Skip to content

ADVOCATETANMOY LAW LIBRARY

Research & Library Database

Primary Menu
  • News
  • Opinion
  • Countries198
    • National Constitutions: History, Purpose, and Key Aspects
  • Judgment
  • Book
  • Legal Brief
    • Legal Eagal
  • LearnToday
  • HLJ
    • Supreme Court Case Notes
    • Daily Digest
  • Sarvarthapedia
    • Sarvarthapedia (Core Areas)
    • Systemic-and-systematic
    • Volume One
03/04/2026
  • Money and Banking

RBI guidelines on Tokenisation – Card Transactions

advtanmoy 13/01/2019 7 minutes read

© Advocatetanmoy Law Library

  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook
  • Share on Telegram (Opens in new window) Telegram
Reserve Bank of India

Home » Law Library Updates » Sarvarthapedia » Business and Industry » Money and Banking » RBI guidelines on Tokenisation – Card Transactions

The Reserve Bank has released guidelines on tokenisation for debit/credit/ prepaid card transactions as a part of its continuous endeavour to enhance the safety and security of the payment systems in the country. Tokenisation involves a process in which a unique token masks sensitive card details. Thereafter, in lieu of actual card details, this token is used to perform card transactions in contactless mode at Point Of Sale(POS) terminals, Quick Response(QR) code payments, etc.

These guidelines permit authorised card payment networks to offer card tokenisation services to any token requestor (third party app provider), subject to conditions enumerated in these guidelines. A cardholder may avail of these services by registering the card on the token requestor’s app after giving explicit consent. No charges shall be recovered from the customer for availing this service.


RBI/2018-19/103
DPSS.CO.PD No.1463/02.14.003/2018-19

Read Next

  • Asia Pacific Economic Outlook 2024: IMF Key Growth Projections
  • India’s Forex Reserves 2024 | RBI 43rd Half Yearly Report
  • Cross-border Payments: Global Future of Fast & Safe Transfer

January 08, 2019

The Chief Executive Officer / President
All authorised card payment networks

Madam / Dear Sir,

Tokenisation – Card transactions

Read Next

  • Asia Pacific Economic Outlook 2024: IMF Key Growth Projections
  • India’s Forex Reserves 2024 | RBI 43rd Half Yearly Report
  • Cross-border Payments: Global Future of Fast & Safe Transfer

Continuing the efforts to improve safety and security of card transactions, Reserve Bank of India had permitted card networks for tokenisation in card transactions for a specific use case.

  1. It has now been decided to permit authorised card payment networks to offer card tokenisation services to any token requestor (i.e., third party app provider), subject to the conditions listed in Annex 1. This permission extends to all use cases / channels [e.g., Near Field Communication (NFC) / Magnetic Secure Transmission (MST) based contactless transactions, in-app payments, QR code-based payments, etc.] or token storage mechanisms (cloud, secure element, trusted execution environment, etc.). For the present, this facility shall be offered through mobile phones / tablets only. Its extension to other devices will be examined later based on experience gained.
  2. All extant instructions of Reserve Bank on safety and security of card transactions, including the mandate for Additional Factor of Authentication (AFA) / PIN entry shall be applicable for tokenised card transactions also.

  3. All other instructions related to card transactions shall be applicable for tokenised card transactions as well. The ultimate responsibility for the card tokenisation services rendered rests with the authorised card networks.

    Read Next

    • Asia Pacific Economic Outlook 2024: IMF Key Growth Projections
    • India’s Forex Reserves 2024 | RBI 43rd Half Yearly Report
    • Cross-border Payments: Global Future of Fast & Safe Transfer

  4. No charges should be recovered from the customer for availing this service.

  5. Before providing card tokenisation services, authorised card payment networks shall put in place a mechanism for periodic system (including security) audit at frequent intervals, at least annually, of all entities involved in providing card tokenisation services to customers. This system audit shall be undertaken by empanelled auditors of Indian Computer Emergency Response Team (CERT-In) and all related instructions of Reserve Bank in respect of system audits shall also be adhered to. A copy of this audit report shall be furnished to the Reserve Bank, with comments of auditors on deviations, if any, from the conditions listed in Annex 1, along with the compliance thereto. Further, a report on the details provided in Annex 2 shall be submitted at monthly intervals to the Chief General Manager, Reserve Bank of India, Department of Payment and Settlement Systems, Central Office, Mumbai and by email.

