HomeCirculars › RBI/2023-24/91

RBI Allows Card Tokenisation Directly via Issuing Banks

Current · Source: Reserve Bank of India · RBI/2023-24/91 · issued 20 Dec 2023 · ~2 min read
Quick answerRBI now permits card issuers to tokenise cards directly, giving cardholders a single process to tokenise for multiple merchants. This expands tokenisation beyond card networks and issuers, enhancing convenience and security.
The rule, in the simplest words
How it plays out — a real example

Ravi, a branch operations officer in Indore, logs into his bank's mobile app to tokenise his debit card for multiple online stores. He selects 'Flipkart' and 'Amazon' from the bank's list, enters an OTP to confirm, and the bank creates one token for both merchants, making his future payments faster and safer.

What changed

Previously, card-on-file tokenisation (CoFT) services were provided by card issuers and card networks. Now, RBI has enabled card issuing banks and institutions to directly offer CoFT services, allowing cardholders to tokenise their cards for multiple merchants in one go via mobile or internet banking.

What it means for you

Banks can now offer tokenisation as a direct service, reducing reliance on third-party networks and simplifying the process for customers. This could increase adoption of tokenisation, reduce card data storage risks, and enhance customer loyalty. Lenders must update their mobile and internet banking platforms to support this feature.

What you must do

Who it affects

Card issuing banks and institutions, Payment system providers and participants, Cardholders using UPI and digital payments, Merchants accepting card payments

❓ Common questions

What is the key benefit of this change for cardholders?

Cardholders can now tokenise their cards directly through their issuing bank's mobile or internet banking, in a single process for multiple merchants, instead of doing it separately on each merchant site.

Do we need to update our existing tokenisation systems?

Yes, banks must enable CoFT generation through their digital channels, ensure AFA validation, and provide a merchant list. Existing tokenisation rules from earlier RBI circulars still apply.

Can tokens be issued by both the card network and the issuer?

Yes, the token may be issued by either the card network, the issuer, or both, as per the requirements.

📜 Read the original circular — full text as issued by RBI
RBI/2023-24/91 CO.DPSS.POLC.No.S-919/02-14-003/2023-24 December 20, 2023 All Payment System Providers and Payment System Participants Madam / Dear Sir, Card-on-File Tokenisation (CoFT) – Enabling Tokenisation through Card Issuing Banks The card tokenisation services are being currently provided by card issuers and card networks in terms of Reserve Bank of India circulars DPSS.CO.PD No.1463/02.14.003/2018-19 dated January 8, 2019 on “Tokenisation – Card transactions”, CO.DPSS.POLC.No.S-516/02-14-003/2021-22 dated September 07, 2021 on “Tokenisation – Card Transactions: Permitting Card-on-File Tokenisation (CoFT) Services” and CO.DPSS.POLC.No.S-567/02-14-003/2022-23 dated June 24, 2022 on “Restriction on Storage of Actual Card Data [i.e. Card-on-File (CoF)]”. 2. As announced in the Statement on Development and Regulatory Policies dated October 6, 2023 , it has been decided to enable CoFT directly through card issuing banks / institutions also. This will provide cardholders with an additional choice to tokenise their cards for multiple merchant sites through a single process. Detailed requirements for the same are listed in the Annex . 3. This directive is issued under Section 10 (2) read with Section 18 of Payment and Settlement Systems Act, 2007 (Act 51 of 2007). Yours faithfully, (Gunveer Singh) Chief General Manager-in-Charge Annex (CO.DPSS.POLC.No.S-919/02-14-003/2023-24 dated December 20, 2023) CoFT through card issuers - Requirements 1. Generation of CoF Tokens for a card, through the card issuer, can be enabled through mobile banking and internet banking channels. 2. CoFT generation shall be done only on explicit customer consent, and with AFA validation. If the cardholder selects multiple merchants for which to tokenise his/her card, AFA validation may be combined for all these merchants. 3. The tokens thus generated shall be made available on the merchant’s payment page, in the cardholder’s account with the merchant. 4. The cardholder may tokenise the card at any time of his convenience, either on receipt of the new card or later. 5. The card issuer shall provide a complete list of merchants for whom it can provide tokenisation services. The cardholders shall select the merchants with whom he/she wishes to maintain tokens. (Alternatively – “The cardholder can make his selection from the list”). 6. The card token so issued may be either by the card network or the issuer or both. 7. All other provisions of RBI circulars dated January 8, 2019 , August 25, 2021 , September 7, 2021 and July 28, 2022 shall remain applicable.
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2023-24/91 · issued 20 Dec 2023. The plain-English explanation above is BankPulse’s own independent summary.
🧰 Tools — save, print, templates & related
Topics: Digital Payments / UPI
Key dataSee the live numbers behind this topic: RBI Penalty Tracker, Credit & Deposit Growth — updated from official RBI data.
Key termsPlain-English definitions of terms in this circular — see the full Indian banking glossary. UPI · KYC / AML · Deposit insurance (DICGC) · NEFT / RTGS
Worked example & action-note template

Example: if you are a Compliance officer at a bank this circular applies to (Card issuing banks and institutions, Payment system providers and participants, Cardholders using UPI and digital payments, Merchants accepting card payments), your first concrete step on “RBI Allows Card Tokenisation Directly via Issuing Banks” is: “Enable CoFT generation through mobile banking and internet banking channels.” (RBI issued this 20 Dec 2023).

  1. Circular: RBI/2023-24/91 -- RBI Allows Card Tokenisation Directly via Issuing Banks
  2. Issued: 20 Dec 2023
  3. Action required: Enable CoFT generation through mobile banking and internet banking channels.
  4. Action required: Ensure explicit customer consent and AFA validation for token generation, with combined AFA for multiple merchants.
  5. Action required: Provide cardholders a list of merchants for tokenisation and allow them to select merchants.
  6. Action required: Make generated tokens available on merchant payment pages and in cardholder accounts.
  7. Action required: Comply with all existing RBI circulars on tokenisation from January 2019, August 2021, September 2021, and July 2022.
  8. Owner: ____________ Target date: ____________
  9. Board/committee approval needed? Y / N
  10. Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.

💬 Banker Discussion

Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.

Loading comments…
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly).
Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=12573&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