Brief By Newsbrief / 8:40 AM on 26 Mar 2026
The Reserve Bank of India has announced new, stricter regulations to enhance the safety of online transactions, set to take effect from April 1, 2026. Under the revised framework, all digital payments will require mandatory two-factor authentication, moving beyond the current reliance on OTPs or passwords alone.
Each transaction must include at least two verification methods, with one being dynamic, such as OTP, UPI PIN, fingerprint, or facial recognition. The RBI has also introduced a risk-based authentication system, where smaller transactions will face minimal checks, while high-value or suspicious payments will undergo stricter scrutiny based on user behaviour patterns.
The rules will apply across UPI, debit and credit cards, net banking, digital wallets, and prepaid systems, with international transactions covered from October 1, 2026. The move aims to curb rising cyber fraud and reinforce trust in India’s rapidly expanding digital payment ecosystem.