UPSC Darpan

Science & TechnologyGS310 October 2026

RBI authentication rules regulate outcomes, not technology: OTPs, Apple Pay and the fraud question

Open in the app — quiz, notes, Mistake Vault हिंदी में पढ़ें

The news

New Delhi. Apple Pay arrived in India on September 30, 12 years after its global debut; the real story is the Reserve Bank of India (RBI), argues former consumer affairs secretary Rohit Kumar Singh in The Economic Times. RBI’s Authentication Mechanisms for Digital Payment Transactions Directions of September 2025, in force since April, retain two-factor authentication but widen the factors allowed, including biometrics built into a phone, and hold card issuers answerable to customers when they fall short. In Singh’s words, RBI “chose to regulate the outcome, instead of prescribing the tool”, ending the de facto rule that a card payment needed a one-time password (OTP). NPCI allowed on-device biometrics for UPI in October 2025; in June, over 611 million UPI payments worth ₹25,416 crore were authorised by fingerprint or face. Apple Pay does not yet support RuPay or UPI, which carries about 84% of digital payment volume.

The chain in one line: An extra factor, in practice the OTP, becomes the norm → fraudsters phish the six-digit code → RBI’s 2024 draft on alternative authentication → 2025 Directions fix outcomes and issuer liability → biometric UPI and Apple Pay arrive

Static syllabus linkage

  1. The Payment and Settlement Systems Act, 2007 gives RBI its payments powers. The Act makes RBI the regulator of payment systems; no one may run one without its authorisation, which is how NPCI operates UPI and RuPay. Section 18 lets RBI issue directions to system participants, the basis for authentication rules.
  2. The IT Act, 2000 sets liability for data and security lapses. Section 43A makes a body corporate that handles sensitive personal data, such as passwords or biometrics, pay compensation if negligent security causes loss. RBI’s 2017 circular on customer liability adds zero liability for customers who report third-party fraud within three working days.

Why UPSC loves this

  1. Digital payments security sits in two GS3 lines. The syllabus names “awareness in the fields of IT, computers” and “basics of cyber security”.

Prelims nuggets

  • Two-factor authentication requires proof from two different categories: something you know (PIN), something you have (phone) or something you are (fingerprint).
  • Tokenisation replaces a card number with a unique token, so merchants never store the real card details.
  • Risk-based authentication asks for extra proof only when a transaction looks unusual by device, place, amount or behaviour.
  • NPCI, which runs UPI and RuPay, is authorised by RBI under the Payment and Settlement Systems Act, 2007.
  • Under RBI’s 2017 rules a customer has zero liability for third-party fraud reported within three working days.

Analysis

  1. The OTP made fraud easier because it was a single, shareable secret. Every “your account will be blocked” message, Singh notes, aims to extract one six-digit code. A fingerprint checked on the phone cannot be read out over a call, and risk-based checks can flag a payment from a new device. Fixing outcomes and liability, not tools, lets defences evolve with attacks.
  2. The device-maker becomes part of the security chain. When the phone checks the face, a few global platforms hold a critical function. Singh welcomes their secure hardware but warns of concentration, and says issuers must hold platform partners to the same standard. Outcome rules work only if accountability flows all the way down.
  3. Lens — Innovation and safeguards: inclusion means choice, not one mandated gate. Fingerprints wear with age and manual work, and not every citizen owns a phone with secure biometrics. Singh argues biometrics should complement, not replace, PINs and OTPs. A sensible regulator keeps several safe doors open and insists that UPI and RuPay work inside global wallets too.

Possible Mains question

Outcome-based regulation suits fast-changing technology better than prescriptive rules. Evaluate with reference to RBI’s 2025 directions on authentication of digital payments. (10 marks, 150 words)

Model approach

  1. Directive — Evaluate. Weigh merits and limits; give a verdict.
  2. Introduction — from the OTP mandate to outcome rules. Apple Pay’s entry as the trigger.
  3. Body — outcome rules let defences evolve and fix liability on issuers. Value addition: 611 million biometric UPI payments in June; draw a flow: user → device biometric → issuer’s risk check → payment, marking where liability sits.
  4. Body — but they concentrate power in device-makers and can exclude. Worn fingerprints, basic phones.
  5. Conclusion — outcomes plus choice plus interoperability. Keep PIN and OTP as fallbacks.

Administrator's brainstorm

As a bank’s grievance officer, a farmer says a fingerprint payment he never made drained his account. What do you do?

I would block the channel and record the complaint time, since prompt reporting limits his liability under RBI rules. The bank must prove the payment was genuine, so I would pull the device and authentication logs and credit the amount if they do not.