RBI's Final Deadline for POS Terminal Security: No More Extensions
Current · Source: Reserve Bank of India · RBI/2013-14/296 · issued 27 Sep 2013 · ~2 min read
Quick answerRBI has denied further extensions for POS terminal security compliance (UKPT/DUKPT/TLE) beyond September 30, 2013. Non-compliant banks must compensate cardholders for fraud losses within 7 working days, with Rs.100 per day penalty for delays.
The rule, in the simplest words
The deadline for making POS (point-of-sale, the machine where you swipe your card) terminals secure with UKPT/DUKPT/TLE (special codes that protect your card info) is September 30, 2013, and RBI (the central bank) will NOT give any more extra time.
If a bank's POS terminal is not secure after that date and a customer's card is misused, the bank must pay the customer back within 7 working days, and if they are late, they must pay Rs.100 extra for each day they delay.
When a customer reports a fraud, the bank that issued the card must check within 3 working days if the POS terminal was secure, and if it wasn't, they must give the money back to the customer.
The bank that owns the non-secure POS terminal must pay back the issuing bank within 3 working days, or RBI can take money directly from their account.
How it plays out — a real example
A branch operations officer in Indore, Priya, gets a call from a customer whose card was used fraudulently at a POS terminal. She checks the terminal's security status within 3 days and finds it wasn't compliant with UKPT/DUKPT/TLE. She immediately processes the refund to the customer within 7 working days, then claims the amount from the acquiring bank, which pays her back in 3 days, avoiding any penalty.
What changed
RBI rejected all requests for extending the September 30, 2013 deadline for implementing UKPT/DUKPT/TLE on POS terminals. Issuing banks must now verify terminal compliance within 3 working days of a fraud complaint and pay the disputed amount within 7 working days, with a Rs.100 per day penalty for delays. Acquiring banks must reimburse issuing banks within 3 working days or face RBI debiting their account.
What it means for you
Banks and lenders face strict liability for fraud at non-compliant POS terminals after September 30, 2013. Issuers must quickly process customer claims and recover from acquirers, while acquirers must ensure all terminals are compliant or bear losses. Non-compliance may also invite penal action under the Payment and Settlement Systems Act, 2007.
What you must do
Ensure all POS terminals are compliant with UKPT/DUKPT/TLE by September 30, 2013.
Submit a compliance status report signed by CMD/CEO to RBI by October 7, 2013.
Present compliance status to the Board in its next meeting and send a board-approved copy to RBI.
Set up internal processes to verify terminal compliance within 3 working days of a fraud complaint and pay customers within 7 working days.
Prepare to reimburse issuing banks within 3 working days of a claim to avoid RBI action.
Who it affects
All scheduled commercial banks including RRBs, Urban Co-operative Banks, State Co-operative Banks, District Central Co-operative Banks, Authorised Card Payment Networks, Issuing banks, Acquiring banks
❓ Common questions
What happens if a bank fails to comply with the September 30, 2013 deadline?
Non-compliant banks must compensate cardholders for any fraudulent POS transactions occurring after that date. The issuing bank pays the customer within 7 working days, with a Rs.100 per day penalty for delays, and recovers from the acquiring bank.
How quickly must an issuing bank respond to a fraud complaint?
The issuing bank must ascertain POS terminal compliance within 3 working days of the customer approaching them, and pay the disputed amount within 7 working days, or face a Rs.100 per day penalty from the 8th working day.
What are the consequences for acquiring banks that delay reimbursement?
Acquiring banks must pay the issuing bank within 3 working days of the claim. If they fail, RBI may debit their account to compensate the issuing bank, and penal provisions under the Payment and Settlement Systems Act, 2007 may be invoked.
📜 Read the original circular — full text as issued by RBI
RBI/2013-14/296
DPSS (CO) PD No.719/02.14.011/2013-14
September 27, 2013
The Chairman and Managing Director / Chief Executive Officers
All Scheduled Commercial Banks including RRBs / Urban Co-operative Banks /
State Co-operative Banks / District Central Co-operative Banks/
Authorised Card Payment Networks
Madam / Dear Sir,
Security and Risk Mitigation Measures for Card Present Transactions
A reference is invited to our circular DPSS.PD.CO.No.513 / 02.14.003 /2011-2012 dated September 22, 2011 on security issues and risk mitigation measures related to Card Present (CP) transactions and circulars DPSS (CO) PD No.1462 / 2377/ 02.14.003/2012-13 dated February 28, 2013 and June 24, 2013 respectively on security and risk mitigation measures for electronic payment transactions, wherein various timelines were indicated for compliance.
2. Various banks have approached us, seeking further extension of the time line of September 30, 2013 for complying with the task of securing the technology infrastructure (Unique Key Per Terminal- UKPT or Derived Unique Key Per Transaction- DUKPT/ Terminal Line Encryption- TLE) as stated under Para 4(a)(3) of our circular dated September 22, 2011.
