HomeCirculars › RBI/2008-2009/387

RBI mandates 2FA and alerts for card-not-present transactions

Current · Source: Reserve Bank of India · RBI/2008-2009/387 · issued 18 Feb 2009 · ~1 min read
Quick answerFrom August 1, 2009, banks must implement additional authentication (using data not on the card) for all online card-not-present transactions (except IVR) and send real-time alerts for transactions of ₹5,000 or more. Non-compliance invites penalties under the Payment and Settlement Systems Act, 2007.
The rule, in the simplest words
How it plays out — a real example

A branch operations officer in Indore, Priya, processes a customer's online repayment of ₹7,500 using a debit card. Because the rule says any card-not-present transaction of ₹5,000 or more needs a real-time alert, Priya's bank system automatically sends a text message to the customer confirming the payment, and also requires the customer to enter a one-time password (OTP) sent to their phone before the transaction goes through.

What changed

RBI made it mandatory for banks to deploy an extra layer of authentication for online card transactions that do not require the physical card, using information not printed on the card. Additionally, banks must now send online alerts to cardholders for all card-not-present transactions of ₹5,000 and above.

What it means for you

Banks and card issuers must upgrade their payment systems to support two-factor authentication for e-commerce and other card-not-present scenarios, excluding IVR. This increases operational costs and requires coordination with card networks and merchants. The alert system also demands real-time notification infrastructure, adding to compliance burden but reducing fraud risk.

What you must do

Who it affects

All scheduled commercial banks including RRBs, Urban co-operative banks, State co-operative banks, District central co-operative banks, Card-issuing institutions, Merchants accepting card-not-present transactions

❓ Common questions

What is the deadline for implementing these security measures?

The deadline is August 1, 2009, as per the circular dated February 18, 2009.

Are IVR transactions covered under the additional authentication requirement?

No, IVR transactions are excluded from the additional authentication mandate; separate instructions will be issued for them.

What happens if a bank fails to comply with these directives?

Non-compliance will attract penalties under the Payment and Settlement Systems Act, 2007 (Act 51 of 2007).

📜 Read the original circular — full text as issued by RBI
RBI/2008-2009/387 RBI / DPSS No. 1501 / 02.14.003 / 2008-2009 February 18, 2009 The Chairman and Managing Director / Chief Executive Officers All Scheduled Commercial Banks including RRBs / Urban Co-operative Banks / State Co-operative Banks /. District Central Co-operative Banks Madam / Dear Sir Credit/Debit Card transactions- Security Issues and Risk mitigation measures The use of Credit/Debit Cards has been increasing in the country. We have been reviewing various options to enhance the security of online card transactions. After extensive consultations with banks/card companies, it has been decided as under: 2. It would be mandatory to put in place with effect from August 01, 2009: i) A system of providing for additional authentication/validation based on information not visible on the cards for all on-line card not present transactions except IVR transactions (for which separate instructions will follow). ii) A system of "Online Alerts" to the cardholder for all 'card not present' transactions of the value of Rs. 5,000/ and above. 3. Banks are advised to strictly adhere to the instructions and time discipline indicated in this circular. Non-adherence to the directives shall attract penalties prescribed under the Payment and Settlement Systems Act 2007 (Act 51 of 2007). 4. This directive is issued under section 18 of Payment and Settlement Systems Act 2007, (Act 51 of 2007). 5. Please acknowledge receipt. Yours faithfully (G. Padmanabhan) Chief General Manager
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2008-2009/387 · issued 18 Feb 2009. The plain-English explanation above is BankPulse’s own independent summary.
🧰 Tools — save, print, templates & related
Who does what — compliance checklist
⚙️ Operations
  • Ensure compliance with the Payment and Settlement Systems Act, 2007, as non-adherence will attract penalties.
💻 IT / Systems
  • Set up a system to send real-time alerts to cardholders for every card-not-present transaction of ₹5,000 or more.
📜 Compliance
  • Implement additional authentication (e.g., OTP, PIN) for all online card-not-present transactions by August 1, 2009, except IVR transactions.
  • Coordinate with card networks and merchants to integrate the new authentication and alert mechanisms.
Grouped from the action items above — a single circular may involve more than one team.
Worked example & action-note template

Example: if you are a Compliance officer at a bank this circular applies to (All scheduled commercial banks including RRBs, Urban co-operative banks, State co-operative banks, District central co-operative banks, Card-issuing institutions, Merchants accepting card-not-present transactions), your first concrete step on “RBI mandates 2FA and alerts for card-not-present transactions” is: “Implement additional authentication (e.g., OTP, PIN) for all online card-not-present transactions by August 1, 2009, except IVR transactions.” (RBI issued this 18 Feb 2009).

  1. Circular: RBI/2008-2009/387 -- RBI mandates 2FA and alerts for card-not-present transactions
  2. Issued: 18 Feb 2009
  3. Action required: Implement additional authentication (e.g., OTP, PIN) for all online card-not-present transactions by August 1, 2009, except IVR transactions.
  4. Action required: Set up a system to send real-time alerts to cardholders for every card-not-present transaction of ₹5,000 or more.
  5. Action required: Ensure compliance with the Payment and Settlement Systems Act, 2007, as non-adherence will attract penalties.
  6. Action required: Coordinate with card networks and merchants to integrate the new authentication and alert mechanisms.
  7. Owner: ____________ Target date: ____________
  8. Board/committee approval needed? Y / N
  9. Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.

💬 Banker Discussion

Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.

Loading comments…
BankPulse Compliance Evidence Pack — generated 05 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly).
Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=4844&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