  6. This directive is issued under Section 10 (2) read with Section 18 of Payment and Settlement Systems Act, 2007 (Act 51 of 2007).

Yours faithfully,

(P Vasudevan)
Chief General Manager

Encl.: As above



Annex 1

(DPSS.CO.PD.No.1463/02.14.003/2018-19 dated January 08, 2019)

Card tokenisation services

Tokenisation refers to replacement of actual card details with an unique alternate code called the “token”, which shall be unique for a combination of card, token requestor and device (referred hereafter as “identified device”).

Conditions

Tokenisation – de-tokenisation service

i. Tokenisation and de-tokenisation shall be performed only by the authorised card network and recovery of original Primary Account Number (PAN) should be feasible for the authorised card network only. Adequate safeguards shall be put in place to ensure that PAN cannot be found out from the token and vice versa, by anyone except the card network. Integrity of token generation process shall be ensured at all times.

ii. Tokenisation and de-tokenisation requests should be logged by the card network and available for retrieval, if required.

iii. Actual card data, token and other relevant details shall be stored in a secure mode. Token requestors shall not store PAN or any other card detail.

Certification of systems of card issuers/acquirers, token requestors and their app, etc.

iv. Card network shall get the token requestor certified for (a) token requestor’s systems, including hardware deployed for this purpose, (b) security of token requestor’s application, (c) features for ensuring authorised access to token requestor’s app on the identified device, and, (d) other functions performed by the token requestor, including customer on-boarding, token provisioning and storage, data storage, transaction processing, etc.

v. Card networks shall get the card issuers/acquirers, their service providers and any other entity involved in payment transaction chain, certified in respect of changes done for processing tokenised card transactions by them.

vi. All certification / security testing by the card network shall conform to international best practices / globally accepted standards.

Registration by customer

vii. Registration of card on token requestor’s app shall be done only with explicit customer consent through Additional Factor of Authentication (AFA), and not by way of a forced / default / automatic selection of checkbox, radio button, etc.

viii. AFA validation during card registration, as well as, for authenticating any transaction, shall be as per extant Reserve Bank instructions for authentication of card transactions.

ix. Customers shall have option to register / de-register their card for a particular use case, i.e., contactless, QR code based, in-app payments, etc.

x. Customers shall be given option to set and modify per transaction and daily transaction limits for tokenised card transactions.

xi. Suitable velocity checks (i.e., how many such transactions will be allowed in a day /week/month) may be put in place by card issuers/card network as considered appropriate, for tokenised card transactions.

xii. For performing any transaction, the customer shall be free to use any of the cards registered with the token requestor app.

Secure storage of tokens

xiii. Secure storage of tokens and associated keys by token requestor on successful registration of card shall be ensured.

Customer service and dispute resolution

xiv. Card issuers shall ensure easy access to customers for reporting loss of “identified device” or any other such event which may expose tokens to unauthorised usage. Card network, along with card issuers and token requestors, shall put in place a system to immediately de-activate such tokens and associated keys.

xv. Dispute resolution process shall be put in place by card network for tokenised card transactions.

Safety and security of transactions

xvi. Card network shall put in place a mechanism to ensure that the transaction request has originated from an “identified device”.

xvii. Card network shall ensure monitoring to detect any malfunction, anomaly, suspicious behaviour or the presence of unauthorized activity within the tokenisation process, and implement a process to alert all stakeholders.

xviii. Based on risk perception, etc., card issuers may decide whether to allow cards issued by them to be registered by a token requestor.


Annex 2

Reporting format for tokenisation service by authorised card networks 
(DPSS.CO.PD.No.1463/02.14.003/2018-19 dated January 08, 2019)
(to be furnished by 10th of each month)

Name of authorised card network: …………………………………..

