Homeβ€Ί Indiaβ€Ί Reserve Bank of Indiaβ€Ί Central Payments Fraud Information Registry – Migration of R...
Date: 2022-12-26 Category: Not Applicable State: Union Government Country: India

Central Payments Fraud Information Registry – Migration of Reporting to DAKSH

Issued by Reserve Bank of India Β· Not Applicable

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task

Executive Summary & Key Takeaways

Executive Summary: This document announces the migration of payment fraud reporting from the Electronic Data Submission Portal (EDSP) to the DAKSH (Reserve Bank's Advanced Supervisory Monitoring System) platform. The migration aims to streamline reporting, enhance efficiency, and automate fraud management. Effective January 1, 2023, entities must report payment frauds in DAKSH. Key Points / Main Content: Reporting Platform Migration: * The Central Payments Fraud Information Registry (CPFIR) reporting module is moving from EDSP to DAKSH. * Effective January 1, 2023, all payment fraud reporting must be done through DAKSH. * After January 1, 2023, new fraud cannot be reported in EDSP. * Historical data from EDSP will be migrated to DAKSH by the Reserve Bank. Reporting Guidelines: * All RBI-authorized Payment System Operators (PSOs), providers, and participants must report all payment frauds, including attempted incidents, regardless of value. * The issuer bank/PPI issuer/credit card issuing NBFC whose payment instrument was used in the fraud is responsible for reporting. * Entities must validate payment fraud information reported by customers before reporting it to RBI. * Payment frauds (domestic and international) must be reported to CPFIR within 7 calendar days from the date of reporting by the customer or date of detection by the entity. * The reporting format remains unchanged. DAKSH Functionalities: * DAKSH provides functionalities such as maker-checker facility, online screen-based reporting, options for requesting additional information, alerts/advisories, and generation of dashboards and reports. * Entities can report payment frauds using the bulk upload facility or the screen-based facility in DAKSH. EDSP Usage: * Entities can continue to update and close payment frauds reported in EDSP until December 31, 2022. Reporting Format Details: * The reporting format consists of a header row (metadata) and data rows (fraud details). * The header row includes fields like Return Code, Flag, Reporting Entity Code, File Submission Date, and Record Count, separated by colons. * Data rows contain mandatory and optional fields about the fraud incident separated by pipes. Impact Analysis: Banks, Non-bank Payment System Operators (PSOs), and Credit Card Issuing Non-Banking Financial Companies (NBFCs) Impact: These entities are required to change their reporting mechanism for payment frauds from EDSP to DAKSH, and adapt to the new functionalities offered by DAKSH. Action Required: * Familiarize themselves with the DAKSH platform. * Ensure systems are in place to report payment frauds via DAKSH starting January 1, 2023. * Continue to update and close payment frauds reported in EDSP until December 31, 2022. RBI Authorised Payment System Operators PSOs providers and payment system participants operating in India Impact: All are required to report all payment frauds, including attempted incidents, irrespective of value, either reported by their customers or detected by the entities themselves. Action Required: * Comply with reporting requirements and specified timelines.

