RBI - Master Directions on Cyber Resilience and Digital Payment Security Controls for Non-bank Payment System Operators, 2024
AI / PRIVACY / CYBER RELEVANCE
Relevant to AI fraud systems, payment analytics, AI APIs, cloud processing and third-party AI providers in payment infrastructure.
AI: HighPrivacy: HighCybersecurity: Very High
READ FIRST
- Section I applicability
- Section II governance
- Section III data security, APIs, vendor risk and cloud security
- new technology risk assessment before deployment
PURVIEW
Establishes RBI’s cyber-resilience and digital-payment security controls for non-bank Payment System Operators. It covers governance, information-security architecture, access control, application security, vulnerability assessment, incident response, business continuity, data security and resilience of payment infrastructure. For AI, the Directions are important because non-bank payment systems increasingly use analytics, machine learning, automated fraud detection and AI-enabled customer-service tools while processing highly sensitive financial information. The framework therefore requires AI-enabled payment operations to sit inside a broader cyber-resilience programme with controlled access, secure processing, monitoring, auditability and incident response.
Classification and legal status. Binding RBI Master Directions for authorised non-bank PSOs, with phased compliance dates.