IN · run world-payments-2026-06-24 v13.3.0
content: ai_generated 104 sources retrieved model claude-opus-4-8 ·

India

IN schema world-payments-v1 trajectory: not recorded

Last updated · 14 modules · 61 sourced findings · 104 sources in the cumulative register

14Modulesbaseline.modules[]
61Findingsmodules[].findings[]
16Tier-1 sourcesrun_metadata.t1_source_count
Confidence mix (sums to 14 rendered modules; click to filter)
No modules moved this cycle.

Jurisdiction brief

Lead Signal

This cycle establishes the full India (IN) payments baseline across all fourteen modules of the spine, and the defining feature is unambiguous: India operates a uniquely state-rail-centric payments architecture in which the Reserve Bank of India is simultaneously the authorising authority, the settlement operator, and the conduct supervisor. UPI handles roughly 86% of India's digital transaction volume, processing more than 23 billion payments per month at around INR30 lakh crore. That volume runs on rails where merchant discount revenue has been statutorily zero since January 2020 for RuPay debit cards and BHIM-UPI, under Section 10A of the PSS Act and Section 269SU of the Income-tax Act, funded instead by a government incentive scheme paid to acquiring banks. The architecture is CBDC-led rather than stablecoin-permissive: the Digital Rupee retail and wholesale pilots are live, while RBI advocates prioritising central bank digital currency over privately issued stablecoins and maintains no in-force stablecoin framework. This concentration of public infrastructure power is the structural fact distinguishing India from the EU, UK and US payments markets.

14 of 14 modules
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

RBI finalised a comprehensive rewrite of the Payment Aggregator (PA) framework (RBI/DPSS/2025-26/141, notified 15 Sept 2025), covering Online PAs, Cross-Border PAs (PA-CB) and, for the first time, Offline PAs. Compliance timelines run into 2026.

Standing sub-brief247 words · last cycle wpm-2026-09-05

Licensing, Authorisation & Market Access

India's payment-aggregator licensing perimeter has moved from transition into full operation. The RBI (Regulation of Payment Aggregators) Directions, 2025, issued 15 September 2025 and effective immediately, require non-bank payment aggregators to obtain RBI authorisation under the PSS Act, carrying a Payment Aggregator authorisation under Section 7 with no exemption available. The prudential ladder sets net worth at INR15cr at application, rising to INR25cr by the end of the third financial year, alongside escrow-only settlement and Companies Act 2013 incorporation.

Periodic update · new data 2026-09-08 · run wpm-2026-09-05

Licensing, Authorisation & Market Access

The Reserve Bank of India's rewritten Payment Aggregator Directions, reference RBI/DPSS/2025-26/141 and notified 15 September 2025, constitute a confirmed, high-impact, comprehensive rewrite of the licensing and market-access framework for payment aggregators in India. The central structural innovation is the introduction of an Offline PA category for the first time, bringing offline-context payment aggregation into an authorisation regime that had previously applied only to online aggregation. The directions explicitly repeal the prior 2020 intermediary-transactions circular except for decisions already pending authorisation, a confirmed finding that establishes a clean regulatory handover rather than an overlapping dual regime.

The new framework carries distinct compliance timelines for different aggregator sub-categories. Existing offline PAs were required to apply for RBI authorisation by 31 December 2025, a probable-confidence deadline; critically, this leeway is not available for merchants onboarded after 1 January 2026, who face the new requirements immediately upon onboarding rather than benefiting from any transition window. This bifurcation means firms operating offline-PA business lines must track two distinct compliance populations -- pre-existing merchants under a grace period, and new merchants under immediate compliance -- within the same regulatory category.

Cross-border payment aggregators (PA-CBs) see a combined liberalisation and tightening. Their permissible scope is liberalised: PA-CBs may now process any permissible current-account transaction under FEMA, rather than being restricted to trade transactions alone, a probable-confidence expansion of their addressable business. This liberalisation is paired with a new INR 25 crore net-worth requirement, due by 31 March 2026, meaning the broadened scope of permissible activity is conditioned on a materially higher capital base than may have previously applied to smaller cross-border aggregators. Separately, non-bank payment aggregators, including the newly created offline PA-P category, are confirmed as PMLA reporting entities that must register with FIU-IND, carrying this finding through from the AML-adjacent scope of the same directions rather than from original AML analysis produced here.

Throughout this framework, the distinction between bank-affiliated PSPs and non-bank payment institution/e-money-institution aggregators remains operationally significant: the net-worth threshold, authorisation deadlines and PMLA registration obligations bear most directly on the non-bank PI/EMI population, which had previously operated under lighter-touch oversight relative to bank-affiliated payment processors.

