Reserve Bank of India Mandates 2FA
Analysis based on 8 articles · First reported Mar 22, 2026 · Last updated Mar 29, 2026
The new regulations by the State Bank of India are expected to increase trust in digital payments in India, potentially boosting adoption and transaction volumes. While transaction times may slightly increase, the enhanced security measures aim to reduce fraud, which could positively impact financial institutions by reducing liability and improving customer confidence.
The State Bank of India has mandated two-factor authentication (2FA) for all digital payments in India, effective April 1, 2026. This change requires users to provide at least two layers of verification, such as an OTP combined with a PIN, password, or biometric authentication, for transactions including UPI, debit cards, credit cards, and mobile wallets. The move aims to combat rising online fraud cases like phishing and SIM swap scams, which have exploited vulnerabilities in OTP-based systems. The new system will also adopt a risk-based approach, applying stronger authentication for high-risk transactions. Additionally, the State Bank of India has increased accountability for banks and payment platforms, requiring them to compensate customers for fraud resulting from system failures. Similar 2FA rules are planned for international and cross-border card payments by October 2026. Experts from Easebuzz, Policybazaar, Veritas Juris, and Global Citizen Solutions generally view this as a positive step towards enhancing security and trust in India's rapidly growing digital payment ecosystem.
Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.
Open Dashboard