Executive Summary:
This document from the Reserve Bank of India (RBI) outlines directions for enhanced due diligence and risk management regarding Aadhaar Enabled Payment System (AePS) touchpoint operators (ATOs) to combat fraud and maintain system security. It mandates stricter onboarding processes and ongoing monitoring of ATOs by acquiring banks. The directions are issued under the Payment and Settlement Systems Act, 2007 and will come into effect on January 1, 2026.
Key Points / Main Content:
* **Definitions:**
* AePS: A payment system using Aadhaar for transactions like cash withdrawal, deposit, fund transfer, balance enquiry, etc.
* Acquiring Bank: Bank that onboards AePS touchpoint operators.
* AePS Touchpoint: Terminal deployed by acquiring banks for AePS transactions (mobile and fixed points).
* AePS Touchpoint Operator (ATO): Individual onboarded by acquiring bank to operate the AePS touchpoint.
* **Due Diligence of AePS Touchpoint Operators:**
* Acquiring banks must perform due diligence on all ATOs before onboarding, following KYC guidelines for individuals as per RBI's Master Direction.
* Existing due diligence for Business Correspondent sub-agents can be adopted if already completed. Periodic KYC updates are required.
* Inactive ATOs (no transactions for three months) require updated KYC before reactivation.
* **Risk Management:**
* Acquiring banks must continuously monitor ATO activities via transaction monitoring systems and set operational parameters based on their business risk profile.
* Operational parameters should consider factors like ATO location, type, transaction volume, and velocity.
* Regular review of operational parameters is required to address emerging fraud trends.
* Adequate system-level controls are needed to ensure technological integrations (APIs) are solely for enabling AePS operations.
Impact Analysis:
* **Scheduled Commercial Banks (including RRBs), Urban Cooperative Banks, State Cooperative Banks, District Central Cooperative Banks:**
* Impact: These banks, especially acquiring banks, will need to implement stricter due diligence procedures for onboarding and monitoring AePS touchpoint operators. They will also need to enhance their risk management frameworks and transaction monitoring systems.
* Action Required: Update onboarding processes, implement ongoing monitoring systems, review and adjust operational parameters, and ensure compliance with the new directions by January 1, 2026.
* **National Payments Corporation of India (NPCI):**
* Impact: NPCI, as the operator of AePS, will be affected by the changes in how member banks manage ATOs and maintain system security.
* Action Required: Support member banks in implementing the new guidelines and potentially update AePS system specifications to facilitate enhanced due diligence and risk management.
* **AePS Touchpoint Operators (ATOs):**
* Impact: ATOs will be subject to more stringent due diligence and ongoing monitoring. Those who are inactive may face delays or require re-verification before being allowed to transact again.
* Action Required: Comply with requests for information and documentation from acquiring banks to facilitate due diligence and KYC updates.
* **Bank Customers:**
* Impact: Enhanced security of the AePS system, reducing the risk of fraud and identity theft related to AePS transactions.
* Action Required: No direct action required, but customers should remain vigilant about protecting their Aadhaar information and reporting any suspicious activity.
Key Entities Referenced
Aadhaar Enabled Payment System (AePS): A payment system operated by National Payments Corporation of India (NPCI) that facilitates interoperable transactions using Aadhaar enabled authentication.
National Payments Corporation of India (NPCI): An organization that operates the Aadhaar Enabled Payment System (AePS) and other payment systems.
Payment and Settlement Systems (PSS) Act, 2007: The Act under which the directions regarding Aadhaar Enabled Payment System (AePS) are issued. Section 18 read with Section 102 of the Payment and Settlement Systems PSS Act, 2007 Act 51 of 2007
Aadhaar Targeted Delivery of Financial and Other Subsidies, Benefits and Services Act, 2016: The act defining terms pertaining to Aadhaar, Aadhaar biometric authentication
AePS Touchpoint Operators (ATO): Individuals onboarded by acquiring banks who operate AePS touchpoints.
Reserve Bank: The issuing authority for the Know Your Customer (KYC) direction.
Urban Cooperative Banks: A type of bank to which the notification is addressed.
State Cooperative Banks: A type of bank to which the notification is addressed.
