HomeCirculars › RBI/2009-2010/420

RBI mandates extra authentication for all card-not-present transactions including IVR

Current · Source: Reserve Bank of India · RBI/2009-2010/420 · issued 23 Apr 2010 · ~1 min read
Quick answerRBI has extended mandatory additional authentication to all card-not-present transactions, including IVR, effective January 1, 2011. Banks must implement this to enhance security and avoid penalties under the Payment and Settlement Systems Act, 2007.
The rule, in the simplest words
How it plays out — a real example

A branch operations officer in Indore, Priya, gets a call from a customer wanting to pay his monthly loan EMI using his credit card over the phone. Before this rule, Priya would just take the card number and expiry date. Now, after January 1, 2011, she must ask the customer for a one-time password sent to his registered mobile number, making the payment safer for both of them.

What changed

Previously, additional authentication was required only for online card-not-present transactions, excluding IVR. Now, after discussions with banks and card companies, RBI has decided to include IVR transactions as well. The new requirement takes effect from January 1, 2011.

What it means for you

Banks must update their IVR systems to support additional authentication, such as one-time passwords or other verification methods not visible on the card. This will reduce fraud risk but may require system upgrades and customer education. Non-compliance could lead to penalties under the Payment and Settlement Systems Act.

What you must do

Who it affects

All scheduled commercial banks including RRBs, Urban co-operative banks, State co-operative banks, District central co-operative banks, Card companies

❓ Common questions

Regulatory timeline

Built from our lineage records — each fact carries its provenance; missing history simply is not shown (never guessed).

What is the effective date for this new requirement?

The additional authentication for IVR transactions must be implemented from January 1, 2011.

What happens if a bank does not comply?

Non-adherence to these directions will attract penalties prescribed under the Payment and Settlement Systems Act, 2007.

📜 Read the original circular — full text as issued by RBI
RBI/2009-2010/420 RBI / DPSS No. 2303 / 02.14.003 / 2009-2010 April 23, 2010 The Chairman and Managing Director / Chief Executive Officers All Scheduled Commercial Banks including RRBs / Urban Co-operative Banks / State Co-operative Banks / District Central Co-operative Banks Madam / Dear Sir, Credit/Debit Card transactions- Security Issues and Risk mitigation measures for IVR transactions. Please refer to our circular RBI/DPSS/No.1501/02.14.003/2008-2009 dated February 18, 2009, wherein a directive was issued making it mandatory for banks to put in place additional authentication/validation based on information not visible on the cards for all on-line card not present (CNP) transactions except IVR transactions. 2. After extensive deliberations with the banks/card companies it has been decided to extend this requirement of additional authentication/validation to all CNP transactions including IVR transactions. Accordingly, banks are advised to implement the contents of the above circular to all CNP transactions with effect from January 01, 2011 . 3. These Directions are issued by the Reserve Bank of India, in exercise of the powers conferred by Section 18 of the Payment and Settlement Systems Act, 2007 (Act 51 of 2007). Banks are advised to strictly adhere to the instructions and time discipline indicated in this circular. Non-adherence to the directions shall attract penalties prescribed under the Act. 4. Please acknowledge receipt. Yours faithfully (G. Padmanabhan) Chief General Manager
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2009-2010/420 · issued 23 Apr 2010. The plain-English explanation above is BankPulse’s own independent summary.
🧰 Tools — save, print, templates & related
Who does what — compliance checklist
⚙️ Operations
  • Ensure compliance with the circular to avoid penalties under the Payment and Settlement Systems Act, 2007.
💻 IT / Systems
  • Update IVR systems to support verification based on information not visible on the card.
📜 Compliance
  • Implement additional authentication for all card-not-present transactions including IVR by January 1, 2011.
  • Acknowledge receipt of this circular to RBI.
Grouped from the action items above — a single circular may involve more than one team.
Worked example & action-note template

Example: if you are a Compliance officer at a bank this circular applies to (All scheduled commercial banks including RRBs, Urban co-operative banks, State co-operative banks, District central co-operative banks, Card companies), your first concrete step on “RBI mandates extra authentication for all card-not-present transactions including IVR” is: “Implement additional authentication for all card-not-present transactions including IVR by January 1, 2011.” (RBI issued this 23 Apr 2010).

  1. Circular: RBI/2009-2010/420 -- RBI mandates extra authentication for all card-not-present transactions including IVR
  2. Issued: 23 Apr 2010
  3. Action required: Implement additional authentication for all card-not-present transactions including IVR by January 1, 2011.
  4. Action required: Update IVR systems to support verification based on information not visible on the card.
  5. Action required: Ensure compliance with the circular to avoid penalties under the Payment and Settlement Systems Act, 2007.
  6. Action required: Acknowledge receipt of this circular to RBI.
  7. Owner: ____________ Target date: ____________
  8. Board/committee approval needed? Y / N
  9. Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.

💬 Banker Discussion

Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.

Loading comments…
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly).
Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=5618&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