RBI Master Direction on Digital Payment Security Controls
No longer current — withdrawn, no replacement on file yet
Source: Reserve Bank of India · RBI/2020-21/74 · issued 18 Feb 2021 · ~2 min read
Quick answerRBI issued a Master Direction mandating banks and credit card NBFCs to implement minimum security controls for digital payments, including governance, authentication, and fraud management, effective from August 2021.
The rule, in the simplest words
The bank’s Board must approve a written policy that explains how to keep digital payments safe (policy = rules signed off by top managers).
All internet banking, mobile banking and card payment systems must use the basic security steps the RBI listed (minimum security controls = required safety measures).
The bank must set up ways to prove a user’s identity (authentication = checking who you are) and to watch for and stop cheating (fraud management = spotting fraud early).
All these steps must be finished within six months of Feb 18 2021 (by Aug 2021) or the RBI may take action.
How it plays out — a real example
Priya Sharma, a digital‑payments officer at a small finance bank in Delhi, spent her Monday morning preparing the Board‑approved digital‑payment security policy, then worked with the IT team to add two‑factor authentication for mobile banking and set up real‑time fraud alerts, ensuring everything was ready well before the August 2021 deadline.
What changed
RBI issued the Master Direction on Digital Payment Security Controls (2021), replacing earlier piecemeal circulars with a comprehensive framework. It mandates a Board-approved policy for digital payment products, covering governance, risk management, and security controls for internet, mobile, and card payments. The direction applies to scheduled commercial banks (excluding RRBs), small finance banks, payments banks, and credit card-issuing NBFCs, effective six months from issuance (February 18, 2021).
What it means for you
Banks and NBFCs must now formalize digital payment security policies at the Board level, ensuring robust governance and minimum security standards. This raises compliance costs but reduces fraud risk and enhances customer trust. Non-compliance could attract supervisory action, so lenders must prioritize implementation within the timeline.
Historical instruction — do not use for current compliance. This is what was required at the time; it no longer reflects current RBI requirements. If no replacement rule is linked above, that only means none is recorded on our register yet — it does not prove no later applicable rule exists. Confirm on the official RBI source below.
What banks were required to do at the time
Formulate a Board-approved policy for digital payment products and services covering risk management, compliance, and customer experience.
Implement common minimum security controls for internet banking, mobile payments, and card payments as per the direction's chapters.
Ensure authentication frameworks and fraud risk management mechanisms are in place within six months from February 18, 2021.
Review and align existing security measures with the new direction, especially for any previously issued circulars that take immediate effect.
repealed_by — Consolidation of Regulations — Withdrawal of circulars (28 Nov 2025)
Built from our lineage records — each fact carries its provenance; missing history simply is not shown (never guessed).
When does this Master Direction come into effect?
It comes into effect six months from February 18, 2021, i.e., by August 18, 2021. However, instructions already issued by RBI departments take immediate effect or as per their original timelines.
Does this apply to Regional Rural Banks?
No, Regional Rural Banks (RRBs) are explicitly excluded from the applicability of this direction.
What are the key areas covered under general controls?
General controls include governance and management of security risks, application security life cycle, authentication framework, fraud risk management, reconciliation mechanism, and customer protection, awareness, and grievance redressal.
📜 This document’s life story (1 recorded event, each backed by RBI’s own words)
Repealed byRBI/2025-26/100 — Consolidation of Regulations — Withdrawal of circulars (28 Nov 2025)
RBI’s words: “Official withdrawal register entry #29: DoS.CO.CSITE.SEC.No.1852/31.01.015/2020-21 — "Master Direction on Digital Payment Security Controls" dated February 18, 2021”
📜 Read the original circular — full text as issued by RBI
RBI/2020-21/74
DoS.CO.CSITE.SEC.No.1852/31.01.015/2020-21
February 18, 2021
The Chairman/ Managing Director/ Chief Executive Officer
All Scheduled Commercial Banks excluding RRBs/
Small Finance Banks/Payments Banks/ Credit Card issuing NBFCs.
Madam/ Dear Sir,
Master Direction on Digital Payment Security Controls
Please refer to para II (7) of the Statement on Developmental and Regulatory Policies of the Bi-monthly Monetary Policy Statement for 2020-21 dated December 4, 2020 ( extract given below ). The Master Direction provides necessary guidelines for the regulated entities to set up a robust governance structure and implement common minimum standards of security controls for digital payment products and services.
Yours faithfully,
(T.K. Rajan)
Chief General Manager
Digital Payment Security Controls
Going by the pre-eminent role being played by digital payment systems in India, RBI gives highest importance to the security controls around it. Now it is proposed to issue Reserve Bank of India (Digital Payment Security Controls) Directions 2020, for regulated entities to set up a robust governance structure for such systems and implement common minimum standards of security controls for channels like internet, mobile banking, card payments, among others. While the guidelines will be technology and platform agnostic, it will create an enhanced and enabling environment for customers to use digital payment products in more safe and secure manner. Necessary guidelines will be issued separately.
Index
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2020-21/74 · issued 18 Feb 2021. The plain-English explanation above is BankPulse’s own independent summary.
Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly). Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=12032&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Help us keep this accurate
Found an inaccuracy or have an improvement? Tell us. Every report is reviewed by our team before any change is made — nothing goes live unverified.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗
BANKPULSE · FREE DAILY BRIEF
Get RBI updates for your role
Every important RBI update, decoded in plain English — for your career, exams & financial awareness.
We collect only your email, name and role, used solely to send your brief — never sold or shared. Withdraw anytime via the unsubscribe link in any email. Independent platform, not affiliated with the RBI. Information, not legal advice.
REPORT AN ERROR · BETA
Spotted an error? Earn 500 BankPulse Credits
Help us stay accurate. If your correction is verified true and approved by our founder, you earn 500 BankPulse Credits — redeemable when the platform monetises.
Reviewed by a human before any credit is awarded. We never change the site from crowd input without verification.
WANT A NEW FEATURE · BETA
What would make BankPulse more useful for you?
Tell us what to build next — a tool, a data view, a role page, anything. We read every suggestion.
Thank you — your ideas directly shape what we build.