What DPSC Actually Means for Your Bank

RBI's Master Direction on Digital Payment Security Controls (DPSC), issued February 18, 2021, is the most operationally dense cybersecurity regulation the Indian banking sector has faced. It covers 75+ mandatory controls across six digital payment channels — and unlike SEBI CSCRF which is an annual declaration exercise, RBI inspectors verify DPSC controls during IT examinations.

Non-compliance triggers penalty letters, corrective action plans, and in serious cases, business restrictions. The reputational impact of a published penalty often exceeds the financial penalty itself.

Who Must Comply

DPSC applies to a wider set of entities than most compliance teams initially assume:

  • Scheduled Commercial Banks (including Private, PSU, Foreign)
  • Small Finance Banks
  • Payment Banks
  • White Label ATM Operators (WLAOs)
  • Card Payment Networks operating in India
  • Prepaid Payment Instrument (PPI) issuers regulated by RBI
  • NBFCs providing digital payment services (treat DPSC as baseline even without explicit mandate)

Six Control Domains: What RBI Actually Checks

Each of the six domains carries specific technical and procedural requirements. The "most common inspection gap" in each domain reflects patterns from DPSC-related examination observations.

Domain 01

Internet Banking Security

  • Mandatory multi-factor authentication (MFA) for all transactions — OTP alone does not satisfy MFA for high-value transfers
  • Risk-based transaction limits configurable by customers; defaults must be conservative
  • Device binding for registered internet banking sessions
  • Session timeout ≤15 minutes for inactive sessions
  • End-to-end encryption for all data in transit (TLS 1.2 minimum, TLS 1.3 recommended)
  • Anti-phishing controls: DMARC/DKIM/SPF enforced, visual indicators validated quarterly
Most Common Inspection Gap Device fingerprinting either absent or not logged for forensics. Session tokens that are transferable across devices fail the device binding requirement even when device registration exists at onboarding.
Domain 02

Mobile Banking Security

  • Certificate pinning mandatory for mobile banking apps
  • Jailbreak/root detection with session termination
  • No caching of sensitive data (account numbers, credentials) on device storage
  • App hardening: code obfuscation, anti-tampering, binary protection
  • API security: signed requests, replay attack prevention, rate limiting
Most Common Inspection Gap Older app versions remain live without force-upgrade mechanisms. RBI expects a documented sunset policy for versions older than 12 months. Apps published before the DPSC effective date and never sunsetted are a systemic finding.
Domain 03

Card Security Controls

  • PCI-DSS compliance is a prerequisite, not a substitute — RBI maps PCI controls to DPSC requirements
  • EMV chip mandate fully enforced; mag-stripe-only fallback must be disabled for domestic transactions
  • Card-Not-Present (CNP) transactions: mandatory 2FA, no exemptions for low-value domestic transactions
  • International card usage: default OFF, customer activation required per transaction type
  • Real-time velocity checks: bank must define and enforce at both issuer and switch level
Most Common Inspection Gap Tokenization roadmap incomplete. RBI mandated card-on-file tokenization by December 2021; many smaller banks still have merchant integrations storing raw PANs. Inspectors ask for a merchant-by-merchant tokenization status report.
Domain 04

ATM Security

  • Logical security: hard disk encryption, BIOS password, USB port disabling
  • Anti-skimming: physical inspection protocol (frequency: minimum monthly for high-risk ATMs)
  • Network security: ATM must be on isolated VLAN, no direct internet connectivity
  • Software: OS must not be end-of-life; Windows 7/XP ATMs are a critical finding
  • Surveillance: CCTV with 90-day retention minimum, monitored centrally
Most Common Inspection Gap ATM patch management. RBI expects patches within 30 days of vendor release; most banks operate on quarterly patch cycles. Inspectors ask for the patch log per ATM — not a bank-wide policy statement.
Domain 05

Prepaid Payment Instruments (PPI)

  • Full KYC PPI: transaction limits as per RBI PPI Master Directions; limits cannot be enhanced without KYC upgrade
  • Semi-closed PPI: interoperability requirements, fund transfer velocity limits
  • Fraud monitoring: real-time transaction monitoring mandatory; 24-hour fraud dispute resolution SLA
  • Dormancy: auto-block after 1 year of inactivity; customer notification 30 days prior
Most Common Inspection Gap PPI issuers often lack a documented Fraud Risk Management Framework (FRMF). RBI considers this a standalone Board-approved deliverable — not just a fraud section inside the IS Policy. The absence of a standalone FRMF is flagged as a primary finding.
Domain 06

Fraud Risk Management (Cross-Channel)

"RBI inspectors ask for the Fraud Risk Management Framework as Document 1. If you hand them your general IS Policy with a 'fraud' section, the examination begins poorly."

