India Imposes Stricter Authentication Rules to Combat Digital Payments Fraud
The Reserve Bank of India has unveiled stringent new guidelines aimed at curbing the alarming rise in digital payment fraud. Effective April 1, 2026, all domestic transactions must incorporate dynamic authentication factors—such as one-time passwords or biometric verification—on top of existing two-factor protocols.
The MOVE signals growing regulatory scrutiny of India's rapidly expanding digital payments ecosystem. While the rules exempt card-present transactions, they mandate real-time, non-reusable credentials for every digital payment—a measure likely to increase security but potentially add friction for users.
Payment providers across banks and fintech firms now face a six-month compliance deadline. The RBI's framework deliberately avoids prescribing specific authentication methods, leaving room for innovation in biometrics, hardware tokens, or emerging technologies.