What Happened?
On July 31, 2026, the Reserve Bank of India issued the Reserve Bank of India (Commercial Banks โ Digital Payment Security Controls) Directions, 2026 (RBI/DoS/2026-27/411). These new directions replace all previous digital payment security guidelines and come into effect immediately. This comprehensive regulation applies to all commercial banks operating in India and mandates rigorous security controls across internet banking, mobile payments, card payments, and other digital payment services.
The directions establish a complete framework for cybersecurity governance, multi-factor authentication, fraud risk management, and customer protection across all digital payment channels.
Background & Legal Context
These directions are issued by RBI under its authority granted by:
- Banking Regulation Act, 1949 - Section 5 (definitions of banking companies)
- Payment and Settlement Systems Act, 2007 - Chapter IV
- Information Technology Act, 2000 - for cybersecurity standards
- Companies Act, 2013 - for corporate governance requirements
The directions represent a significant evolution in RBI's approach to digital payment security, shifting from prescriptive rules to a holistic framework covering:
- Board-level governance and policy formulation
- Risk assessment and management frameworks
- Technical security controls (encryption, authentication)
- Application security lifecycle management
- Fraud detection and prevention mechanisms
- Customer protection and awareness requirements
Key Legal Framework: While there is no direct mention of Income Tax Act sections in these directions, banks must ensure that their compliance costs are properly accounted for in their financial statements under the Income Tax Act, 2025. Deductions under Section 37 (business expenditure) may apply to security infrastructure investments. Additionally, banks must maintain proper audit trails for IT security expenses, which are relevant for tax assessment under Section 44AB (compulsory audit for specified businesses).
What Does This Mean for You?
For Commercial Banks:
- Immediate Compliance Burden: Banks must now implement comprehensive governance frameworks, with Board approval required for all digital payment policies. The Board must review these policies at least annually, creating additional compliance documentation requirements.
- Multi-Factor Authentication (MFA) Mandatory: All digital payments, fund transfers, and ATM cash withdrawals now require MFA with at least one dynamic or non-replicable authentication method (OTP, biometrics, hardware tokens, or PKI). This applies with immediate effect, requiring technology upgrades for all digital channels.
- Enhanced Fraud Controls: Banks must implement real-time or near-real-time reconciliation (within 24 hours maximum) across all stakeholders - payment system operators, business correspondents, card networks, and aggregators. This demands significant IT infrastructure investment.
- Vulnerability and Security Testing: Vulnerability Assessment (VA) must be conducted at least half-yearly; Penetration Testing (PT) at least annually. New applications or major infrastructure changes require additional testing. This increases operational costs for banks.
- Mobile App Security: Mobile applications must implement device binding, version management (only one active version at a time), rooted device detection, and code obfuscation. Banks cannot store sensitive data like passwords or PINs on devices. Older app versions must be deactivated within 6 months of new version release.
- Card Payment Standards: Banks issuing cards must follow PCI-DSS, PCI-PIN, PCI-PTS, PCI-HSM, and PCI-P2PE standards. ATMs must implement BIOS passwords, USB port disabling, anti-skimming solutions, and latest OS patches.
- Customer Data Protection: Sensitive information (account numbers, card numbers, CVV) must not be stored in HTML fields, cookies, or client-side storage. Card data cannot be stored in plain text anywhere in the bank's ecosystem or vendors' systems.
For Bank Customers:
- Enhanced security through mandatory MFA - provides better protection against fraud
- Mandatory security awareness guidelines during app onboarding - you must acknowledge secure usage practices
- Clear grievance redressal mechanisms with defined timelines - easier dispute resolution
- Prohibition of SMS/email transmission of sensitive data (account/card numbers) - improved privacy
- Transparent merchant name display in payment alerts (not payment aggregator name) - better transaction tracking
For Third-Party Service Providers (Payment Aggregators, Gateways, Technology Vendors):
- Must provide source code escrow arrangements or continuity commitments for licensed applications
- Subject to bank oversight and RCSA (Risk and Control Self-Assessment) evaluation
- Must maintain security certifications and provide vulnerability assessment reports annually
- Must comply with data protection and PCI standards as applicable to their role
What Should You Do Now?
