HomeCirculars › RBI/2021-22/92

Tokenisation Extended to Laptops, Wearables, IoT Devices

Current · Source: Reserve Bank of India · RBI/2021-22/92 · issued 25 Aug 2021 · ~1 min read
Quick answerRBI now allows card tokenisation for laptops, desktops, wearables, and IoT devices, expanding beyond mobile phones and tablets. This aims to boost secure, convenient digital payments across more consumer devices.
The rule, in the simplest words
How it plays out — a real example

A branch operations officer in Indore, Priya, now lets her customers save their card details as tokens on their laptops when they pay gold loan EMIs online. She explains to a customer, 'Instead of typing your full card number each time, your laptop gets a secret code that works just for your card, so it's safer.' This makes repeat payments faster and reduces fraud risk for her branch.

What changed

Previously, card tokenisation was limited to mobile phones and tablets. Now, RBI has extended the scope to include consumer devices like laptops, desktops, wearables (e.g., wrist watches, bands), and IoT devices. All other conditions from the January 2019 circular remain unchanged.

What it means for you

Banks and card networks can now offer tokenisation for a wider range of devices, potentially increasing tokenised transaction volumes. This enhances security by replacing actual card details with tokens, reducing fraud risk. Lenders should prepare for higher adoption and integrate tokenisation support across these new device categories.

What you must do

Who it affects

All authorised card networks, Banks issuing cards, Merchants accepting card payments, Payment aggregators and token requestors, Cardholders using non-mobile devices

❓ Common questions

Regulatory timeline

Built from our lineage records — each fact carries its provenance; missing history simply is not shown (never guessed).

What devices are now covered under tokenisation?

Tokenisation now covers laptops, desktops, wearables like wrist watches and bands, and Internet of Things (IoT) devices, in addition to mobile phones and tablets.

Does this circular change any other tokenisation rules?

No, only the scope of permitted devices has been expanded. All other provisions from the January 2019 circular on tokenisation remain applicable.

When did this circular take effect?

The circular was issued on August 25, 2021, and is effective from that date.

📜 This document’s life story (1 recorded event, each backed by RBI’s own words)
Extended by RBI Expands Card Tokenisation to Card-on-File (CoFT) Services
RBI’s words: “vide our circular CO.DPSS.POLC.No.S-469/02-14-003/2021-22 dated August 25, 2021 on “Tokenisation – Card Transactions : Extending the Scope of Permitted Devices””
📜 Read the original circular — full text as issued by RBI
RBI/2021-22/92 CO.DPSS.POLC.No.S-469/02-14-003/2021-22 August 25, 2021 The Chief Executive Officer / President All authorised card networks Madam / Dear Sir, Tokenisation – Card Transactions : Extending the Scope of Permitted Devices We invite reference to our circular DPSS.CO.PD No.1463/02.14.003/2018-19 dated January 08, 2019 on “Tokenisation – Card transactions”, permitting authorised card networks to offer card tokenisation services to any token requestor, subject to the conditions listed therein. The facility was available only for mobile phones and tablets of interested card holders. There has been an uptake in the volume of tokenised card transactions during the recent months. 2. On a review of the framework and keeping in view stakeholder feedback, it has been decided to extend the scope of tokenisation to include consumer devices – laptops, desktops, wearables (wrist watches, bands, etc.), Internet of Things (IoT) devices, etc. All other provisions of the circular referred to above shall continue to be applicable. This initiative is expected to make card transactions more safe, secure and convenient for the users. 3. This directive is issued under Section 10 (2) read with Section 18 of Payment and Settlement Systems Act, 2007 (Act 51 of 2007). Yours faithfully, (P. Vasudevan) Chief General Manager
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2021-22/92 · issued 25 Aug 2021. The plain-English explanation above is BankPulse’s own independent summary.
🧰 Tools — save, print, templates & related
Who does what — compliance checklist
💻 IT / Systems
  • Update tokenisation systems to support laptops, desktops, wearables, and IoT devices.
📜 Compliance
  • Communicate the expanded scope to merchants and payment partners for seamless integration.
  • Monitor tokenised transaction volumes and adjust fraud prevention measures accordingly.
  • Ensure compliance with all existing conditions from the January 2019 circular.
Grouped from the action items above — a single circular may involve more than one team.
Worked example & action-note template

Example: if you are an IT/Systems lead at a bank this circular applies to (All authorised card networks, Banks issuing cards, Merchants accepting card payments, Payment aggregators and token requestors, Cardholders using non-mobile devices), your first concrete step on “Tokenisation Extended to Laptops, Wearables, IoT Devices” is: “Update tokenisation systems to support laptops, desktops, wearables, and IoT devices.” (RBI issued this 25 Aug 2021).

  1. Circular: RBI/2021-22/92 -- Tokenisation Extended to Laptops, Wearables, IoT Devices
  2. Issued: 25 Aug 2021
  3. Action required: Update tokenisation systems to support laptops, desktops, wearables, and IoT devices.
  4. Action required: Communicate the expanded scope to merchants and payment partners for seamless integration.
  5. Action required: Monitor tokenised transaction volumes and adjust fraud prevention measures accordingly.
  6. Action required: Ensure compliance with all existing conditions from the January 2019 circular.
  7. Owner: ____________ Target date: ____________
  8. Board/committee approval needed? Y / N
  9. Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.

💬 Banker Discussion

Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.

Loading comments…
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly).
Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=12152&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