Skip to content
BankPulseBETARegulatory intelligence for Indian banking
Directions · Reserve Bank of India

Reserve Bank of India (Authentication mechanisms for digital payment transactions) Directions, 2025

UR

The four dates on this rule

At a glanceRBI says authentication means checking who sent the payment order. Every digital payment transaction in India needs two factors of authentication.

Official RBI page

What it says

Must know

1. Two-factor rule for all payments

Every digital payment transaction in India needs two factors of authentication.

2. Comply by April 2026

All payment providers and participants must comply with these rules by April 01, 2026.

3. Covers all payment system players

These rules cover every payment system provider and participant, banks and non-banks.

4. Domestic transactions only, unless exempt

The rules apply to domestic digital payments, unless specifically exempted.

5. Minimum two authentication factors required

Every digital payment must use at least two separate authentication factors, unless exempted.

6. One factor must be dynamic

For most transactions, at least one authentication factor must be created fresh each time.

7. Factors must not depend together

If one factor is broken, the other one must still work on its own.

8. Issuer pays for non-compliance losses

If a loss happens because the issuer broke these rules, it must repay the customer in full.

9. Cross-border card deals excluded

These directions do not apply to cross-border digital payment transactions.

10. A ₹2,000 exemption is repealed

RBI has repealed the old rule letting small card payments under ₹2,000 skip extra checks.

Do it

1. Issuers may offer factor choice

Issuers may let customers choose which authentication factors to use.

2. Open access to authentication tools

Providers must make their authentication or tokenisation service open to every application.

3. Issuers may weigh transaction risk

Issuers may check transactions against risk signals like location and device details.

4. DigiLocker may flag risky payments

Issuers may use DigiLocker to notify and confirm high-risk transactions.

5. Issuer must test its system

The issuer must check its login system is sound before using it.

6. Follow the data protection law

Issuers must follow the Digital Personal Data Protection Act, 2023.

7. Validate cross-border card requests soon

By October 01, 2026, card issuers must set up checks for one-time cross-border card payments.

8. Register card numbers with networks

Card issuers must register their BINs with card networks.

9. Second cross-border risk check

By October 01, 2026, card issuers must also add a risk-based check for cross-border card payments.

Background

1. Legal basis for these rules

RBI issues these rules under Sections 18 and 10(2) of the PSS Act, 2007.

2. What authentication means

RBI says authentication means checking who sent the payment order.

3. What a CNP transaction is

A CNP transaction is one where the card is not physically present.

4. What card-present means

A card-present transaction is done by physically using the card at the transaction point.

5. What cross-border CNP means

A cross-border CNP transaction is an Indian card used to pay an overseas merchant.

6. What a factor is

A factor of authentication is a credential used to confirm the customer.

7. Who counts as issuer

The issuer is the bank or non-bank that holds the customer's account.

8. Undefined terms follow PSS Act

Any word not defined here takes its meaning from the PSS Act, 2007.

9. Extra checks allowed for risk

Riskier transactions may get checks beyond the minimum two-factor authentication.

10. Old card-security circulars are repealed

This rule replaces a list of older card-security circulars listed in Annexure-2.

Where to go next