RBI Two-Factor Authentication Rules for Digital Payments
Why in the news
RBI issued fresh directions in September 2025 to tighten the way digital payments are authenticated and to reduce fraud.
Key facts
- Rule: two-factor authentication (2FA) for every digital transaction, effective 1 April 2026.
- Dynamic factor: at least one factor must change with each transaction.
- Cross-border: extra authentication for international card-not-present (CNP) deals from 1 October 2026.
Types of authentication factor
| Factor type | Example |
|---|---|
| Something the user knows | PIN or password |
| Something the user has | Device or token |
| Something the user is | Biometric |
Other provisions
- Risk-based checks: methods may vary by amount, user behaviour, device features and past patterns.
- Interoperability: payment systems must work smoothly and securely across platforms.
- Issuers: banks and non-bank payment service providers must comply, with robust and user-friendly systems.
Exam angle
- Full form: 2FA, two-factor authentication.
- Effective dates: 1 April 2026 and 1 October 2026 (CNP cross-border).
- Regulator: RBI.