HomeCirculars › RBI/2011-12/145

RBI Mandates Extra Authentication for All Card-Not-Present Transactions by May 2012

Current · Source: Reserve Bank of India · RBI/2011-12/145 · issued 04 Aug 2011 · ~2 min read
Quick answerRBI has directed banks to implement additional factor of authentication for all card-not-present (CNP) transactions, including IVR, by May 1, 2012. Issuers must reimburse customers for losses from non-compliant transactions after that date.
The rule, in the simplest words
How it plays out — a real example

Rohit Sharma, a gold‑loan officer in Indore, gets a call from a customer who wants to buy a gold necklace online using his debit card. Before the transaction is approved, Rohit’s bank system sends an OTP to the customer’s phone, which the customer enters, satisfying the extra authentication rule. Because the bank has the OTP step, the purchase goes through safely and the bank is protected from any loss.

What changed

RBI extended the mandatory additional authentication requirement to all CNP transactions previously listed in its December 31, 2010 circular, with a compliance deadline of May 1, 2012. Previously, only certain CNP transactions (excluding IVR) were covered from August 2009, and IVR was added from February 2011. Now, no CNP transaction category is exempt.

What it means for you

Banks must ensure every online card transaction without the card's physical presence uses a second authentication factor (like OTP or password) by May 2012. Failure to do so makes the issuer bank liable for any customer losses from unauthorized transactions. This tightens security for cardholders but requires banks to upgrade systems and coordinate with payment networks.

What you must do

Who it affects

All scheduled commercial banks including RRBs, Urban co-operative banks, State and district central co-operative banks, Authorised card payment networks, Card-issuing banks

❓ Common questions

What is the deadline for implementing additional authentication for all CNP transactions?

The deadline is May 1, 2012. All CNP transactions listed in the December 31, 2010 circular must have an additional factor of authentication by this date.

What happens if a bank processes a CNP transaction without additional authentication after the deadline?

If a customer complains about a loss from such a transaction, the issuer bank must reimburse the customer without any objection.

Does this circular apply to IVR transactions?

Yes, IVR transactions were already covered from February 1, 2011, and this circular confirms they are included in the mandatory additional authentication requirement.

📜 Read the original circular — full text as issued by RBI
RBI/2011-12/145 DPSS.PD.CO. No.223/02.14.003/2011-2012 August 04, 2011 The Chairman and Managing Director / Chief Executive Officers All Scheduled Commercial Banks including RRBs / Urban Co-operative Banks / State Co-operative Banks / District Central Co-operative Banks/Authorised Card Payment Networks Madam / Dear Sir Security Issues and Risk mitigation measures related to Card Not Present (CNP) transactions. Please refer to our circular RBI/DPSS No. 1501 / 02.14.003 / 2008-2009 dated February 18, 2009 wherein a directive was issued making it mandatory for banks to put in place additional authentication / validation based on information not visible on the cards for all on-line card not present(CNP) transactions except IVR transactions from August 01, 2009. This mandate was extended to cover all IVR transactions with effect from February 01, 2011 vide our circular RBI/DPSS No. 1503 / 02.14.003 /2010-2011 dated December 31, 2010 . 2. Banks had been advised vide para 4 of the directions contained in RBI/DPSS No. 1503 / 02.14.003 /2010-2011 dated December 31, 2010 to revert on the introduction of additional factor of authentication for certain category of  CNP transactions detailed therein. The matter was discussed in a meeting of banks with the Reserve Bank of India on June 22, 2011 wherein it was emphasizedby the Reserve Bank that while it was not advocating any specific solution in this regard, it is imperative that all CNP transactions are brought within the ambit of additional factor of authentication without further delay. To this end, banks were advised to evaluate possible alternatives at the earliest.Based on the feedback from the stakeholders and keeping in view the interest of card holders the following directions are issued: It is mandatory to put in place additional factor of authentication for all CNP transactions indicated in para 4 of our directions dated December 31, 2010 with effect from May 01, 2012. In case of customer complaint regarding issues, if any,arising out of transactions effected without the additional factor of authentication after the stipulated date , the issuer bank shall reimburse the loss to the customer further without demur. 3. The directive is issued under section 18 of Payment and Settlement Systems Act 2007, (Act 51 of 2007). 4. Please acknowledge receipt. Yours faithfully, Vijay Chugh Chief General Manager.
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2011-12/145 · issued 04 Aug 2011. The plain-English explanation above is BankPulse’s own independent summary.
🧰 Tools — save, print, templates & related
Who does what — compliance checklist
💻 IT / Systems
  • Update IT systems and merchant agreements to support additional factor authentication for IVR and other CNP transactions.
📜 Compliance
  • Audit all CNP transaction categories to ensure additional authentication is in place for those listed in the December 31, 2010 circular by May 1, 2012.
  • Prepare a customer complaint and reimbursement mechanism for losses arising from non-compliant transactions after the deadline.
  • Coordinate with card payment networks to implement the required authentication solutions.
Grouped from the action items above — a single circular may involve more than one team.
Worked example & action-note template

Example: if you are a Compliance officer at a bank this circular applies to (All scheduled commercial banks including RRBs, Urban co-operative banks, State and district central co-operative banks, Authorised card payment networks, Card-issuing banks), your first concrete step on “RBI Mandates Extra Authentication for All Card-Not-Present Transactions by May 2012” is: “Audit all CNP transaction categories to ensure additional authentication is in place for those listed in the December 31, 2010 circular by May 1, 2012.” (RBI issued this 04 Aug 2011).

  1. Circular: RBI/2011-12/145 -- RBI Mandates Extra Authentication for All Card-Not-Present Transactions by May 2012
  2. Issued: 04 Aug 2011
  3. Action required: Audit all CNP transaction categories to ensure additional authentication is in place for those listed in the December 31, 2010 circular by May 1, 2012.
  4. Action required: Update IT systems and merchant agreements to support additional factor authentication for IVR and other CNP transactions.
  5. Action required: Prepare a customer complaint and reimbursement mechanism for losses arising from non-compliant transactions after the deadline.
  6. Action required: Coordinate with card payment networks to implement the required authentication solutions.
  7. Owner: ____________ Target date: ____________
  8. Board/committee approval needed? Y / N
  9. Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.

💬 Banker Discussion

Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.

Loading comments…
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly).
Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=6657&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