HomeCirculars › RBI/2021-22/96

RBI Expands Card Tokenisation to Card-on-File (CoFT) Services

Current · Source: Reserve Bank of India · RBI/2021-22/96 · issued 07 Sep 2021 · ~2 min read
Quick answerRBI now permits Card-on-File Tokenisation (CoFT) for card payments, extending device-based tokenisation to stored card credentials. Card issuers can act as Token Service Providers. From Jan 1, 2022, no entity except card issuers/networks can store actual card data; existing stored data must be purged.
The rule, in the simplest words
How it plays out — a real example

Ravi, a branch operations officer in Indore, is updating his bank's system before the January 1, 2022 deadline. He makes sure all stored full card numbers of customers who took gold loans are deleted, keeping only the last four digits and the bank's name for records. He also sets up a new process where customers must give a clear 'yes' and enter an OTP to create a token for their saved card, so their gold loan EMIs can be paid safely without storing the real card number.

What changed

RBI extended device-based tokenisation to Card-on-File Tokenisation (CoFT), allowing card issuers to become Token Service Providers (TSPs) for their own cards. Tokenisation now requires explicit customer consent with AFA validation. From January 1, 2022, all entities except card issuers and networks must stop storing actual card data and purge any previously stored data.

What it means for you

Banks and payment aggregators must stop storing full card credentials by Jan 1, 2022, and purge existing data. Card issuers can now offer tokenisation services, enhancing security for recurring payments. Merchants and PAs must rely on tokens instead of storing card-on-file data, reducing fraud risk but requiring system upgrades.

What you must do

Who it affects

All Payment System Providers and Participants, Card issuers (banks), Payment Aggregators and Payment Gateways, Merchants storing card-on-file data, Card networks

❓ Common questions

What is the deadline for purging stored card data?

All entities except card issuers and card networks must purge stored actual card data by January 1, 2022. Only last four digits and issuer name can be retained for reconciliation.

Can card issuers now offer tokenisation services?

Yes, RBI now permits card issuers to act as Token Service Providers (TSPs) for cards issued by them, subject to explicit customer consent and AFA validation.

What happens if a card is renewed or replaced?

The card issuer must seek explicit consent from the cardholder before linking the new card to merchants where the old card was registered for CoFT.

