Home India Reserve Bank of India Aadhaar Enabled Payment System – Due Diligence of AePS Touch...
Date: 2025-06-27 Category: Not Applicable State: Union Government Country: India

Aadhaar Enabled Payment System – Due Diligence of AePS Touchpoint Operators

Issued by Reserve Bank of India · Not Applicable

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task

Executive Summary & Key Takeaways

Executive Summary: This document from the Reserve Bank of India (RBI) outlines directions for enhanced due diligence and risk management regarding Aadhaar Enabled Payment System (AePS) touchpoint operators (ATOs) to combat fraud and maintain system security. It mandates stricter onboarding processes and ongoing monitoring of ATOs by acquiring banks. The directions are issued under the Payment and Settlement Systems Act, 2007 and will come into effect on January 1, 2026. Key Points / Main Content: * **Definitions:** * AePS: A payment system using Aadhaar for transactions like cash withdrawal, deposit, fund transfer, balance enquiry, etc. * Acquiring Bank: Bank that onboards AePS touchpoint operators. * AePS Touchpoint: Terminal deployed by acquiring banks for AePS transactions (mobile and fixed points). * AePS Touchpoint Operator (ATO): Individual onboarded by acquiring bank to operate the AePS touchpoint. * **Due Diligence of AePS Touchpoint Operators:** * Acquiring banks must perform due diligence on all ATOs before onboarding, following KYC guidelines for individuals as per RBI's Master Direction. * Existing due diligence for Business Correspondent sub-agents can be adopted if already completed. Periodic KYC updates are required. * Inactive ATOs (no transactions for three months) require updated KYC before reactivation. * **Risk Management:** * Acquiring banks must continuously monitor ATO activities via transaction monitoring systems and set operational parameters based on their business risk profile. * Operational parameters should consider factors like ATO location, type, transaction volume, and velocity. * Regular review of operational parameters is required to address emerging fraud trends. * Adequate system-level controls are needed to ensure technological integrations (APIs) are solely for enabling AePS operations. Impact Analysis: * **Scheduled Commercial Banks (including RRBs), Urban Cooperative Banks, State Cooperative Banks, District Central Cooperative Banks:** * Impact: These banks, especially acquiring banks, will need to implement stricter due diligence procedures for onboarding and monitoring AePS touchpoint operators. They will also need to enhance their risk management frameworks and transaction monitoring systems. * Action Required: Update onboarding processes, implement ongoing monitoring systems, review and adjust operational parameters, and ensure compliance with the new directions by January 1, 2026. * **National Payments Corporation of India (NPCI):** * Impact: NPCI, as the operator of AePS, will be affected by the changes in how member banks manage ATOs and maintain system security. * Action Required: Support member banks in implementing the new guidelines and potentially update AePS system specifications to facilitate enhanced due diligence and risk management. * **AePS Touchpoint Operators (ATOs):** * Impact: ATOs will be subject to more stringent due diligence and ongoing monitoring. Those who are inactive may face delays or require re-verification before being allowed to transact again. * Action Required: Comply with requests for information and documentation from acquiring banks to facilitate due diligence and KYC updates. * **Bank Customers:** * Impact: Enhanced security of the AePS system, reducing the risk of fraud and identity theft related to AePS transactions. * Action Required: No direct action required, but customers should remain vigilant about protecting their Aadhaar information and reporting any suspicious activity.

