Disclaimer

By clicking, "I Accept" below, you accept and acknowledge the following:

The purpose of this website is to provide general information and insights about TLH, Advocates & Solicitors, and not to advertise or solicit work in any manner whatsoever.

Please note that as per the Bar Council of India Rules, advocates in India are prohibited from advertising or soliciting work in any form or manner. You acknowledge that you are visiting this website at your discretion and that there has been no solicitation, invitation, or inducement of any sort whatsoever from TLH, Advocates & Solicitors or any of its professionals in relation to this website.

The content available on this website does not constitute legal or other professional advice and should not be substituted for advice relevant to particular circumstances.

The access and use of this website does not establish any fiduciary or other relationship between you and TLH, Advocates & Solicitors or any of its advocates.

Please read the ‘Terms of Use’ and our ‘Privacy Policy’ before accessing this website.

Blog default background
Blog
Banking & Finance

From OTP To Biometrics: Analysing RBI’s Directions On Payment Authentication

Authors:
Arko Mitra
June 23, 2026
5 min read
Share this post
Copied!

Introduction

The Reserve Bank of India ("RBI") issued the RBI (Authentication Mechanisms for Digital Payment Transactions) Directions, 2025 ("Directions"),1 effective 1 April 2026, applicable to all payment system providers, participants, banks, and non-banks for domestic digital payment transactions.2 We examine the reforms and the regulatory concerns associated with the Directions.

Analysis

Key Improvements:

1. Enhanced Authentication Method

In 2009, RBI mandated an additional factor of authentication ("AFA") for online card transactions, without properly defining or explaining the methodology.3 The Directions now fill this gap by classifying AFA as something the user is/has/knows, which may include passwords, one-time passwords ("OTP"), PINs, card hardware, software token, fingerprints, and other forms of biometrics (device-native or Aadhaar-based).4 With the adoption of biometric mechanisms (including fingerprint scanners and smartphone facial recognition), a broader definition would enable a move from the outdated OTP system to a more secure and convenient method.

2. Flexible Authentication with Built-in Safeguards

The Directions mandate a minimum of two factors of authentication, unless exempted, for all digital payment transactions, out of which one must be dynamic (i.e., generated or verified specifically for that transaction to ensure proof of identity provided is unique to that particular transaction).5 Issuers6 may offer their customers a choice of authentication factors.7 Furthermore, issuers can incorporate checks beyond the AFA for high-risk transactions, in line with their internal risk management policies.8

It may reasonably be concluded that dynamic authentication encompasses mechanisms such as transaction-specific OTPs sent via email or generated through an authenticator application, as well as real-time authentication prompts delivered to a registered device.9 In contrast, non-dynamic authentication may be interpreted to encompass authentication methods that lack a dynamic or transaction-specific element, such as biometric methods like fingerprint recognition and facial scans.10

3. Cross-Border Card Transaction Provisions

Previous regulatory directions were silent on cross-border card transactions. The Directions address this gap directly. By 01 October 2026, card issuers are required to establish mechanisms to validate non-recurring cross-border card-not-present (“CNP”) transactions initiated by an overseas entity.11 A risk-based mechanism for all cross-border CNP transactions must also be in place by the same deadline, with issuers required to register their Bank Identification Numbers with the relevant card networks.12  

In effect, this mandates that Indian issuers participate in global authentication protocols, such as EMV 3-D Secure (an international card authentication protocol), thereby reducing both transaction failures and cross-border fraud.

Regulatory Concerns:

1. Transition Friction

Implementation is left to individual issuers, with no prescriptive technical standard from the RBI. A sudden shift to a non-SMS-based OTP may cause inconvenience to some users. Rural and non-tech-savvy individuals are likely to be more affected, as they may not have access to smartphones with biometric features. Checks beyond AFA for high-risk transactions may lock out some users from using these facilities. Financial institutions might require a transition period to implement a new framework effectively.  

2. The Data Protection Gap

The Directions require issuers to comply with the Digital Personal Data Protection Act, 2023 (“DPDP Act”).13 Although the DPDP Act was notified on 14 November 2025, the substantive operative provisions will come into force 18 months later, i.e., on 14 May 2027. The Directions are already operative, but the data protection obligations they invoke are not yet enforceable. This creates a tangible regulatory gap.

The concern is amplified by the nature of the data involved. Biometric identifiers are immutable, as a compromised fingerprint cannot be reset like a password. Section 8(4) of the DPDP Act requiresdata fiduciaries to implement “appropriate technical and organisational measures,” but this formulation is vague and leaves the applicable standard to individual issuers, falling short of mandating end-to-end encryption.14 When the Digital Personal Data Protection Rules, 2025 ("DPDP Rules") take full effect, Rule 6 of the DPDP Rules will introduce minimum safeguards, including encryption, access controls, logging, and a one-year log retention requirement, while Rule 7 of the DPDP Rules will establish breach notification obligations requiring prompt intimation to affected data principals.15 Until then, the data protection aspects of these Directions remain in a grey area.

Conclusion

The Directions overall mark a significant leap forward for the Indian regulatory regime on digital transactions. Card issuers will have to significantly alter and modernise their systems, which will requireinitial investments and technical expertise. Merchants may notice a slight increase in transaction processing time and a small drop in transaction volume; however, in the long run, this is likely to be offset by fewer instances of fraud and increased consumer trust. Individual consumers stand to benefit the most from a more secure and robust framework. Still, it is incumbent on the RBI, as the sectoral regulator, to remain cognizant of any potential concerns and introduce future amendments in this regard.

No items found.

Footnotes

Share this post
Copied!

Latest posts

Banking & Finance
June 23, 2026
From OTP To Biometrics: Analysing RBI’s Directions On Payment Authentication
Read more
Arrow Right
Deal Announcement
June 23, 2026
TLH Advises CtrlS Datacenters in USD 1 Billion Strategic Partnership with CPP Investments
Read more
Arrow Right
Corporate Update
June 17, 2026
TLH, Advocates & Solicitors Advises Bijlibox India on Pre-Seed CCPS Fundraise
Read more
Arrow Right
Litigation update
June 16, 2026
TLH, Advocates & Solicitors Secures Decisive Victory for Piramal Pharma Limited Before the Principal District & Sessions Court, Sangareddy
Read more
Arrow Right
Firm updates
June 4, 2026
TLH, Advocates & Solicitors Announces Annual Promotions for 2025–26
Read more
Arrow Right
Deal Announcement
May 19, 2026
TLH, Advocates & Solicitors Advises KiwiTech, LLC on Strategic Acquisition of Majority Stake in Soft Suave Technologies Private Limited
Read more
Arrow Right
View All Blogs
Arrow Right