RBI's New Authentication Rules for Digital Payments
Current · Source: Reserve Bank of India · RBI/2025-26/79 · issued 25 Sep 2025 · ~2 min read
Quick answerRBI has issued new directions for digital payment authentication, effective April 1, 2026. The rules mandate two-factor authentication but allow alternative mechanisms beyond SMS OTP. They apply to all domestic digital transactions and include specific provisions for cross-border card transactions.
The rule, in the simplest words
From April 1, 2026, banks must use two different ways to check it's really you for digital payments (like a password plus a fingerprint or a code from an app).
Banks can now use other methods besides SMS OTP (a code sent by text message) to prove it's you, such as your fingerprint or a software token (a secret code from an app).
For payments with a card from another country where you don't swipe the card (like online shopping), the same strong checking rules apply.
Banks must decide how much checking to do based on how risky the payment is (for example, a small payment might need less checking than a big one).
How it plays out — a real example
A branch operations officer in Indore is updating the bank's app for customers who take gold loans. She knows that from April 1, 2026, she can let customers approve their loan repayments using their fingerprint instead of waiting for an SMS OTP, making it faster and safer for everyone.
What changed
RBI has replaced the existing SMS OTP-centric authentication framework with a principles-based approach, allowing alternative authentication mechanisms like biometrics or software tokens. The new directions, issued under the PSS Act, 2007, also introduce specific rules for cross-border card-not-present transactions. Compliance is mandatory by April 1, 2026.
What it means for you
Banks and payment system participants can now adopt diverse authentication methods beyond SMS OTP, potentially improving user experience and security. The risk-based approach allows issuers to tailor authentication based on transaction risk. For cross-border CNP transactions, similar safety standards apply, which may reduce fraud but require system upgrades.
What you must do
Review and update authentication systems to comply with the new principles by April 1, 2026.
Assess and implement alternative authentication mechanisms (e.g., biometrics, software tokens) as per the risk-based approach.
Ensure cross-border card transaction processes align with the new authentication requirements.
Train staff and update internal policies to reflect the principles-based framework.
Who it affects
All banks issuing payment instruments, Non-bank payment system providers and participants, Card issuers and acquirers handling cross-border transactions, Digital payment ecosystem participants
❓ Common questions
Regulatory timeline
Stated effective dateeffective April 1, 2026
Decoded by BankPulse2026-06-18 01:02 IST
Built from our lineage records — each fact carries its provenance; missing history simply is not shown (never guessed).
What is the effective date for these new authentication directions?
All payment system providers and participants must comply by April 1, 2026, unless a specific provision states otherwise.
Do these directions apply to cross-border transactions?
Yes, for online international card transactions where the card is issued in India and the merchant is acquired overseas, specific instructions are included to ensure similar safety levels.
Can we still use SMS OTP for authentication?
Yes, SMS OTP remains a valid factor, but the directions encourage adoption of alternative mechanisms like biometrics or software tokens, as long as two-factor authentication is maintained.
📜 Read the original circular — full text as issued by RBI
Notifications - Reserve Bank of India
Skip to main content
Selected
Selected
Change Language
हिंदी
Search the Website
Search
Home
About Us ▼
About Us
Organisation & Functions ▶
Organisation Structure
Departments
Offices
Training Establishment ▶
College of Agricultural Banking
Reserve Bank Staff College
College of Supervisors
RBI's Functions and Working
Governors
Deputy Governors
Executive Directors
Communication Policy of RBI
Sources of Information ▶
Annual Publications
Half-yearly Publications
Quarterly Publications
Monthly Publications
Weekly Publications
Occasional Publications
SDDS
NSDP
Data Releases
Publications available on Subscription
General Information
RBI History
Museum ▶
The RBI Museum
RBI Monetary Museum
Notification ▼
Notifications
Master Directions
Master Circulars
Amendment Directions
Draft Notifications/Guidelines ▶
Draft Notifications/Guidelines
Draft Directions (RE-wise)
Index To RBI Circulars
Standalone Circulars
Circulars Withdrawn
Press Releases
Speeches & Media Interactions ▼
Speeches
Media Interactions
Memorial Lectures
Podcasts
Publications ▼
Biennial
Annual
Half-Yearly
Quarterly
Bi-monthly
Monthly
Weekly
Occasional
Reports
Working Papers
Legal Framework ▼
Act
Rules
Regulations
Schemes
Research ▼
External Research Schemes
RBI Occasional Papers
Working Papers
RBI Bulletin
History
DRG Studies
KLEMS
State Statistics and Finances
Statistics ▼
Data Releases
Database on Indian Economy
Public Debt Statistics
Regulatory Reporting ▼
List of Returns
Data Definition
Validation rules/ Taxonomy
List of RBI Reporting Portals
FAQs of RBI Reporting Portals
Home
Notifications
Notifications
( 268 kb )
Reserve Bank of India (Authentication mechanisms for digital payment transactions) Directions, 2025
RBI/2025-26/79
CO.DPSS.POLC.No. S 668/02-14-015/2025-2026
September 25, 2025
Reserve Bank of India (Authentication mechanisms for digital payment transactions) Directions, 2025
Index
1. Introduction
2. Short title
3. Effective Date
4. Applicability
5. Definitions
6. Principles for authentication of digital payment transactions
7. Interoperability / Open Access
8. Risk based approach
9. Responsibility of the issuer
10. Cross-border transactions
11. Repeal
Annexure-1
Annexure-2
1. Introduction
All digital payment transactions in India are required to meet the norm of two factors of authentication. While no specific factor was mandated for authentication, the digital payments ecosystem has primarily adopted SMS-based One Time Password (OTP) as the additional factor.