Report for the month: ……………………….

Sr. No. Name of token requestor Brand name, if any, of the service Use cases enabled (contactless – NFC / MST, in-app, QR code-based, etc.) Token storage mechanism employed Effective date of arrangement No. of cards registered
Credit Cards Debit Cards Prepaid Cards

Note: Above data shall be as at end of month

Sr. No. Name of token requestor Transaction data for the month*
Credit Cards Debit Cards Prepaid Cards
Number Value (in Rs.) Number Value (in Rs.) Number Value (in Rs.)

*Transaction data to be provided for each use case enabled by the card network

Tags: Reserve Bank Guidelines

Post navigation

Previous: THE CONSTITUTION (ONE HUNDRED AND TWENTY-FOURTH AMENDMENT) Bill, 2019
Next: RBI guidelines on restructuring of advances to Micro, Small and Medium Enterprises (MSME) sector
Arrest
Sarvarthapedia

Latin Maxims in Criminal Law: Meaning, Usage, and Courtroom Application

Sarvarthapedia
Sarvarthapedia

Research Methodology and Investigation: Concepts, Frameworks, and Emerging Trends

IPS Cadre Strength 2025: State-wise Authorised Strength

Uric Acid: From 18th Century Discovery to Modern Medical Science

Christian Approaches to Interfaith Dialogue: Orthodox, Catholic, Protestant, and Pentecostal Views

Origin of Central Banking in India: From Hastings to RBI and the History of Preparatory Years (1773–1934)

Howrah District Environment Plan: Waste Management, Water Quality & Wetland Conservation

Bharatiya Nyaya Sanhita 2023: Sections (1-358), Punishments, and Legal Framework

Bengali Food Culture: History, Traditions, and Class Influences

West Bengal Court-Fees Act, 1970: Fees, Schedules, and Procedures

WB Land Reforms Tribunal Act 1997: History, Features, Provisions, Structure, Powers and Functions

Civil Procedure Law of the Democratic People’s Republic of Korea (1976)

Knowledge Management in the Modern Era: From History to Digital Transformation

Vedic Interpretation Methodical Style: History, Principles, and Evolution  From Yaska to Aurobindo

  • Sarvarthapedia

  • Delhi Law Digest

  • Howrah Law Journal

  • Amit Arya vs Kamlesh Kumari: Doctrine of merger
  • David Vs. Kuruppampady: SLP against rejecting review by HC (2020)
  • Nazim & Ors. v. State of Uttarakhand (2025 INSC 1184)
  • Geeta v. Ajay: Expense for daughter`s marriage allowed in favour of the wife
  • Ram v. Sukhram: Tribal women’s right in ancestral property [2025] 8 SCR 272
  • Naresh vs Aarti: Cheque Bouncing Complaint Filed by POA (02/01/2025)
  • Bharatiya Nagarik Suraksha Sanhita 2023 (BNSS)
  • Bharatiya Sakshya Adhiniyam 2023 (BSA): Indian Rules for Evidence
  • Bharatiya Nyaya Sanhita (BNS) 2023
  • The Code of Civil Procedure (CPC)
  • Supreme Court Daily Digest
  • U.S. Supreme Court Orders
  • U.k. Supreme Court Orders
Indian Government

IPS Cadre Strength 2025: State-wise Authorised Strength

Sarvarthapedia

Uric Acid: From 18th Century Discovery to Modern Medical Science

Christian Education

Christian Approaches to Interfaith Dialogue: Orthodox, Catholic, Protestant, and Pentecostal Views

Reserve Bank Of India

Origin of Central Banking in India: From Hastings to RBI and the History of Preparatory Years (1773–1934)

2026 © Advocatetanmoy Law Library

  • About
  • Global Index
  • Judicial Examinations
  • Indian Statutes
  • Glossary
  • Legal Eagle
  • Subject Guide
  • Journal
  • SCCN
  • Constitutions
  • Legal Brief (SC)
  • MCQs (Indian Laws)
  • Sarvarthapedia (Articles)
  • Contact Us
  • Privacy Policy
  • FAQs
  • Library Updates