📜 Read the original circular — full text as issued by RBI
RBI/2021-22/96 CO.DPSS.POLC.No.S-516/02-14-003/2021-22 September 07, 2021 All Payment System Providers and Payment System Participants Madam / Dear Sir, Tokenisation – Card Transactions: Permitting Card-on-File Tokenisation (CoFT) Services We invite reference to our circular DPSS.CO.PD No.1463/02.14.003/2018-19 dated January 8, 2019 on “Tokenisation – Card transactions”, permitting authorised card networks to offer card tokenisation services subject to the conditions listed therein. Initially limited to mobile phones and tablets, this facility was subsequently extended to laptops, desktops, wearables (wrist watches, bands, etc.), Internet of Things (IoT) devices, etc., vide our circular CO.DPSS.POLC.No.S-469/02-14-003/2021-22 dated August 25, 2021 on “Tokenisation – Card Transactions : Extending the Scope of Permitted Devices”. 2. Reference is also invited to our circulars DPSS.CO.PD.No.1810/02.14.008/2019-20 dated March 17, 2020 (as updated from time to time) and CO.DPSS.POLC.No.S33/02-14-008/2020-2021 dated March 31, 2021 on “Guidelines on Regulation of Payment Aggregators and Payment Gateways”, advising that neither the authorised Payment Aggregators (PAs) nor the merchants on-boarded by them shall store customer card credentials [also known as Card-on-File (CoF)]. 3. On a review of the tokenisation framework and to enable cardholders to benefit from the security of tokenised card transactions as also the convenience of CoF, it has been decided to effect the following enhancements – Extend the device-based tokenisation 1 framework referred to at paragraph 1 above to CoF Tokenisation (CoFT) as well. Permit card issuers to offer card tokenisation services as Token Service Providers 2 (TSPs). The facility of tokenisation shall be offered by the TSPs only for the cards issued by / affiliated to them. The ability to tokenise 3 and de-tokenise card data shall be with the same TSP. Tokenisation of card data shall be done with explicit customer consent requiring Additional Factor of Authentication (AFA) validation by card issuer. Additional requirements relating to CoFT are listed in the Annex . 4. Further, in the interest of cIarity, the following points may be noted – With effect from January 1, 2022, no entity in the card transaction / payment chain, other than the card issuers and / or card networks, shall store the actual card data. Any such data stored previously shall be purged. For transaction tracking and / or reconciliation purposes, entities can store limited data – last four digits of actual card number and card issuer’s name – in compliance with the applicable standards. Complete and ongoing compliance with the above by all entities involved, shall be the responsibility of the card networks. 5. This directive is issued under Section 10 (2) read with Section 18 of Payment and Settlement Systems Act, 2007 (Act 51 of 2007). Yours faithfully, (P. Vasudevan) Chief General Manager Annex (CO.DPSS.POLC.No.S-516/02-14-003/2021-22 dated September 07, 2021) Conditions to be fulfilled for offering CoFT services 1. For the purpose of CoFT, the token shall be unique for a combination of card, token requestor and merchant 4 . 2. If card payment for a purchase transaction at a merchant is being performed along with the registration for CoFT, then AFA validation may be combined. 3. The merchant shall give an option to the cardholder to de-register the token. Further, a token requestor having direct relationship with the cardholder shall list the merchants in respect of whom the CoFT has been opted through it by the cardholder; and provide an option to de-register any such token. 4. A facility shall also be given by the card issuer to the cardholder to view the list of merchants in respect of whom the CoFT has been opted by her / him, and to de-register any such token. This facility shall be provided through one or more of the following channels – mobile application, internet banking, Interactive Voice Response (IVR) or at branches / offices. 5. Whenever a card is renewed or replaced, the card issuer shall seek explicit consent of the cardholder for linking it with the merchants with whom (s)he had earlier registered the card. 6. The TSP shall put in place a mechanism to ensure that the transaction request has originated from the merchant and the token requestor with whom the token is associated. 7. All other provisions of the RBI circulars dated January 8, 2019 and August 25, 2021 shall be applicable. 8. The TSPs shall monitor and ensure compliance in this regard. 1 The term “device-based tokenisation” wherever used in this circular refers to card tokenisation framework laid down vide RBI circulars dated January 8, 2019 and August 25, 2021 . 2 Token Service Provider (TSP) refers to the entity which tokenises the actual card credentials and de-tokenises them whenever required. Earlier only card networks were allowed to act as TSPs. 3 In this circular, the word “token” wherever used includes token reference number, card reference number or any other similar term. 4 The word “merchant” wherever used in this circular refers to the end-merchant. However, in case of an e-commerce marketplace entity, merchant refers to the said e-commerce entity. Further, token requestor and merchant may or may not be the same entity.
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2021-22/96 · issued 07 Sep 2021. The plain-English explanation above is BankPulse’s own independent summary.
🧰 Tools — save, print, templates & related
Topics: Digital Payments / UPI
Key dataSee the live numbers behind this topic: RBI Penalty Tracker, Credit & Deposit Growth — updated from official RBI data.
Key termsPlain-English definitions of terms in this circular — see the full Indian banking glossary. UPI · KYC / AML · Deposit insurance (DICGC) · NEFT / RTGS
Who does what — compliance checklist
🏦 Branch Manager
  • Provide cardholders with options to view and de-register tokens via mobile app, internet banking, IVR, or branches.
⚙️ Operations
  • Ensure your systems purge all stored actual card data by January 1, 2022, retaining only last four digits and issuer name for reconciliation.
📜 Compliance
  • If you are a card issuer, prepare to offer CoFT services as a Token Service Provider with explicit customer consent and AFA.
  • Update merchant onboarding agreements to prohibit storage of card credentials and mandate tokenisation for recurring transactions.
Grouped from the action items above — a single circular may involve more than one team.
Worked example & action-note template

Example: if you are an Operations officer at a bank this circular applies to (All Payment System Providers and Participants, Card issuers (banks), Payment Aggregators and Payment Gateways, Merchants storing card-on-file data, Card networks), your first concrete step on “RBI Expands Card Tokenisation to Card-on-File (CoFT) Services” is: “Ensure your systems purge all stored actual card data by January 1, 2022, retaining only last four digits and issuer name for reconciliation.” (RBI issued this 07 Sep 2021).

  1. Circular: RBI/2021-22/96 -- RBI Expands Card Tokenisation to Card-on-File (CoFT) Services
  2. Issued: 07 Sep 2021
  3. Action required: Ensure your systems purge all stored actual card data by January 1, 2022, retaining only last four digits and issuer name for reconciliation.
  4. Action required: If you are a card issuer, prepare to offer CoFT services as a Token Service Provider with explicit customer consent and AFA.
  5. Action required: Update merchant onboarding agreements to prohibit storage of card credentials and mandate tokenisation for recurring transactions.
  6. Action required: Provide cardholders with options to view and de-register tokens via mobile app, internet banking, IVR, or branches.
  7. Owner: ____________ Target date: ____________
  8. Board/committee approval needed? Y / N
  9. Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.

💬 Banker Discussion

Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.

Loading comments…
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly).
Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=12159&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