Reserve Bank of India (Non-Banking Financial Companies – Digital Payment Security Controls) Directions, 2026
भारतीय įरज़वर् बैंक Reserve Bank of India पयर्वेक्षण ͪ वभाग, भारतीय ǐरज़वर् बैंक, केंद्रȣय कायार्लय, मेकर टावर-ई, 20वीं मंिजल, कफ परेड, कोलाबा, मुंबई-400 005 दूरभाष: 022-2216 1816 ई-मेल: csite@rbi.org.in Department of Supervision, Reserve Bank of India, Central Office, Maker Tower-E, 20th floor, Cuffe Parade, Colaba, Mum…
Source details
- Source
- Reserve Bank of India
- Type
- master-direction
- Published by source
- 30 Jul 2026
- Coverage area
- banking
Document text
भारतीय रिज़र्व बैंक Reserve Bank of India पयर्वेक्षण विभाग, भारतीय रिज़र्व बैंक, केंद्रȣय कायार्लय, मेकर टावर-ई, 20वीं मंिजल, कफ परेड, कोलाबा, मुंबई-400 005 दूरभाष: 022-2216 1816 ई-मेल: csite@rbi.org.in Department of Supervision, Reserve Bank of India, Central Office, Maker Tower-E, 20th floor, Cuffe Parade, Colaba, Mumbai- 400 005 Tel: 022- 2216 1816 Email: csite@rbi.org.in
Ǒहंदȣ आसान है इसका प्रयोग बढ़ाइए RBI/DoS/2026-27/462 DoS.CO.CSITEG.56/31.01.015/2026-27
July 31, 2026 Reserve Bank of India (Non-Banking Financial Companies – Digital Payment Security Controls) Directions, 2026 Table of Contents Chapter I - Preliminary ............................................................................................. 2 A. Short Title and Commencement ..................................................................... 2 B. Applicability ..................................................................................................... 2 C. Definitions ........................................................................................................ 3 Chapter II - Role of the Board .................................................................................. 5 A. Board Approved Policies ................................................................................ 5 Chapter III - General Controls ................................................................................. 6 A. Governance and Management of Security Risks .......................................... 6 B. Other Generic Security Controls .................................................................. 10 C. Application Security Life Cycle .................................................................... 11 D. Authentication Framework ............................................................................ 14 E. Fraud Risk Management ............................................................................... 16 F. Reconciliation Mechanism ............................................................................ 17 G. Customer Protection, Awareness and Grievance Redressal Mechanism. 18 Chapter IV - Web Application Security Controls ................................................. 20 Chapter V - Mobile Application Security Controls ............................................... 21 Chapter VI - Card Payment Security Controls ..................................................... 25 Chapter VII - Repeal and Other Provisions .......................................................... 29 A. Repeal and Saving ......................................................................................... 29 B. Application of Other Laws not barred .......................................................... 29 C. Interpretations ................................................................................................ 30
RBI (NBFCs – Digital Payment Security Controls) Directions, 2026
2
In exercise of the powers conferred under extant provisions of Chapter III-B of the Reserve Bank of India Act, 1934, Chapter IV of the Payment and Settlement Systems Act, 2007, Section 6 of the Factoring Regulation Act, 2011, and all other provisions / laws enabling the Reserve Bank of India (‘RBI’) in this regard, RBI being satisfied that it is necessary and expedient in the public interest so to do, hereby issues Directions hereinafter specified. Chapter I - Preliminary A. Short Title and Commencement
- These Directions shall be called the Reserve Bank of India (Non-Banking Financial Companies – Digital Payment Security Controls) Directions, 2026.
- These Directions shall come into effect immediately upon issuance. B. Applicability
- These Directions shall be applicable to Credit-Card issuing Non-Banking Financial Companies (hereinafter collectively referred to as ‘NBFCs’ and individually as ‘NBFC’).
