Differences
This shows you the differences between two versions of the page.
| — | rbi-2fa-payment-authentication-rules-april-2026 [2026/07/22 17:44] (current) – created - external edit 127.0.0.1 | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| + | {{htmlmetatags> | ||
| + | ====== RBI 2FA Payment Authentication Rules from April 2026 ====== | ||
| + | |||
| + | |||
| + | {{ : | ||
| + | |||
| + | <WRAP center round info 95%> | ||
| + | **Quick Reply:** From 1 April 2026 the RBI requires two-factor authentication on digital payments, with one dynamic factor for non-card transactions. SMS OTP stays valid. | ||
| + | </ | ||
| + | |||
| + | From 1 April 2026, every digital payment in India must still pass two-factor authentication, | ||
| + | |||
| + | This does NOT mean OTP-free payments. Authentication is not abolished. The Reserve Bank of India has made the rules technology-neutral, | ||
| + | |||
| + | If you are short on time, jump to "What you should do" below to see the few practical steps that matter for you as a customer. | ||
| + | |||
| + | ===== What the rule actually says ===== | ||
| + | |||
| + | The instrument is the Reserve Bank of India Authentication Mechanisms for Digital Payment Transactions Directions, 2025. The RBI issued it on 25 September 2025. The compliance date for domestic digital payments is 1 April 2026. | ||
| + | |||
| + | The core principle is simple. Two factors must authenticate every digital payment transaction. For a non-card-present transaction, | ||
| + | |||
| + | The framework is risk-based. For a suspicious or high-risk transaction, | ||
| + | |||
| + | ===== Old norm vs new framework ===== | ||
| + | |||
| + | The biggest myth is that the rule removes OTP. It does not. The table below shows the real shift: from one de-facto method to a choice of compliant methods. | ||
| + | |||
| + | ^ Point ^ Old position (before 1 April 2026) ^ New framework (from 1 April 2026) ^ | ||
| + | | Is 2FA required? | Yes | Yes, still required for every digital payment | | ||
| + | | Allowed second factor | SMS OTP was the de-facto method used by almost everyone | SMS OTP plus biometrics, passkeys, in-app approval or hardware tokens | | ||
| + | | Dynamic factor | OTP was dynamic by habit | At least one dynamic factor is mandatory for non-card-present payments | | ||
| + | | Is SMS OTP banned? | Not applicable | No, SMS OTP stays fully valid | | ||
| + | | High-risk transactions | Handled case by case | Banks may apply extra authentication on a risk basis | | ||
| + | |||
| + | Read the table once more if you skimmed: two-factor authentication is still compulsory. The rule widens the menu of factors, it does not let you pay with nothing. | ||
| + | |||
| + | ===== Cross-border card payments ===== | ||
| + | |||
| + | There is a separate timeline for cross-border card-not-present payments. For non-recurring cross-border card-not-present transactions, | ||
| + | |||
| + | ===== What you should do ===== | ||
| + | |||
| + | You do not need to apply for anything. Your bank handles the change. A few practical steps still help. | ||
| + | |||
| + | - Keep your registered mobile number active so OTP-based authentication keeps working as a fallback. | ||
| + | - When your banking app offers to set up a passkey, app approval or biometric login, accept it. These are the new compliant dynamic factors. | ||
| + | - Do not share any OTP, passkey approval or biometric prompt with anyone. The rule strengthens security; social engineering still defeats it if you approve a stranger' | ||
| + | - Remember that small-value contactless card payments up to Rs 5,000 per transaction can still be done without an additional factor under existing RBI norms. This is an established exemption and is unchanged by the principle. | ||
| + | - For recurring e-mandates and certain small-value flows, existing RBI exemptions continue to apply. | ||
| + | |||
| + | ===== A quick example ===== | ||
| + | |||
| + | Dr. Shrawan Kumar Pathak pays for a streaming subscription through his bank app. Before April 2026 he typed an SMS OTP every time. After the new framework starts, his bank lets him approve the same payment with a fingerprint inside the app. That fingerprint is his dynamic factor, generated fresh for that transaction, | ||
| + | |||
| + | ===== How RTI helps you here ===== | ||
| + | |||
| + | You can use the [[https:// | ||
| + | |||
| + | The RBI is a public authority, so an RTI application to the RBI works well. You can ask for the text of the Authentication Mechanisms Directions 2025, any frequently asked questions the RBI has published, and the policy reasoning behind the change. Frame your request narrowly and factually for a faster reply. | ||
| + | |||
| + | Private banks are generally not public authorities, | ||
| + | |||
| + | To draft a clean RTI to the RBI, use the [[https:// | ||
| + | |||
| + | ===== Frequently asked questions ===== | ||
| + | |||
| + | ==== Does the new rule mean OTP-free payments? ==== | ||
| + | No. This is the most common misunderstanding. Two-factor authentication stays mandatory for every digital payment. The rule only allows alternatives to SMS OTP, such as biometrics, passkeys or in-app approval. SMS OTP itself remains a valid method, so nothing breaks if your bank keeps using it. | ||
