It is almost public consensus that banking apps in Pakistan are unreliable. Their failures tend to cluster around the points of access: logins that don’t go through, biometric prompts that hang, OTPs that never arrive, and transfers that fail after the money has already left. Outages are frequent enough to have become almost routine.
In June 2026, Easypaisa, a wallet with roughly 22 million monthly active users, suffered a disruption that left customers unable to log in despite entering the correct PIN, while biometric verification also failed. The company acknowledged only “intermittent” issues and disclosed neither the cause nor a restoration timeline before services were restored the following day. More recently, it was Allied Bank’s turn, with myABL, ATM and POS services reportedly offline for hours.
Growing digitization means these failures matter more than they used to because they now have a tangible effect on people’s lives. The regulator has spent a decade pushing banking onto digital rails: 132 million users are registered on mobile banking apps and wallets, 92% of retail payment volume now moves through digital channels, the Raast instant-payment system is expanding, and banks face hard targets to move merchants onto digital acceptance.
As the app becomes the primary way people reach their money, reliability stops being a convenience feature and becomes a condition of access. The State Bank of Pakistan increasingly takes the same view and has begun regulating accordingly. HBL’s July app revamp offers a useful case study in what happens when that reliability breaks. We use app-store ratings and around 2,200 reviews to identify what actually went wrong. We then look at how failures in banking apps in Pakistan are regulated, and where the SBP’s existing rules still leave gaps.
The Rollout and Its Immediate Reception
In mid-July, HBL rolled out a full redesign of its app with a revamped interface and navigation. The updated builds (2.20.78 on Android, 4.35 on iOS) were released around 16–17 July per the app stores, although references to the new version began appearing in reviews a few days earlier, consistent with a phased rollout. To assess the reception, we pulled daily ratings and around 2,200 post-launch reviews across both stores from Appfigures. We also constructed a matched, roughly 28-day pre-launch baseline of comparable volume so the change could be measured against prior performance rather than viewed in isolation.
HBL’s rebuild comes amid a broader industry shift toward shipping software faster. App releases have accelerated sharply. According to Sensor Tower, new iOS releases reached about 560,000 in the first half of 2026, already nearing the full-year 2025 figure. Appfigures, meanwhile, reported cross-store releases up roughly 60% year-on-year in Q1. One factor behind that acceleration is AI-assisted coding. GitHub estimates AI now writes close to half the code committed on its platform.
Yet faster development does not remove the need for review. In a 2025 survey of more than 1,100 developers by Sonar, a company that develops code-quality and bug-detection tools, 96% said they did not fully trust AI-generated code without manual review. None of this is evidence that HBL’s revamp was developed this way. However, the pressure to ship quickly is now industry-wide, and testing is one area that can be compressed as release cycles shorten.
HBL App Ratings Fell Sharply After the Rollout

On Android, the seven-day rolling average rating stepped down from roughly 3.8 before the revamp to the 1.5–2.0 range afterwards. More importantly, it stayed there through the three weeks to August 9, with no meaningful recovery. The star mix shifted with it. The share of new five-star ratings collapsed while one-star ratings came to dominate the daily flow.
Underneath that, the net flows moved in reverse. Net one-star ratings rose by thousands while net five-star ratings turned negative. In other words, the app was no longer earning enough new five-star ratings to offset the store’s routine removal of older ones. iOS weakened too, with its mean daily rating fell from about 4.2 to about 3.2, although on a much smaller ratings base.
What HBL Users Said Was Breaking
To understand the cause, we tagged the 910 negative (1–2★) Android reviews by theme and compared the post-launch distribution against the pre-launch baseline. The shift is specific. Vague negativity, the largest category before the update, fell the most, by around twelve points, as complaints moved from undirected gripes to named problems. Login, OTP and registration failures rose the most, by over nine points, to become the single biggest complaint after the update. Crashes and freezes rose more than eight points, and slowness around five, as reviews shifted toward the update’s concrete faults.

The Cost of Bad App Updates
Botched app releases are not unique to Pakistan, and international precedents show they can carry substantial costs. Sonos, the US home-speaker company, redesigned its app in May 2024 and removed or disrupted working features including sleep timers, alarms and accessibility options for blind users. Some customers were left unable to use parts of their systems altogether. Revenue fell 16% the following quarter, the company laid off around 100 employees, and in January 2025 its CEO stepped down. Analysts estimated the episode erased close to half a billion dollars from Sonos’s market value. The stakes are arguably higher for a bank. A speaker app sits between a customer and their music. A banking app sits between a customer and their money. The tolerance for failure should therefore be considerably lower.
