Why in the News
The Reserve Bank of India (RBI) has launched a tap and pay facility for Unified Payments Interface (UPI) transactions in partnership with the National Payments Corporation of India (NPCI). It settles RuPay credit card payments of up to Rs 5,000 without a one time password or a QR code, and transactions above that threshold still require a PIN. The facility answers the RBI’s own mandate of two factor authentication for UPI transactions from 1 April 2026, which forced payment companies to find a second factor that is not an interceptable code. The tension is that the instrument being removed, the one time password, is also the instrument that recorded a customer’s explicit consent, and the rail carrying about 85 percent of India’s electronic payment transactions is being re engineered around its absence.
How does the tap and pay facility work?
- The connectivity shift: The transaction runs on the point of sale terminal’s own internet connection. The customer’s phone does not need internet access for the payment to complete.
- What is removed: Neither a QR code nor a one time password is required for the payment to be authorised within the threshold.
- The value ceiling: The facility currently covers transactions of up to Rs 5,000. Above that, the customer enters a PIN.
- The instrument carried: It settles payments made on a RuPay credit card linked to the UPI rail, rather than a direct bank account debit.
Why is authentication being redesigned rather than strengthened?
- The fraud vector is the code itself: The growth of digital payments has been accompanied by theft and inadvertent sharing of one time passwords and other authentication credentials, so the credential is the attack surface.
- The regulatory trigger: The RBI mandated two factor authentication for UPI transactions from 1 April 2026, which required a second factor that could not simply be a second code.
- Friction as an adoption limit: UPI’s adoption rested on the convenience of retail and utility payments without cash, and each added verification step works against the property that produced the adoption.
- Possession replaces knowledge: Moving the second factor to the card and the terminal replaces something a fraudster can extract by conversation with something they must physically hold.
What alternatives to the one time password are payment companies building?
- Passkeys: Visa and Mastercard have introduced passkeys, cryptographic credentials stored on the user’s own device, as an additional authentication mechanism in place of a transmitted code.
- Device biometrics: Mastercard has showcased its Consumer Device Cardholder Verification Method (CDCVM), which authenticates a transaction through the device’s fingerprint or facial recognition. Mastercard has partnered with Google Pay to offer it.
- Terminal side authentication: The RBI and NPCI facility shifts verification to the merchant terminal, which is a different design choice from the card networks’ device side methods.
What does the shift mean for UPI’s market structure?
- Scale of the rail: UPI accounts for about 85 percent of electronic payment transactions in India, so a change in its authentication design is a change in the country’s default payment method.
- Credit on an account to account rail: Routing RuPay credit card payments through UPI converts a transfer rail into a credit distribution channel, which changes who earns on each transaction.
- A contestable margin: Amazon Pay, which accounts for less than 1 percent of UPI transactions, has introduced a tap and pay facility for its partner merchants as it seeks to expand its share, so the new interface is being treated as a market entry point.
- Origins of the volume: UPI was introduced in the aftermath of demonetisation and its adoption was driven by the convenience of cashless retail and utility payments, not by a pricing incentive that could be withdrawn.
Challenges to a code-less payment system
- Loss of an explicit consent step: Removing the one time password removes the moment where a user actively confirms a specific amount to a specific payee. Eg. A contactless card in a lost wallet can be used repeatedly below the no PIN threshold before the loss is noticed.
The Fix: Require a cumulative daily cap across all no PIN taps on a card, after which a PIN is forced regardless of individual transaction size. - Terminal dependence shifts risk to the merchant: The transaction now relies on the merchant terminal’s connectivity and software integrity rather than on the customer’s device. Eg. Card skimming at compromised point of sale terminals has been a recurring source of card data theft in India.
The Fix: Mandate certified tamper responsive terminals with remote attestation before a merchant is enabled for no PIN acceptance. - Dispute resolution is weaker without a credential trail: A customer contesting a tap based transaction has no credential event to point to, which shifts the evidentiary burden onto them. Eg. Digital payment complaints have consistently formed a large share of grievances handled under the RBI’s Ombudsman scheme.
The Fix: Fix a defined chargeback window with reversal by default for contested no PIN transactions below the threshold, with the loss allocated between acquirer and issuer. - Concentration risk on a single rail: A rail carrying about 85 percent of electronic payment transactions turns a single outage into a nationwide payments failure. Eg. UPI has experienced multi hour outages that halted retail payments across merchants simultaneously.
The Fix: Require large merchants and aggregators to maintain a certified fallback acceptance mode that does not route through the same rail. - Exclusion by device and connectivity: A design built around modern terminals and cards leaves out merchants and users without them. Eg. Feature phone users depend on the offline UPI123Pay channel rather than on app based flows.
The Fix: Set a floor requirement that every new acceptance standard is released on the feature phone and offline channels before it is promoted to merchants.
Conclusion
India’s dominant payment rail is being rebuilt around the removal of the credential fraudsters were harvesting, with possession of a card and a terminal replacing knowledge of a code. The design transfers security responsibility from the customer to merchant infrastructure, and the dispute rules have not been rewritten to match that transfer. The marker to watch is whether the RBI raises the no PIN ceiling, since that threshold is the only thing currently bounding the exposure.
Back2Basics: National Payments Corporation of India
- What it is: NPCI is the umbrella organisation for retail payments and settlement systems in India.
- Origins: It was set up in 2008 as an initiative of the Reserve Bank of India and the Indian Banks’ Association.
- Legal form: It is a not for profit company registered under Section 8 of the Companies Act, 2013, so it is an industry utility rather than a government department or a regulator.
- What it operates: It runs UPI, RuPay, the Immediate Payment Service, the National Automated Clearing House, FASTag and the Aadhaar Enabled Payment System.
Matching Previous Year Question
“[2026] Which one of the following statements about Unified Payments Interface (UPI) and Central Bank Digital Currency (Digital Rupee) is NOT correct? (a) UPI is a real-time payment system but Digital Rupee is akin to sovereign paper currency (b) In case of UPI, settlement for end users happens instantly; in case of Digital Rupee, wallet balance gets transferred to another wallet (no traditional settlement) (c) UPI transactions are recorded by banks and reflected in bank statements; in case of Digital Rupee, no data is captured in bank statements (d) In both the cases (UPI and Digital Rupee), the liability lies with the users and their respective banks Answer: (d)”
