What you need to know - at a glance:
|
Change |
Detail |
Effective Date |
|---|---|---|
|
Mandatory 2FA for all digital payments |
RBI directions require two independent authentication factors |
April 1, 2026 |
|
On-device biometric authentication |
Optional UPI PIN alternative for eligible transactions |
October 7, 2025 |
|
Biometric transaction limit raised |
NPCI circular OC-226A increases limit from Rs 5,000 to Rs 10,000 |
August 7, 2026 |
|
Aadhaar face authentication |
Optional method for UPI PIN set/reset (replaces card credentials) |
October 2025 |
|
UPI Circle - delegated payments |
Secondary users can make payments within limits set by primary users |
Live |
|
Cross-border 2FA requirement |
International card-not-present transactions require 2FA |
October 1, 2026 |
|
Market share cap (proposed) |
No single third-party UPI app to exceed 30% of transaction volume |
December 31, 2026 |
The shift from single-factor to two-factor authentication is the most consequential change. Previously, a stolen UPI PIN was sufficient to authorise a fraudulent transaction. Under the new RBI framework (RBI/2025-26/219), every transaction must use at least two of the following: something you know (PIN or password), something you have (a registered device or token), or something you are (biometric). For most UPI users on familiar trusted devices, this change operates in the background with minimal friction. For new or unrecognised devices, additional verification steps are now triggered automatically.
As Dilip Asbe, MD and CEO of NPCI, has noted publicly that UPI's next phase is about being not just ubiquitous but intelligent - systems that can authenticate seamlessly, detect fraud in real time, and expand access without expanding risk.
NPCI's circular OC-201 (October 7, 2025) introduced on-device biometric authentication as an optional alternative to the UPI PIN - beginning at Rs 5,000 per transaction and raised to Rs 10,000 from August 7, 2026. This means eligible users can authenticate a UPI payment using their device's fingerprint sensor or face recognition instead of typing a PIN.
Critically, this is not a mandatory biometric requirement for all UPI transactions. It is an opt-in alternative that requires device compatibility, biometric enrolment on the device, consent from the customer (which can be withdrawn at any time), and bank-level eligibility verification. Biometric authentication is automatically disabled if the UPI PIN changes or resets - fresh consent must then be obtained before the feature is reactivated.
The security architecture behind biometric UPI is robust. The issuing bank will independently run cryptographic checks on each transaction - the biometric data will not be transmitted off the device and the transaction will be verified via secure communication between the device and the bank. The NPCI has set a requirement for key rotation, inactivity controls, and has set strict requirements for rooted or jailbroken devices which are not eligible for biometric authentication.
On one of the other changes, NPCI introduces the option for face authentication to set/reset UPI PIN in eligible situations instead of using card credentials and Aadhaar OTP. This is especially vital for those who don't have a physical debit card or have a hard time creating an OTP PIN - thereby improving access and ensuring an adequate identity verification baseline using UIDAI's face authentication foundation.
Also Read: India Post Payments Bank Rolls Out Aadhaar-Based Facial Recognition
The 2026 framework goes beyond biometrics and proposes risk-based authentication as an authentication layer for UPI. The underlying authentication system can leverage enhanced checks in the background, while safe transactions are handled with a reduced degree of friction in the foreground, on trusted devices with established device patterns. High risk signals such as a new device, a suspicious amount of transactions, a new person on the benefits list or an abnormal transaction behavior is investigated before the transaction can be completed.
RBI's instructions also encourage in-app approvals that are to be encrypted over the years instead of SMS OTPs, thereby eliminating the SIM-swap and SMS interception attack surface that has been traditionally used by fraudsters.