- These Directions are applicable for digital payment products and services provided by the NBFC as detailed below: (1) Any digital payment product or service offered by the Credit-Card issuing NBFC to customers for carrying out financial transactions or non-financial transactions such as balance enquiry, set / change Personal Identification Number (PIN), mobile application registration, generation of one-time password (OTP), mini-statement, facility of checking transaction status, and option to the customer to raise dispute / grievance. Such digital payment products and services offered directly by the NBFC, or a system operated by any of the RBI authorised Payment System Operators (PSOs), and the associated IT assets (applications, systems, infrastructure) shall be considered for the scope of these Directions.
RBI (NBFCs – Digital Payment Security Controls) Directions, 2026
3
C. Definitions 5. The following definitions are sourced from Financial Stability Board (FSB) Cyber Lexicon unless explicitly mentioned otherwise. In these Directions, unless the context states otherwise, the terms herein shall bear the meaning assigned to them below: (1) ‘Availability’ - Property of being accessible and usable on demand by an authorised entity. (2) ‘Confidentiality’ - Property that information is neither made available nor disclosed to unauthorised individuals, entities, processes, or systems. (3) ‘Cyber’ - Relating to, within, or through the medium of the interconnected information infrastructure of interactions among persons, processes, data, and information systems. (4) ‘Cybersecurity’ - Preservation of confidentiality, integrity, and availability of information and / or information systems through the cyber medium. In addition, other properties, such as authenticity, accountability, non- repudiation, and reliability can also be involved. (5) ‘Cyber-attack’ - Malicious attempt(s) to exploit vulnerabilities through the cyber medium to damage, disrupt, or gain unauthorised access to assets. (6) ‘Distributed Denial of Service (DDoS)’ - A denial of service that is carried out using numerous sources simultaneously. (7) ‘Framework’ - A framework is a structured set of strategies, policies, procedures, methods, and best practices that guides organisational activities, enables governance, and supports the achievement of defined objectives. (Source: adapted from ISACA glossary) (8) ‘Information System’ - Set of applications, services, information technology assets, or other information-handling components, which includes the operating environment and networks.
RBI (NBFCs – Digital Payment Security Controls) Directions, 2026
4
(9) ‘Integrity’ - Property of accuracy and completeness. (10) ‘Malware’ - Software designed with malicious intent containing features or capabilities that can potentially cause harm directly or indirectly to entities or their information systems. (11) ‘Penetration Testing’ - A test methodology in which assessors typically working under specific constraints, attempt to circumvent, or defeat the security features of an information system. (12) ‘Phishing’ - A digital form of social engineering that attempts to acquire private or confidential information by pretending to be a trustworthy entity in an electronic communication. (13) ‘Vulnerability’ - A weakness, susceptibility, or flaw of an asset or control that can be exploited by one or more threats. (14) ‘Vulnerability Assessment (VA)’ - Systematic examination of an information system or product to determine the adequacy of security measures, identify security deficiencies, provide data from which to predict the effectiveness of proposed security measures and confirm the adequacy of such measures after implementation. 6. All other expressions unless defined herein shall have the same meaning as have been assigned to them under the Reserve Bank of India Act, 1934, the Banking Regulation Act, 1949, the Payment and Settlement Systems Act, 2007, the Information Technology Act, 2000, the Companies Act, 2013 or any statutory modification or re-enactment thereto or other regulations issued by the RBI or the Glossary of Terms published by the RBI or as used in commercial parlance, as the case may be.
RBI (NBFCs – Digital Payment Security Controls) Directions, 2026
5
Chapter II - Role of the Board A. Board Approved Policies 7. The Board of Directors shall approve the policies related to digital payment products and services. Such policies shall be reviewed at least annually by the Board.