3. As you are aware the timelines indicated in the aforesaid circulars were decided after a series of meetings/discussions with the stakeholders. It was also clearly emphasized in our circular dated June 24, 2013 that no further extensions would be granted. In addition, it was also indicated that in the event of a customer complaining of misuse of card after the date stipulated in this circular, the issuer or the acquirer who has not adhered to the timelines should bear the loss.
4. In the circumstances, it has been decided not to grant any further extension of time . Accordingly, banks not complying with the requirements shall compensate loss, if any, incurred by the card holder using card at POS terminals not adhering to the mandated standards.
5. In this context, since the card holder/s would be approaching his/her card issuing bank for any fraudulent POS transaction/s in India (which have occurred after September 30, 2013), the following course of action is mandated:
The issuing bank would ascertain, within 3 working days from the date of cardholder approaching the bank, whether the respective POS terminal/s where the said transaction/s occurred is/are compliant with TLE and UKPT/DUKPT as mandated.
In the event it is found that the POS terminals are non-compliant as mandated, the issuing bank shall pay the disputed amount to the customer within 7 working days, failing which a compensation of Rs.100 per day will be payable to the customer from the 8th working day.
The issuing bank shall claim the amount paid by it to the customer from the respective bank/s which have acquired the POS transaction/s in question.
The acquiring banks have to pay the amount paid by the issuing bank without demur within 3 working days of the issuing bank raising the claim, failing which the Reserve Bank of India would be constrained to compensate the issuing bank by debiting the account of the acquiring bank maintained with the Bank.
6. Acquiring banks are advised to send a status report of compliance with respect to TLE and UKPT/DUKPT as on 30 September 2013, duly signed/ approved by the CMD/CEO of the bank on or before October 07, 2013. The position in this regard may also be put up to the Board in its next meeting, and a duly approved copy of this may be sent to us.
7. RBI will also consider invoking the penal provisions under the Payment and Settlement Systems Act, 2007 for banks that have failed to adhere to the timeline of September 30, 2013.
8. These instructions are issued under Section 18 of Payment and Settlement Systems Act, 2007.
Please acknowledge receipt
Yours faithfully,
Nilima Ramteke
General Manager (Officer-in-Charge)
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2013-14/296 · issued 27 Sep 2013. The plain-English explanation above is BankPulse’s own independent summary.
Example: if you are a Compliance officer at a bank this circular applies to (All scheduled commercial banks including RRBs, Urban Co-operative Banks, State Co-operative Banks, District Central Co-operative Banks, Authorised Card Payment Networks, Issuing banks, Acquiring banks), your first concrete step on “RBI's Final Deadline for POS Terminal Security: No More Extensions” is: “Ensure all POS terminals are compliant with UKPT/DUKPT/TLE by September 30, 2013.” (RBI issued this 27 Sep 2013).
Circular: RBI/2013-14/296 -- RBI's Final Deadline for POS Terminal Security: No More Extensions
Issued: 27 Sep 2013
Action required: Ensure all POS terminals are compliant with UKPT/DUKPT/TLE by September 30, 2013.
Action required: Submit a compliance status report signed by CMD/CEO to RBI by October 7, 2013.
Action required: Present compliance status to the Board in its next meeting and send a board-approved copy to RBI.
Action required: Set up internal processes to verify terminal compliance within 3 working days of a fraud complaint and pay customers within 7 working days.
Action required: Prepare to reimburse issuing banks within 3 working days of a claim to avoid RBI action.
Owner: ____________ Target date: ____________
Board/committee approval needed? Y / N
Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.
💬 Banker Discussion
Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly). Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=8469&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Help us keep this accurate
Found an inaccuracy or have an improvement? Tell us. Every report is reviewed by our team before any change is made — nothing goes live unverified.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗
BANKPULSE · FREE DAILY BRIEF
Get RBI updates for your role
Every important RBI update, decoded in plain English — for your career, exams & financial awareness.
We collect only your email, name and role, used solely to send your brief — never sold or shared. Withdraw anytime via the unsubscribe link in any email. Independent platform, not affiliated with the RBI. Information, not legal advice.
REPORT AN ERROR · BETA
Spotted an error? Earn 500 BankPulse Credits
Help us stay accurate. If your correction is verified true and approved by our founder, you earn 500 BankPulse Credits — redeemable when the platform monetises.
Reviewed by a human before any credit is awarded. We never change the site from crowd input without verification.
WANT A NEW FEATURE · BETA
What would make BankPulse more useful for you?
Tell us what to build next — a tool, a data view, a role page, anything. We read every suggestion.
Thank you — your ideas directly shape what we build.