Outlook

The compliance calendar is front-loaded through the first three quarters of the 2025-26 to 2026-27 window: the offline-PA authorisation deadline of 31 December 2025 has already passed, an extended merchant-CDD compliance deadline runs to 15 September 2026 for merchants onboarded before 31 December 2025, and the PA-CB net-worth threshold falls due 31 March 2026. Supervisory attention through this period is likely to concentrate on authorisation-status verification for offline PAs and net-worth compliance for cross-border aggregators. Watch for RBI guidance clarifying the merchant-CDD extended-deadline population and for any enforcement action against aggregators that miss the passed 31 December 2025 offline-PA authorisation deadline.

Sources and findings (4)
  1. T1RBI (Regulation of Payment Aggregators) Directions 2025 (15 Sep 2025) (rbi.org.in)
  2. T1RBI PA Directions 2025 — ₹15cr/₹25cr net worth (rbi.org.in)
  3. T3https://www.mondaq.com/india/corporate-and-company-law/877826/part-i-rbi-proposes-regulation-licensing-of-payment-aggregator-and-gateways [CAVEAT: Tier 3 secondary source — Assessed; verify vs primary pre-publication]
  4. T3https://www.businesstoday.in/latest/corporate/story/rbi-grants-payment-aggregator-licence-to-32-entities-heres-the-full-list-370397-2023-02-15 [CAVEAT: Tier 3 secondary source — Assessed; verify vs primary pre-publication]

#

Customer-fund safeguarding for both PAs and non-bank PPI issuers rests on a mandatory escrow account held with a single scheduled commercial bank, with no co-mingling, day-end balance floors, and quarterly statutory-auditor certification. For escrow purposes the non-bank PPI issuer/PA is deemed a 'designated payment system' under the PSS Act. Conduct is supervised by RBI's DPSS; the draft PPI MD 2026 adds codified fit-and-proper criteria, multilingual disclosure and grievance-redress obligations. [CAVEAT: draft PPI Master Direction released 22 Apr 2026, comments to 22 May 2026; not yet finalised as of late Jun 2026.]

Horizon · 2026-H2 (±half_year)Final RBI Master Direction on Prepaid Payment Instruments 2026consultation · T2
Standing sub-brief212 words · last cycle wpm-2026-09-05

Conduct, Safeguarding & Promotions

India's safeguarding model for non-bank PPI issuers and payment aggregators rests on a mandatory single-bank INR escrow account held with a scheduled commercial bank, with no co-mingling, a day-end balance floor not below outstanding PPIs plus acquirer dues, and quarterly statutory-auditor certification. The non-bank PPI issuer or PA is deemed a designated payment system under Section 23A(3) of the PSS Act, and the PPI issuer holds a perpetual, conditional Certificate of Authorisation. This escrow-based approach contrasts with the EU/UK segregation-plus-insurance models, carrying the bank versus non-bank distinction explicitly through the safeguarding mechanism.

Periodic update · new data 2026-09-08 · run wpm-2026-09-05

Conduct, Safeguarding & Financial Promotions

The 2025 Payment Aggregator Directions impose a confirmed, high-impact conduct and safeguarding obligation on all payment aggregators operating in India: a board-approved dispute-resolution policy with clear refund timelines is now mandatory, alongside maintenance of PCI-DSS/PA-DSS data-security standards. This combines a customer-facing conduct requirement -- ensuring merchants and consumers have a defined, governed path to dispute resolution and refunds -- with a technical data-security baseline that aggregators must demonstrably maintain rather than merely aspire to.

The safeguarding mechanism specified is procedural rather than a discrete asset-segregation rule: the requirement centres on the board-approved policy itself and the underlying PCI-DSS/PA-DSS compliance posture, rather than, for example, a specific customer-funds-segregation mechanism of the kind seen in some other jurisdictions' payment-institution safeguarding regimes. Security-incident reporting is bound to this same conduct framework: aggregators must report security incidents to RBI within stipulated timeframes, including a monthly cyber-incident reporting cadence, meaning conduct obligations and operational-security obligations are woven together in the same directive rather than sitting in separate regulatory tracks.

This conduct and safeguarding tightening applies across the newly authorised online, offline and cross-border aggregator categories established by the same directions, meaning the non-bank PI/EMI population bears the primary weight of these new board-governance and data-security obligations, consistent with the directions' overall focus on non-bank aggregator oversight rather than bank-affiliated PSP conduct specifically.

Outlook

Watch for RBI supervisory guidance detailing the specific stipulated timeframes for security-incident reporting beyond the monthly cyber-incident cadence already specified, and for any published enforcement action addressing aggregators found not to have implemented a board-approved dispute-resolution policy. As the broader PA Directions rewrite beds in through 2026, conduct-related supervisory findings are likely to surface alongside the authorisation and net-worth compliance actions tracked under the licensing module.

