Verihubs Logo
Home Blog Decision 2345 Biometric Authentication: Vietnamese Bank Guide
10 min read • Deepfake Detection • Published on September 26, 2026

Decision 2345 Biometric Authentication: Vietnamese Bank Guide

Decision 2345 Biometric Authentication: Vietnamese Bank Guide

Vietnamese banks and e-wallets must run a biometric check in three cases. According to Decision 2345/QD-NHNN, these are a single transfer above VND 10 million, a day’s transfers passing VND 20 million, and the first transaction on a new device. In each case, the face must match a chip-based citizen ID card, a VNeID account, or biometric data the bank has already verified.

What Decision 2345 Requires: Thresholds, New Devices, and Chip CCCD Matching

The State Bank of Vietnam signed Decision 2345/QD-NHNN on 18 December 2023, and it applied from 1 July 2024. It sets out which online payments need biometric authentication and which forms of it count. Below the thresholds, an OTP is still enough. Above them, however, the bank must match the customer’s face against an official identity record, not against an old selfie in its own files.

Three triggers matter for day-to-day operations.

TriggerWhat Decision 2345 requiresSource in the decision
A single transfer above VND 10 millionBiometric matching against an official identity recordArticle 1 and Appendix 01, categories C and D
Transfers above VND 20 million in one dayBiometric matching on the transaction that crosses the totalArticle 1 and Appendix 01
First mobile banking transaction, or first transaction on a new deviceBiometrics, or biometrics plus an SMS, voice, or token OTP, and a notice to the customerArticle 2(1) and 2(2)

Which records count as a valid match

This is where many vendor conversations go wrong. Appendix 02 accepts only three sources. One is the biometric data stored in the chip of the citizen ID card that the police issue. Another is authentication through the customer’s VNeID account. Finally, the bank can use biometric data it already collected and verified through one of those two routes. So a selfie from a video call does not qualify.

The card payment half of the rule

Card payments, however, sit in a separate article. Article 3 asks providers to send transaction alerts, offer daily limits, and let customers switch online payment on and off. It also requires 3D Secure or an equivalent for international card payments. Yet teams preparing for an audit often treat 2345 as a transfer rule and miss this half of it.

How Circulars 17 and 18/2024 Extended Decision 2345 from 1 January 2025

Decision 2345 governs transactions, while Circular 17/2024/TT-NHNN went further and governs the account itself. According to the Vietnam Government Portal (2024), from 1 January 2025 individual customers can only withdraw or pay electronically once the bank has checked their ID and biometrics. The match has to come from a chip-based citizen ID card, the National Population Database, or biometric data the bank already verified.

In practice, this forced a one-time cleanup of the customer base. Accounts whose owners never completed the biometric update lost digital access at the start of 2025. Banks then spent months on remediation at branches and inside their apps. Specially controlled credit institutions also had until 1 January 2025 to comply with Decision 2345 itself, under Article 5(2).

Two regimes now run side by side. One asks whether the bank ever verified the account holder against the population database. The other asks whether the person approving this high-value transfer, right now, is that same account holder. But passing the first tells you nothing about the second.

Where Decision 2345 Stops: Face Matching Is Not Proof of a Live Person

At first glance, Decision 2345 looks complete, since the captured face must match an official record. But it does not say how a bank should prove that the face belongs to a living person who is present at that moment. The text has no liveness clause and no presentation attack requirement. It also never mentions synthetic media.

Cases that exploited the gap

Fraud crews found that gap soon after the rule took effect. In May 2025, Ninh Binh police broke up a laundering ring. According to VnExpress International (2025), it moved about VND 1 trillion, roughly USD 39 million, between September 2024 and April 2025. The group collected 30-second face videos from people who agreed to open accounts. Then, according to the same report, it turned them into AI faces that passed the check on transfers above VND 10 million. Police froze around 1,000 accounts, and investigators called it Vietnam’s first recorded case of AI face scans used for money laundering.

That was not a one-off. Police in Lai Chau went public in June 2026 with a warning about modified phones built to get around the biometric step in banking apps. Three months later, Quang Ninh economic police described a suspect who bought 27 bank accounts and recorded the owners’ faces. After that, he used software to feed those recordings into the live face check, then rented the accounts out through Telegram. Police are investigating the case under Article 291 of the Penal Code.

Why a better face matcher does not fix it

What is often missed is the direction of the attack. In fact, these criminals do not try to fool a face matcher with a better photograph. Instead, the face is genuine and it does match the population database, because it belongs to the real holder who sold or rented the account. The control that fails is one the regulation never wrote down: proving the face is live, unedited, and coming from the camera rather than a file.

Two layers close that gap, and they answer different questions. Liveness detection separates a live face from a replayed or printed one. Deepfake detection, by contrast, looks for signs of synthetic generation in an image that may well be live. So a bank that buys one and assumes it covers the other has bought half a control.

