Customers can report digital payment fraud directly through banking apps.
Banks face tighter checks on payment, app and card security.
Customers will get clearer complaint processes and digital safety guidance.
Customers can report digital payment fraud directly through banking apps.
Banks face tighter checks on payment, app and card security.
Customers will get clearer complaint processes and digital safety guidance.
Customers will be able to flag fraudulent digital payment transactions directly through mobile and Netbanking applications under new security directions issued by the Reserve Bank of India (RBI) on July 31, 2026. Once a customer reports a transaction as fraudulent through the app, the bank or financial institution will then work towards instantly reporting the same to the beneficiary or counterparty entity.
Banks are also mandated to provide multi-factor authentication (MFA) and alerts for payment transactions, including debits and credits. Alerts must also be sent for new account linkages, addition, modification or deletion of beneficiaries, changes in account details and revisions to fund transfer limits.
RBI has also directed banks and the payment ecosystem to create a real-time or near-real-time reconciliation framework, with reconciliation completed within 24 hours of receiving settlement files. Backed-up data related to digital payment services must be tested, by bank or other regulated entities, at least once every six months to ensure transactions and audit trails can be recovered without loss, according to the directions.
Older versions of mobile banking and payment apps will also have to be phased out within six months of a newer version's release, RBI said in its guidelines.
The directions also cover device binding, remote-access application detection, secure app installation and minimum customer data collection. Customers are to be notified when a new device is registered and given a facility to disable registered devices.
Banks should also inform customers about failed login or authentication attempts and set a maximum number of failed attempts, after which digital payment access is to be blocked.
Banks will have to keep a closer watch on card transactions, especially overseas cash withdrawals. They can set transaction limits based on their risk assessment at the card, Bank Identification Number (BIN) or bank level. These limits will be monitored round the clock, including weekends and holidays, to detect suspicious activity and limit potential losses.
Card details also cannot be stored in plain text by banks or their vendors.
According to the guidelines, digital payment apps will have to provide a clear way for customers to raise complaints, along with details of the required forms, contact information and expected response time.
Customers will also have to be informed about the risks, benefits and liabilities linked to digital payment services. This will include their rights and responsibilities in situations, such as service outages, processing errors, and security breaches.