Sources and findings (4)
  1. T1RBI Master Directions — PPI & PA conduct/safeguarding (rbi.org.in)
  2. T2https://community.nasscom.in/communities/public-policy/key-highlights-rbi-draft-master-direction-prepaid-payment-instruments
  3. T3https://www.lexology.com/library/detail.aspx?g=741da40c-2952-4c9b-8f94-886e57b874ec [CAVEAT: Tier 3 secondary source — Assessed; verify vs primary pre-publication]
  4. T3https://www.argus-p.com/updates/updates/rbi-issues-master-directions-on-prepaid-payment-instruments/ [CAVEAT: Tier 3 secondary source — Assessed; verify vs primary pre-publication]

#

India's digital-money posture is CBDC-led and stablecoin-sceptical. The RBI's Digital Rupee (e₹), a tokenised CBDC and legal tender backed by RBI, launched wholesale (Nov 2022) and retail (Dec 2022) pilots and by 2026 carries ~7-8 million retail users with programmable use-cases in welfare schemes. The RBI strongly advocates prioritising CBDCs over privately issued stablecoins; there is no in-force stablecoin framework, though the Ministry of Finance's Economic Survey 2025-26 signals possible regulation, diverging from the cautious RBI stance.

Horizon · 2026-27 (±year)RBI bilateral/multilateral cross-border CBDC pilotsproposed · T2
Standing sub-brief190 words · last cycle wpm-2026-06-27

Stablecoins & Digital Money

India's digital-money posture is CBDC-led and stablecoin-sceptical. The Digital Rupee (e-Rupee) comprises wholesale e-Rupee-W, launched 1 November 2022 for G-sec settlement, and retail e-Rupee-R, launched 1 December 2022; the instrument is legal tender, bears no interest, and provides cash-like settlement finality. The retail user base is estimated at around 6-10 million by mid-2026, a range reflecting source variance and an unanchored primary count.

No periodic updates recorded against this sub-brief.

Sources and findings (4)
  1. T1RBI Digital Rupee (e₹) pilot — CBDC framework (rbi.org.in)
  2. T2https://www.business-standard.com/finance/news/rbi-cross-border-cbdc-pilots-digital-currency-2026-27-126052900721_1.html
  3. T3https://coinmarketcap.com/academy/article/india-central-bank-pushes-for-prioritizing-cbdcs-over-stablecoins [CAVEAT: Tier 3 secondary source — Assessed; verify vs primary pre-publication]
  4. T3https://www.cryptotimes.io/2026/04/15/rbi-urges-indians-to-join-cbdc-pilot-calls-e-rupee-future-of-money/ [CAVEAT: Tier 3 secondary source — Assessed; verify vs primary pre-publication]

#

Operational resilience for payments rests on the RBI Master Directions on Cyber Resilience and Digital Payment Security Controls for non-bank PSOs (July 2024), the Master Direction on IT Governance, Risk, Controls and Assurance Practices (effective 1 April 2024) and the Master Direction on Outsourcing of IT Services (10 April 2023), supplemented by 2025 Outsourcing Directions for commercial banks and NBFCs. Core obligations: board-approved cyber/IT governance, business-continuity/DR, vendor (third-party/cloud) risk management and incident reporting to RBI within six hours of detection.

Standing sub-brief205 words · last cycle wpm-2026-09-05

Operational Resilience & Critical Infrastructure

India's operational-resilience regime for payments rests on a layered set of Master Directions rather than a single statute. These comprise the Master Directions on Cyber Resilience & Digital Payment Security Controls for non-bank PSOs (July 2024), the Master Direction on IT Governance, Risk, Controls & Assurance Practices (effective 1 April 2024), the Master Direction on Outsourcing of IT Services (10 April 2023), and the RBI (Commercial Banks — Managing Risks in Outsourcing) Directions 2025. Core obligations include board-approved cyber and IT governance, BCP/DR, vendor and cloud risk management, and cyber-incident reporting to RBI within six hours of detection; existing outsourcing arrangements must comply by 10 April 2026. The framework applies to both banks and non-bank PSOs.

Periodic update · new data 2026-09-08 · run wpm-2026-09-05

Operational Resilience & Critical Infrastructure

The 2025 Payment Aggregator Directions formalise a confirmed operational-resilience obligation requiring payment aggregators to present reports on risk assessment, security-compliance posture, security audits and incidents to their board, and to report the same to RBI. This sits alongside the confirmed PCI-DSS/PA-DSS data-security standard and the monthly cyber-incident reporting cadence carried within the same directions, together constituting a materially strengthened operational-resilience framework for the payment-aggregator sector relative to the prior 2020 regime.

The structural significance of formalising board-level presentation of security and risk-assessment reporting is that it embeds operational-resilience accountability at governance level rather than leaving it purely as a technical-compliance function reporting only to management. Combined with the monthly cyber-incident reporting obligation to RBI, this creates a dual accountability channel -- internal board oversight and external regulatory reporting -- operating on overlapping but distinct cadences.

