Thursday, March 26, 2026
News

RBI unveils new directions to strengthen digital payment security

SocialTwist Tell-a-Friend    Print this Page   COMMENT

Mumbai (Maharashtra) | September 25, 2025 3:17:30 PM IST
As digital payments become an integral part of everyday life in India, the Reserve Bank of India (RBI) has taken a significant step to enhance the security of these transactions.

The RBI, in February 2024, had announced its intention to modernize the authentication mechanisms used across the country's payment ecosystem. This vision was formalized in the Reserve Bank of India (Authentication mechanisms for digital payment transactions) Directions, 2025, which will come into effect on April 1, 2026.

"All Payment System Providers and Payment System Participants, including banks and non-bank entities, shall ensure compliance with these directions by April 01, 2026, unless indicated otherwise for any specific provision herein," RBI said in a statement.

Currently, most digital payments in India rely on SMS-based One Time Passwords (OTP) as a second factor of authentication. However, recognizing the rapid advancements in technology and the evolving landscape of cyber threats, the RBI has mandated that all digital payments must now be secured by at least two distinct factors of authentication. Importantly, at least one factor must be dynamic--unique to each transaction--to prevent fraud and unauthorized access.

These directions apply to all payment system providers and participants, including banks and non-bank entities, covering all domestic digital payment transactions, with specific provisions for cross-border card-not-present transactions. For the latter, card issuers must implement mechanisms by October 1, 2026, to validate international transactions where the card is not physically present, further safeguarding Indian consumers shopping globally.

The RBI's framework emphasizes robustness, interoperability, and a risk-based approach. Issuers are encouraged to evaluate transactions based on behavior patterns, location, and other contextual data to decide if additional authentication is required. This flexible, layered security model aims to balance convenience and protection.

In addition to technical requirements, issuers bear full responsibility for compensating customers in case of losses arising from non-compliance with the directions. The RBI also aligns these directions with the Digital Personal Data Protection Act, 2023, reinforcing data privacy alongside payment security.

With these new directions, the RBI is steering India's digital payment ecosystem toward a safer, more resilient future building trust and confidence for millions of users nationwide. (ANI)

 
  LATEST COMMENTS ()
POST YOUR COMMENT
Comments Not Available
 
POST YOUR COMMENT
 
 
TRENDING TOPICS
 
 
CITY NEWS
MORE CITIES
 
 
 
MORE BUSINESS NEWS
Best Hospital for Eye Surgery in India: ...
Embee Software Expands Cybersecurity Por...
Chhattisgarh offers incentives up to 200...
GAIL (India) Limited to acquire 49% stak...
L&T Finance's 'Pillion Rider to Ride...
ICICI Bank projects India's FY27 growth ...
More...
 
INDIA WORLD ASIA
Emergency, Gujarat riots, 1993 Mumbai an...
'Victory for the people of Panihati': RG...
'Edappadi not fighting for Tamil Nadu, b...
Chhattisgarh: Poultry sales halted withi...
20 lakh LPG cylinders needed for Char Dh...
Parliamentary panel recommends constitut...
More...    
 
 Top Stories
Kajaria brings Ranveer Singh and Ra... 
First look for 'Valmiki Ramayana' o... 
Best Hospital for Eye Surgery in In... 
JGU Achieves Historic Higher Rankin... 
Tech Mahindra inks MoU with IIT Bom... 
L&T Finance's 'Pillion Rider to... 
"Khelo India aims to nurture, devel... 
"It's not for the US to dictate ter...