What DPSC Actually Means for Your Bank
RBI's Master Direction on Digital Payment Security Controls (DPSC), issued February 18, 2021, is the most operationally dense cybersecurity regulation the Indian banking sector has faced. It covers 75+ mandatory controls across six digital payment channels — and unlike SEBI CSCRF which is an annual declaration exercise, RBI inspectors verify DPSC controls during IT examinations.
Non-compliance triggers penalty letters, corrective action plans, and in serious cases, business restrictions. The reputational impact of a published penalty often exceeds the financial penalty itself.
Who Must Comply
DPSC applies to a wider set of entities than most compliance teams initially assume:
- Scheduled Commercial Banks (including Private, PSU, Foreign)
- Small Finance Banks
- Payment Banks
- White Label ATM Operators (WLAOs)
- Card Payment Networks operating in India
- Prepaid Payment Instrument (PPI) issuers regulated by RBI
- NBFCs providing digital payment services (treat DPSC as baseline even without explicit mandate)
Six Control Domains: What RBI Actually Checks
Each of the six domains carries specific technical and procedural requirements. The "most common inspection gap" in each domain reflects patterns from DPSC-related examination observations.
Internet Banking Security
- Mandatory multi-factor authentication (MFA) for all transactions — OTP alone does not satisfy MFA for high-value transfers
- Risk-based transaction limits configurable by customers; defaults must be conservative
- Device binding for registered internet banking sessions
- Session timeout ≤15 minutes for inactive sessions
- End-to-end encryption for all data in transit (TLS 1.2 minimum, TLS 1.3 recommended)
- Anti-phishing controls: DMARC/DKIM/SPF enforced, visual indicators validated quarterly
Mobile Banking Security
- Certificate pinning mandatory for mobile banking apps
- Jailbreak/root detection with session termination
- No caching of sensitive data (account numbers, credentials) on device storage
- App hardening: code obfuscation, anti-tampering, binary protection
- API security: signed requests, replay attack prevention, rate limiting
Card Security Controls
- PCI-DSS compliance is a prerequisite, not a substitute — RBI maps PCI controls to DPSC requirements
- EMV chip mandate fully enforced; mag-stripe-only fallback must be disabled for domestic transactions
- Card-Not-Present (CNP) transactions: mandatory 2FA, no exemptions for low-value domestic transactions
- International card usage: default OFF, customer activation required per transaction type
- Real-time velocity checks: bank must define and enforce at both issuer and switch level
ATM Security
- Logical security: hard disk encryption, BIOS password, USB port disabling
- Anti-skimming: physical inspection protocol (frequency: minimum monthly for high-risk ATMs)
- Network security: ATM must be on isolated VLAN, no direct internet connectivity
- Software: OS must not be end-of-life; Windows 7/XP ATMs are a critical finding
- Surveillance: CCTV with 90-day retention minimum, monitored centrally
Prepaid Payment Instruments (PPI)
- Full KYC PPI: transaction limits as per RBI PPI Master Directions; limits cannot be enhanced without KYC upgrade
- Semi-closed PPI: interoperability requirements, fund transfer velocity limits
- Fraud monitoring: real-time transaction monitoring mandatory; 24-hour fraud dispute resolution SLA
- Dormancy: auto-block after 1 year of inactivity; customer notification 30 days prior
Fraud Risk Management (Cross-Channel)
"RBI inspectors ask for the Fraud Risk Management Framework as Document 1. If you hand them your general IS Policy with a 'fraud' section, the examination begins poorly."
- Documented FRMF covering all six channels — must be Board-approved
- Transaction monitoring system with defined rules, thresholds, and review cadence
- Suspicious Transaction Reporting (STR) escalation to FIU-IND within 7 days
- Customer awareness: RBI mandates quarterly SMS/email advisories — log evidence required
- Incident reporting: any fraud above ₹1 lakh must be reported to RBI within 2–3 days (channel-specific timelines)
10 Gaps RBI Inspectors Most Commonly Flag
-
No documented FRMF — IS Policy fraud sections don't satisfy the requirement for a standalone Board-approved framework covering all six payment channels.
-
Stale app versions live — No force-upgrade or version sunset policy for mobile banking apps. Apps older than 12 months without a retirement plan are flagged individually.