As announced in Statement on Developmental and Regulatory Policies dated February 08, 2024 , in order to enable the payments ecosystem to leverage the technological advancements for implementing alternative authentication mechanisms, it has been decided to publish Reserve Bank of India (Authentication mechanisms for digital payment transactions) Directions, 2025 (hereinafter referred to as “Directions”) . The directions provide the broad principles which shall be complied with by all the participants in the payment chain, while using a form of authentication.
While these directions are applicable only to domestic transactions, in order to provide a similar level of safety for online international transactions undertaken using cards issued in India, the directions also incorporate necessary instructions for specific cross-border card transactions, in line with the Statement on Developmental and Regulatory Policies dated February 07, 2025 .
These directions are issued under Section 18 read with Section 10(2) of the Payment and Settlement Systems (PSS) Act, 2007 (Act 51 of 2007).
2. Short title
These directions shall be called Reserve Bank of India (Authentication mechanisms for digital payment transactions) Directions, 2025
3. Effective Date
All Payment System Providers and Payment System Participants, including banks and non-bank entities, shall ensure compliance with these directions by April 01, 2026, unless indicated otherwise for any specific provision herein.
4. Applicability
These directions shall be applicable to all Payment System Providers and Payment System Participants (banks and non-banks).
These directions apply to all domestic digital payment transactions, unless specifically exempted otherwise.
5. Definitions
I. Unless the context otherwise requires, the following terms shall bear the meanings assigned to them as below:
Authentication : Process of validating and confirming the credentials of the customer who is originating the payment instruction.
Card Not Present (CNP) transaction : A transaction where the card and acceptance infrastructure are not present in close proximity while making the transaction.
Card Present transaction : A transaction that is carried out through the physical use of card at the point of transaction.
Cross-border CNP transaction : A payment instruction wherein the card, issued by an Indian issuer, is used for undertaking a payment transaction favouring a merchant acquired by an overseas acquirer. For such transactions, outflow of foreign exchange is envisaged.
Digital Payment Transaction shall have the same meaning as “Electronic Funds Transfer” as defined in the PSS Act, 2007.
Factor of Authentication : Credential of the customer which is used for authentication. The factors of authentication can be from “something the user has”, “something the user knows” or “something the user is” and may comprise, inter-alia, password, SMS based OTP, passphrase, PIN, card hardware, software token, fingerprint, or any other form of biometrics (device native or Aadhaar based).
Issuer : A bank or a non-bank that maintains the customer’s account from which payment is made, such as a deposit account or a credit line or a prepaid instrument.
II. Words and expressions used but not defined in these directions and defined in the PSS Act, 2007 shall have the meanings assigned to them in that Act.
6. Principles for authentication of digital payment transactions
The technology and process deployed for authenticating a payment instruction by the Payment System Provider / Payment System Participant(s) shall comply with the following principles:
a. Minimum two factors of authentication
All digital payment transactions shall be authenticated by at least two distinct factors of authentication as defined in paragraph-5(f), unless exempted. The list of exemptions which are currently in force are listed in Annexure-1 .
Note - Issuers may, at their discretion, offer a choice of authentication factors to their customers in compliance with these directions.
b. At least one of the factors to be dynamic
It shall be ensured that for digital payment transactions, other than card present transactions, at least one of the factors of authentication is dynamically created or proven, i.e., the proof of possession of the factor, being sent as part of the transaction, is unique to that transaction.
c. Robust
The factor of authentication shall be such that compromise of one factor does not affect reliability of the other.
7. Interoperability / Open Access
System Providers and System Participants shall offer authentication or tokenisation service that is accessible to all the applications / token requestors functioning in that operating environment for all use cases / channels or token storage mechanisms.
Note –
Operating environment includes device hardware, operating system, etc.