If You Are a Commercial Bank:
- Audit Existing Policies: Review all current digital payment policies against the new requirements. Ensure Board approval for updated policies by September 2026.
- Implement MFA Across All Channels: If not already in place, implement multi-factor authentication for all digital payments, ATM withdrawals, and fund transfers immediately. Conduct a technology audit to identify gaps.
- Strengthen Testing Frameworks: Ensure VA is conducted at least twice yearly and PT at least once yearly. Document all testing results and remediation efforts. Schedule additional tests for any new applications or major changes.
- Review Mobile App Architecture: Audit all mobile applications for device binding, version management, encryption of sensitive data, and removal of hardcoded credentials. Implement deactivation processes for older versions within 6 months.
- Establish Reconciliation Framework: Implement automated near-real-time reconciliation (within 24 hours) with all payment stakeholders. Establish monitoring dashboards and escalation procedures.
- Card Payment Compliance: If issuing cards, verify compliance with all PCI standards. For PoS terminals, ensure PCI-PTS certification for PIN terminals. Document all compliance status in IT Strategy Committee reports.
- Fraud Control Enhancement: Train fraud control teams on new monitoring parameters (transaction velocity, geo-location anomalies, behavioral biometrics, etc.). Update rules and monitoring systems accordingly.
- Customer Communication: Prepare communication materials explaining new security features, MFA requirements, and secure usage guidelines. Ensure these are available in multiple languages.
- Vendor Management: Conduct assessments of all third-party vendors for compliance with these directions. Ensure service provider agreements include penalty clauses for non-compliance.
- Documentation: Maintain comprehensive audit trails of all security controls, testing results, incidents, and remediation efforts. This documentation is essential for regulatory audits and for IT tax deductions under Income Tax Act, 2025.
If You Are a Bank Customer:
- Update Your Login: Change your internet banking and mobile app passwords if you haven't recently. Enable all available security features offered by your bank.
- Review Registered Devices: If your bank allows device binding, check which devices are registered with your account. Remove any unrecognized devices.
- Enable Alerts: Ensure SMS and email alerts are activated for all transactions and account modifications (beneficiary changes, limit changes, etc.).
- Update Your App: Always download the latest version of your bank's mobile app. Do not use older versions after they are deactivated.
- Secure Your Device: Install OS and app updates regularly. Use only authorized app stores for downloads. Install anti-malware software.
Key Takeaways
- Regulatory Shift: RBI's new directions represent a comprehensive shift from prescriptive rules to holistic security governance, with Board-level responsibility for digital payment security across all banks in India.
- MFA is Now Mandatory: All digital payments and fund transfers must use multi-factor authentication with at least one dynamic element (like OTP or biometrics), effective immediately across all banks.
- Continuous Testing Required: Banks must conduct vulnerability assessments at least twice yearly and penetration testing at least once yearly, with additional testing for new applications or major changes.
- Data Protection Stringent: Sensitive customer data (card numbers, PINs, account details) cannot be stored in plain text anywhere in the bank's ecosystem or with vendors, ensuring enhanced customer privacy and fraud prevention.
- Increased Compliance Costs: These directions will increase operational and technology costs for banks, impacting technology investments that may be deductible under Section 37 of Income Tax Act, 2025, for tax assessment purposes in AY 2026-27 and onwards.
Important Note for Tax Professionals: While these RBI directions do not directly impact Income Tax, they affect banks' IT spending, audit obligations, and data protection measures. Banks claiming deductions for security infrastructure under Section 37 must maintain detailed records of compliance efforts. Additionally, under Section 44AB (compulsory audit), banks' audit reports must increasingly verify compliance with these cybersecurity directions.
Need expert help with this? EaseValue CAs in Jaipur โ WhatsApp 63677 44602
EaseValue