HomeCirculars › RBI/2008-09/402

UCBs: Security Measures for Card Transactions

Current · Source: Reserve Bank of India · RBI/2008-09/402 · issued 18 Feb 2009 · ~1 min read
Quick answerRBI directs all Primary Urban Co-operative Banks to adopt enhanced risk mitigation and security measures for online credit/debit card transactions, as per enclosed DPSS circular dated Feb 18, 2009, issued under Payment and Settlement Systems Act 2007.
The rule, in the simplest words
How it plays out — a real example

A card payment operations team leader at a Primary Urban Co-operative Bank in Mumbai will need to review the new security guidelines and implement enhanced risk mitigation measures for all online credit and debit card transactions, to reduce the risk of fraud and ensure the bank's compliance with the RBI directive. This team leader will also need to update the bank's internal policies and train the staff on the new security requirements. By doing so, the team leader will be playing a crucial role in securing digital payments for the bank's customers.

What changed

RBI has issued a circular to all Primary Urban Co-operative Banks (UCBs) requiring them to implement enhanced security and risk mitigation measures for online credit and debit card transactions. The directive is based on a separate circular from the Department of Payment and Settlement Systems (DPSS) dated February 18, 2009, and is issued under Section 18 of the Payment and Settlement Systems Act, 2007.

What it means for you

UCBs must now strengthen their security protocols for card-not-present transactions to reduce fraud risk. This aligns with broader RBI efforts to secure digital payments. Banks need to review and upgrade their card transaction systems and processes to comply with the enclosed DPSS guidelines.

What you must do

Who it affects

All Primary Urban Co-operative Banks (UCBs), Chief Executive Officers of UCBs, Card payment operations teams at UCBs

❓ Common questions

What is the legal basis for this circular?

The circular is issued under Section 18 of the Payment and Settlement Systems Act, 2007, which empowers RBI to issue directions to payment system participants.

Do we need to take any action beyond implementing the security measures?

Yes, you must acknowledge receipt of this circular to your respective RBI Regional Office as specified in paragraph 2.

What types of transactions are covered?

The circular covers online credit and debit card transactions, focusing on security issues and risk mitigation measures.

📜 Read the original circular — full text as issued by RBI
We enclose a copy of circular issued by Department of Payment and Settlement Systems, Reserve Bank of India, DPSS.No.1501/02.14.003/2008-09 dated February 18, 2009 advising the banks to enhance the risk mitigation security measures for online card transactions. The directions have been issued under Section 18 of Payment and Settlement Systems Act 2007 (Act 51 of 2007). 2. Please acknowledge receipt to the respective Regional Office of Reserve Bank of India.
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2008-09/402 · issued 18 Feb 2009. The plain-English explanation above is BankPulse’s own independent summary.
🧰 Tools — save, print, templates & related
Worked example & action-note template

Example: if you are a Compliance officer at a bank this circular applies to (All Primary Urban Co-operative Banks (UCBs), Chief Executive Officers of UCBs, Card payment operations teams at UCBs), your first concrete step on “UCBs: Security Measures for Card Transactions” is: “Review the enclosed DPSS circular (DPSS.No.1501/02.14.003/2008-09 dated Feb 18, 2009) for detailed security measures.” (RBI issued this 18 Feb 2009).

  1. Circular: RBI/2008-09/402 -- UCBs: Security Measures for Card Transactions
  2. Issued: 18 Feb 2009
  3. Action required: Review the enclosed DPSS circular (DPSS.No.1501/02.14.003/2008-09 dated Feb 18, 2009) for detailed security measures.
  4. Action required: Implement enhanced risk mitigation measures for all online credit and debit card transactions.
  5. Action required: Acknowledge receipt of this circular to your respective RBI Regional Office.
  6. Action required: Update internal policies and train staff on the new security requirements.
  7. Owner: ____________ Target date: ____________
  8. Board/committee approval needed? Y / N
  9. Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.

💬 Banker Discussion

Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.

Loading comments…
BankPulse Compliance Evidence Pack — generated 05 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly).
Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=4877&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