2026-07-31

Added · Updated

Reserve Bank of India (Commercial Banks – Digital Payment Security Controls) Directions, 2026

These Directions apply to Commercial Banks and mandate the formulation of Board-approved policies for digital payment products and services covering functionality, security, and performance. Banks must conduct Vulnerability Assessments at least half-yearly and Penetration Testing annually, alongside continuous automated scanning and source code reviews. The regulations require multi-factor authentication for electronic payments and fund transfers, with at least one dynamic or non-replicable factor, and prohibit storing sensitive information in client-side storage like HTML hidden fields or cookies.

Reserve Bank of India logo

India

Reserve Bank of India

Click to view full text

More like this from RBI

RBI published 77 documents in the last 30 days. We email you each new one the day it's published.

Share