Skip to content

RBI Risk-Based Authentication Rules for Digital Payments

7 October 20251 min read
BANKING & FINANCERBI Risk-BasedAuthenticationRules for DigitalPayments7 October 2025safalsetu.com

Why in the news

Worried by fraud and cyber risk, the central bank swaps a fixed OTP step for risk-based checks.

Key facts

  • Signals used: device compromise, behaviour, location, history.
  • Extra verification only for suspicious activity: new device, odd timing, overseas use.
  • Bill payments and small purchases stay seamless.
  • Approach is layered and zero-trust, with fewer false rejections.

Challenges

  • Banks may need AI-driven fraud detection and behavioural analytics.
  • A possible rural-urban divide: limited smartphones, so OTPs still matter.
  • Legal issues must be addressed too.

Exam angle

  • Effective: April 2026.
  • Terms: RBA, 2FA, OTP, device-binding.

Test yourself

1. From when do the RBI's risk-based authentication digital payment directions take effect?

The notes say the directions are effective from April 2026.

2. Under RBI's new framework, which authentication requirement remains mandatory?

Two-factor authentication stays mandatory under the RBA framework.

3. Which of these may a bank use as one of the two factors under the RBI risk-based framework?

Banks can offer biometrics, device-binding or other methods as a factor.