The terms, ‘tokenisation’, ‘token requestor’, ‘use cases/channels’ and ‘token storage mechanisms’ shall have the same meaning as assigned to them in the RBI directions on “Tokenisation – Card Transactions” dated January 08, 2019 , as amended from time to time.
8. Risk based approach
Issuers may, in line with their internal risk management policies, identify transactions for evaluation against behavioural / contextual parameters such as transaction location, user behaviour patterns, device attributes, historical transaction profile, etc. Based on the perceived risk associated with the transaction, additional checks beyond the minimum two-factor authentication may be resorted to. Issuers may also explore using DigiLocker as a platform for notification and confirmation for high-risk transactions.
9. Responsibility of the issuer
An issuer shall ensure the robustness and integrity of the authentication mechanism before deployment.
If any loss arises out of transactions effected without complying with these directions, the issuer shall compensate the customer for the loss in full without demur.
Issuers shall ensure adherence to the provisions of Digital Personal Data Protection Act, 2023.
10. Cross-border transactions
The directions outlined above are not applicable to cross-border digital payment transactions. However, card issuers shall, by October 01, 2026, put in place a mechanism to validate non-recurring, cross-border card not present (CNP) transactions, where request for authentication is raised by an overseas merchant or overseas acquirer. To ensure compliance, card issuers shall register their Bank Identification Numbers (BINs) with card networks.
Further, a risk-based mechanism for handling all cross-border CNP transactions shall also be put in place by card issuers by October 01, 2026.
11. Repeal
The list of circulars / directions that are repealed are listed in Annexure-2 .
Annexure-1
(Reference: CO.DPSS.POLC.No. S 668/02-14-015/2025-2026 dated September 25, 2025)
Existing exemptions from the requirement of at least two factors of authentication under paragraph-6(a) of these directions. Any subsequent additions / modifications made, from time to time, will also be applicable.
S. No. Use case Existing directions
1. Small-value Contactless Card transactions DPSS.CO.PD No.752/02.14.003/2020-21 dated December 04, 2020
2. Recurring transactions (other than the first) under the e-mandate framework DPSS.CO.PD.No.447/02.14.003/2019-20 dated August 21, 2019
DPSS.CO.PD No.754/02.14.003/2020-21 dated December 04, 2020
CO.DPSS.POLC.No.S-882/02.14.003/2023-24 dated December 12, 2023
3. Select Prepaid Instruments such as PPI-MTS and Gift PPIs CO.DPSS.POLC.No.S-479/02.14.006/2021-22 dated August 27, 2021
4. NETC transactions DPSS.CO.PD No.1227/02.31.001/2019-20 dated December 30, 2019
5. Small value digital payments in offline mode CO.DPSS.POLC.No.S1264/02-14-003/2021-2022 dated January 03, 2022
6. Travel bookings, including Global Distribution System / IATA, through commercial / corporate cards. Letter dated April 17, 2012 (DPSS.CO.PD.No.1910/02.14.003/2011-12) issued to Indian Bank’s Association
Annexure-2
(Reference: CO.DPSS.POLC.No. S 668/02-14-015/2025-2026 dated September 25, 2025)
List of circulars / directions that are repealed:
No Circular No. Date Subject
1. RBI/DPSS No. 1501/02.14.003/2008-2009 February 18, 2009 Credit/Debit Card transactions-Security Issues and Risk mitigation measures
2. RBI/DPSS No. 2303/02.14.003/2009-2010 April 23, 2010 Credit/Debit Card transactions- Security Issues and Risk mitigation measures for IVR transactions
3. RBI/DPSS No.914/02.14.003/2010-2011 October 25, 2010 Credit/Debit Card transactions- Security Issues and Risk mitigation measures for Card Not Present Transactions
4. DPSS.CO.No.1503/02.14.003/2010-2011 December 31, 2010 Security Issues and Risk mitigation measures related to Card Not present transactions
5. DPSS. CO. PD 2224/02.14.003/2010-2011 March 29, 2011 Security Issues and Risk mitigation measures - Online alerts to the cardholder for usage of credit/debit cards
6. DPSS.PD.CO. No.223/02.14.003/2011-2012 August 04, 2011 Security Issues and Risk mitigation measures related to Card Not Present (CNP) transactions
7. DPSS.PD.CO. No.371/02.14.003/2014-2015 August 22, 2014 Security Issues and Risk mitigation measures related to Card Not Present (CNP) transactions
8. DPSS.CO.PDNo.1431/02.14.003/2016-17 December 06, 2016 Card Not Present transactions – Relaxation in Additional Factor of Authentication for payments upto ₹2,000/- for card network provided authentication solutions
2026
All Months January February March April May June July August September October November December
2025
All Months January February March April May June July August September October November December
2024
All Months January February March April May June July August September October November December
2023
All Months January February March April May June July August September October November December
2022
All Months January February March April May June July August September October November December
2021
All Months January February March April May June July August September October November December
2020
All Months January February March April May June July August September October November December
2019
All Months January February March April May June July August September October November December
2018
All Months January February March April May June July August September October November December
2017
All Months January February March April May June July August September October November December
Archives
2016
All Months January February March April May June July August September October November December
2015
All Months January February March April May June July August September October November December
2014
All Months January February March April May June July August September October November December
2013