RBI (NBFCs – Digital Payment Security Controls) Directions, 2026
6
Chapter III - General Controls A. Governance and Management of Security Risks 8. The NBFC shall formulate a policy for digital payment products and services with the approval of its Board. The contours of the policy, while discussing the parameters of any ‘new product’ including its alignment with the overall business strategy and inherent risk of the product, risk management / mitigation measures, compliance with regulatory instructions, and customer experience, shall explicitly cover payment security requirements from Functionality, Security and Performance (FSP) angles such as: (1) necessary controls to protect the confidentiality of customer data and integrity of data and processes associated with the digital product / services offered; (2) availability of requisite infrastructure such as human resources and technology with necessary backup; (3) assurance that the payment product is built in a secure manner offering robust performance ensuring safety, consistency, and rolled out after necessary testing for achieving desired FSP; (4) capacity building and expansion with scalability (to meet the growth for efficient transaction processing); (5) minimal customer service disruption with high availability of systems / channels (to have minimal technical declines); (6) efficient and effective dispute resolution mechanism and handling of customer grievance; and (7) adequate and appropriate review mechanism followed by swift corrective action, in case any one of the above requirements is hampered or having high potential to get hampered. 9. The Board and Senior Management shall be responsible for implementation of this policy. The policy shall be reviewed at least annually. The NBFC may
RBI (NBFCs – Digital Payment Security Controls) Directions, 2026
7
formulate this policy separately for its different digital products / services or include the same as part of its overall product policy. 10. The policy shall require that every digital payment product / service offered addresses the mechanics, clear definition of starting point, critical intermittent stages / points and end point in the digital payment cycle, security aspects, validations till the digital payment is settled, clear pictorial representation of digital path, exception handling, signing off of the above requirements, mechanism for carrying out User Acceptance Tests (UAT) in multiple stages before roll-out, sign off from multiple stakeholders [post User Acceptance Tests (UAT)], and data archival requirements. 11. The NBFC shall clearly articulate the need for an external assessment of the entire process including the logic, build, and security aspects of the application(s) supporting the digital product or service. 12. The NBFC shall incorporate appropriate processes into its governance and risk management programs for identifying, analysing, monitoring, and managing the specific risks, including compliance risk and fraud risk, associated with the portfolio of digital payment products and services on a continual basis and in a holistic manner. 13. The Senior Management of the NBFC shall have appropriate performance monitoring systems / key performance indicators for assessing whether the product or service offered through digital payment channels meets operational and security norms. As part of this process, the NBFC shall define product-level limits on the level of acceptable security risk, document specific security objectives, and performance criteria including quantitative benchmarks for: (1) evaluating the success of the security built into the digital payment product or service; (2) comparing actual results with projections and qualitative benchmarks on a periodic basis to detect and address adverse trends or concerns in a timely manner; and
RBI (NBFCs – Digital Payment Security Controls) Directions, 2026
8
(3) modifying the business plan / strategy involving the product or service, when appropriate, based on its security performance. [Note: Limits may be qualitative or quantitative in nature. Illustrative examples of such limits include, inter alia, parameters derived from multiple fraud risk indicators; defined Recovery Time Objective (RTO) and Recovery Point Objective (RPO); key performance indicators such as transaction failure rates and system uptime or availability; customer complaint metrics; third-party or supply chain risk factors; and financial losses incurred by the NBFC or customers due to cyber-attacks on the payment product or service. With respect to product- level limits, the NBFC shall be guided by its internal risk assessment.] 14. The NBFC shall have trained resources with necessary expertise to manage the digital payment infrastructure. Wherever the NBFC is dependent on third-party service providers, adequate oversight, and controls for monitoring the activities of the third-party personnel shall be put in place. 15. The NBFC shall conduct risk assessments with regard to the safety and security of digital payment products / services and associated processes as well as suitability and appropriateness of the same vis-à-vis the target users, both prior to establishing the service(s) and regularly thereafter. The risk assessment shall factor in: (1) the technology stack and solutions used; (2) known vulnerabilities at each of the touchpoints of the digital product / service and the remedial action taken by the NBFC; (3) dependence on third-party service providers and oversight over such providers; (4) risk arising out of integration of digital payment platform with other systems both internal and external to the NBFC, including core systems, and systems of PSOs; (5) customer experience, convenience and technology adoption required to use such products / services;