This resilience obligation applies to the newly authorised online, offline and cross-border aggregator categories alike, meaning the non-bank PI/EMI population that dominates the payment-aggregator sector in India now faces board-governance and regulatory-reporting obligations for operational resilience that more closely approach, though do not necessarily match, the standards historically expected of bank-affiliated payment infrastructure.

Outlook

Watch for the first cycle of monthly cyber-incident reports to RBI under the new framework, and for any RBI commentary on aggregate incident volumes or patterns across the newly regulated offline-PA population, which entered the authorisation regime for the first time this cycle. Any high-profile security incident at a payment aggregator in the coming cycles would be the first real test of whether the board-reporting and RBI-notification cadence functions as intended under the new directions.

Sources and findings (4)
  1. T3https://www.getastra.com/blog/compliance/rbi-cybersecurity-compliance-checklist/ [CAVEAT: Tier 3 secondary source — Assessed; verify vs primary pre-publication]
  2. T2https://taxguru.in/rbi/rbi-commercial-banks-managing-risks-outsourcing-directions-2025.html
  3. T3https://thedigitalfifth.com/decoding-rbis-master-direction-on-it-governance/ [CAVEAT: Tier 3 secondary source — Assessed; verify vs primary pre-publication]
  4. T3https://aiplexorm.com/blog/rbi-master-direction-digital-payment-security-controls [CAVEAT: Tier 3 secondary source — Assessed; verify vs primary pre-publication]

#

Scheme/network economics are heavily regulated. Debit-card MDR is capped by RBI (up to 0.90% across card networks), UPI P2M MDR capped by NPCI (up to 0.30%), but since January 2020 MDR has been statutorily zero for RuPay debit cards and BHIM-UPI via amendments to Section 10A PSS Act and Section 269SU Income-tax Act, with government incentive schemes funding the ecosystem. Credit cards carry no regulatory MDR cap. PCI-DSS adherence and card-on-file tokenisation are mandated; a parliamentary committee in 2026 is pushing to reintroduce MDR on large UPI merchants.

Horizon · 2027 (±year)Possible reintroduction of MDR on large UPI merchantsproposed · T3
Horizon · 2027 (±year)Possible reintroduction of MDR on large UPI merchantsproposed · T3
Standing sub-brief211 words · last cycle wpm-2026-06-27

Scheme & Network Compliance

Scheme economics in India are dominated by the zero-MDR regime. RBI caps debit-card MDR at up to 0.90% and NPCI caps UPI P2M MDR at up to 0.30%, but since January 2020 MDR is statutorily zero for RuPay debit cards and BHIM-UPI via Section 10A of the PSS Act and Section 269SU of the Income-tax Act, funded by a government incentive scheme paid to acquiring banks. Credit cards carry no regulatory MDR cap, and a roughly 1.1% interchange applies to PPI-routed UPI merchant transactions over INR2,000. The regime applies across both bank and non-bank acquirers.

No periodic updates recorded against this sub-brief.

Sources and findings (4)
  1. T1https://www.pib.gov.in/PressReleasePage.aspx?PRID=2114335&reg=3&lang=2
  2. T3https://www.medianama.com/2026/03/223-parliamentary-committee-calls-return-mdr-upi-implications-users-small-merchants/
  3. T3https://razorpay.com/learn/upi-transaction-charges/
  4. T2https://www.npci.org.in/what-we-do/rupay/circulars

#

India's cross-border corridor strategy is UPI/NPCI-led and rapidly internationalising. The flagship UPI-PayNow linkage (RBI-MAS) is the world's first cloud-based real-time cross-border corridor; UPI is live in eight-plus countries and the RBI has joined BIS Project Nexus to interlink fast-payment systems. Cross-border UPI transactions are governed by FEMA (LRS USD 250,000/year limit, corridor daily caps), with remittances the principal use-case for the Indian diaspora.

Standing sub-brief189 words · last cycle wpm-2026-06-27

Payment Corridor Dynamics

India's corridor strategy is UPI-led and run through NPCI International (NIPL) in concert with RBI. The UPI-PayNow linkage with the Monetary Authority of Singapore, launched February 2025, is the world's first cloud-based real-time cross-border remittance corridor — a bilateral India-Singapore arrangement now expanded to 19 participating Indian banks. Daily caps run at SGD1,000 / INR60,000, governed by FEMA under the LRS USD250,000/year limit.

No periodic updates recorded against this sub-brief.

