2026-07-31

Added · Updated

Reserve Bank of India (Commercial Banks – Digital Payment Security Controls) Directions, 2026

These Directions apply to Commercial Banks and mandate the formulation of Board-approved policies for digital payment products and services covering functionality, security, and performance. Banks must conduct Vulnerability Assessments at least half-yearly and Penetration Testing annually, alongside continuous automated scanning and source code reviews. The regulations require multi-factor authentication for electronic payments and fund transfers, with at least one dynamic or non-replicable factor, and prohibit storing sensitive information in client-side storage like HTML hidden fields or cookies.

Reserve Bank of India logo

India

Reserve Bank of India

Scan of the document's first page
Share

RBI published 31 documents in the last 30 days — get each new one by email the day it lands.

Read the rest free

Lineage: In force

Circular No. 66 dated 2026-07-31Circular No. 66 dated 2026-07-31Reserve Bank of India(Commercial Banks – Digital P…2026-07-31 · this documentReserve Bank of India (Commercial Banks – Digital Payment Security Controls) Directions, 2026 (2026-07-31)
amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: Reserve Bank of India — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from RBI

RBI published 31 documents in the last 30 days. We email you each new one the day it's published.