RBI (NBFCs – Digital Payment Security Controls) Directions, 2026
9
(6) reconciliation process; (7) interoperability aspects; (8) data storage, security, and privacy protection as per extant laws / instructions; (9) operational risk including fraud risk; (10) business continuity and service availability; (11) compliance with extant cybersecurity requirements; and (12) compatibility aspects. 16. The risk assessment shall cover the surrounding ecosystem as well and address the need to protect and secure payment data (such as customer data, customer and beneficiary account details, payment credentials, and transaction data) and evaluate the resilience of systems. The internal Risk and Control Self- Assessment (RCSA) exercise shall cover the risks (inherent) and controls vis-à- vis the probability and impact of threats to arrive at residual risk. The NBFC shall maintain database of all systems and applications storing customer data in the payment ecosystem and compliance with applicable Payment Card Industry (PCI) standards in each of the systems (notwithstanding mandatory requirements of certification / standard accreditation). The periodicity of RCSA may be determined by the NBFC based on changes in the scope of the risk assessment. In case of vendors, the NBFC shall evaluate the RCSA conducted by the vendor. 17. The NBFC shall evaluate the risks associated with the chosen technology platforms, application architecture, both on the server and client side. Further, the NBFC shall undertake a review of the risk scenarios and existing security measures based on incidents affecting its services, before any major change to the infrastructure or procedures, or whenever any new threats are identified through risk monitoring activities. Further, unused, or unwanted features of the platform shall be closely controlled to minimise risk.
RBI (NBFCs – Digital Payment Security Controls) Directions, 2026
10
- The NBFC shall develop sound internal control systems and take into account the operational risk before offering digital payment products and related services. This shall include ensuring adequate safeguards to protect integrity of data, customer confidentiality, and security of data.
- The NBFC shall ensure that its digital payment architecture is robust and scalable, commensurate with the transaction volumes and customer growth. The Information Technology (IT) strategy of the NBFC shall ensure that a robust capacity management plan is in place to meet evolving demand. The NBFC shall also put in place a mechanism to review its IT / IT security architecture and technology platform overhaul on a periodic basis based on the Board-approved policy.
- The NBFC shall have necessary capacity, systems, and procedures in place to periodically test backed-up data and applications pertaining to digital products / services to ensure recovery without loss of transactions or audit-trails. These facilities shall be tested at least on a half-yearly basis. B. Other Generic Security Controls
- The communication protocol in the digital payment channels (especially over internet) shall adhere to a secure standard. An appropriate level of encryption and security shall be implemented in the digital payment ecosystem.
- Web applications providing the digital payment products and services shall not store sensitive information in Hyper-Text Mark-up Language (HTML) hidden fields, cookies, or any other client-side storage to avoid any compromise in the integrity of the data.
- The NBFC shall implement Web Application Firewall (WAF) solution and Distributed Denial of Service (DDoS) mitigation techniques to secure the digital payment products and services offered over internet.
- The key length (for symmetric / asymmetric encryption, hashing), algorithms (for encryption, signing, exchange of keys, creation of message digest, random number generators), cipher suites, digital certificates, and applicable protocols
RBI (NBFCs – Digital Payment Security Controls) Directions, 2026
11
used in transmission channels, processing of data, and for authentication purposes shall be strong. The NBFC shall adopt internationally accepted and published standards that are not deprecated / demonstrated to be insecure / vulnerable and shall ensure that the configurations involved in implementing such controls are compliant with extant laws and regulatory instructions. 25. The NBFC shall renew its digital certificates used in the digital payment ecosystem well in time. 26. The mobile and web application of the NBFC shall have effective logging and monitoring capabilities to track user activity, security changes, and identify anomalous behaviour and transactions. C. Application Security Life Cycle 27. The NBFC shall implement multi-tier application architecture, segregating application, database and presentation layer in the digital payment products and services. 28. The NBFC shall follow a ‘secure by design’ approach in the development of digital payment products and services. The NBFC shall ensure that digital payment applications are inherently more secure by embedding security within their development lifecycle. 29. The NBFC shall explicitly define security objectives (including protection of customer information / data) during (1) requirements gathering; (2) designing; (3) development; (4) testing including source code review; (5) implementation, maintenance, and monitoring; and (6) decommissioning phases of the digital payment applications.
