RBI draft framework mandates additional authentication for all digital payments

AFA is using more than one factor for authentication to complete a payment instruction. Currently, the digital payments ecosystem uses SMS-based OTP as AFA. Back in February, the RBI had stated that alternative authentication mechanisms have emerged in recent years with tech innovations, prompting the need to adopt a principle-based framework for authentication of digital payments.

The draft framework says that issuers — banks and non-banks — can adopt a risk-based approach in deciding the appropriate AFA, based on the risk profile of the customer and/or beneficiary, transaction value, channel of origin etc. The draft framework further mandates issuers to alert customers, in real time, for all eligible digital payment transactions.

Additionally, issuers cannot enter into any exclusivity arrangement with any payment service provider/technology service provider, which could limit its ability to deploy alternative authentication solutions. Also, for transactions involving tokenised cards on various devices, the issuer must ensure the device environment supports tokenisation on a non-exclusive basis.

Leave a Reply

Your email address will not be published. Required fields are marked *