The Egypt Financial Regulatory Authority has warned nonbank finance providers that it will take strict legal action over breaches of customer data verification rules. The framework, most recently amended in July 2026, requires supervised firms using financial technology and related outsourcing providers to verify customers’ national identification data, mobile phone ownership and status on money laundering and asset disposal prohibition lists. Consumer finance companies and providers of medium, small and microenterprise finance must also send and record a one-time password when entering into a contract and each time financing is used. The requirement is already in place for entities operating through financial technology, while other covered entities have until January 2027 to align their operations. The warning follows sanctions against a consumer finance company after an international school used parents’ data to obtain financing in breach of customer verification and financing controls.