Reserve Bank of India (Urban Co-operative Banks – Digital Payment Security Controls) Directions, 2026
RBI/DoS/2026-27/438 DoS.CO.CSITEG.32/31.01.015/2026-27 July 31, 2026 Reserve Bank of India (Urban Co-operative Banks – Digital Payment Security Controls) Directions, 2026 Table of Contents Chapter I - Preliminary A. Short Title and Commencement B. Applicability C. Definitions Chapter II - Role of the Board A. Board App…
Source details
- Source
- Reserve Bank of India
- Type
- master-direction
- Published by source
- 30 Jul 2026
- Coverage area
- banking
Document text
RBI/DoS/2026-27/438 DoS.CO.CSITEG.32/31.01.015/2026-27 July 31, 2026
Reserve Bank of India (Urban Co-operative Banks – Digital Payment Security Controls) Directions, 2026
Table of Contents
- Chapter I - Preliminary
- A. Short Title and Commencement
- B. Applicability
- C. Definitions
- Chapter II - Role of the Board
- A. Board Approved Policies
- Chapter III - General Controls
- A. Governance and Management of Security Risks
- B. Other Generic Security Controls
- C. Application Security Life Cycle
- D. Authentication Framework
- E. Fraud Risk Management
- F. Reconciliation Mechanism
- G. Customer Protection, Awareness and Grievance Redressal Mechanism
- Chapter IV - Internet Banking Security Controls
- Chapter V - Mobile Payments Application Security Controls
- Chapter VI - Card Payment Security Controls
- Chapter VII - Repeal and Other Provisions
- A. Repeal and Saving
- B. Application of Other Laws Not barred
- C. Interpretations
In exercise of the powers conferred by Section 35-A read with Section 56 of the Banking Regulation Act, 1949, extant provisions of the Payment and Settlement Systems Act, 2007, and all other provisions / laws enabling the Reserve Bank of India (‘RBI’) in this regard, RBI being satisfied that it is necessary and expedient in the public interest so to do, hereby, issues Directions hereinafter specified.
Chapter I - Preliminary
A. Short Title and Commencement
- These Directions shall be called the Reserve Bank of India (Urban Co-operative Banks – Digital Payment Security Controls) Directions, 2026.
- These Directions shall come into force with effect immediately upon issuance.
B. Applicability
- These Directions shall be applicable to Urban Co-operative Banks (hereinafter collectively referred to as ‘UCBs’ and individually as ‘UCB’).
For the purpose of these Directions, ‘Urban Co-operative Banks’ shall mean Primary Co-operative Banks as defined under Section 5(ccv) read with Section 56 of Banking Regulation Act, 1949.
- These Directions are applicable for digital payment products and services provided by the UCB as detailed below: (1) Any digital payment product or service offered by the UCB to customers for carrying out financial transactions or non-financial transactions such as balance enquiry, set / change Personal Identification Number (PIN), mobile banking registration, generation of one-time password (OTP), mini-statement, facility of checking transaction status, and option to the customer to raise dispute / grievance. Such digital payment products and services offered directly by the UCB or through a system operated by RBI or a system operated by any of the RBI authorised Payment System Operators (PSOs), and the associated IT assets (applications, systems, infrastructure) shall be considered for the scope of these Directions.
C. Definitions
-
The following definitions are sourced from Financial Stability Board (FSB) Cyber Lexicon unless explicitly mentioned otherwise. In these Directions, unless the context states otherwise, the terms herein shall bear the meanings assigned to them below: (1) ‘Availability’ - Property of being accessible and usable on demand by an authorised entity. (2) ‘Confidentiality’ - Property that information is neither made available nor disclosed to unauthorised individuals, entities, processes, or systems. (3) ‘Cyber’ - Relating to, within, or through the medium of the interconnected information infrastructure of interactions among persons, processes, data, and information systems. (4) ‘Cybersecurity’ - Preservation of confidentiality, integrity, and availability of information and / or information systems through the cyber medium. In addition, other properties, such as authenticity, accountability, non-repudiation, and reliability can also be involved. (5) ‘Cyber-attack’ - Malicious attempt(s) to exploit vulnerabilities through the cyber medium to damage, disrupt, or gain unauthorised access to assets. (6) ‘Distributed Denial of Service (DDoS)’ - A denial of service that is carried out using numerous sources simultaneously. (7) ‘Framework’ - A framework is a structured set of strategies, policies, procedures, methods, and best practices that guides organisational activities, enables governance, and supports the achievement of defined objectives. (Source: adapted from ISACA glossary) (8) ‘Information System’ - Set of applications, services, information technology assets, or other information-handling components, which includes the operating environment and networks. (9) ‘Integrity’ - Property of accuracy and completeness. (10) ‘Malware’ - Software designed with malicious intent containing features or capabilities that can potentially cause harm directly or indirectly to entities or their information systems. (11) ‘Penetration Testing’ - A test methodology in which assessors typically working under specific constraints, attempt to circumvent or defeat the security features of an information system. (12) ‘Phishing’ - A digital form of social engineering that attempts to acquire private or confidential information by pretending to be a trustworthy entity in an electronic communication. (13) ‘Vulnerability’ - A weakness, susceptibility, or flaw of an asset or control that can be exploited by one or more threats. (14) ‘Vulnerability Assessment (VA)’ - Systematic examination of an information system or product to determine the adequacy of security measures, identify security deficiencies, provide data from which to predict the effectiveness of proposed security measures and confirm the adequacy of such measures after implementation.
