{"id":84653,"date":"2025-09-25T11:12:07","date_gmt":"2025-09-25T11:12:07","guid":{"rendered":"https:\/\/www.europesays.com\/ie\/84653\/"},"modified":"2025-09-25T11:12:07","modified_gmt":"2025-09-25T11:12:07","slug":"rbi-sets-ball-rolling-to-secure-digital-payments-paves-way-for-checks-beyond-two-factor-authentication-details-here","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ie\/84653\/","title":{"rendered":"RBI sets ball rolling to secure digital payments, paves way for checks beyond two-factor authentication\u2014 details here"},"content":{"rendered":"<p>The Reserve Bank of India (RBI) on Thursday rolled out a new framework for authenticating digital payments beyond two-factor authentication (2FA), which will come into force from 1 April 2026.<\/p>\n<p>The new rules are part of the <a class=\"backlink\" target=\"_blank\" href=\"https:\/\/www.livemint.com\/industry\/rbi-lending-rules-banks-exposure-to-corporates-hdfc-loans-private-capex-11758691484907.html\" data-vars-page-type=\"story\" data-vars-link-type=\"Manual\" rel=\"dofollow noopener\" data-vars-anchor-text=\"Reserve Bank of India\">Reserve Bank of India<\/a> (Authentication Mechanisms for <a class=\"backlink\" target=\"_blank\" href=\"https:\/\/www.livemint.com\/money\/indian-digital-payment-upi-financial-inclusion-finance-ministry-rbi-npci-fintech-parliament-11753707982877.html\" data-vars-page-type=\"story\" data-vars-link-type=\"Manual\" rel=\"dofollow noopener\" data-vars-anchor-text=\"digital payment transactions\">Digital Payment Transactions<\/a>) Directions, 2025, announced today.<\/p>\n<p>New guidelines issued<\/p>\n<p>I. Card issuers are encouraged to introduce new <a class=\"backlink\" target=\"_blank\" href=\"https:\/\/www.livemint.com\/money\/personal-finance\/additional-factor-authentication-afa-online-international-transactions-digital-payments-rbi-security-11739358928444.html\" data-vars-page-type=\"story\" data-vars-link-type=\"Manual\" rel=\"dofollow noopener\" data-vars-anchor-text=\"factors of authentication\">factors of authentication<\/a> by leveraging technological advancements. However, it does NOT mean that SMS-based OTP as an authentication tool would get discontinued.<\/p>\n<p>II. The latest direction also enable card issuers to embrace additional risk-based checks beyond the minimum two-factor authentication. This could be based on the fraud risk perception of the underlying transaction.<\/p>\n<p>III. The directions also emphasise facilitating <a class=\"backlink\" target=\"_blank\" href=\"https:\/\/www.livemint.com\/money\/personal-finance\/ppi-interoperability-how-rbi-s-new-upi-rule-set-to-ease-digital-payments-an-explainer-11735386893536.html\" data-vars-page-type=\"story\" data-vars-link-type=\"Manual\" rel=\"dofollow noopener\" data-vars-anchor-text=\"interoperability\">interoperability<\/a> and enabling open access to technology. As a result, system providers will offer an authentication or tokenisation service that is accessible to all the applications\/token requestors functioning in that operating environment.<\/p>\n<p>IV. The RBI also delineates the responsibility of issuers.<\/p>\n<p>V. Additionally, the central bank mandates card issuers to validate <a class=\"backlink\" target=\"_blank\" href=\"https:\/\/www.livemint.com\/money\/personal-finance\/additional-factor-authentication-afa-online-international-transactions-digital-payments-rbi-security-11739358928444.html\" data-vars-page-type=\"story\" data-vars-link-type=\"Manual\" rel=\"dofollow noopener\" data-vars-anchor-text=\"AFA\">AFA<\/a> in non-recurring cross-border CNP (card-not-present) transactions whenever such a request is raised by the overseas merchant or acquirer.<\/p>\n<p>Principles for authenticating digital payments\u00a0<\/p>\n<p>1. <strong>Minimum two<\/strong>: There should be a minimum of two factors of authentication.<\/p>\n<p>2. <strong>Dynamic<\/strong>: At least one of the factors of authentication is dynamically created or proven.<\/p>\n<p>3. <strong>Robust<\/strong>: The factor of authentication will be such that the compromise of one factor does not affect the reliability of the other.<\/p>\n<p>Stakeholders&#8217; suggestions incorporated<\/p>\n<p>Last year, in July, the RBI issued <a class=\"backlink\" target=\"_blank\" href=\"https:\/\/www.livemint.com\/money\/rbi-wants-all-digital-payments-to-have-additional-factor-of-authentication-afa-details-here-11722514431126.html\" data-vars-page-type=\"story\" data-vars-link-type=\"Manual\" rel=\"dofollow noopener\">draft directions<\/a> on Alternative Authentication Mechanisms for Digital Payment Transactions, followed by draft directions on the introduction of Additional Factor of Authentication (AFA) in <a class=\"backlink\" target=\"_blank\" href=\"https:\/\/www.livemint.com\/industry\/banking\/rbi-issues-new-guidelines-for-payment-aggregators-minimum-net-worth-cross-border-rules-announced-11757994715994.html\" data-vars-page-type=\"story\" data-vars-link-type=\"Manual\" rel=\"dofollow noopener\" data-vars-anchor-text=\"cross-border\">cross-border <\/a>CNP transactions in February this year to seek comments from stakeholders.<\/p>\n<p>The views of the public were examined and incorporated in the directions which were issued today.<\/p>\n<p>However, these measures outlined above will not be implemented in cross-border digital payments.<\/p>\n<p>Meanwhile, the RBI has instructed card issuers to put in place a mechanism to validate non-recurring, cross-border CNP transactions by October 1 next year, where a request for <a class=\"backlink\" target=\"_blank\" href=\"https:\/\/www.livemint.com\/money\/rbi-wants-all-digital-payments-to-have-additional-factor-of-authentication-afa-details-here-11722514431126.html\" data-vars-page-type=\"story\" data-vars-link-type=\"Manual\" rel=\"dofollow noopener\" data-vars-anchor-text=\"authentication\">authentication<\/a> is raised by an overseas merchant or overseas acquirer.<\/p>\n<p>To ensure compliance, card issuers will register their Bank Identification Numbers (BINs) with card networks.<\/p>\n<p>For all personal finance updates, visit <a class=\"backlink\" target=\"_blank\" href=\"https:\/\/www.livemint.com\/money\" data-vars-page-type=\"story\" data-vars-link-type=\"Manual\" rel=\"dofollow noopener\" data-vars-anchor-text=\"here\">here<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"The Reserve Bank of India (RBI) on Thursday rolled out a new framework for authenticating digital payments beyond&hellip;\n","protected":false},"author":2,"featured_media":84654,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[257],"tags":[56123,39766,8490,18,19,17,279,6509,82,56124],"class_list":{"0":"post-84653","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-mobile","8":"tag-authenticating-digital-payments","9":"tag-authentication","10":"tag-digital-payments","11":"tag-eire","12":"tag-ie","13":"tag-ireland","14":"tag-mobile","15":"tag-rbi","16":"tag-technology","17":"tag-two-factor-authentication"},"share_on_mastodon":{"url":"","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/84653","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/comments?post=84653"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/posts\/84653\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media\/84654"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/media?parent=84653"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/categories?post=84653"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ie\/wp-json\/wp\/v2\/tags?post=84653"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}