Let's talk: editor@tmv.in
RBI powers up digital payment security

RBI powers up digital payment security

Yellarthi Chennabasava
September 26, 2025

The Reserve Bank of India (RBI) has issued new directions aimed at enhancing the security of digital payment transactions across the country. These measures, formalised under the Reserve Bank of India (Authentication Mechanisms for Digital Payment Transactions) Directions, 2025, are set to come into effect from April 1, 2026.

The directions require all Payment System Providers and Payment System Participants, including banks and non-bank entities, to comply with the new security protocols by the specified date, unless otherwise indicated for specific provisions.

Currently, most digital transactions in India rely on SMS-based One Time Passwords (OTPs) as a second factor of authentication. Recognising the growing risks posed by cyber threats and the rapid evolution of fraud techniques, the RBI has mandated that all digital payments must now be secured using at least two distinct factors of authentication, with at least one factor being dynamic and unique to each transaction. This measure is designed to prevent unauthorised access and transaction fraud.

For practical understanding, this means that from April 1, 2026, every digital payment will require two different security checks. For example:

• While making a payment, a user might need to enter a password and then verify the transaction via an OTP sent to their mobile.

• Another scenario could involve using a fingerprint scan on a banking app along with a push notification approval in the app itself.

The directions apply to all domestic digital payment transactions and include specific provisions for cross-border card-not-present transactions. For these international transactions, card issuers are required to implement mechanisms to validate payments where the card is not physically present by October 1, 2026, thereby strengthening protections for Indian consumers engaging in global online commerce.

The framework emphasises a risk-based approach, encouraging issuers to assess transactions using behavioural patterns, location, and other contextual data to determine whether additional authentication is required. This layered approach aims to maintain a balance between security and convenience for users.

Under the new guidelines, payment issuers will be fully responsible for compensating customers for any losses arising from non-compliance with these directions. The RBI has also aligned the measures with the Digital Personal Data Protection Act, 2023, reinforcing the importance of safeguarding user data alongside transaction security.

The move reflects India’s commitment to building a more resilient digital payments ecosystem and increasing trust among millions of users nationwide. As digital transactions continue to expand rapidly, these measures aim to protect consumers from emerging cyber threats and ensure safer adoption of digital payment channels.

RBI powers up digital payment security - The Morning Voice