RBI master-direction RBI/DOR/2025-26/383 · 28 Nov 2025
Official title
Reserve Bank of India (Local Area Banks – Digital Banking Channels Authorisation) Directions, 2025
Summary
Check the official recordThe Reserve Bank of India establishes a regulatory framework for Local Area Banks to provide digital banking channels. These channels include internet and mobile banking for financial and non-financial transactions. Banks must implement Core Banking Solutions and enable IPv6 infrastructure to offer these services. Banks may provide view-only facilities after notifying the Reserve Bank through the PRAVAAH portal. Banks require prior Reserve Bank approval to offer transactional banking facilities. Applicants must meet specific capital, technical, and compliance standards, including a Gap Assessment and Internal Controls Adequacy report. Banks must ensure customer consent, provide clear terms, and maintain risk mitigation measures. These directions take effect on January 01, 2026, and replace previous instructions on this subject.
What you must do
Key dates
Who is affected
Thresholds
Exceptions
If you do not comply
RBI/DOR/2025-26/383
DOR.RAUG.AUT.REC.306/24.01.041/2025-26
November 28, 2025
In exercise of the powers conferred under Section 35A of the Banking Regulation Act, 1949 (hereinafter called the Act), the Reserve Bank, being satisfied that it is necessary and expedient in the public interest so to do, hereby, issues the following directions.
These Directions shall be called the Reserve Bank of India (Local Area Banks - Digital Banking Channels Authorisation) Directions, 2025.
These Directions shall come into effect from January 01, 2026.
The provisions of these Directions shall be applicable to Local Area Banks (hereinafter collectively referred to as 'banks' and individually as a 'bank').
4.1 In these Directions, unless the context otherwise requires, the following definitions shall be applicable:
(a) Digital Banking Channels – Digital Banking Channels refer to modes provided by the banks over web sites (i.e., internet banking), mobile phones (i.e., mobile banking) or other digital channels through customer’s electronic devices/equipment for the execution of financial and other banking transactions as required for digital banking services involving significant level of process automation and/or interfacing with other institutions/entities.
(b) Internet Banking Channel – Digital banking channel offered by a bank to its customers for operating their accounts and accessing its services over the internet (including web browser-based applications but excluding mobile applications).
(c) Mobile Banking Channel – Digital banking channel offered by a bank to its customers for operating their accounts and accessing its services using mobile applications, unstructured supplementary service data (USSD) and short message service (SMS).
(d) View Only Banking Facility – A feature of digital banking channels which only allows banking services that do not alter the asset or liability of the customer viz. balance enquiry, balance viewing, account statement download, etc.
Note:
Loans, funds transfers, and other such facilities, which create liability for the customer and/or involve movement of funds, cannot be provided by banks having view only facility over digital channels. However, banks providing view only facility can provide downloadable forms for such facilities.
(e) Transactional Banking Facility – A feature of digital banking channels through which all transactions involving funds or other banking services can be provided.
4.2 All other expressions unless defined herein shall have the same meaning as have been assigned to them under the Banking Regulation Act, 1949 or the Reserve Bank of India Act, 1934 and rules / regulations made thereunder, or any statutory modification or re-enactment thereto, or Glossary of terms published by the Reserve Bank or as used in commercial parlance, as the case may be.
Banks shall put in place comprehensive policy(ies) for all digital banking channels keeping in account all statutory and regulatory requirements (including on management of liquidity and operational risks in digital banking scenario).
6.1 All banks which have implemented Core Banking Solution (CBS) and have enabled their public facing Information technology (IT) infrastructure to handle Internet Protocol Version 6 (IPv6) traffic are eligible to provide view only banking facility for internet banking, mobile banking, and other digital banking channels-based services.
6.2 The banks commencing view only digital banking channel(s), from date of applicability of these Directions, shall intimate the Department of Regulation, Reserve Bank of India (through the PRAVAAH portal) along with a copy of the ‘Gap Assessment and Internal Controls Adequacy’ (GAICA) Report as prescribed in para 7.1(e)(i) below within thirty days from the decision to launch the facility with the approval of bank board. The process shall be subject to scrutiny as deemed fit by the supervisors.
7.1 Banks shall require prior approval of the Reserve Bank for launching transactional banking facility. Subject to fulfilment of the eligibility criteria as enumerated below, banks may apply to the Department of Regulation, Reserve Bank of India (through the PRAVAAH portal) for launch of transactional banking facility, along with the approval of bank board and other necessary supporting documents.
a) Implementation of CBS and public facing IT infrastructure being enabled to handle IPv6 traffic.
b) Compliance with minimum regulatory CRAR requirement.
c) Minimum paid up capital/Net worth as per the applicable licensing requirement (as amended from time to time) or ₹50 crores, whichever is higher, as on March 31st of the immediately preceding financial year.
d) Availability of adequate financial and technical capabilities for this facility. The applicant bank shall submit detailed report indicating the expected expenditure (on set up, maintenance, and upgradation) along with availability of funds for offering the proposed facility on an ongoing basis. Further, the report shall also include the details of cost-benefit analysis, third-party technology service providers (if any), technology proposed to be adopted, and availability of skilled personnel to manage the operations / oversee the outsourcing partners’ operations.
e) A satisfactory track record of regulatory compliance including with cyber security guidelines and a sound internal control system. This shall be assessed through the following:
7.2 Once an approval is granted under these Directions, the bank can provide all types of digital banking channels. If a bank had received approval for a particular digital banking channel (like mobile banking) before the date of applicability of these Directions, it shall ensure compliance to the eligibility criteria as detailed in para 7.1(a) to (d) above before launching any other digital banking channel. Further, the GAICA Report, certified by (third party) CERT-In empanelled auditor(s), addressing the specific requirement for the new proposed channels shall be sent to the Department of Regulation, Reserve Bank of India (through the PRAVAAH portal) with the approval of bank board within thirty days from the decision to launch the facility. The process shall be subject to scrutiny as deemed fit by the supervisors.
(1) Guidelines on Outsourcing of Information Technology Services as specified in Reserve Bank of India (Commercial Banks – Managing Risks in Outsourcing) Directions, 2025 dated November 28, 2025, as amended from time to time.
(2) DoS.CO.CSITE.SEC.No.1852/31.01.015/2020-21 dated February 18, 2021 – Master Direction on Digital Payment Security Controls, as amended from time to time. (Chapters II, III and IV of the MD are now extended to LABs.)
(3) Working Group on Information Security, Electronic Banking, Technology Risk Management and Cyber Frauds- Implementation of recommendations.
(As specified in para (ii) of the Annex to Master Direction on Information Technology, Governance, Risks, Controls and Assurance Practices dated November 07, 2023, as amended from time to time)
(4) UBD.No.Admn.46b/17:36:00/97-98 dated March 30, 1998 – Risks and Control in Computer and Telecommunication Systems, as amended from time to time.