Sources and findings (4)
  1. T2https://ibsintelligence.com/ibsi-news/npci-adds-13-banks-to-upi-paynow-for-faster-cross-border-payments/
  2. T3https://corporate.cyrilamarchandblogs.com/2026/05/upi-goes-global-the-regulatory-reckoning-ahead/
  3. T3https://thepaymentsassociation.org/article/cross-border-payments-and-upi-revolution-in-india/
  4. T3https://www.policycircle.org/industry/upi-global-expansion-cross-border/

#

The retail-payments market is UPI-dominated (~86% of digital transaction volume, 23bn+ payments/month worth ~₹30 lakh crore) and structurally concentrated in a PhonePe/Google Pay duopoly, whose combined share fell below 80% for the first time in May 2026 (PhonePe 46.2%, Google Pay 32.7%). NPCI's proposed 30% per-app volume cap (deadline December 2026) remains far from achievable; challengers Navi, Flipkart's super.money, BHIM and WhatsApp Pay are gaining share, and Amazon/Meta are lobbying NPCI over dominance.

Horizon · 2026-12-31 (±quarter)NPCI 30% per-app UPI volume capproposed · T3
Standing sub-brief187 words · last cycle wpm-2026-06-27

Industry Structure & Commercial Dynamics

The Indian payments market is structurally concentrated but eroding at the top. UPI handles around 86% of India's digital transaction volume — over 23 billion payments per month, around INR30 lakh crore. PhonePe (46.2%) and Google Pay (32.7%) combined fell to around 79% in May 2026, the first time below 80%. Challengers are gaining: Navi (from 0.21% to 3.6%), Flipkart's super.money (1.8%), BHIM and WhatsApp Pay. NPCI's proposed 30% per-app volume cap has been deferred to 31 December 2026, and Amazon and Meta have joined lobbying over duopoly dominance. UPI-enabled banks grew to 685 by December 2025. This module sits on the non-bank PI/EMI side of the market structure, with per-app share data derived from Tier-3 NPCI-sourced journalism, held at Assessed confidence.

No periodic updates recorded against this sub-brief.

Sources and findings (4)
  1. T3https://www.outlookbusiness.com/economy-and-policy/phonepe-google-pay-combined-upi-market-share-drops-below-80-for-first-time
  2. T3https://www.niftytrader.in/markets/phonepe-google-pay-share-falls/
  3. T3https://techcrunch.com/2026/04/29/amazon-meta-join-fight-to-end-google-pay-phonepe-dominance-in-india/
  4. T3https://www.oxigenwallet.com/upi/apps-market-share/

Payments enforcement is active. The RBI imposed monetary penalties on 353 entities totalling ₹54.78cr in FY 2024-25 for compliance failures, with PSO-specific actions under Sections 30/31 PSS Act for KYC/PPI lapses (e.g. Appnit Technologies, May 2026). A landmark RBI Ombudsman order in 2026 shifted liability onto banks whose receiving-side KYC/AML systems failed, departing from the prior 'contributory negligence' defence. The PayPal/OPGSP case established broad construction of 'payment system' under PMLA.

Standing sub-brief169 words · last cycle wpm-2026-06-27

Legal & Litigation

RBI runs an active payments-enforcement posture. It imposed monetary penalties on 353 entities totalling INR54.78cr in FY2024-25, and on 15 May 2026 penalised Appnit Technologies INR5.8 lakh for KYC/PPI non-compliance under Sections 30/31 of the PSS Act. The pivotal legal development is a 2026 RBI Ombudsman order that shifted liability onto banks whose receiving-side KYC, AML, transaction-monitoring and STR systems failed, departing from the prior contributory-negligence OTP-disclosure defence. Separately, a court held that 'payment system' under PMLA must be broadly construed to include OPGSPs, in the PayPal/Abhijit Mishra case. The enforcement reach spans both bank and non-bank entities.

No periodic updates recorded against this sub-brief.

Sources and findings (4)
  1. T3https://www.bhavyasharmaandassociates.com/rbi-ppi-kyc-penalty-fintech-founder-checklist-2026/
  2. T3https://www.multibagg.ai/market-pulse/articles/rbi-digital-fraud-compensation-rules-cmnbhiarudsmcpa0jlgnczxa7
  3. T3https://clatgurukul.com/rbi-ombudsman-digital-arrest-malhotra-22-crore-kyc-clat-2027/
  4. T3https://www.taxtmi.com/article/detailed?id=13006

#

Acquiring is governed by the PA Directions (escrow settlement, merchant KYC/onboarding by the PA) and card-scheme rulebooks (Visa/Mastercard/RuPay) for the chargeback/dispute cycle. RBI mandates an Online Dispute Resolution (ODR) system for digital payments (DPSS circular 2020-21/21) and card-on-file tokenisation/eMandate rules for recurring transactions. Card chargebacks follow a 45-120 day network-driven cycle with issuer temporary credit; UPI disputes use a separate NPCI 3-day mechanism, with escalation to the RBI Integrated Ombudsman.

