A REVIEW OF AUTHENTICATION MECHANISMS IN INDIA’S DIGITAL PAYMENT ECOSYSTEM: FROM OTP TO BEHAVIOURAL BIOMETRIC, IN LIGHT OF RBI’S 2025 AUTHENTICATION DIRECTIONS

Authors

  • Divyaraj Parmar Parul University, Vadodara, India.
  • Pankaj Rathod Parul University, Vadodara, India.
  • Vatsal Chandrapal Parul University, Vadodara, India
  • Khyati Kariya Parul University, Vadodara, India

DOI:

https://doi.org/10.70917/ijcisim-2026-4382

Keywords:

India digital payments, authentication mechanisms, OTP, behavioural biometric, RBI 2025 directions, two-factor authentication, UPI security, card-not-present payment, risk-based authentication, digital financial regulation

Abstract

Digital payment, a journey of tremendous growth in India, from the inception of Unified Payments Interface, card-not-present transactions, mobile banking, prepaid payment products, Aadhaar services and merchant digitisation. The scale and convenience that this expansion brings have rendered authentication a key governance and security concern as it can open up opportunities for account takeover, phishing, social engineering, SIM-swap fraud, device compromise, and transaction manipulation. The Reserve Bank of India (RBI) has issued directions on authentication for 2025 that mark a significant shift from a one-time password (OTP) driven authentication system based on SMS to a more comprehensive, principles-based and risk-sensitive authentication framework. The directions continue to mandate two factor authentication for the majority of digital payments transactions, but add the requirement for at least two authenticating factors for digital payments transactions (non-card-present) and at least one dynamic or provable factor for digital payments transactions that are not card-present. They also enable more risk based checks depending on the context of the transactions, as well as the perception of fraud, but not any one specific technical pathway. 
This paper discusses the different type of authentication models that have been developed in India, ranging from pin, otp, biometric to behavioural biometric model and its regulatory, technical and operational implications as per the directions issued in 2025. A comparative analysis of the regulatory materials is carried out and a doctrinal and analytical review methodology is applied which takes into account all the authentication factors (knowledge, possession, inherence, contextual intelligence) with the most recent security discourse. The results section is designed in a manner that allows for comparison of the mainstream methods based on the strength of the security, ease of use, deployability, resistance to fraud, impact on privacy visibility and regulatory fit in the RBI context.
The paper concludes that OTP-based systems are also important, but also become increasingly inadequate as a solution to today's frauds, due to their susceptibility to interception, manipulation, and social engineering. While not ideal, behavioural biometric systems provide a strong second line of risk scoring, anomaly detection and adaptive authentication. What will work best for India is not simply to replace OTP with biometrics with a single model, but a multi-layered model where aspects of dynamic authentication, device intelligence, behavioural signals and transaction risk analytics all play a part within a standards-based interoperable compliance regime. The RBI guidelines underscore the importance of transitioning towards the adaptive trust mechanism rather than phasing out the existing mechanism for digital transactions.

Downloads

Download data is not yet available.

Downloads

Published

2026-08-08

How to Cite

Divyaraj Parmar, Pankaj Rathod, Vatsal Chandrapal, & Khyati Kariya. (2026). A REVIEW OF AUTHENTICATION MECHANISMS IN INDIA’S DIGITAL PAYMENT ECOSYSTEM: FROM OTP TO BEHAVIOURAL BIOMETRIC, IN LIGHT OF RBI’S 2025 AUTHENTICATION DIRECTIONS. International Journal of Computer Information Systems and Industrial Management Applications, 18(15s), 150–160. https://doi.org/10.70917/ijcisim-2026-4382

Issue

Section

Original Articles