RBI: New Payment Authentication Rules from April 2026

By By Rediff Money Desk, Mumbai
Sep 25, 2025 18:25
RBI announces new digital payment authentication rules beyond SMS OTP, effective April 2026. Enhanced security for transactions.
Mumbai, Sep 25 (PTI) The Reserve Bank on Thursday announced that new rules on digital payments, which allow for more ways to comply with the Two-Factor Authentication (2FA) beyond the SMS-based one-time password, will come into effect on April 1.

The factors of authentication can be from "something the user has", "something the user knows" or "something the user is" and may comprise, inter-alia, password, SMS-based OTP, passphrase, PIN, card hardware, software token, fingerprint, or any other form of biometrics (device native or Aadhaar-based), the central bank said.

India is among the markets in the world which insist on 2FA, and financial sector players have been relying on the SMS-based alerts to execute transactions.

The RBI launched the (Authentication mechanisms for digital payment transactions) Directions, 2025, making it clear that 2FA will continue to be mandatory and SMS OTP can also be used.

The central bank had first announced the move in February 2024 to enable the payments ecosystem to leverage the technological advancements for implementing alternative authentication mechanisms.

The new rules specify that at least one of the factors of authentication is dynamically created or proven, wherein the proof of possession of the factor, being sent as part of the transaction, is unique to that transaction.

Additionally, the system should also be robust, wherein compromise of one factor does not affect reliability of the other.

Apart from this, the RBI said that from a risk management perspective, the financial system stakeholders can also identify transactions for evaluation against behavioural /contextual parameters such as transaction location, user behaviour patterns, device attributes, historical transaction profile, etc.

"Based on the perceived risk associated with the transaction, additional checks beyond the minimum two-factor authentication may be resorted to. Issuers may also explore using DigiLocker as a platform for notification and confirmation for high-risk transactions," it said.

If any loss arises out of transactions effected without complying with these directions, the issuer shall compensate the customer for the loss in full without demur, the central bank said.

It also asks card issuers to put in place a mechanism to validate non-recurring, cross-border card not present (CNP) transactions, where request for authentication is raised by an overseas merchant or overseas acquirer from October 1, 2026.
Source: PTI
Read More On:
digital paymentstwo-factor authentication2fasms otprbi
DISCLAIMER - This article is from a syndicated feed. The original source is responsible for accuracy, views & content ownership. Views expressed may not reflect those of rediff.com India Limited.

You May Like To Read

MORE NEWS

Punjab Seeks Korean Investment: Mann Visits Seoul

Punjab CM Mann urges Korean investment in Seoul, highlighting industry-friendly...

India-EU FTA Talks with Goyal: Key Issues &...

EU team meets Piyush Goyal to discuss India-EU Free Trade Agreement. Focus on steel,...

AI/ML in Power Distribution: Manohar Lal Keynote

Manohar Lal highlights AI/ML role in power distribution at national conference. Focus...

UIDAI Aadhaar Verification: New Rules & App

UIDAI to mandate registration for Aadhaar verification. New app & rules discourage...

Gold Price Outlook: Fed Decision & Rupee Impact

Gold prices to watch Fed meeting, rupee movement. Analysts predict potential gains amid...

Paint Makers Expect Q3 Uptick, Margin Improvement

Paint makers anticipate sales & volume growth in Q3 with improved margins due to benign...

Urban Vault Leases to Japanese Firms in Bengaluru

Urban Vault leases 21,000 sq ft office space in Bengaluru to Nachi, Pioneer, & Komatsu....

Dwarka Expressway Housing Prices Surge 3.5x in...

Dwarka Expressway property prices jumped 3.5 times in 5 years! Report by Square Yards...

Govt to Convert 40 GW Renewable Energy to FDRE:...

Suzlon expects the government to convert 40 GW of uncontracted renewable energy to...

Ola Electric Delivers 4680 Bharat Cell EVs

Ola Electric starts mass deliveries of 4680 Bharat Cell powered S1 Pro+ scooters....

Read More »

Sectoral Indices Market Indicators Listed Companies Gainers Losers Mutual Funds Portfolio Watchlist
© 2025 Rediff.com