RBI (NBFCs – Digital Payment Security Controls) Directions, 2026
12
- The NBFC (including those partnering with other entities to co-brand / co-develop applications) shall adopt and incorporate a threat modelling approach during application lifecycle management into its policies, processes, guidelines, and procedures.
- For digital payment applications licensed by a third-party vendor, the NBFC shall put in place a source code escrow arrangement or other arrangements for ensuring continuity of services in case the vendor defaults or is unable to provide services.
- The NBFC shall conduct security testing including review of source code, Vulnerability Assessment (VA) and Penetration Testing (PT) of its digital payment applications to assure that the application is secure for putting through transactions while preserving confidentiality and integrity of the data that is stored and transmitted. Such testing shall invariably cover compliance with various standards like Open Worldwide Application Security Project (OWASP). In those cases, where the source code is not owned by the NBFC, the NBFC shall obtain a certificate from the application developer stating that the application is free of known vulnerabilities, malware, and any covert channels in the code. Further, the NBFC shall ensure the following: (1) The VA shall be conducted at least on a half-yearly basis; PT shall be conducted at least annually. In addition, VA / PT shall be conducted as and when any new IT infrastructure or digital payment application is introduced or when any major change is performed in the application or infrastructure. (2) Testing related to review of source code / certification shall be conducted / obtained and shall be continued annually, if changes / upgrades have been made to the application during the year. (3) Testing / Certification shall address the objective that the product / version / module(s) functions only in a manner that it is intended for, is developed as per the best secure design / coding practices and standards, addressing known flaws / threats due to insecure coding.
RBI (NBFCs – Digital Payment Security Controls) Directions, 2026
13
(4) Penal provisions are included in third-party contractual arrangements for any non-compliance by the application provider. 33. The NBFC may also run automated VA scanning tools on a continuous / more frequent basis to automatically scan all systems on the network that are critical, public facing or store customer sensitive data. 34. The NBFC shall compare the results from earlier vulnerability scans to verify / ascertain that vulnerabilities are addressed either by patching, implementing a compensating control, or documenting and accepting the residual risk with necessary approval and that there is no recurrence of the known vulnerabilities. The identified vulnerabilities shall be fixed in a time-bound manner. 35. The NBFC shall ensure that vulnerability scanning is performed in authenticated mode either with agents running locally on the system to analyse the security configuration or with remote scanners that are given administrative rights on the system being tested. 36. The NBFC shall verify and thoroughly test the functionality (to validate whether the system meets the functional requirements / specifications) and security controls of payment products and services before their launch / moving to the production environment. 37. The NBFC shall institute a mechanism to actively monitor for non-genuine / unauthorised / malicious applications (with similar name / features) on popular app-stores and the web and respond appropriately to bring them down. 38. The server at the NBFC’s end shall have adequate checks and balances to ensure that no transaction is carried out through non-genuine / unauthorised digital payment products / applications and the authentication process is robust, secure, and centralised. 39. The security controls for digital payment applications shall focus on how these applications handle, store, and protect payment data. The Application Programming Interfaces (APIs) for secure data storage and communication shall be implemented and used correctly in order to be effective. The NBFC shall refer
RBI (NBFCs – Digital Payment Security Controls) Directions, 2026
14
to standards such as OWASP-Mobile Application Security Verification Standard (OWASP-MASVS), OWASP-Application Security Verification Standard (OWASP-ASVS), and other relevant OWASP standards, security and data protection guidelines in ISO 12812, threat catalogues and guides developed by National Institute of Standards and Technology (NIST) (including for Bluetooth and Long-Term Evolution (LTE) security), for application security, and other protection measures. Such testing shall necessarily verify for vulnerabilities including, but not limited to OWASP / OWASP Mobile Top 10, application security guidelines / requirements developed / shared by operating system providers / Original Equipment Manufacturers (OEMs). 