-
All other expressions unless defined herein shall have the same meaning as have been assigned to them under the Reserve Bank of India Act, 1934, the Banking Regulation Act, 1949, the Payment and Settlement Systems Act, 2007, Information Technology Act, 2000, the Companies Act, 2013, or any statutory modification or re-enactment thereto or other regulations issued by the RBI or the Glossary of Terms published by the RBI or as used in commercial parlance, as the case may be.
Chapter II - Role of the Board
A. Board Approved Policies
- The Board of Directors shall approve the policies related to digital payment products and services. Such policies shall be reviewed at least annually by the Board.
Chapter III - General Controls
A. Governance and Management of Security Risks
-
The UCB shall formulate a policy for digital payment products and services with the approval of its Board. The contours of the policy, while discussing the parameters of any ‘new product’ including its alignment with the overall business strategy and inherent risk of the product, risk management / mitigation measures, compliance with regulatory instructions, and customer experience, shall explicitly cover payment security requirements from Functionality, Security and Performance (FSP) angles such as: (1) necessary controls to protect the confidentiality of customer data and integrity of data and processes associated with the digital product / services offered; (2) availability of requisite infrastructure such as human resources and technology with necessary backup; (3) assurance that the payment product is built in a secure manner offering robust performance ensuring safety, consistency, and rolled out after necessary testing for achieving desired FSP; (4) capacity building and expansion with scalability (to meet the growth for efficient transaction processing); (5) minimal customer service disruption with high availability of systems / channels (to have minimal technical declines); (6) efficient and effective dispute resolution mechanism and handling of customer grievance; and (7) adequate and appropriate review mechanism followed by swift corrective action, in case any one of the above requirements is hampered or having high potential to get hampered.
-
The Board and Senior Management shall be responsible for implementation of this policy. The policy shall be reviewed at least annually. The UCB may formulate this policy separately for its different digital products / services or include the same as part of its overall product policy.
-
The policy shall require that every digital payment product / service offered addresses the mechanics, clear definition of starting point, critical intermittent stages / points and end point in the digital payment cycle, security aspects, validations till the digital payment is settled, clear pictorial representation of digital path, exception handling, signing off of the above requirements, mechanism for carrying out User Acceptance Tests (UAT) in multiple stages before roll-out, sign off from multiple stakeholders [post User Acceptance Tests (UAT)], and data archival requirements.
-
The UCB shall clearly articulate the need for an external assessment of the entire process including the logic, build, and security aspects of the application(s) supporting the digital product or service.
-
The UCB shall incorporate appropriate processes into its governance and risk management programs for identifying, analysing, monitoring, and managing the specific risks, including compliance risk and fraud risk, associated with the portfolio of digital payment products and services on a continual basis and in a holistic manner.
-
The Senior Management of the UCB shall have appropriate performance monitoring systems / key performance indicators for assessing whether the product or service offered through digital payment channels meets operational and security norms. As part of this process, the UCB shall define product-level limits on the level of acceptable security risk, document specific security objectives, and performance criteria including quantitative benchmarks for: (1) evaluating the success of the security built into the digital payment product or service; (2) comparing actual results with projections and qualitative benchmarks on a periodic basis to detect and address adverse trends or concerns in a timely manner; and (3) modifying the business plan / strategy involving the product or service, when appropriate, based on its security performance.
Research the source law
Find the provision behind this update.
No high-confidence provision match was found. Browse the law library, choose the affected provision and ask against the exact statutory text.
Browse source lawsRelated RBI updates
- Governor’s Statement: August 5, 2026
- Monetary Policy Statement, 2026-27 Resolution of the Monetary Policy Committee August 3 to 5, 2026
- Money Market Operations as on August 4, 2026
- Statement on Developmental and Regulatory Policies
- Directions under Section 35A read with Section 56 of the Banking Regulation Act, 1949 – The Pusad Urban Co-operative Bank Ltd., Pusad, Dist. Yavatmal, Maharashtra – Extension of Period