RBI/2025-26/63
CO.DPSS.POLC.No.S339/02-01-001/2025-2026 June 27, 2025
The Chairman / Managing Director / Chief Executive
All Scheduled Commercial Banks including RRBs /
Urban Cooperative Banks / State Cooperative Banks / District Central Cooperative
Banks / National Payments Corporation of India (NPCI)
Madam / Dear Sir,
Aadhaar Enabled Payment System – Due Diligence of AePS Touchpoint
Operators
Aadhaar Enabled Payment System (AePS) is a payment system operated by National
Payment Corporation of India (NPCI) that facilitates interoperable transactions using
Aadhaar enabled authentication. AePS plays a prominent role in enabling financial
inclusion.
2. In recent times, there have been reports of frauds perpetuated through AePS due
to identity theft or compromise of customer credentials. To protect bank customers
from such frauds, and to maintain trust and confidence in the safety and security of
the system, a need is felt to enhance the robustness of AePS. Accordingly, as
announced in Statement on Developmental and Regulatory Policies dated February
08, 2024, it has been decided to issue directions for streamlining the process for
onboarding of AePS touchpoint operators and strengthening fraud risk management.
Detailed instructions are placed in the Annex.
3. These directions are issued under Section 18 read with Section 10(2) of the
Payment and Settlement Systems (PSS) Act, 2007 (Act 51 of 2007) and shall come
into effect from January 01, 2026.
Yours faithfully,
(Gunveer Singh)
Chief General Manager-in-Charge
Encl.: AnnexAnnex
CO.DPSS.POLC.No.S339/02-01-001/2025-2026 June 27, 2025
Aadhaar Enabled Payment System -
Due Diligence of AePS Touchpoint Operators
1. Definitions
I. In these directions, the terms herein shall bear the meanings assigned to them
below:
a. Aadhaar Enabled Payment System (AePS): It is a Payment System in which
transactions are enabled through Aadhaar number and biometrics or OTP
authentication providing financial services such as cash withdrawal, cash
deposit, fund transfer, and non-financial services such as mini statement and
balance enquiry. etc.
b. Acquiring bank: The bank which onboards the AePS touchpoint operators.
c. AePS Touchpoint: The terminal deployed by acquirer banks to facilitate
AePS transactions, which shall include both mobile and fixed points.
d. AePS Touchpoint Operator (ATO): The individual onboarded by the
acquiring bank who operates the AePS touchpoint.
II. Terms pertaining to Aadhaar, Aadhaar biometric authentication, etc., shall have
the same meaning as assigned to them in the Aadhaar (Targeted Delivery of
Financial and Other Subsidies, Benefits and Services) Act, 2016 (18 of 2016),
and the rules made thereunder.
III. Words and expressions used but not defined in I and II above and defined in
the Payment and Settlement Systems Act, 2007 shall have the meanings
assigned to them in that Act.
2. Due diligence of AePS Touchpoint Operators
2.1 The acquiring bank shall carry out due diligence of all ATOs before onboarding
them, adopting the same process as indicated in the Customer Due Diligence
procedure for individuals, stipulated in paragraph 16 of Part-I, Chapter-VI of the
Master Direction – Know Your Customer Direction, 2016 (as updated from time
to time), issued by the Reserve Bank. However, if the due diligence of ATOs
has already been done in their capacity as Business Correspondent / sub-
agent, then the same may be adopted. The acquiring bank shall also carry out
periodic updation of KYC of ATOs.2.2 In cases where an ATO has remained inactive, i.e. has not performed any
financial / non-financial transaction for a customer for a continuous period of
three months, acquiring bank shall carry out KYC of ATO before enabling him /
her to transact further.
3. Risk Management
3.1 The acquiring bank shall monitor the activities of ATOs through their
transaction monitoring systems on an ongoing basis and set operational
parameters, based on business risk profile of the ATOs. Aspects such as location
and type of the ATO, volume and velocity of transactions, etc. shall form part of
bank’s fraud risk management framework.
3.2 The operational parameters regarding ATOs shall be reviewed on a periodic
basis, reflecting emerging fraud trends.
3.3 The acquiring bank shall put in place adequate system level controls to ensure
that any technological integrations like APIs are used only for enabling AePS
operations.
***