Key Entities Referenced

Aadhaar Enabled Payment System (AePS): A payment system operated by National Payments Corporation of India (NPCI) that facilitates interoperable transactions using Aadhaar enabled authentication. National Payments Corporation of India (NPCI): An organization that operates the Aadhaar Enabled Payment System (AePS) and other payment systems. Payment and Settlement Systems (PSS) Act, 2007: The Act under which the directions regarding Aadhaar Enabled Payment System (AePS) are issued. Section 18 read with Section 102 of the Payment and Settlement Systems PSS Act, 2007 Act 51 of 2007 Aadhaar Targeted Delivery of Financial and Other Subsidies, Benefits and Services Act, 2016: The act defining terms pertaining to Aadhaar, Aadhaar biometric authentication AePS Touchpoint Operators (ATO): Individuals onboarded by acquiring banks who operate AePS touchpoints. Reserve Bank: The issuing authority for the Know Your Customer (KYC) direction. Urban Cooperative Banks: A type of bank to which the notification is addressed. State Cooperative Banks: A type of bank to which the notification is addressed.
Official Source Record View Original Source →
See Full Document Text
RBI/2025-26/63 CO.DPSS.POLC.No.S339/02-01-001/2025-2026 June 27, 2025 The Chairman / Managing Director / Chief Executive All Scheduled Commercial Banks including RRBs / Urban Cooperative Banks / State Cooperative Banks / District Central Cooperative Banks / National Payments Corporation of India (NPCI) Madam / Dear Sir, Aadhaar Enabled Payment System – Due Diligence of AePS Touchpoint Operators Aadhaar Enabled Payment System (AePS) is a payment system operated by National Payment Corporation of India (NPCI) that facilitates interoperable transactions using Aadhaar enabled authentication. AePS plays a prominent role in enabling financial inclusion. 2. In recent times, there have been reports of frauds perpetuated through AePS due to identity theft or compromise of customer credentials. To protect bank customers from such frauds, and to maintain trust and confidence in the safety and security of the system, a need is felt to enhance the robustness of AePS. Accordingly, as announced in Statement on Developmental and Regulatory Policies dated February 08, 2024, it has been decided to issue directions for streamlining the process for onboarding of AePS touchpoint operators and strengthening fraud risk management. Detailed instructions are placed in the Annex. 3. These directions are issued under Section 18 read with Section 10(2) of the Payment and Settlement Systems (PSS) Act, 2007 (Act 51 of 2007) and shall come into effect from January 01, 2026. Yours faithfully, (Gunveer Singh) Chief General Manager-in-Charge Encl.: AnnexAnnex CO.DPSS.POLC.No.S339/02-01-001/2025-2026 June 27, 2025 Aadhaar Enabled Payment System - Due Diligence of AePS Touchpoint Operators 1. Definitions I. In these directions, the terms herein shall bear the meanings assigned to them below: a. Aadhaar Enabled Payment System (AePS): It is a Payment System in which transactions are enabled through Aadhaar number and biometrics or OTP authentication providing financial services such as cash withdrawal, cash deposit, fund transfer, and non-financial services such as mini statement and balance enquiry. etc. b. Acquiring bank: The bank which onboards the AePS touchpoint operators. c. AePS Touchpoint: The terminal deployed by acquirer banks to facilitate AePS transactions, which shall include both mobile and fixed points. d. AePS Touchpoint Operator (ATO): The individual onboarded by the acquiring bank who operates the AePS touchpoint. II. Terms pertaining to Aadhaar, Aadhaar biometric authentication, etc., shall have the same meaning as assigned to them in the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 (18 of 2016), and the rules made thereunder. III. Words and expressions used but not defined in I and II above and defined in the Payment and Settlement Systems Act, 2007 shall have the meanings assigned to them in that Act. 2. Due diligence of AePS Touchpoint Operators 2.1 The acquiring bank shall carry out due diligence of all ATOs before onboarding them, adopting the same process as indicated in the Customer Due Diligence procedure for individuals, stipulated in paragraph 16 of Part-I, Chapter-VI of the Master Direction – Know Your Customer Direction, 2016 (as updated from time to time), issued by the Reserve Bank. However, if the due diligence of ATOs has already been done in their capacity as Business Correspondent / sub- agent, then the same may be adopted. The acquiring bank shall also carry out periodic updation of KYC of ATOs.2.2 In cases where an ATO has remained inactive, i.e. has not performed any financial / non-financial transaction for a customer for a continuous period of three months, acquiring bank shall carry out KYC of ATO before enabling him / her to transact further. 3. Risk Management 3.1 The acquiring bank shall monitor the activities of ATOs through their transaction monitoring systems on an ongoing basis and set operational parameters, based on business risk profile of the ATOs. Aspects such as location and type of the ATO, volume and velocity of transactions, etc. shall form part of bank’s fraud risk management framework. 3.2 The operational parameters regarding ATOs shall be reviewed on a periodic basis, reflecting emerging fraud trends. 3.3 The acquiring bank shall put in place adequate system level controls to ensure that any technological integrations like APIs are used only for enabling AePS operations. ***

Continue your research