device check, the same cooling-off period and the same silent sign-up.

    How Ostorlab helps

    Ostorlab completes SMS, email or TOTP one-time codes with your test accounts and tests MFA enforcement and step-up flows, including how attackers try to manipulate them, together with the API calls behind account changes. API tests cover abuse such as enumeration, replay and automation.

    What stays with you

    Device binding design, NADRA biometric verification, call-back confirmation and customer notifications.

  7. BPRD Circular No. 04 of 2023, Annexure A, 3-B(v) and 3-E

    Encrypt and mask customer data

    What the text says

    Encrypt data in transit and at rest at all stages of a transaction, based on its classification and sensitivity, including personally identifiable information and payment card data. Customer information is stored or transmitted in hashed or encrypted form with non-obsolete algorithms such as AES 256 and SHA256, biometric information is never stored or transmitted unencrypted, and critical information such as card numbers is masked.

    Source:BPRD Circular No. 04 of 2023, Annexure A, 3-B(v) and 3-E

    What it means for your mobile app

    The app is one stage of the transaction. What it writes to the device, puts in logs or sends over the network is in scope.

    How Ostorlab helps

    Ostorlab looks for session tokens and personal data in local storage, caches, logs and screenshots, checks for misconfigurations that weaken transport and session protections, and tests the APIs behind transactions.

    What stays with you

    Key management, data classification and encryption on your servers.

  8. BPRD Circular No. 04 of 2023, cover letter and Annexure A, 4(iii)(f) and 4(v)

    Be able to show your controls were in place

    What the text says

    Banks and microfinance banks that fail to implement the controls within the timeline are liable to compensate victim customers within three working days of the reporting of fraud, apart from enforcement action. Under the liability framework, FIs compensate customers where they cannot establish that transactions were executed through the customer’s registered device, and originating FIs compensate customers where any stipulated control is not implemented or has failed.

    Source:BPRD Circular No. 04 of 2023, cover letter and Annexure A, 4(iii)(f) and 4(v)

    What it means for your mobile app

    When a fraud claim comes in, the question is whether your controls existed and worked. Test results for each release help you answer it.

    How Ostorlab helps

    Scan results, findings with reproduction steps and retest results give you a dated record of how the app’s controls were tested and fixed, release after release.

    What stays with you

    Fraud monitoring, dispute handling in FTDH and the compensation decision.

  9. Framework on Outsourcing to Cloud Service Providers, Section T

    Test cloud-hosted systems at least once a year

    What the text says

    Conduct vulnerability assessment, penetration testing and scenario-based security testing of systems hosted with cloud service providers, at least once annually, taking into account threats unique to cloud services such as weak application programming interfaces. Vulnerabilities in cloud workloads are categorized by risk, tracked and rectified, including post validation.

    Source:Framework on Outsourcing to Cloud Service Providers, Section T

    What it means for your mobile app

    If the backend or APIs behind your app run in the cloud, they need at least a yearly assessment and penetration test, and API weaknesses are named as a scenario to cover.

    How Ostorlab helps

    Ostorlab intercepts the app's traffic, even with TLS pinning, and tests the APIs for broken authorization (BOLA, BFLA, IDOR), misuse of tokens and sessions, and abuse such as enumeration, replay and automation, with request and response evidence for each finding.

    What stays with you

    Testing of the cloud infrastructure, the provider's own assessments and data centre reviews.

Summary of public SBP texts, checked on 27 September 2026. Some texts apply only to banks and microfinance banks, as noted. This page is not legal advice.

Mapping

SBP rules, control by control

The controls the SBP texts point to, how Ostorlab tests them in your app and its APIs, and the evidence you can keep.

SBP rules, control by control
ControlHow Ostorlab helpsEvidence you keep
Security review of each new or changed digital productBPRD 04/2023, Annex A 2(vii)Mobile SAST and DAST in the release pipeline, before the app reaches the store. Details Scan results for each build
Critical, high and medium findings fixed and validated before launchBPRD 04/2023, Annex A 2(viii)Groups findings into tickets in the platform or in Jira and ServiceNow, and retests after the fix. Details Ticket history and retest result for each finding
Periodic vulnerability assessments and penetration testsETGRMF 2.7; BPRD 04/2023, Annex BAI-agent pentest of the app and its APIs, behind login, on the build you ship. Details A working exploit you can replay for each AI-agent finding, and a coverage heatmap
Two-factor authentication, failed log-ins and session time-outsInternet banking regulations, 2.2.1Logged-in testing with one-time codes, and checks of sessions, tokens, timeouts and MFA enforcement. Details Findings on login, session and step-up flows with reproduction steps
Device checks and cooling-off on key account changesBPRD 04/2023, Annex A 3-ALogs in with one-time codes and tests MFA enforcement and step-up flows, and the API calls behind them. Details Findings on login and step-up flows, with reproduction steps
Sign-up that does not reveal whether an account existsBPRD 04/2023, Annex A 3-A(ix)Intercepts traffic even with TLS pinning and tests authorization, token misuse and abuse such as enumeration and replay. Details Request and response evidence for each API finding
Encryption and masking of customer dataBPRD 04/2023, Annex A 3-B(v), 3-ELooks for tokens and personal data in storage, caches, logs and screenshots, and checks transport protections. Details File system evidence showing what was written, where and when
Security and vulnerability assessment of software modulesETGRMF 4.2.1(d)Fingerprints statically compiled libraries and maps them to known vulnerabilities, release to release. Details Mapped vulnerabilities with upgrade or replace recommendations, and closure tracked across releases
Yearly testing of cloud-hosted APIsCloud framework, Section TLogged-in testing that follows the app into its APIs to test authorization, sessions and MFA enforcement. Details Request and response logs and reproduction steps for each finding
A record of tested controls for fraud claimsBPRD 04/2023, Annex A 4Keeps scan results, tickets and retests for each release. Dated scan history, tickets and retest results

Ostorlab tests controls in the app and its APIs. Fraud monitoring, FTDH disputes, NADRA biometric verification, call center controls, PCI DSS and PCI SSF accreditation, business continuity and reporting to SBP stay with your teams.

Action plan

SBP controls to test in your mobile app

A practical list for security, technology risk and fraud teams, based on the SBP texts on this page.

  1. Review each release

    Scan every build before it reaches the store, and hold the release while critical, high or medium findings are open.

  2. Validate the fixes

    Retest each fix before launch and keep the result, so the validation step is on record.

  3. Periodic deep tests

    Plan periodic penetration tests and code reviews of the app and its APIs, and a test after each major update.

  4. Login and one-time passwords

    Check two-factor login, lockout after failed attempts, session time-outs, re-authentication for high-value transfers and one-time password validity.

  5. Device binding and cooling-off

    Try credential resets and key account changes from an unregistered device and directly through the APIs, and check that the 2-hour cooling-off holds.

  6. Silent sign-up

    Check that registration never confirms whether an account exists before the process is complete, including through repeated API calls.

  7. Data on the device and in transit

    Look for tokens, personal data and card numbers in storage, caches, logs and screenshots, and check that traffic is encrypted.

  8. Evidence for fraud claims

    Keep dated results and retests for each release, to show which controls were in place and tested.

A suggested list, not an SBP template. This is not legal advice.

Sources

The official texts this page is based on, checked on 27 September 2026.

FAQ

Frequently asked questions

Straight answers on coverage, setup, and how results reach your team.

Can't find your answer? Book a demo or contact us.

Test your mobile banking app against the SBP controls

Start with a free scan of your app from the store, or book a demo to run logged-in and API tests with our team.