2026-07-31
Added · Updated
These Directions apply to Commercial Banks and mandate the formulation of Board-approved policies for digital payment products and services covering functionality, security, and performance. Banks must conduct Vulnerability Assessments at least half-yearly and Penetration Testing annually, alongside continuous automated scanning and source code reviews. The regulations require multi-factor authentication for electronic payments and fund transfers, with at least one dynamic or non-replicable factor, and prohibit storing sensitive information in client-side storage like HTML hidden fields or cookies.