Skip to content

RBI Two-Factor Authentication Rules for Digital Payments

26 September 20251 min read
BANKING & FINANCERBI Two-FactorAuthenticationRules for DigitalPayments26 September 2025safalsetu.com

Why in the news

RBI issued fresh directions in September 2025 to tighten the way digital payments are authenticated and to reduce fraud.

Key facts

  • Rule: two-factor authentication (2FA) for every digital transaction, effective 1 April 2026.
  • Dynamic factor: at least one factor must change with each transaction.
  • Cross-border: extra authentication for international card-not-present (CNP) deals from 1 October 2026.

Types of authentication factor

Factor typeExample
Something the user knowsPIN or password
Something the user hasDevice or token
Something the user isBiometric

Other provisions

  • Risk-based checks: methods may vary by amount, user behaviour, device features and past patterns.
  • Interoperability: payment systems must work smoothly and securely across platforms.
  • Issuers: banks and non-bank payment service providers must comply, with robust and user-friendly systems.

Exam angle

  • Full form: 2FA, two-factor authentication.
  • Effective dates: 1 April 2026 and 1 October 2026 (CNP cross-border).
  • Regulator: RBI.

Test yourself

1. From which date does RBI's two-factor authentication mandate for digital payments apply?

The directions take effect on 1 April 2026.

2. What is true of at least one factor in RBI's 2FA rules?

At least one factor must be dynamic.

3. From when do international card-not-present transactions need additional authentication under RBI's directions?

CNP cross-border deals need extra authentication from 1 October 2026.