40. The NBFC shall redact / mask customer information such as account numbers / card numbers / other sensitive information when transmitted via SMS / emails (including attachments). D. Authentication Framework 41. The NBFC shall implement, except where explicitly permitted / relaxed, multi- factor authentication for payments through electronic modes and fund transfers, including cash withdrawals from ATMs / micro-ATMs / business correspondents, through digital payment applications. At least one of the authentication methodologies shall be dynamic or non-replicable. [e.g., Use of OTP, mobile devices (device binding and Subscriber Identification Module (SIM)), biometric / Public Key Infrastructure (PKI) / hardware tokens, ‘Europay, Mastercard, and Visa’ (EMV) chip card (for Card Present Transactions) with server-side verification could be termed either in dynamic or non-replicable methodologies]. 42. The NBFC shall ensure to design and implement robust multi-factor authentication methods to: (1) act as a strong fraud deterrent; (2) more difficult to compromise; (3) protect the confidentiality of payment data; and
RBI (NBFCs – Digital Payment Security Controls) Directions, 2026
15
(4) enhance confidence in digital payment by effectively addressing various cyber-attack mechanisms like phishing, keylogging, spyware / malware, and other internet-based frauds targeted at the NBFC and its customers. 43. The NBFC may also adopt adaptive authentication to select the right authentication factors depending on risk assessment, user risk profile, and behaviour. 44. The implementation of appropriate authentication methods shall be based on an assessment of the risks posed by the NBFC’s digital payment products and services. The risks shall be evaluated in light of the type of customer (e.g., retail / corporate / commercial), the customer transactional requirements / pattern (e.g., bill payment, fund transfer), the sensitivity of customer information and the volume, value of transactions involved. 45. The authentication methods shall take into consideration, inter alia, customer acceptance, ease of use, reliable performance, scalability to accommodate growth, customer profile, location, transaction, and interoperability with other systems. 46. The NBFC shall implement multi factor authentication and alerts (through channels such as SMS and email) for all payment transactions (including debits and credits), change in account details or revision to fund transfer limits. In devising these security features, the NBFC shall take into account their efficacy and differing customer preferences for additional online protection. 47. The alerts and OTPs received by the customer for online transactions shall identify the merchant name, wherever applicable, rather than the payment aggregator through which the transaction was effected. 48. As an integral part of the multi factor authentication architecture, the NBFC shall also implement appropriate measures to minimise exposure to middleman attack which is more commonly known as a man-in-the-middle attack (MITM), man-in- the browser (MITB) attack or man-in-the application attack. The NBFC shall, inter alia, ensure, that the data in transit is secured and the transactions are authenticated only by genuine / authorised source / process.
RBI (NBFCs – Digital Payment Security Controls) Directions, 2026
16
- The NBFC shall ensure that an authenticated session, together with its encryption protocol, shall remain intact throughout the interaction with the customer. In the event of interference or in case of closure of the application by the customer, the session shall be terminated, and the affected transactions shall be resolved or reversed out. The customer shall be promptly notified about the status of the transaction by email, SMS, or other means.
- The NBFC shall set down the maximum number of failed login or authentication attempts after which access to the digital payment product / service is blocked.
- The NBFC shall have a secure procedure in place to re-activate the access to blocked product / service. The NBFC shall notify the customer of failed login or authentication attempts. E. Fraud Risk Management
- The NBFC shall document and implement the configuration requirements for identifying suspicious transactional behaviour, including rules, preventive and detective controls, mechanism to alert the customers in case of failed authentication attempts, and the applicable time frames.
- The NBFC shall parameterise and monitor system alerts in terms of various applicable parameters. Such parameters, as applicable could include: Transaction velocity (e.g., fund transfers, cash withdrawals, and payments through electronic modes) in a short period, more so in the accounts of customers who have never used mobile / web application / card (depending upon the type of payment channel), high risk merchant category codes (MCC) parameters, counterfeit card parameters (e.g., String of Invalid Card Verification Value (CVV) / PINs indicates an account generation attack), new account parameters (excessive activity on a new account), time zones, geo-locations, IP address origin (in respect of unusual patterns, prohibited zones / rogue IPs), behavioural biometrics, transaction origination from point of compromise, transactions to mobile wallets / mobile numbers / Virtual Payment Address (VPAs) on whom vishing fraud or other types of fraud is / are registered / recorded, declined transactions, and transactions with no approval code.
