HomeCirculars › RBI/2010-2011/243

RBI Clarifies 2FA Mandate for Card-Not-Present Transactions

Current · Source: Reserve Bank of India · RBI/2010-2011/243 · issued 25 Oct 2010 · ~2 min read
Quick answerRBI clarifies that the additional authentication mandate for card-not-present transactions applies to all Indian-issued cards used on domestic merchant sites, regardless of overseas payment gateway links. Foreign-issued cards on Indian sites are exempt for now.
The rule, in the simplest words
How it plays out — a real example

Priya, a compliance officer at a bank in Mumbai, checks a new merchant's setup. The merchant is an Indian clothing store but uses a payment gateway based in Singapore. Priya confirms that her bank's system still requires an OTP for every Indian card used on that site, because the rule says the gateway's location doesn't matter—the card is Indian and the purchase is domestic.

What changed

RBI issued a clarification on October 25, 2010, regarding the scope of the additional authentication mandate for card-not-present transactions. It confirmed that the mandate covers all transactions using Indian-issued cards on merchant sites where no foreign exchange outflow occurs, even if the payment gateway is overseas. Foreign-issued cards used on Indian merchant sites remain exempt from this requirement.

What it means for you

Banks must ensure that all online and IVR transactions using Indian-issued cards on domestic merchant sites include an additional authentication factor not visible on the card. Linking to an overseas payment gateway does not exempt these transactions. This strengthens security for domestic e-commerce while keeping cross-border card usage rules clear.

What you must do

Who it affects

All scheduled commercial banks including RRBs, Urban co-operative banks, State co-operative banks, District central co-operative banks, Authorised card payment networks

❓ Common questions

Does the additional authentication mandate apply to Indian cards used on foreign websites?

The mandate applies to Indian-issued cards used on merchant sites where no foreign exchange outflow is involved. For transactions on foreign websites involving forex outflow, the mandate is not addressed in this circular; banks should refer to other RBI guidelines.

Are foreign-issued cards used on Indian merchant sites exempt from this mandate?

Yes, the mandate is not applicable for cards issued outside India when used on Indian merchant sites, as per this clarification.

What is the effective date for IVR transactions under this mandate?

The mandate was extended to IVR transactions effective January 1, 2011, as per a previous RBI circular dated April 23, 2010.

📜 Read the original circular — full text as issued by RBI
RBI/2010-2011/243 RBI / DPSS No.914/02.14.003/2010-2011 October 25, 2010 The Chairman and Managing Director / Chief Executive Officers All Scheduled Commercial Banks including RRBs / Urban Co-operative Banks / State Co-operative Banks /. District Central Co-operative Banks Authorised card payment networks Madam / Dear Sir Credit/Debit Card transactions- Security Issues and Risk mitigation measures for Card Not Present Transactions. We had vide our circular RBI/2008-2009/ 387, DPSS No. 1501 / 02.14.003 / 2008-2009, dated February 18, 2009 , mandated that with effect from August 01, 2009, banks shall provide an “additional authentication/validation based on information not visible on the cards for all on-line card not present transactions”. ( This mandate has been extended to all IVR transactions with effect from January 01, 2011, vide our circular RBI/2009-2010/420, DPSS No. 2303 / 02.14.003 / 2009-2010 April 23, 2010 ) 2. We have been receiving references regarding the applicability of this mandate for online transactions effected using cards issued by banks outside India on Indian merchant sites, and the use of Indian cards for transactions on foreign websites. 3. In this regard, it is clarified that the mandate shall apply to all transactions using cards issued in India, for payments on merchant site where no outflow of foreign exchange is contemplated. The linkage to an overseas website/payment gateway cannot be the basis for permitting relaxations from implementing the mandate. 4. The mandate is not presently applicable for use of cards issued outside India, on Indian merchant sites. Yours faithfully G. Padmanabhan Chief General Manager
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2010-2011/243 · issued 25 Oct 2010. The plain-English explanation above is BankPulse’s own independent summary.
🧰 Tools — save, print, templates & related
Who does what — compliance checklist
💻 IT / Systems
  • Verify that your systems enforce additional authentication for all Indian-issued card transactions on domestic merchant sites, regardless of payment gateway location.
📜 Compliance
  • Update compliance procedures to exclude foreign-issued cards from this mandate when used on Indian merchant sites.
  • Communicate the clarification to your merchant acquiring teams and payment gateway partners to avoid misinterpretation.
  • Monitor transaction flows to ensure no relaxation is granted based solely on overseas gateway links.
Grouped from the action items above — a single circular may involve more than one team.
Worked example & action-note template

Example: if you are an IT/Systems lead at a bank this circular applies to (All scheduled commercial banks including RRBs, Urban co-operative banks, State co-operative banks, District central co-operative banks, Authorised card payment networks), your first concrete step on “RBI Clarifies 2FA Mandate for Card-Not-Present Transactions” is: “Verify that your systems enforce additional authentication for all Indian-issued card transactions on domestic merchant sites, regardless of payment gateway location.” (RBI issued this 25 Oct 2010).

  1. Circular: RBI/2010-2011/243 -- RBI Clarifies 2FA Mandate for Card-Not-Present Transactions
  2. Issued: 25 Oct 2010
  3. Action required: Verify that your systems enforce additional authentication for all Indian-issued card transactions on domestic merchant sites, regardless of payment gateway location.
  4. Action required: Update compliance procedures to exclude foreign-issued cards from this mandate when used on Indian merchant sites.
  5. Action required: Communicate the clarification to your merchant acquiring teams and payment gateway partners to avoid misinterpretation.
  6. Action required: Monitor transaction flows to ensure no relaxation is granted based solely on overseas gateway links.
  7. Owner: ____________ Target date: ____________
  8. Board/committee approval needed? Y / N
  9. Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.

💬 Banker Discussion

Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.

Loading comments…
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly).
Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=6055&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