| + | |||
| + | ==== When does the rule take effect? ==== | ||
| + | The domestic compliance date is 1 April 2026. The Directions were issued by the RBI on 25 September 2025. A separate timeline of 1 October 2026 applies to additional-factor validation for non-recurring cross-border card-not-present transactions. | ||
| + | |||
| + | ==== What is a dynamic factor? ==== | ||
| + | A dynamic factor is an authentication element created fresh for a single transaction. Examples are a one-time password, an app-generated code, a passkey approval or a live biometric prompt. A saved password is static, so for a non-card-present payment at least one of the two factors must be dynamic. | ||
| + | |||
| + | ==== Do I need to do anything to switch over? ==== | ||
| + | No application is needed. Your bank and payment provider implement the change. You only need to keep your registered mobile number active and accept new options like passkeys or biometric approval when your app offers them. | ||
| + | |||
| + | ==== Are small contactless payments affected? ==== | ||
| + | Small-value contactless card payments up to Rs 5,000 per transaction can still be done without an additional factor. This is an existing RBI norm and is not removed by the new principle. Certain recurring e-mandates also keep their existing exemptions. | ||
| + | |||
| + | ==== Can I file an RTI with the RBI about this rule? ==== | ||
| + | Yes. The RBI is a public authority under the RTI Act 2005. You can request the Directions text, any official FAQs and the policy reasoning. The PIO must reply within 30 days. RTI to a private bank is limited, so use the RBI Integrated Ombudsman for transaction disputes. | ||
| + | |||
| + | ==== Will high-value or suspicious payments need more checks? ==== | ||
| + | Possibly. The framework is risk-based. For a transaction that looks suspicious or high-risk, your bank or payment provider may add authentication beyond the basic two factors. This is a safeguard against fraud, not a routine extra step for normal payments. | ||
| + | |||
| + | ==== Is SMS OTP being phased out? ==== | ||
| + | No. The rule is technology-neutral and does not ban any single method. SMS OTP remains a fully valid second factor. Banks may offer newer options alongside it, but they are free to continue using OTP where they choose. | ||
| + | |||
| + | ===== What to do in the next 30 minutes ===== | ||
| + | |||
| + | - Check that your registered mobile number with your bank is current. | ||
| + | - Open your main banking app and enable any offered passkey, biometric or in-app approval. | ||
| + | - If you have a pending payment dispute, note your bank complaint date so you can escalate to the RBI Ombudsman if needed. | ||
| + | - If you want the official text, draft an RTI to the RBI using the AI RTI Drafter linked above. | ||
| + | |||
| + | ===== Related on RTI Wiki ===== | ||
| + | |||
| + | * [[https:// | ||
| + | * [[https:// | ||
| + | * [[https:// | ||
| + | * [[https:// | ||
| + | * [[https:// | ||
| + | |||
| + | ===== Sources ===== | ||
| + | |||
| + | * Reserve Bank of India, press release and Authentication Mechanisms for Digital Payment Transactions Directions, 2025, dated 25 September 2025, rbi.org.in | ||
| + | * Business Standard, RBI issues directions on authentication mechanisms for digital payment transactions, | ||
| + | * KPMG India, analysis of the RBI Authentication Mechanisms Directions 2025 | ||
| + | ===== RBI 2FA payment authentication rules April 2026: What changed ===== | ||
| + | |||
| + | - **Step 1: What are RBI's 2FA payment authentication rules and what changed in April 2026?** (a) RBI 2FA: (i) Two-Factor Authentication — mandatory for online payments, (ii) OTP + password/ | ||
| + | |||
| + | - **Step 2: Comparison table — 2FA scenarios.** (a) OTP not received: (i) issue: OTP not received — transaction fails, (ii) remedy: bank complaint + RBI Ombudsman, (iii) timeline: 7-30 days, (iv) example: not received; complained; fixed, (b) 2FA failed: (i) issue: bank refuses transaction — 2FA failed, (ii) remedy: bank complaint + RBI Ombudsman, (iii) timeline: 7-30 days, (iv) example: failed; complained; resolved, (c) Unauthorized: | ||
| + | |||
| + | - **Step 3: How to handle 2FA issues.** (a) Step 1: Check OTP settings — with bank, (b) Step 2: Bank complaint — for 2FA issues, (c) Step 3: Dispute unauthorized transaction — within 3 days, (d) Step 4: RBI Banking Ombudsman — if bank doesn' | ||
| + | |||
| + | - **Step 4: E-E-A-T signals.** (a) Sources: rbi.gov.in, pib.gov.in, india.gov.in, | ||
| + | |||
| + | - **Step 5: Practical tips.** (a) 2FA is for your security — don't disable, (b) report unauthorized transactions within 3 days — zero liability, (c) RBI Ombudsman very effective — free + fast, (d) check recurring mandates — regularly, (e) Example: A customer' | ||
| + | |||
| + | - **Step 6: Key provisions.** (a) RBI Act 1934, (b) Payment and Settlement Systems Act 2007, (c) RBI Master Directions, (d) 2FA mandatory, (e) Zero liability: if 2FA bypassed. | ||
| + | |||
| + | See [[https:// | ||
| + | |||
| + | {{tag> | ||