RBI (NBFCs – Digital Payment Security Controls) Directions, 2026
17
- The NBFC shall conduct fraud analysis to identify the reason for fraud occurrence and determine mechanism to prevent such frauds.
- The NBFC shall educate the staff, especially in the fraud control function, about frauds and train them in the following skills and areas of expertise: (1) fraud control tools and their usage; (2) investigative techniques and procedures; (3) cardholder and merchant education techniques to prevent fraud; (4) scheme / card operating regulations; (5) data processing and analysis, liaising or communicating with law enforcement agencies; and (6) the requisite skills required to (i) set and update appropriate rules, (ii) monitor the exceptions thrown based on the rules on a continuous basis and take necessary actions promptly, (iii) communicate / escalate wherever required to appropriate authorities, and (iv) differentiate false positives from the rest.
- The NBFC shall maintain updated contact details of service providers, intermediaries, external agencies, and other stakeholders for coordination in incident response. The NBFC shall put in place a mechanism with the stakeholders to update and verify such contact details. The NBFC shall also formulate specific Standard Operating Procedures (SOPs) to handle incidents related to payment ecosystem to mitigate the loss either to the customer or the NBFC. F. Reconciliation Mechanism
- A real-time / near-real-time [not later than 24 hours from the time of receipt of settlement file(s)] reconciliation framework for all digital payment transactions between the NBFC and all other stakeholders such as payment system operators, business correspondents, card networks, payment system processors, payment aggregators, payment gateways, third-party technology
RBI (NBFCs – Digital Payment Security Controls) Directions, 2026
18
service providers, and other participants, shall be put in place for better detection and prevention of suspicious transactions. The NBFC shall also have a mechanism to monitor the implementation and effectiveness of such framework. G. Customer Protection, Awareness and Grievance Redressal Mechanism 58. The NBFC shall incorporate secure, safe, and responsible usage guidelines and training materials for end users within the digital payment applications. The NBFC shall make it mandatory (i.e., not providing any option to circumvent / avoid the material) for the customer to go through secure usage guidelines (in the customer’s preferred language) while obtaining and recording confirmation during the on-boarding procedure in the first instance and first use after each update of the digital payment application or after major updates to secure and safe usage guidelines. 59. The NBFC shall incorporate a section in the digital payment application clearly specifying the process and procedure (including relevant forms and contact information) to lodge customer grievances. A mechanism shall be put in place to keep this information periodically updated. The reporting facility on the application shall provide an option for registering a grievance. Customer dispute handling, reporting, and resolution procedures, including the expected timelines for the NBFC’s response, shall be clearly defined. 60. The NBFC shall be guided by
RBI/2020-21/21 DPSS.CO.PD No.116/02.12.004/2020-21 dated August 6, 2020 on ‘Online Dispute Resolution (ODR) System for Digital Payments’ updated from time to time, for putting in place system(s) for online dispute resolution for resolving disputes and grievances of customers pertaining to digital payments. 61. The NBFC shall educate customers about the need to maintain the physical and logical security of their devices accessing digital payment products and services. This shall include but not be limited to recommending secure and regular installation of operating system and application updates, downloading applications only from authorised sources, and having anti-malware / anti-virus applications on devices.
RBI (NBFCs – Digital Payment Security Controls) Directions, 2026
19
- The NBFC shall ensure that its customers are provided information about the risks, benefits, and liabilities of using digital payment products and related services before they subscribe to them. The NBFC shall also inform the customers clearly and precisely on their rights, obligations and responsibilities on matters relating to digital payments, and any problems that may arise from its service unavailability, processing errors, and security breaches. The terms and conditions including customer privacy and security policy applying to digital payment products and services shall be readily available to customers within the product. All digital channels shall be offered on express willingness of customers and shall not be bundled without their knowledge.
