RBI Guidelines and Regulations on Cybersecurity for Banks and Digital Payments

RBI Guidelines and Regulations on Cybersecurity for Banks and Digital Payments

The Reserve Bank of India (RBI) has built a layered cybersecurity framework for banks and digital payment entities through statutory powers, master directions, and security controls. These rules cover governance, incident reporting, authentication, risk management, and fraud prevention across the financial system.

Regulatory Architecture for Cybersecurity

The RBI administers cybersecurity regulations under primary statutes, including Section 35A of the Banking Regulation Act, 1949, the Reserve Bank of India Act, 1934, and the Payment and Settlement Systems Act, 2007. The framework sets mandatory baselines for governance, risk assessment, and technical controls for commercial banks, NBFCs, cooperative banks, and payment operators.

Cyber Security Framework in Banks (2016)

Issued in June 2016, this framework laid the foundation for cybersecurity requirements for Scheduled Commercial Banks (SCBs).

  • Board-Approved Policy: Banks must have a cybersecurity policy approved by the Board of Directors.
  • CISO: Every bank must appoint a dedicated Chief Information Security Officer to implement the cybersecurity strategy.
  • SOC: Banks must establish a Security Operations Centre to monitor IT infrastructure continuously.
  • CCMP: Regulated entities must maintain a Cyber Crisis Management Plan to handle cyber incidents and disruptions.
  • Incident Reporting: Cybersecurity incidents must be reported to the RBI within 2 to 6 hours of detection.
  • Audit and Logs: System logs must be retained for at least two years for forensic investigation.

Master Directions on IT Governance, Risk, Controls, and Assurance Practices (2023)

This consolidated direction, effective from April 1, 2024, unifies earlier circulars and notifications. It applies to SCBs, NBFCs, cooperative banks, and housing finance companies.

  • IT Strategy Committee: The Board must establish a dedicated IT Strategy Committee, chaired by an independent director.
  • IT Risk Management Framework: Entities must designate a separate IT risk management function to identify, measure, and mitigate technology risks.
  • Asset Inventory: Banks must maintain an updated inventory of all IT assets, classified by business criticality.
  • Access Control: Organizations must enforce least-privilege access and multi-factor authentication for administrative users.

Master Direction on Digital Payment Security Controls (DPSC) Directions, 2021

Introduced in February 2021, these directions set minimum security standards for digital payment channels such as mobile banking, internet banking, and card payments.

  • Application Security Life Cycle (ASLC): Regulated entities must follow secure coding practices during development, testing, and deployment.
  • Device Fingerprinting: Internet and mobile banking systems must verify device-specific attributes to detect unauthorized logins.
  • Dynamic OTP Timeouts: OTPs for digital transactions must have a strict timeout and dynamic generation mechanism.
  • API Security: APIs used for data sharing and integration must follow recognized secure communication protocols.
  • Behavioral Biometrics: Pattern-recognition features such as typing speed and swipe movements should be used to detect bot activity and fraud.

Master Directions on Cyber Resilience and Digital Payment Security Controls for Non-Bank PSOs, 2024

Issued on July 30, 2024, this framework applies to non-bank Payment System Operators (PSOs) such as third-party payment apps, wallets, and payment aggregators.

  • Five Core Objectives: Anticipate, Withstand, Contain, Recover, and Evolve.
  • Unregulated Entities: PSOs must ensure that payment gateways and third-party vendors follow these guidelines through formal agreements.
  • Phased Implementation: Compliance is linked to the size of the PSO.
  • Large PSOs: Must comply by April 1, 2025.
  • Medium PSOs: Must comply by April 1, 2026.
  • Small PSOs: Must comply by April 1, 2028.

Authentication Mechanisms for Digital Payment Transactions Directions, 2025

Issued on September 25, 2025, and effective from April 1, 2026, this regulation updates validation mechanisms for domestic digital transactions.

  • Principle-Based 2FA: Every digital payment transaction must use at least two distinct authentication factors.
  • Authentication Factors: These may include something the user has, something the user knows, and something the user is, such as biometrics.
  • Dynamic Validation Requirement: For non-card-present transactions, at least one authentication factor must be dynamically created for that specific transaction.
  • Risk-Based Authentication: Providers may adjust checks based on transaction value, user location, and device ID.
  • Exemptions from Multi-Factor Authentication: Certain low-value transactions are exempt.
  • Offline payments: Up to ₹500.
  • Small-value card-present transactions: Up to ₹5,000.
  • Recurring e-mandate payments: Up to ₹15,000, or ₹1,00,000 for specific segments such as insurance and mutual funds.
  • Pre-paid instruments: For mass transit and toll collections.

Advanced Counter-Fraud Interventions

The RBI uses advanced technology to detect and prevent digital fraud across the banking ecosystem.

  • Indian Digital Payment Intelligence Corporation (IDPIC): Established as a Section 8 company on October 16, 2025, it uses AI and Big Data Analytics to detect fraud in real time.
  • MuleHunter.AI: This AI/ML-based solution helps banks identify and block money mule accounts used for laundering stolen funds. It is live across 26 commercial banks.
  • Customer Liability Guidelines: These rules limit customer liability in unauthorized electronic transactions and provide compensation timelines and dispute-resolution windows.

Summary of Key Cybersecurity Regulations

Regulation Name Year of Issuance / Effect Target Entities Key Focus Area
Cyber Security Framework in Banks 2016 Scheduled Commercial Banks SOC installation, CISO appointment, CCMP formulation, and prompt incident reporting.
Digital Payment Security Controls (DPSC) 2021 Banks, Credit Card Issuing NBFCs Baseline security for internet banking, API controls, ASLC, and device fingerprinting.
Master Directions on IT Governance 2023 (Effective 2024) Banks, NBFCs, Cooperative Banks Structured IT strategy committees, asset inventory, and IT risk assessment reports.
Master Directions on Cyber Resilience for Non-Bank PSOs 2024 (Phased to 2028) Non-Bank Payment Operators Vendor risk management, cyber crisis management plans, and system resiliency.
Authentication Mechanisms for Digital Payments 2025 (Effective 2026) All Payment System Providers Principle-based 2FA, risk-based authentication, and transaction-specific dynamic validation.

Rare Facts for Prelims

  • Section 35A Power: The RBI can issue binding directions to banks under Section 35A of the Banking Regulation Act, 1949.
  • Log Retention: The 2016 framework requires system logs to be preserved for at least two years.
  • Independent Director Role: The IT Strategy Committee under the 2023 directions must be chaired by an independent director.
  • Transaction-Specific Authentication: For non-card-present payments, one factor must be dynamically generated for that exact transaction.
  • Section 8 Company: IDPIC was set up as a Section 8 company, which means it is a not-for-profit entity under company law.
  • Phased PSO Compliance: The 2024 cyber resilience framework gives the longest compliance window to small PSOs, up to April 1, 2028.
Originally written on December 19, 2015 and last modified on August 18, 2026.

Leave a Reply

Your email address will not be published. Required fields are marked *