  • Documented FRMF covering all six channels — must be Board-approved
  • Transaction monitoring system with defined rules, thresholds, and review cadence
  • Suspicious Transaction Reporting (STR) escalation to FIU-IND within 7 days
  • Customer awareness: RBI mandates quarterly SMS/email advisories — log evidence required
  • Incident reporting: any fraud above ₹1 lakh must be reported to RBI within 2–3 days (channel-specific timelines)

10 Gaps RBI Inspectors Most Commonly Flag

Important These 10 gaps are drawn from DPSC-related inspection observations and penalty letters in the public domain. They represent the highest-frequency findings across examination cycles — your remediation prioritisation should start here.
  1. No documented FRMF — IS Policy fraud sections don't satisfy the requirement for a standalone Board-approved framework covering all six payment channels.
  2. Stale app versions live — No force-upgrade or version sunset policy for mobile banking apps. Apps older than 12 months without a retirement plan are flagged individually.
  3. Insufficient device binding — Internet banking sessions not tied to device fingerprints; session tokens transferable across devices.
  4. Missing certificate pinning — Mobile API calls vulnerable to MITM; found in older app codebases where SSL validation was bypassed for compatibility.
  5. ATM OS end-of-life — Windows 7/XP ATMs still in production. Inspectors flag each affected ATM individually — not as a single finding.
  6. Card tokenization gaps — Merchants still storing raw PANs; bank's tokenization rollout incomplete beyond the December 2021 mandate deadline.
  7. Weak session timeout — Internet banking timeouts configured at 30 minutes instead of the mandatory 15-minute maximum.
  8. No quarterly phishing simulation evidence — DPSC requires evidence of anti-phishing control testing each quarter; a policy stating that testing happens is insufficient.
  9. PPI dormancy policy not automated — Manual dormancy review processes fail at scale. RBI expects system-enforced controls with audit logs.
  10. STR reporting delays — FIU-IND STR submissions beyond the 7-day window, with incomplete audit trail linking the fraud event to the STR timestamp.

Building Your DPSC Compliance Evidence Pack

Structure the evidence pack by control domain. RBI inspectors typically request five categories of evidence per domain. A policy document alone satisfies none of them.

Evidence Structure Per Domain

  • Policy document (Board-approved, version-dated, reviewed within 12 months)
  • System configuration screenshots or logs — not just policy assertions about what is configured
  • Testing evidence (penetration test reports for internet/mobile banking — annual minimum)
  • Monitoring data (fraud monitoring alert logs, review records, escalation trail)
  • Incident register (with RBI reporting dates for any reportable incidents)

Practical Compliance Checklist

  • FRMF document: Board-approved, covers all 6 channels, last reviewed within 12 months
  • Internet banking: MFA implementation evidence, session timeout config, device fingerprinting logs
  • Mobile banking: VAPT report (annually), app version sunset policy, certificate pinning evidence
  • Cards: PCI-DSS AOC (current), tokenization status report by merchant, CNP 2FA config evidence
  • ATMs: Full inventory with OS version, patch status per unit, last physical security inspection date
  • PPI: Transaction monitoring rule set, FIU-IND STR log with timestamps, dormancy automation evidence
  • Customer advisories: Last 4 quarters of fraud awareness communications with dispatch logs

DPSC and Other RBI Frameworks: Avoiding Double Documentation

DPSC is one of four overlapping RBI frameworks. A siloed approach to each framework creates document sprawl and gaps. The better approach is a single control register cross-mapped to all four.

Framework Primary Focus Overlap with DPSC
RBI Cyber Security Framework (2016) Overall bank cyber posture Incident response, CISO mandate, SOC requirements
DPSC (2021) Digital payment channels specifically Authentication, fraud monitoring, ATM/card controls
RBI IT Governance Framework (2023) IT strategy, risk, vendor management Vendor security, IT audit, change management
CERT-In Directions (2022) Incident reporting 6-hour clock, log retention 180 days, VAPT
Key Insight Build a single control register mapped to all four frameworks. Where DPSC requires quarterly phishing testing and the Cyber Security Framework requires annual security awareness, one programme satisfies both — but you need cross-references in your evidence pack. One piece of evidence serving multiple requirements is the goal; duplicated evidence packs is the anti-pattern.

RBI's Enforcement Sequence

Enforcement Reality RBI has levied penalties ranging from ₹50 lakh to ₹2 crore on banks for DPSC-related deficiencies. Penalties are published on the RBI website. The reputational impact often exceeds the financial penalty. Inspection observations from one bank frequently signal what RBI will look for at peers in the same examination cycle.
  1. 01
    IT Examination Observation Issued as part of the inspection report. Bank has 30 days to submit a written response. Observations are internally graded by severity; critical observations require immediate corrective action timelines.
  2. 02
    Corrective Action Plan (CAP) Bank submits remediation timeline for each observation. RBI monitors progress quarterly. Slippage against the CAP is itself a finding in the next examination cycle.
  3. 03
    Penal Action Letter If remediation is insufficient or repeat gaps are found. Penalty quantum is disclosed publicly on the RBI website. Most DPSC penalties fall in the ₹50 lakh to ₹2 crore range.
  4. 04
    Business Restriction For severe or systemic gaps. Rare but has been invoked for digital payment services. May include temporary suspension of specific payment channels pending remediation proof.

Map DPSC Across All 4 Frameworks — Automatically

Managing DPSC evidence across 6 channels, 4 overlapping frameworks, and quarterly inspection cycles is operationally intensive. RiskSage AI maps your controls to DPSC, CERT-In, RBI CSF, and IT Governance Framework simultaneously — so one piece of evidence satisfies multiple requirements automatically.