The Reserve Bank of India (RBI) on June 16, 2025, issued the Master Direction – Reserve Bank of India (Electronic Trading Platforms) Directions, 2025.
The following has been stated namely: -
• RBI mandates two-factor authentication (2FA) for all digital payment transactions, with authentication factors drawn from “something you know,” “something you have,” or “something you are,” such as passwords, tokens, or biometrics.
• At least one factor shall be dynamic (i.e., unique to each transaction), such as a one-time password (OTP) or a transaction-specific token, especially for non–non-card-present payments.
• Issuers are required to adopt a risk-based authentication model, checking transactions based on behavior, device, location, and transaction history; high-risk transactions may trigger additional checks, like using DigiLocker.
• For cross-border card-not-present (CNP) transactions, by October 01, 2026, issuers shall validate non-recurring transactions, register their Bank Identification Numbers (BINs) with card networks, and apply risk-based authentication.
• The framework strengthens consumer protection: issuers shall ensure secure systems and may be liable for compensating customers if non-compliance leads to fraud.
[Notification no. - RBI/FMRD/2025-26/137 FMRD.MIOD.No. 02/14.03.027/2025-26]