RBI issues the RBI (NBFC – Digital Payment Security Controls) Directions, 2026

RBI issues the RBI (NBFC - Digital Payment Security Controls) Directions, 2026; Effective Immediately from 31.07.2027

Pursuant to a comprehensive exercise to consolidate the existing universe of Digital Payment Security Controls Directions, the Reserve Bank of India (“RBI”) has issued the Reserve Bank of India (Non-Banking Financial Companies – Digital Payment Security Controls) Directions, 2026 which has gained effect immediately from 31.07.2026.

With the issue of these Directions, the existing directions, instructions, and guidelines relating to Digital Payment Security Controls as applicable to Non-Banking Financial Companies stand repealed. The directions, instructions, and guidelines repealed prior to the issuance of these Directions shall continue to remain repealed.

Background:

Applicability:

(i) These Directions are applicable to Credit-Card issuing Non-Banking Financial Companies (NBFCs).

(ii) These Directions are applicable for any digital payment product or service offered by the Credit-Card issuing NBFC to customers for carrying out financial transactions or non-financial transactions such as balance enquiry, set / change Personal Identification Number (PIN), mobile application registration, generation of one-time password (OTP), mini-statement, facility of checking transaction status, and option to the customer to raise dispute / grievance.

Key Highlights:

  1. Chapter 3 deals with General Controls where NBFCs are required to formulate a policy for digital payment products and services with the approval of its Board, articulate the need for an external assessment of the entire process, incorporate appropriate processes into its governance and risk management programs, conduct risk assessments, educate customers about the need to maintain the physical and logical security of their devices accessing digital payment products and services and provide a mechanism on its mobile and web application for its customers, with necessary authentication, to identify / mark a transaction as fraudulent for seamless and immediate notification to the NBFC
  2. Chapter 4 deals with Web Application Security Controls where NBFC shall implement additional levels of authentication to web application such as adaptive authentication, strong CAPTCHA (with anti-bot features) with server-side validation, take appropriate measures to prevent Domain Name System (DNS) cache poisoning attacks and ensure secure delivery of password for login purpose.
  3. Chapter 5 deals with Mobile Application Security Controls where NBFCs are required to verify the version of the mobile application before the transactions are enabled, ensure implementation of the required specific controls for mobile applications, perform validation on the security and compatibility condition of the device / operating system and the mobile application, explore the feasibility of implementing a code that checks if the device is rooted / jailbroken prior to the installation of the mobile application and host the checksum of current active version of its mobile application on public platform so that users can verify the same
  4. Chapter 6 deals with Card Payment Security Controls where NBFC shall follow various payment card standards, put up a status report on compliance with these standards to its IT Strategy Committee and implement the needed controls at the HSMs.

Source: RBI

https://lexplosion.in/

Lexplosion Solutions Private Limited is a pioneering Indian Legal-Tech company that provides legal risk and compliance management solutions through cloud-based software and expert services.