2026-07-31

Added · Updated

Reserve Bank of India (Non-Banking Financial Companies – Digital Payment Security Controls) Directions, 2026

These Directions apply to Credit-Card issuing Non-Banking Financial Companies (NBFCs) for all digital payment products and services, including those operated by RBI-authorized Payment System Operators. NBFCs must establish Board-approved policies covering governance, risk management, and security controls, with annual reviews and senior management oversight. Specific mandates include conducting Vulnerability Assessments at least half-yearly and Penetration Testing annually, implementing multi-factor authentication with at least one dynamic method, and ensuring robust encryption, logging, and dispute resolution mechanisms. The Directions come into effect immediately upon issuance on July 31, 2026.

Reserve Bank of India logo

India

Reserve Bank of India

Scan of the document's first page
Share

RBI published 31 documents in the last 30 days — get each new one by email the day it lands.

Read the rest free

Lineage: In force

DOS.CO.PPG Circular No. 66 date…DOS.CO.PPG Circular No. 66 dated 2026-07-31Reserve Bank of India(Non-Banking Financial Compan…2026-07-31 · this documentReserve Bank of India (Non-Banking Financial Companies – Digital Payment Security Controls) Directions, 2026 (2026-07-31)
amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: Reserve Bank of India — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from RBI

RBI published 31 documents in the last 30 days. We email you each new one the day it's published.