RBI Mandates New Two-Factor Authentication Rules for Digital Payments Starting 2026

Abstract illustration depicting cybersecurity concepts with a robotic arm holding a shield, surrounded by icons representing security features like encryption, authentication, and system monitoring.

The Reserve Bank of India (RBI) has announced comprehensive new guidelines for digital payment authentication, set to take effect on April 1, 2026. The framework establishes stringent security requirements while encouraging technological innovation across the banking and fintech sectors, building upon India’s growing digital payments infrastructure that includes the widely-adopted Unified Payments Interface (UPI).

Under the new rules, all digital payment transactions must implement Two-Factor Authentication (2FA) using at least two distinct verification methods. These can include device tokens, passwords, passphrases, or biometric factors such as fingerprints or Aadhaar-based verification. The framework specifies that at least one authentication factor must be dynamic and unique to each transaction. The expanded authentication options support the NPCI’s recent development of facial recognition capabilities for UPI transactions.

The guidelines expand authentication options beyond traditional SMS-based one-time passwords (OTPs) to include next-generation tools while mandating interoperability across all payment platforms and channels. The changes come as India has witnessed increasing incidents of banking malware and fraud targeting mobile users. Payment issuers will bear responsibility for their authentication systems’ effectiveness and must compensate customers for any losses resulting from non-compliance.

The framework introduces risk-based authentication checks, allowing issuers to implement additional security measures based on factors such as unusual device usage or transaction patterns. For cross-border card-not-present transactions, Indian card issuers must establish additional authentication validation mechanisms by October 1, 2026, and register their Bank Identification Numbers with card networks. The requirement follows several high-profile financial fraud cases in India involving SIM swap attacks.

Certain transactions remain exempt from 2FA requirements, including small offline payments, recurring e-mandates, and transit-related transactions. The guidelines also mandate compliance with the Digital Personal Data Protection Act, 2023, ensuring authentication processes maintain user privacy and data security. The requirements complement broader efforts to update India’s digital identity infrastructure to meet evolving privacy standards.

“The clarity and flexibility provided will enable issuers and payment players to embrace next-generation tools like biometrics, tokenisation, and contextual risk checks,” said Vishwas Patel, Chair of the Payments Council of India and Joint Managing Director of Infibeam Avenues. “By keeping security at the core, the RBI has paved the way for a safer, simpler, and more inclusive digital payments experience for both consumers and businesses.”

Sources: Entrackr, Economic Times, Stocktwits, Caalley, Angel One, Times of India