**Policy Summary: Enabling Card-on-File Tokenization (CoFT) Through Card Issuing Banks**
This policy, issued by the Reserve Bank of India (RBI) on December 20, 2023, under directive number RBI/2023-24/91 CO.DPSS.POLC.No.S919/02.14.003/2023-24, expands the framework for Card-on-File Tokenization (CoFT) by enabling card issuing banks to directly provide these services. This supplements the existing system where CoFT services are offered by card issuers and card networks, as per earlier RBI circulars (DPSS.CO.PD No.1463/02.14.003/2018-19 dated January 8, 2019; CO.DPSS.POLC.No.S516/02.14.003/2021-22 dated September 07, 2021; and CO.DPSS.POLC.No.S567/02.14.003/2022-23 dated June 24, 2022).
The key provisions of this policy are:
* Card issuers can enable CoFT generation through mobile and internet banking channels.
* Tokenization requires explicit customer consent and Additional Factor Authentication (AFA) validation, which may be combined for multiple merchants.
* Generated tokens will be available on the merchant's payment page within the cardholder's account.
* Cardholders can initiate tokenization upon receiving a new card or at their convenience.
* Card issuers must provide a comprehensive list of merchants for whom tokenization services are available, allowing cardholders to select preferred merchants.
* Tokens can be issued by the card network, the issuer, or both.
* All provisions of previous RBI circulars pertaining to tokenization remain in effect.
This directive is issued under Section 10(2) read with Section 18 of the Payment and Settlement Systems Act, 2007 (Act 51 of 2007).
For further information, contact Gunveer Singh, Chief General Manager-in-Charge, Department of Payment and Settlement Systems, Central Office, 14th Floor, Central Office Building, Shahid Bhagat Singh Road, Fort, Mumbai – 400001. Phone: 91-22-2264 4995; Fax: 91-22-22691557; email: cgmdpsscorbi.org.in.
Key Entities Referenced
Reserve Bank of India: The central bank of India, responsible for regulating the payment systems.
Payment System Providers: Entities that provide payment services to customers.
Payment System Participants: Entities that participate in payment systems.
Card-on-File Tokenisation (CoFT): A process of replacing actual card details with a token to secure card transactions.
Payment and Settlement Systems Act, 2007: An act of the Indian Parliament that provides for the regulation and supervision of payment systems in India.
Card Issuing Banks: Banks that issue credit and debit cards.
Mumbai, Maharashtra: Location of the Central Office of the Department of Payment and Settlement Systems.
Gunveer Singh: Chief General Manager-in-Charge, Department of Payment and Settlement Systems, Reserve Bank of India
RBI/2023-24/91
CO.DPSS.POLC.No.S-919/02-14-003/2023-24 December 20, 2023
All Payment System Providers and Payment System Participants
Madam / Dear Sir,
Card-on-File Tokenisation (CoFT) – Enabling Tokenisation through Card
Issuing Banks
The card tokenisation services are being currently provided by card issuers and
card networks in terms of Reserve Bank of India circulars DPSS.CO.PD
No.1463/02.14.003/2018-19 dated January 8, 2019 on “Tokenisation – Card
transactions”, CO.DPSS.POLC.No.S-516/02-14-003/2021-22 dated September 07,
2021 on “Tokenisation – Card Transactions: Permitting Card-on-File Tokenisation
(CoFT) Services” and CO.DPSS.POLC.No.S-567/02-14-003/2022-23 dated June 24,
2022 on “Restriction on Storage of Actual Card Data [i.e. Card-on-File (CoF)]”.
2. As announced in the Statement on Development and Regulatory Policies dated
October 6, 2023, it has been decided to enable CoFT directly through card issuing
banks / institutions also. This will provide cardholders with an additional choice to
tokenise their cards for multiple merchant sites through a single process. Detailed
requirements for the same are listed in the Annex.
3. This directive is issued under Section 10 (2) read with Section 18 of Payment
and Settlement Systems Act, 2007 (Act 51 of 2007).
Yours faithfully,
(Gunveer Singh)
Chief General Manager-in-Charge
भगु तान और �नपटान प्रणाल� �वभाग, क�द्र�य कायार्लय, 14वी मिंजल, क�द्र�य कायार्लय भवन, शह�द भगत �सहं माग,र् फोटर्, मम्ु बई - 400001
फोन Tel: (91-22) 2264 4995; फैक् स Fax: (91-22) 22691557; ई-मेल e-mail : cgmdpssco@rbi.org.in
Department of Payment and Settlement Systems, Central Office, 14th Floor, Central Office Building, Shahid Bhagat Singh Road, Fort, Mumbai -
400001
�हदं � आसान है, इसका प्रयोग बढ़ाइएAnnex
(CO.DPSS.POLC.No.S-919/02-14-003/2023-24 dated December 20, 2023)
CoFT through card issuers - Requirements
1. Generation of CoF Tokens for a card, through the card issuer, can be enabled
through mobile banking and internet banking channels.
2. CoFT generation shall be done only on explicit customer consent, and with AFA
validation. If the cardholder selects multiple merchants for which to tokenise
his/her card, AFA validation may be combined for all these merchants.
3. The tokens thus generated shall be made available on the merchant’s payment
page, in the cardholder’s account with the merchant.
4. The cardholder may tokenise the card at any time of his convenience, either on
receipt of the new card or later.
5. The card issuer shall provide a complete list of merchants for whom it can
provide tokenisation services. The cardholders shall select the merchants with
whom he/she wishes to maintain tokens. (Alternatively – “The cardholder can
make his selection from the list”).
6. The card token so issued may be either by the card network or the issuer or
both.
7. All other provisions of RBI circulars dated January 8, 2019, August 25, 2021,
September 7, 2021 and July 28, 2022 shall remain applicable.