Multi-Factor Authentication and RBI's Rules
Two factors of different types, one of them dynamic. Here is what RBI requires and where MFA still fails.
Multi-factor authentication (MFA) means proving who you are with two or more independent kinds of evidence, so a fraudster who steals one still can't get in. A card PIN plus the physical card is two factors. A password plus an OTP sent to a registered phone is two factors.
In Indian banking, MFA is not optional. RBI requires every domestic digital payment to be authenticated by at least two factors, and its 2025 directions set out the principles every bank and payment company must follow from 1 April 2026.
You save ₹300
- Full 120-question mocks
- Cyber law coverage
- Module-wise practice
One payment, no subscription · Valid for 2 months
The Three Factor Types
Knowledge
Meaning
Something the user knows
Examples from RBI's definition
Password, passphrase, PIN
Possession
Meaning
Something the user has
Examples from RBI's definition
Card hardware, SMS OTP to a registered phone, software token
Inherence
Meaning
Something the user is
Examples from RBI's definition
Fingerprint or other biometrics, device-native or Aadhaar based
| Factor | Meaning | Examples from RBI's definition |
|---|---|---|
| Knowledge | Something the user knows | Password, passphrase, PIN |
| Possession | Something the user has | Card hardware, SMS OTP to a registered phone, software token |
| Inherence | Something the user is | Fingerprint or other biometrics, device-native or Aadhaar based |
RBI's Authentication Directions, 2025
Issued 25 September 2025; banks and non-banks had to comply by 1 April 2026.
- check_circleMinimum two distinct factors for every domestic digital payment, unless specifically exempted.
- check_circleFor any transaction other than a card-present one, at least one factor must be dynamic: unique to that transaction, like an OTP.
- check_circleFactors must be independent: compromise of one must not affect the reliability of the other.
- check_circleNo specific factor is mandated. SMS OTP became the default by habit, and the directions let issuers adopt alternatives such as biometrics or app-based tokens.
- check_circleIssuers may add checks beyond two factors for risky transactions, based on location, device, behaviour and transaction history.
- check_circleIf a loss arises from a transaction processed without complying with these directions, the issuer must compensate the customer in full without demur.
- check_circleCard issuers must, by 1 October 2026, have a mechanism to validate non-recurring cross-border card-not-present transactions where an overseas merchant or acquirer requests authentication.
Exemptions From the Two-Factor Rule
Annexure-1 of the 2025 directions lists the use cases currently exempt, each under its own RBI instruction. They include:
- check_circleSmall-value contactless card transactions
- check_circleRecurring transactions under the e-mandate framework, other than the first
- check_circleNETC (FASTag) transactions
- check_circleSmall-value digital payments in offline mode
- check_circleSelect prepaid instruments such as gift PPIs
Quick practice on banking operations. No signup.
Beyond the Payment Itself
RBI's digital payment security controls apply MFA more widely: to fund transfers and cash withdrawals at ATMs, micro-ATMs and business correspondents, and, with alerts, to adding or changing a beneficiary, changing account details or raising a transfer limit. Banks may use adaptive authentication, choosing factors by risk. Mobile banking apps must be bound to the customer's device.
Inside the bank, RBI's cybersecurity directions make MFA mandatory for privileged users of critical systems: the administrator accounts that can change limits or create users.
How the IIBF Exam Tests This
- check_circleFactor counting: password plus PIN is one factor type used twice, not two-factor. Expect this as a 'which is NOT MFA' option.
- check_circleDynamic factor: the rule that one factor must be unique to the transaction applies to everything except card-present payments.
- check_circleThe OTP scenario: a customer reads an OTP out to a fake KYC caller. MFA worked as designed; the possession factor was handed over. The failure is social engineering, which is why alerts and customer awareness stay in the answer.
- check_circleOld versus new: options citing the ₹2,000 card-not-present relaxation describe circulars the 2025 directions repealed.
Courseware and Current Rules
Older study material describes 'Additional Factor of Authentication' (AFA) for card-not-present transactions under RBI circulars from 2009 to 2016, including the 2016 relaxation for payments up to ₹2,000 through card network authentication solutions. The 2025 directions repealed those circulars and replaced them with the principles above. They were issued before the 30 June 2026 cut-off, so the current rule is testable.
FAQs
Is password plus PIN two-factor authentication?expand_more
No. Both are things you know, so they are one factor type used twice. Two-factor means two different types, such as a PIN (know) and a card or OTP to your phone (have).
What are RBI's new rules on OTP for digital payments?expand_more
RBI's 2025 authentication directions keep the two-factor requirement but no longer treat SMS OTP as the default. Any two distinct factors may be used, with at least one dynamic for transactions other than card-present ones. Compliance was due by 1 April 2026.
Who bears the loss if a bank skips two-factor authentication?expand_more
Under the 2025 directions, if a loss arises from a transaction processed without complying with them, the issuer must compensate the customer in full without demur.
Which payments don't need two-factor authentication?expand_more
The 2025 directions list exemptions including small-value contactless card payments, recurring e-mandate debits after the first, NETC toll payments, small-value offline payments and select prepaid instruments.
Next steps
- Card Not Present Fraudarrow_forward
- Customer Liabilityarrow_forward
- Fraud Controlsarrow_forward
- Social Engineeringarrow_forward
120 questions, 2 hours, scored instantly.
