RBI set to end the tyranny of OTP

Blitz Bureau

NEW DELHI: The Reserve Bank last week announced new rules for digital payments, which allow for more ways to comply with the two-factor authentication (2FA) beyond the SMS-based one-time password (OTP). The new rules will come into effect from April 1, 2026.

The factors of authentication can be from “something the user has”, “something the user knows” or “something the user is” and may comprise, inter-alia, password, SMS-based OTP, passphrase, PIN, card hardware, software token, fingerprint, or any other form of biometrics (device native or Aadhaar-based), the central bank said.

Authentication mechanism of digital payments to be expanded from April 2026

India is among the markets in the world which insist on 2FA, and financial sector players have been relying on the SMS-based alerts to execute transactions.

The factors of authentication can be from “something the user has”, “something the user knows” or “something the user is” and may comprise password, SMS-based OTP, passphrase, PIN, card hardware, software token, fingerprint, or any other form of biometrics (device native or Aadhaar-based).

The RBI launched the (Authentication mechanisms for digital payment transactions) Directions, 2025, making it clear that 2FA will continue to be mandatory and SMS OTP can also be used.

The central bank had first announced the move in February 2024 to enable the payments ecosystem to leverage the technological advancements for implementing alternative authentication mechanisms.

The new rules specify that at least one of the factors of authentication is dynamically created or proven, wherein the proof of possession of the factor, being sent as part of the transaction, is unique to that transaction.

Additionally, the system should also be robust, wherein compromise of one factor does not affect reliability of the other.

Apart from this, the RBI said that from a risk management perspective, the financial system stakeholders can also identify transactions for evaluation against behavioural / contextual parameters such as transaction location, user behaviour patterns, device attributes, historical transaction profile, etc.

“Based on the perceived risk associated with the transaction, additional checks beyond the minimum two-factor authentication may be resorted to. Issuers may also explore using DigiLocker as a platform for notification and confirmation for high-risk transactions,” it said.

If any loss arises out of transactions effected without complying with these directions, the issuer shall compensate the customer for the loss in full without demur, the central bank said.

It has also asked card issuers to put in place a mechanism to validate non-recurring, cross-border card not present (CNP) transactions, where request for authentication is raised by an overseas merchant or overseas acquirer from October 1, 2026.

Latest News

The fat sat- Isro launches its heaviest comm satellite onboard desi tall boy

In a milestone for India’s space sector, the Indian...

Fall of passport

Blitz Bureau NEW DELHI: In the ever-changing world of global...

Who cares? Cost of keeping women tied to homes is huge

SUKUMAR SAH Behind India’s economic engine lies an invisible workforce...

Let’s not turn the boon of numbers into a bane

Blitz Bureau NEW DELHI: For years, India’s youth bulge has...

Poverty of choices before debt-laden rich nations – Increase taxes or let inflation rise

Blitz Bureau NEW DELHI: Government borrowing is unsustainable in the...

Topics

The fat sat- Isro launches its heaviest comm satellite onboard desi tall boy

In a milestone for India’s space sector, the Indian...

Fall of passport

Blitz Bureau NEW DELHI: In the ever-changing world of global...

Who cares? Cost of keeping women tied to homes is huge

SUKUMAR SAH Behind India’s economic engine lies an invisible workforce...

Let’s not turn the boon of numbers into a bane

Blitz Bureau NEW DELHI: For years, India’s youth bulge has...

Poverty of choices before debt-laden rich nations – Increase taxes or let inflation rise

Blitz Bureau NEW DELHI: Government borrowing is unsustainable in the...

Service sector growth falls to 5-month low in October

Blitz Bureau NEW DELHI: India’s services sector growth witnessed the...

OpenAI to use AWS infra for increased workload

Blitz Bureau NEW DELHI: Amazon Web Services (AWS) and OpenAI...

Time for cheap Macs

Blitz Bureau NEW DELHI: Apple is preparing to launch a...
spot_img