Get Updates
Get notified of breaking news, exclusive insights, and must-see stories!

RBI Digital Payments Update 2025: OTP, PIN, Biometrics Among Valid 2FA Methods

In a significant move for the digital payments ecosystem, the Reserve Bank of India (RBI) has issued a new framework on authentication mechanisms for digital payment transactions, set to take effect from April 1, 2025. While the familiar SMS-based one-time password (OTP) will remain a valid option, the new guidelines emphasize the adoption of advanced alternatives to strengthen security and enhance user experience.

What Changes Under the New Rules

The RBI clarified that two-factor authentication (2FA) will continue to be mandatory. Authentication can be based on three categories:

AI Summary

AI-generated summary, reviewed by editors

The Reserve Bank of India (RBI) introduced a new framework for digital payment authentication, effective April 1, 2025, mandating two-factor authentication (2FA) and emphasizing advanced alternatives to enhance security, while SMS-based OTPs remain valid. These guidelines also cover cross-border card transactions, requiring new validation mechanisms by October 1, 2026, and stipulating full compensation for customers in case of financial loss due to security failures.
RBI Digital Payments Update 2025 OTP PIN Biometrics Among Valid 2FA Methods
  • Something the user knows (password, passphrase, PIN)
  • Something the user has (SMS OTP, card hardware, software token)
  • Something the user is (fingerprint, biometrics, including Aadhaar-based or device-native options)

At least one of the authentication factors must be dynamically generated and unique for each transaction. This ensures that compromising one factor does not affect the other, reinforcing overall payment security.

Key Requirements for Financial Institutions

  • 2FA remains mandatory, with SMS OTPs still permitted.
  • Dynamic, transaction-specific authentication is essential.
  • Robust systems must be implemented to protect against single-factor compromise.

Risk-based analysis is now mandatory, requiring institutions to evaluate transactions using behavioural and contextual data.

Customer protection remains paramount: if a security failure leads to financial loss, the issuer must provide full compensation to the affected customer.

Cross-Border Transactions

The guidelines also cover cross-border card transactions. The RBI has mandated that new validation mechanisms must be in place by October 1, 2026, to ensure consistent security standards for international payments.

This update signals a major push by the RBI to move beyond reliance on SMS OTPs and encourage the adoption of modern authentication technologies such as biometrics and software tokens, while still safeguarding customers through mandatory 2FA and robust compensation measures.

Notifications
Settings
Clear Notifications
Notifications
Use the toggle to switch on notifications
  • Block for 8 hours
  • Block for 12 hours
  • Block for 24 hours
  • Don't block
Gender
Select your Gender
  • Male
  • Female
  • Others
Age
Select your Age Range
  • Under 18
  • 18 to 25
  • 26 to 35
  • 36 to 45
  • 45 to 55
  • 55+