- The NBFC shall provide clear and effective communication, along with sufficient instructions, to enable customers to properly utilise any new operating features or functions, particularly those relating to security, integrity, and authentication, introduced to online delivery channels.
- The NBFC may continuously create public awareness on the types of threats and attacks used against the customers while using digital payment products and precautionary measures to safeguard against the same. The NBFC shall caution the customers against commonly observed threats including phishing, vishing, reverse-phishing, remote access of mobile devices, and educate them to secure and safeguard their account details, credentials, PIN, card details, devices and other authentication information.
- The NBFC shall provide digital payment products and services to a customer only at their option based on a specific written or authenticated electronic requisition along with a positive acknowledgement of the terms and conditions.
- The NBFC shall provide a mechanism on its mobile and web application for its customers, with necessary authentication, to identify / mark a transaction as fraudulent for seamless and immediate notification to the NBFC. On such notification by the customer, the NBFC shall endeavour to build the capability for seamless / instant reporting of fraudulent transactions to the corresponding beneficiary / counterparty’s entity. The NBFC may also have a mechanism to receive such fraudulent transactions reported from other entities.
RBI (NBFCs – Digital Payment Security Controls) Directions, 2026
20
Chapter IV - Web Application Security Controls 67. In addition to the controls prescribed in Chapter III, the following instructions are applicable to the NBFC offering / intending to offer web application facility to its customers: (1) The NBFC, based on its risk / vulnerability assessment on authentication- related attacks such as brute force / Denial of Service (DoS) attacks, shall implement additional levels of authentication to web application such as adaptive authentication, strong CAPTCHA (with anti-bot features) with server-side validation, in order to plug the vulnerability and prevent its exploitation. (2) The NBFC shall take appropriate measures to prevent Domain Name System (DNS) cache poisoning attacks and for secure handling of cookies. (3) A virtual keyboard option shall be made available. (4) An online session shall be automatically terminated after a fixed period of inactivity. (5) The NBFC shall ensure secure delivery of password for login purpose. The password generated and dispatched by the NBFC shall be valid for a limited period from the date of its creation. If the password is generated and dispatched by the NBFC, then the user shall be compulsorily required to change the password, on the first login.
RBI (NBFCs – Digital Payment Security Controls) Directions, 2026
21
Chapter V - Mobile Application Security Controls 68. In addition to the controls prescribed in Chapter III, the following instructions are applicable to the NBFC offering / intending to offer mobile application facility to its customers through mobile application: (1) On detection of any anomalies or exceptions for which the mobile application was not programmed, the customer shall be directed to remove the current copy / instance of the application and proceed with installation of a new copy / instance of the application. The NBFC shall be able to verify the version of the mobile application before the transactions are enabled. (2) The NBFC shall ensure implementation of the following specific controls for mobile applications: (i) device policy enforcement [allowing the installation / execution of applications only after baseline requirements defined based on the bank’s risk assessment, are met. The baseline requirements shall include but not be limited to checks for vulnerable operating system, vulnerable or malicious applications, and insecure Wi-Fi configurations]; (ii) application secure download / install; (iii) deactivating older application versions in a phased but time-bound manner (not exceeding six months from the date of release of newer version) i.e., maintaining only one version (excluding the overlap period while phasing out older version) of the mobile application on a platform / operating system; (iv) ability to identify remote access applications (to the extent possible) and prohibit login access to the mobile application; (v) storage of customer data; (vi) device or application encryption (to prevent compromise of sensitive customer information stored on the device);
Research the source law
Find the provision behind this update.
No high-confidence provision match was found. Browse the law library, choose the affected provision and ask against the exact statutory text.
Browse source lawsRelated RBI updates
- Governor’s Statement: August 5, 2026
- Monetary Policy Statement, 2026-27 Resolution of the Monetary Policy Committee August 3 to 5, 2026
- Money Market Operations as on August 4, 2026
- Statement on Developmental and Regulatory Policies
- Directions under Section 35A read with Section 56 of the Banking Regulation Act, 1949 – The Pusad Urban Co-operative Bank Ltd., Pusad, Dist. Yavatmal, Maharashtra – Extension of Period