All Months January February March April May June July August September October November December
2012
All Months January February March April May June July August September October November December
2011
All Months January February March April May June July August September October November December
2010
All Months January February March April May June July August September October November December
2009
All Months January February March April May June July August September October November December
2008
All Months January February March April May June July August September October November December
2007
All Months January February March April May June July August September October November December
2006
All Months January February March April May June July August September October November December
2005
All Months January February March April May June July August September October November December
2004
All Months January February March April May June July August September October November December
2003
All Months January February March April May June July August September October November December
2002
All Months January February March April May June July August September October November December
2001
All Months January February March April May June July August September October November December
2000
All Months January February March April May June July August September October November December
1999
All Months January February March April May June July August September October November December
1998
All Months January February March April May June July August September October November December
1997
All Months January February March April May June July August September October November December
1996
All Months January February March April May June July August September October November December
1995
All Months January February March April May June July August September October November December
1994
All Months January February March April May June July August September October November December
1993
All Months January February March April May June July August September October November December
1992
All Months January February March April May June July August September October November December
1991
All Months January February March April May June July August September October November December
Top
Back to previous page
More Links :
Bank Holidays
Banking Glossary
Citizen's Charter
Complaints
Contact Us
COVID-19 Measures
E-LMS
Events
FAQs
Financial Education
Forms
IFSC/MICR Codes
Important Websites
Opportunities @ RBI
RBI Clarifications
RBI Kehta Hai
RBI’s Vision and Values (1257 kb)-->
Right to Information Act
Tenders
Follow RBI
RSS
Twitter
YouTube
Instagram
Facebook
LinkedIn
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2025-26/79 · issued 25 Sep 2025. The plain-English explanation above is BankPulse’s own independent summary.
Review and update authentication systems to comply with the new principles by April 1, 2026.
Assess and implement alternative authentication mechanisms (e.g., biometrics, software tokens) as per the risk-based approach.
📜 Compliance
Ensure cross-border card transaction processes align with the new authentication requirements.
Train staff and update internal policies to reflect the principles-based framework.
Grouped from the action items above — a single circular may involve more than one team.
Worked example & action-note template
Example: if you are an IT/Systems lead at a bank this circular applies to (All banks issuing payment instruments, Non-bank payment system providers and participants, Card issuers and acquirers handling cross-border transactions, Digital payment ecosystem participants), your first concrete step on “RBI's New Authentication Rules for Digital Payments” is: “Review and update authentication systems to comply with the new principles by April 1, 2026.” (RBI issued this 25 Sep 2025).
Circular: RBI/2025-26/79 -- RBI's New Authentication Rules for Digital Payments
Issued: 25 Sep 2025
Action required: Review and update authentication systems to comply with the new principles by April 1, 2026.
Action required: Assess and implement alternative authentication mechanisms (e.g., biometrics, software tokens) as per the risk-based approach.
Action required: Ensure cross-border card transaction processes align with the new authentication requirements.
Action required: Train staff and update internal policies to reflect the principles-based framework.
Owner: ____________ Target date: ____________
Board/committee approval needed? Y / N
Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.
💬 Banker Discussion
Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly). Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=12898&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Help us keep this accurate
Found an inaccuracy or have an improvement? Tell us. Every report is reviewed by our team before any change is made — nothing goes live unverified.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗
BANKPULSE · FREE DAILY BRIEF
Get RBI updates for your role
Every important RBI update, decoded in plain English — for your career, exams & financial awareness.
We collect only your email, name and role, used solely to send your brief — never sold or shared. Withdraw anytime via the unsubscribe link in any email. Independent platform, not affiliated with the RBI. Information, not legal advice.
REPORT AN ERROR · BETA
Spotted an error? Earn 500 BankPulse Credits
Help us stay accurate. If your correction is verified true and approved by our founder, you earn 500 BankPulse Credits — redeemable when the platform monetises.
Reviewed by a human before any credit is awarded. We never change the site from crowd input without verification.
WANT A NEW FEATURE · BETA
What would make BankPulse more useful for you?
Tell us what to build next — a tool, a data view, a role page, anything. We read every suggestion.
Thank you — your ideas directly shape what we build.