Standing sub-brief174 words · last cycle wpm-2026-06-27

Merchant Acquiring & Risk

Merchant acquiring in India is governed by the PA Directions — escrow settlement, merchant KYC and onboarding — together with the card-scheme rulebooks of Visa, Mastercard and RuPay for the chargeback cycle. RBI mandates an Online Dispute Resolution (ODR) system under DPSS.CO.PD No.116/02.12.004/2020-21, plus card-on-file tokenisation and eMandate rules for recurring transactions. The dispute architecture diverges by rail: card chargebacks follow a 45-120 day network cycle with issuer temporary credit, while UPI disputes use a separate NPCI 3-day mechanism, escalating to the RBI Integrated Ombudsman Scheme 2021. Both bank and non-bank acquirers are in scope.

No periodic updates recorded against this sub-brief.

Sources and findings (4)
  1. T1https://www.rbi.org.in/commonperson/English/Scripts/Notification.aspx?Id=3194
  2. T3https://in.nttdatapay.com/en/company/corporate-governance/grievance-redressal-policy
  3. T3https://merchantriskcouncil.org/advocacy/reserve-bank-of-india-rbi
  4. T4https://righttoinformation.wiki/credit-card-chargeback-guide-india [CAVEAT: Tier 4 source — Assessed; illustrative only, verify pre-publication]

#

India is a global front-runner in rail and product innovation: UPI (real-time rails), UPI 123Pay/UPI Lite (feature-phone and offline low-value), the e₹ CBDC pilots with programmability and offline NFC, and an active RBI regulatory sandbox plus the CBDC and Asset Tokenisation Sandbox. Open-banking-style account aggregation and agentic/AI-powered conversational payments (Razorpay-NPCI-OpenAI) are emerging build-outs; RuPay-credit-card-on-UPI is a key product driving challenger growth.

Standing sub-brief170 words · last cycle wpm-2026-06-27

Product Innovation & Market Development

India's product-innovation frontier layers new commerce and access patterns on top of UPI rails. The thematic build-out spans UPI 123Pay and UPI Lite, offline NFC CBDC, the CBDC & Asset Tokenisation Sandbox, and the Unified Markets Interface (UMI). The emerging product frontier includes agentic and conversational payments: a Razorpay-NPCI-OpenAI tie-up enabling ChatGPT users in India to find products and instantly purchase them with UPI illustrates AI-driven product build-out around real-time rails. This thematic product-access view is distinct from discrete commercial events; the specific Razorpay-NPCI-OpenAI launch is rendered as a W13 commercial event, while the structural UPI product-rail innovation theme sits here in the W9 standing position. The module reflects non-bank PI/EMI product activity built on state rails.

No periodic updates recorded against this sub-brief.

Sources and findings (4)
  1. T2https://www.business-standard.com/finance/news/rbi-cross-border-cbdc-pilots-digital-currency-2026-27-126052900721_1.html
  2. T3https://en.wikipedia.org/wiki/Digital_rupee
  3. T3https://www.pymnts.com/news/ipo/2026/indian-payment-fintech-razorplay-planning-600-million-ipo/
  4. T3https://razorpay.com/learn/upi-transaction-charges/

#

RBI's digital fraud-compensation framework (2026) requires zero-liability compensation for unauthorised digital transactions, provisional-credit issuance within prescribed timelines, and quarterly aggregate fraud-compensation reporting to RBI's Department of Payment and Settlement Systems.

Horizon · 2026-07-01 (±quarter)RBI Draft Third Amendment Directions 2026 — APP-fraud compensation schemeconsultation · T3
Standing sub-brief209 words · last cycle wpm-2026-09-05

Consumer Protection & APP Fraud

India's APP-fraud compensation framework is moving toward an imminent effective date. Draft Third Amendment Directions 2026 (Responsible Business Conduct), proposed 6 March 2026 and effective 1 July 2026, provide that a customer suffering genuine fraud loss up to INR50,000 may receive 85% of net loss or up to INR25,000, whichever is lower, once per lifetime, for transactions on or after 1 July 2026 at commercial banks — excluding small finance banks, payments banks, RRBs and local area banks — reported within five days. RBI bears around 65% of cost, with the remainder split between sending and receiving banks. The scheme applies on the bank-PSP side.

Periodic update · new data 2026-09-08 · run wpm-2026-09-05

Consumer Protection & APP Fraud

The Reserve Bank of India's digital-fraud compensation framework, assessed at probable confidence from a lower-tier source this cycle, requires zero-liability compensation for unauthorised digital transactions where the customer reports promptly and was not negligent. Critically, the burden of proving negligence rests with the bank rather than the customer, a material consumer-protection tightening that shifts the evidentiary burden away from the party with less visibility into the transaction's authentication chain.