The Device Rules Inside Decision 2345 That Most Teams Underuse

Two clauses in Decision 2345 deal with devices rather than faces. Most teams treat them as storage duties rather than as fraud controls.

Article 2(1) puts the trigger on the device itself. Before the first transaction on a device different from the last one, the customer must authenticate again. Article 2(3) then asks banks to keep device data and authentication logs for at least three months. These logs include unique identifiers such as IMEI and MAC address.

Read together, the two clauses already give the bank a device history for every customer. The real question, then, is what the fraud team does with it. For example, one device that signs in for twelve unrelated customers in a week shows up clearly in this data. Indeed, that is exactly the pattern account rental rings produce. So is a device whose hardware identifiers keep changing while the account stays the same.

Signal in Decision 2345 logsWhat it can revealLimit
Same device across many customersAccount rental or a mule farmShared family or office phones cause false alarms at low counts
New device before a large transferTakeover, or a renter operating a rented accountA real phone upgrade looks the same at first
Device identifiers that keep changing for one accountTampered or emulated environmentLogs only show the change; device-level checks confirm it

The most exposed institutions tend to be the ones that treated 2345 as a pure biometrics project. They bought a face matcher and then wired it to the threshold logic. Meanwhile, the device log sat in cold storage for its three months.

How to Evaluate a Biometric Vendor Against Decision 2345

Any vendor with a face matching API can help you reach the Decision 2345 floor. The real differences show up in the layers the decision does not specify. Five questions separate them.

Five questions to ask before you sign

  1. Which reference sources are supported? The decision recognises chip CCCD reading, VNeID authentication, and re-use of verified biometric data. A vendor that supports only one of them narrows your options later.
  2. Has an independent lab tested presentation attack detection? Ask which standard, which lab, and which date. ISO/IEC 30107 is the relevant family for presentation attacks, and Verihubs offers liveness detection certified against ISO/IEC 30107.
  3. Is face matching benchmarked externally? NIST has benchmarked Verihubs face verification in FRVT 1:1, so the result is measured rather than self-reported. Until a vendor shows a benchmark, treat its accuracy number as marketing.
  4. Is deepfake detection a real capability or a bullet point? After the 2025 laundering case, a Vietnamese risk committee will ask this first. Deepfake detection works on different signals from liveness, so it needs its own evaluation.
  5. What happens after a failed check? Step-up paths, manual review, and false rejection handling decide whether the control survives real customers. If a rule blocks too many honest high-value transfers, the business will switch it off.

Why the combination matters

The same questions apply in Vietnam, Indonesia, and the Philippines, even though each market uses different identity sources. Verihubs runs active and passive liveness alongside deepfake detection built for face-swap attacks. The Vietnamese cases point to that combination rather than to either layer alone.

Ready to test where your current setup fails against a synthetic face? Talk to the Verihubs team about a liveness and deepfake assessment for Decision 2345 workflows.

Frequently Asked Questions About Decision 2345

What transactions require biometric authentication under Decision 2345?

According to Decision 2345/QD-NHNN (2023), there are three triggers: a single transfer above VND 10 million, a day’s transfers passing VND 20 million, and the first transaction on a new mobile device. Card payments have their own measures under Article 3.

When did Decision 2345/QD-NHNN take effect?

The State Bank of Vietnam signed it on 18 December 2023, and it applied from 1 July 2024. However, credit institutions under special control had until 1 January 2025 under Article 5(2).

What counts as valid biometric matching under Decision 2345?

A match against the chip data in the police-issued citizen ID card, authentication through the customer’s VNeID account, or a match against biometric data the bank already verified through those routes.

Does Decision 2345 require liveness detection or deepfake detection?

No. The text requires biometric matching but says nothing about liveness or synthetic media. Because it leaves both controls to the bank, AI-generated face scans have passed the threshold check in cases since 2025.

How long must banks keep device and authentication logs?

At least three months, under Article 2(3). The logs must include unique device identifiers such as IMEI and MAC address, as well as the authentication records.

Decision 2345 Sets the Floor for Biometric Authentication, Not the Ceiling

As a compliance checklist, Decision 2345 is finished work for most Vietnamese banks. They have wired in the thresholds, switched on chip CCCD and VNeID matching, and cleaned up the account base for the Circular 17 deadline. Still, the fraud numbers have not followed. According to Vietnam’s National Cybersecurity Association (2026), online scam losses passed VND 6 trillion in the first eleven months of 2025. Meanwhile, the laundering cases that reached court in 2025 and 2026 ran through accounts that were fully compliant on paper.

That is the useful way to read the rule. It fixes who owns the account. But it leaves open whether the face at the camera is live, and whether the holder is acting for themselves at all. Banks that plan their 2026 roadmap around that second question will not be reading about their own accounts in the next police briefing.

Client Verihubs
Detect Face Swap with Verihubs Deepfake Detection
Get FREE Trial
View Blog