-
Insufficient device binding — Internet banking sessions not tied to device fingerprints; session tokens transferable across devices.
-
Missing certificate pinning — Mobile API calls vulnerable to MITM; found in older app codebases where SSL validation was bypassed for compatibility.
-
ATM OS end-of-life — Windows 7/XP ATMs still in production. Inspectors flag each affected ATM individually — not as a single finding.
-
Card tokenization gaps — Merchants still storing raw PANs; bank's tokenization rollout incomplete beyond the December 2021 mandate deadline.
-
Weak session timeout — Internet banking timeouts configured at 30 minutes instead of the mandatory 15-minute maximum.
-
No quarterly phishing simulation evidence — DPSC requires evidence of anti-phishing control testing each quarter; a policy stating that testing happens is insufficient.
-
PPI dormancy policy not automated — Manual dormancy review processes fail at scale. RBI expects system-enforced controls with audit logs.
-
STR reporting delays — FIU-IND STR submissions beyond the 7-day window, with incomplete audit trail linking the fraud event to the STR timestamp.
Building Your DPSC Compliance Evidence Pack
Structure the evidence pack by control domain. RBI inspectors typically request five categories of evidence per domain. A policy document alone satisfies none of them.
Evidence Structure Per Domain
- Policy document (Board-approved, version-dated, reviewed within 12 months)
- System configuration screenshots or logs — not just policy assertions about what is configured
- Testing evidence (penetration test reports for internet/mobile banking — annual minimum)
- Monitoring data (fraud monitoring alert logs, review records, escalation trail)
- Incident register (with RBI reporting dates for any reportable incidents)
Practical Compliance Checklist
- FRMF document: Board-approved, covers all 6 channels, last reviewed within 12 months
- Internet banking: MFA implementation evidence, session timeout config, device fingerprinting logs
- Mobile banking: VAPT report (annually), app version sunset policy, certificate pinning evidence
- Cards: PCI-DSS AOC (current), tokenization status report by merchant, CNP 2FA config evidence
- ATMs: Full inventory with OS version, patch status per unit, last physical security inspection date
- PPI: Transaction monitoring rule set, FIU-IND STR log with timestamps, dormancy automation evidence
- Customer advisories: Last 4 quarters of fraud awareness communications with dispatch logs
DPSC and Other RBI Frameworks: Avoiding Double Documentation
DPSC is one of four overlapping RBI frameworks. A siloed approach to each framework creates document sprawl and gaps. The better approach is a single control register cross-mapped to all four.
| Framework | Primary Focus | Overlap with DPSC |
|---|---|---|
| RBI Cyber Security Framework (2016) | Overall bank cyber posture | Incident response, CISO mandate, SOC requirements |
| DPSC (2021) | Digital payment channels specifically | Authentication, fraud monitoring, ATM/card controls |
| RBI IT Governance Framework (2023) | IT strategy, risk, vendor management | Vendor security, IT audit, change management |
| CERT-In Directions (2022) | Incident reporting | 6-hour clock, log retention 180 days, VAPT |
RBI's Enforcement Sequence
-
01IT Examination Observation Issued as part of the inspection report. Bank has 30 days to submit a written response. Observations are internally graded by severity; critical observations require immediate corrective action timelines.
-
02Corrective Action Plan (CAP) Bank submits remediation timeline for each observation. RBI monitors progress quarterly. Slippage against the CAP is itself a finding in the next examination cycle.
-
03Penal Action Letter If remediation is insufficient or repeat gaps are found. Penalty quantum is disclosed publicly on the RBI website. Most DPSC penalties fall in the ₹50 lakh to ₹2 crore range.
-
04Business Restriction For severe or systemic gaps. Rare but has been invoked for digital payment services. May include temporary suspension of specific payment channels pending remediation proof.
Map DPSC Across All 4 Frameworks — Automatically
Managing DPSC evidence across 6 channels, 4 overlapping frameworks, and quarterly inspection cycles is operationally intensive. RiskSage AI maps your controls to DPSC, CERT-In, RBI CSF, and IT Governance Framework simultaneously — so one piece of evidence satisfies multiple requirements automatically.