The operational mechanics attached to this framework require banks to issue provisional credit to affected customers within prescribed timelines, ensuring consumers are not left without access to disputed funds while a fraud investigation proceeds, and to report aggregate fraud-compensation data to RBI on a quarterly basis. This quarterly reporting obligation gives RBI a standing data feed on the scale of digital-fraud compensation across the banking sector, which could in later cycles support more granular supervisory or policy responses to APP-fraud trends.

This framework applies specifically to the bank/PSP population handling digital transactions, distinct from the non-bank PI/EMI-focused obligations formalised in the same cycle's payment aggregator directions, reflecting the different points in the payment chain at which liability and compensation obligations naturally attach. The lower source-tier basis for this framework's specifics -- relative to the payment aggregator directions material sourced more directly to RBI's own circular index -- means the precise operational parameters merit confirmation against RBI's own published framework text in a future cycle.

Outlook

Watch for the first quarterly aggregate fraud-compensation reports banks submit to RBI under this framework, which would provide the first empirical measure of the scheme's practical scale and effectiveness. Given the probable-confidence, lower-tier sourcing basis for this cycle's finding, a direct RBI primary-source retrieval in a subsequent cycle would materially strengthen confidence in the framework's exact operational parameters.

Sources and findings (4)
  1. T3https://www.angelone.in/news/economy/rbi-proposes-new-rules-effective-july-1-2026-safeguards-against-digital-banking-fraud
  2. T3https://theprint.in/opinion/rbi-compensate-app-fraud-victims/2904306/
  3. T3https://chahalacademy.com/indian-express-editorial-analysis/16-feb-2026/2553
  4. T3https://abclive.in/2026/03/10/rbi-digital-fraud-liability-rules/

#

[Sentinel.gi position] India's payments AML/CFT posture is anchored on the PMLA 2002 and UAPA, supervised by RBI/FIU-IND. The FATF 2024 Mutual Evaluation placed India in 'regular follow-up' (the highest category, alongside few G20 peers), rating it compliant/largely compliant on 37 of 40 Recommendations, but flagged only 'moderate' effectiveness in AML/CFT supervision (IO.3) and that monetary penalties on FIs are generally not proportionate or dissuasive. Cross-border UPI corridors create FEMA/FATF-list interaction risk.

Standing sub-brief177 words · last cycle wpm-2026-06-27

AML/CFT & Financial Crime

This module is carried from the Sentinel.gi feed; no original illicit-finance analysis is performed here. Per the FATF September 2024 Mutual Evaluation Report, India rated compliant or largely compliant on 37 of 40 Recommendations — partial on R.8 (NPOs), R.12 (PEPs) and R.28 (DNFBP supervision) — with 'substantial' effectiveness in six areas but only 'moderate' on AML/CFT supervision (IO.3). FATF found monetary penalties on financial institutions generally not proportionate or dissuasive. India was placed in 'regular follow-up', the highest category, alongside the UK, France and Italy among G20 members. FIU-IND fined a VDA service provider USD2.16m (INR18.2cr) in June 2024 for STR-monitoring failures, and a payments bank was fined and wound down for AML/CFT violations. The intelligence is attributed to the Sentinel feed; see Sentinel.gi for the underlying analysis.

No periodic updates recorded against this sub-brief.

Sources and findings (9)
  1. T3https://risk.lexisnexis.com/insights-resources/article/fatf-new-findings-aml-cft-compliance-india
  2. T?FIM (sentinel.gi) per-JID baseline profile — India — India's AML/CFT regime rests on the Prevention of Money Laundering Act 2002 (PMLA) and the Unlawful Activities (Prevention) Act 1967, supervised by FIU-IND, RBI, SEBI and the Enforcement Directorate. FATF's 2024 MER found strong technical compliance and good results on risk understanding, asset deprivation and international cooperation, but flagged prosecution delays, thin DNFBP supervision and an early-stage VASP regime.
  3. T?FIM (sentinel.gi) gaps_register_cumulative (issue FIM-BASE-GAP-005) — Gap: sourcing-thinness
  4. T2FIM (sentinel.gi) enforcement_action_register (issue FIM-BASE-ENF-002) — Enforcement: US DOJ / SEC / OFAC — Gautam Adani, Sagar Adani, Adani Green Energy CEO Vneet Jaain, Adani Group
  5. T1FIM (sentinel.gi) sanctions_change_register (issue FIM-BASE-SANC-004) — Sanctions: EU listing
  6. T2FIM (sentinel.gi) sanctions_change_register (issue FIM-BASE-SANC-003) — Sanctions: national wind-down
  7. T2FIM (sentinel.gi) enforcement_action_register (issue FIM-BASE-ENF-001) — Enforcement: Indian Coast Guard — Three tankers suspected of dark-fleet oil smuggling off Mumbai
  8. T?FIM (sentinel.gi) gaps_register_cumulative (issue FIM-BASE-GAP-003) — Gap: regulatory-failure
  9. T?FIM (sentinel.gi) gaps_register_cumulative (issue FIM-BASE-GAP-002) — Gap: enforcement-absence

