2026-07-31

Added · Updated

Reserve Bank of India (Payments Banks – Digital Payment Security Controls) Directions, 2026

These Directions apply to Payments Banks regarding digital payment products and services, requiring Board-approved policies reviewed annually and senior management implementation. Banks must conduct Vulnerability Assessments at least half-yearly and Penetration Testing annually, alongside continuous automated scanning, with testing required for new infrastructure or major changes. The regulations mandate multi-factor authentication for electronic payments and fund transfers, ensuring at least one dynamic or non-replicable methodology, and require secure communication protocols, encryption standards, and Web Application Firewall implementation. Additionally, banks must perform risk assessments, maintain capacity for half-yearly backup testing, and ensure source code reviews or vendor certificates for third-party applications.

Reserve Bank of India logo

India

Reserve Bank of India

Scan of the document's first page
Share

RBI published 31 documents in the last 30 days — get each new one by email the day it lands.

Read the rest free

Lineage: In force

Circular No. DoS.CO.PPG.66/11.0…Circular No. DoS.CO.PPG.66/11.01.005/2026-27 dated 2026-07-31Reserve Bank of India(Payments Banks – Digital Pay…2026-07-31 · this documentReserve Bank of India (Payments Banks – Digital Payment Security Controls) Directions, 2026 (2026-07-31)
amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: Reserve Bank of India — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from RBI

RBI published 31 documents in the last 30 days. We email you each new one the day it's published.