HomeCirculars › RBI/2008-09/437

RBI Reiterates Two-Tier Checking for RTGS Transactions

No longer current — withdrawn, no replacement on file yet
Source: Reserve Bank of India · RBI/2008-09/437 · issued 20 Apr 2009 · ~2 min read
Quick answerRBI has reiterated that maker-checker facility is mandatory for RTGS data entry, requiring digital signatures and encryption. Non-compliance may lead to termination or suspension of RTGS membership under Section 14 of RTGS (Membership) Regulations, 2004, or fines under Section 30 of the Payment and Settlement Systems Act, 2007. Banks must tighten internal controls to prevent fraud.

What changed

RBI reiterated that maker-checker facility is mandatory for RTGS data entry, and all transactions must be digitally signed and encrypted. It warned that non-adherence has led to fraudulent transactions and delayed/wrong credits. Banks must fix staff accountability for lapses and ensure robust IT security.

What it means for you

Banks must enforce strict two-tier security for RTGS to prevent fraud. Failure to comply could result in termination of RTGS membership or fines under the Payment and Settlement Systems Act. This raises the bar for internal controls and staff accountability in electronic payment systems.

Historical instruction — do not use for current compliance. This is what was required at the time; it no longer reflects current RBI requirements. If no replacement rule is linked above, that only means none is recorded on our register yet — it does not prove no later applicable rule exists. Confirm on the official RBI source below.

What banks were required to do at the time

Who it affects

All banks participating in RTGS, RTGS system administrators and IT security teams, Bank staff handling RTGS transactions

❓ Common questions

Regulatory timeline

Built from our lineage records — each fact carries its provenance; missing history simply is not shown (never guessed).

What is the two-tier checking requirement for RTGS?

RBI mandates a maker-checker facility during data entry, meaning one person enters the transaction and another authorizes it. All transactions must also be digitally signed and encrypted.

What are the penalties for non-compliance with RTGS security rules?

RBI may terminate or suspend RTGS membership under Section 14 of RTGS (Membership) Regulations, 2004, and impose fines under Section 30 of the Payment and Settlement Systems Act, 2007.

Why did RBI issue this notification?

Due to instances of fraudulent transactions and delayed/wrong credits from non-adherence to maker-checker and misuse of smart cards. RBI wants to strengthen security as RTGS volumes grow.

📜 Read the original circular — full text as issued by RBI
As you are aware, the number of RTGS enabled bank branches have crossed 55,000. The volume and value of transactions settled in RTGS have also grown significantly. In the year 2008-09, RTGS processed 13.37 million transactions as against only 5.84 million transactions in the previous year. Similarly, RTGS processed total value of Rs. 323 trillion in 2008-09 as against Rs. 273 trillion in the previous year. 2. The increasing use of electronic modes of payment underscores the need for putting in place a robust security environment. Accordingly, it has been made mandatory for the members to put in place maker-checker facility during data entry. Further, all transactions put through the RTGS system is to be digitally signed and encrypted. 3. Instances have come to the notice of Reserve Bank where non adherence to procedures has resulted in fraudulent transactions being put through. Further non adherence to maker-checker facility has led to delayed / wrong credit being afforded to customers. We have also come across instances of smart cards meant for different officials being used by the same official for perpetrating fraudulent transactions. 4. We wish to reiterate that strong internal controls and scrupulous adherence to laid down security procedures are extremely important as banks migrate transactions to electronic modes. You are, therefore, advised to put in place adequate checks and balances to prevent any slackening of the two tier security system inherent in the architecture of RTGS. Staff accountability may be fixed for any lapses in this regard. In other words, IT security should be foolproof and the internal control systems strong enough to counter frauds / attempted frauds in the RTGS system. Any breach in the internal control system resulting in fraud / attempted fraud will be viewed seriously by the Bank and may also lead to termination or suspension of RTGS membership as prescribed in Section 14 of RTGS (Membership) Regulations, 2004. In addition, Bank may also consider imposing fines under Section 30 of the Payment and Settlement Systems Act, 2007 (51 of 2007). Please acknowledge receipt and forward an action taken report by May 29, 2009.
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2008-09/437 · issued 20 Apr 2009. The plain-English explanation above is BankPulse’s own independent summary.
🧰 Tools — save, print, templates & related

💬 Banker Discussion

Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.

Loading comments…
BankPulse Compliance Evidence Pack — generated 05 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly).
Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=4937&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