#

Central settlement runs on RBI-owned Centralised Payment Systems — RTGS (large-value, real-time, 24x7x365 since Dec 2020) and NEFT (batch, 24x7 since Dec 2019), both on the e-Kuber core banking system. Since July 2021 the RBI has opened CPS direct membership to authorised non-bank PSPs (PPI issuers, card networks, white-label ATM operators) requiring ₹25cr net worth, Indian incorporation, data-localisation and an RBI current account/IFSC; non-banks are excluded from intra-day liquidity and cannot sponsor sub-members.

Standing sub-brief188 words · last cycle wpm-2026-06-27

Correspondent Banking, Settlement & Access

The analytical spine of this module is the bank versus non-bank settlement-access asymmetry. Central settlement runs on RBI-owned Centralised Payment Systems — RTGS (large-value, real-time, 24x7x365 since December 2020) and NEFT (batch, 24x7 since December 2019), both on the e-Kuber core banking system. Since July 2021 RBI has opened direct CPS membership to authorised non-bank PSPs — PPI issuers, card networks and white-label ATM operators — under Section 10(2) read with Section 18 of the PSS Act, requiring INR25cr net worth, Indian incorporation, data-localisation, a separate IFSC, an RBI current account and INFINET/SFMS membership.

No periodic updates recorded against this sub-brief.

Sources and findings (4)
  1. T2https://www.thenewsminute.com/money/rbi-allows-paytm-phonepe-and-other-non-banks-access-neft-rtgs-payment-systems-153159
  2. T3https://www.drishtiias.com/daily-updates/daily-news-analysis/non-bank-psps-to-join-centralised-payment-system
  3. T3https://affairscloud.com/rbi-allowed-non-banks-to-participate-in-cps-rtgs-neft/
  4. T3https://www.dnaindia.com/personal-finance/report-rtgs-neft-payment-systems-opened-up-for-non-banks-in-phases-rbi-2903037

#

Trailing-12-month commercial intelligence is dominated by a fintech IPO pipeline amid more selective funding. Razorpay confidentially filed a ~$600m IPO (June 2026) and obtained shareholder approval for a ₹2,700cr fresh issue; PhonePe filed in late 2025 and received listing approval in January 2026 at a $9-10.5bn target valuation; Pine Labs progressed toward its IPO. India fintech funding was $513m in Q1 2026 with a sharply falling deal count, signalling consolidation toward stronger players.

Standing sub-brief260 words · last cycle wpm-2026-06-27

Commercial Intelligence (M&A, Investment & Product)

Three discrete commercial events define this cycle's W13 entries. First, Razorpay confidentially filed for a roughly USD600m IPO in June 2026, targeting a year-end debut (last valued at around USD7.5bn in its 2021 round); it separately obtained shareholder approval in May 2026 to raise INR2,700cr (~USD283m) via the fresh-issue component plus an undisclosed offer-for-sale, with a pre-IPO placement planned before filing its RHP with SEBI. This anchors India's fintech listing pipeline and signals public-market appetite for licensed payments platforms with merchant networks.

No periodic updates recorded against this sub-brief.

Sources and findings (4)
  1. T3https://www.pymnts.com/news/ipo/2026/indian-payment-fintech-razorplay-planning-600-million-ipo/
  2. T3https://www.medianama.com/2026/05/223-exclusive-razorpay-shareholder-approval-rs-2700-crore-ipo/
  3. T3https://www.newskart.com/razorpay-files-confidential-ipo-papers-can-indian-fintech-still-command-big-valuations/
  4. T4https://tiimagazine.com/top-30-fintech-companies-in-india-to-watch-in-2026/ [CAVEAT: Tier 4 source — Assessed; illustrative only, verify pre-publication]
No modules match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for India
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: module cards load OPEN; standing positions render in full; sub-briefs and jurisdiction briefs load as a clamped teaser with an explicit “read full” control carrying the true word count; earlier updates stay collapsed behind a counted summary. No text is hidden without disclosing how much of it there is.

Sentinel-fed modules receive no special rendering treatment. sentinel_feed is an attribution chip only: it does not suppress content, does not generate an absence reason code, and does not exclude the module from any count, filter, search index or export on this page.

Family taxonomy is renderer-level presentation config, not a JID field. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; per-module RAG traffic light; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-09-11. A year-precision row is never promoted into a tighter band.

Orphan deltas: 2 cycle_delta row(s) target non-module objects and are listed in the rail rather than attached to a card.

Envelope: baseline resolved at jurisdiction_json.baseline; 14 module(s), 61 finding(s), 109 source(s) in the cumulative register.