The Reserve Bank of India (RBI) has issued the Reserve Bank of India (Commercial Banks – Digital Payment Security Controls) Directions, 2026, effective immediately.
The following has been stated:
• The Directions establish a comprehensive framework for strengthening the security of digital payment products and services offered by commercial banks through Board-approved policies, robust governance, risk management, secure application development, authentication mechanisms, fraud risk management, reconciliation processes, and customer protection measures.
• Banks are required to implement secure-by-design digital payment applications, strong encryption, multi-factor authentication, vulnerability assessments, penetration testing, fraud monitoring, secure customer authentication, resilient payment infrastructure, and robust controls for internet banking, mobile banking, and digital payment channels to safeguard customer data and payment transactions.
• The Directions also prescribe detailed security controls for internet banking, mobile payment applications, and card payment systems, including compliance with international payment security standards, enhanced ATM and card security, customer awareness initiatives, grievance redressal mechanisms, and continuous monitoring to strengthen the overall resilience and security of India's digital payment ecosystem.
Please refer to the document attached below for more details.
[RBI/DoS/2026-27/411]