How Banking Apps in Pakistan Are Regulated
Where tolerance for failure is this low, the problem becomes regulatory as much as it is a product issue. The SBP’s requirements rest largely on three sets of rules. PSP&OD Circular No. 01 of 2023 covers the availability of digital channels, including notification and duration thresholds for downtime. The older Enterprise Technology Governance and Risk Management Framework (BPRD Circular No. 05 of 2017) requires banks to report to the SBP any major disruption that leaves banking services unavailable to customers for more than two hours. BPRD Circular No. 04 of 2023 addresses the security of digital banking products and services, including controls around product changes and liability for customers affected by fraud. These and other consumer-protection requirements were later consolidated into the Business Conduct and Fair Treatment of Consumers Regulatory Framework, or BC&FRF, through BPRD Circular No. 04 of 2025.
The downtime rules explicitly acknowledge that customer reliance on digital channels has “increased manifold.” They require banks to notify customers and the SBP about planned disruptions and to report unanticipated disruptions that exceed specified thresholds. However, those rules, like the technology-governance framework’s two-hour reporting trigger, are still built around the infrastructure definition of an outage, measured by duration rather than by whether the service actually works. In a case such as HBL’s July rollout, that distinction matters. The security framework comes closer to the problem because it focuses on controls around digital products and services rather than merely reporting a disruption after it happens. It also establishes liability for banks that fail to implement required controls where customers are defrauded. Yet neither framework asks whether a release was fit to ship in the first place.
When Is a Banking App Actually “Down”?
Consider what “downtime” means. A total outage is the simple case: the service is unreachable for everyone, the failure is observable, and its duration is easy to measure. Digital failures are rarely that clean, though, since load balancing can send half the userbase to a healthy server and half to a failing one. The same incident would then be an outage for some customers and completely invisible to others. The harder question is functional. If an app opens but users cannot log in, is it up? What if the OTP never arrives? What if a transfer remains stuck in processing? What if money leaves one account but fails to reach the other?
The service may be online by an infrastructure measure but not by the only one a customer cares about. The EU’s payment-incident reporting rules define downtime functionally, as any period when a customer is prevented from initiating a payment or accessing their account. By that test, an app that opens but will not let you log in or move money is down. Pakistan’s rules, which measure disruption by its duration without defining what counts as one, do not clearly capture it.
How Other Regulators Treat Digital Banking Failures
Other regulators have begun closing this gap, although there is no single universal model. The US has taken a lighter approach than Europe, focused on incident reporting rather than resilience testing: banks must notify their primary regulator within 36 hours of determining that a qualifying computer-security incident has occurred, and the definition is functional enough to include incidents that materially disrupt customers’ ability to access their accounts. The UK goes further, requiring financial institutions to identify their important business services, set tolerable limits of disruption, and prove those services can stay within them during severe but plausible scenarios. The EU’s Digital Operational Resilience Act (DORA) is similar in spirit, requiring firms to manage ICT risk, test their resilience, report major incidents, and address the risks posed by critical technology providers.
These regimes shift the regulatory question away from whether a server stayed online and toward whether a service kept working for the people who needed it. Whether either model fits Pakistan is another question. The UK and EU regimes are heavy machinery built largely for mature financial institutions, and applying them wholesale to a market still trying to move millions of people and merchants onto digital rails could impose real costs and slow the adoption regulators are trying to encourage. But the current approach leaves a gap at the other end.
As banking becomes more app-based, the SBP may eventually need a definition of reliability that sits between “the server was online” and full-scale operational-resilience regulation. At a minimum, that could mean treating sustained failures of critical functions, logging in, authenticating, viewing balances, completing payments, as service-availability incidents even when the app itself remains reachable. Once an app becomes the main door to a bank account, one that opens but does not let you use your money is not meaningfully “up.”
Method: Ratings and review text are from Appfigures: around 2,200 post-rollout reviews against a matched roughly 28-day pre-launch baseline, with iOS and Android analysed separately. Android one- and two-star themes n≈910; the iOS negative sample n=51 and is indicative only. Sentiment is based on the user-applied star rating rather than an NLP model. Themes were tagged through a keyword pass and spot-checked; theme shares are multi-label and therefore exceed 100%. “Launch” denotes the mid-July rollout.