Key Entities Referenced

Reserve Bank of India RBI: The central bank of India, responsible for operationalizing the Central Payments Fraud Information Registry (CPFIR) and migrating fraud reporting to DAKSH. Central Payments Fraud Information Registry CPFIR: A registry maintained by the Reserve Bank of India for reporting payment frauds by scheduled commercial banks and non-bank Prepaid Payment Instrument (PPI) issuers. DAKSH: Reserve Bank's Advanced Supervisory Monitoring System, the platform to which payment fraud reporting is being migrated from the Electronic Data Submission Portal (EDSP). Payment and settlement Systems Act, 2007: The act under which the directions for reporting payment frauds are issued. Payment System Operators PSOs: Entities authorized by the RBI and operating in India that are required to report all payment frauds. NonBanking Financial Companies NBFCs: Credit card issuing institutions that are required to report payment frauds. Prepaid Payment Instrument PPI: Non-bank issuers that are required to report payment frauds. Electronic Data Submission Portal EDSP: The previous platform used for reporting payment frauds, which is being replaced by DAKSH.
Official Source Record View Original Source β†’
See Full Document Text
RBI/2022-23/158 CO.DPSS.OVRST.No.S1619/06-08-005/2022-2023 December 26, 2022 The Chairman / Managing Director / Chief Executive Officer Banks, Non-bank Payment System Operators (PSOs) and Credit Card issuing Non-Banking Financial Companies (NBFCs) Madam / Dear Sir, Central Payments Fraud Information Registry – Migration of Reporting to DAKSH As announced in the Monetary Policy Statement 2019-20 on August 07, 2019, the Reserve Bank of India (RBI) had operationalised the Central Payments Fraud Information Registry (CPFIR) in March 2020 with reporting of payment frauds by scheduled commercial banks and non-bank Prepaid Payment Instrument (PPI) issuers. 2. To streamline reporting, enhance efficiency and automate the payments fraud management process, the fraud reporting module is being migrated to DAKSH – Reserve Bank’s Advanced Supervisory Monitoring System. The migration will be effective from January 01, 2023, i.e., entities shall commence reporting of payment frauds in DAKSH from this date. In addition to the existing bulk upload facility to report payment frauds, DAKSH provides additional functionalities, viz. maker-checker facility, online screen-based reporting, option for requesting additional information, facility to issue alerts / advisories, generation of dashboards and reports, etc. The reporting guidelines are mentioned in the Annex. 3. These directions are issued under Section 10 (2) read with Section 18 of Payment and settlement Systems Act, 2007 (Act 51 of 2007). Yours faithfully, (P. Vasudevan) Chief General Manager(Annex to Circular CO.DPSS.OVRST.No.S1619/06-08-005/2022-2023 dated December 26, 2022) Annex CPFIR – Reporting Guidelines β€’ All RBI authorised Payment System Operators (PSOs) / providers and payment system participants operating in India are required to report all payment frauds, including attempted incidents, irrespective of value, either reported by their customers or detected by the entities themselves. This reporting was earlier facilitated through Electronic Data Submission Portal (EDSP) and is being migrated to DAKSH. β€’ The responsibility to submit the reported payment fraud transactions shall be of the issuer bank / PPI issuer / credit card issuing NBFCs, whose issued payment instrument has been used in the fraud. β€’ Entities are required to validate the payment fraud information reported by the customer in their own systems to ensure the authenticity and completeness, before reporting the same to RBI on individual transaction basis. β€’ Entities are required to report payment frauds (domestic and international) to CPFIR as per the specified timelines (currently within 7 calendar days from date of reporting by customer / date of detection by the entity). β€’ Entities may continue to report payment frauds as per the extant reporting format using the bulk upload facility in DAKSH or report individual payment frauds online using the screen-based facility under the Incident Module of the DAKSH platform. β€’ After go-live of payment fraud reporting in DAKSH effective January 01, 2023, entities shall not be able to report any payment frauds in EDSP. Entities may, however, continue to update and close payment frauds that were reported in EDSP until December 31, 2022. Reserve Bank shall subsequently migrate the historical data from EDSP to DAKSH. β€’ The reporting format remains unchanged (Appendix). β€’ Though some elements / fields of the Reporting Format are indicated as β€˜Optional’, entities shall strive to include them as part of initial reporting itself and only in exceptional cases be reported as updates.Appendix CPFIR – Payment Fraud Reporting The data collection file format is a combination of a single Header row and one or more data rows. The Header row is used to collect the metadata information about the data submitted by the reporting entity and data row contains details of the payment fraud reported. Header Format Field Name Field Length Comments Example Return Code 3 Must be β€˜PFR’ (Payment Fraud Reporting) PFR I – To identify the file has come for inserting the records for initial reporting 1 Flag I or U U – To identify file has come for updating the records already reported Reporting Upto 7 digit As per the Centralised Information System for 010 Entity Code Banking Infrastructure (CISBI) of RBI File Submission 8 Must be β€˜DDMMYYYY’ 21012020 Date 20 Number of data rows present in the submitted Record Count 1 file excluding header Note: β€’ All individual fields must be separated by a colon (:). β€’ Header record must end with semi-colon (;) Example: PFR:I:010:21012020:1; Data Row Format Mandatory Field Field Name (M) / Guidelines Comments Length Optional (O) Internal Alphanumeric field that Only alphanumeric, identifier used can be used by reporting underscore, hyphen 20 O by bank / non- entity for their internal and multiple spaces bank entity reference, if required. are allowed.If fraud reported by Was the fraud Customer – Y; reported by 1 M If fraud detected by Bank customer ? / non-bank entity – N; Was it an If attempted fraud – Y; attempted 1 M Else – N; fraud ? Payment Three digit code from the transaction master data code list 3 M instrument provided in Annex of this used document. Three digit code from the Payment master data code list system 3 M provided in Annex of this category document. System System involved to be involved in selected from the master 10 M the fraudulent data provided in Annex transaction of this document. Payment Three digit code from the channel used master data code list 3 M for fraudulent provided in Annex of this transaction document. Three digit code from the Nature of master data code list fraudulent 3 O provided in Annex of this transaction document. Date of occurrence of the fraud as identified by 8 Must be DDMMYYYY the bank / non-bank If Fraud entity Reported by Date of Customer = detection of No; M the fraud by 8 Must be DDMMYYYY bank / non- bank entity Date of entering in the 8 Must be DDMMYYYY system Date of occurrence of the fraud 8 Must be DDMMYYYY transaction If Fraud reported by Reported by customer Customer = Yes; M Time of occurrence of 8 Must be HH:MM:SS the fraudtransaction reported by customer Reporting date of fraud by the 8 Must be DDMMYYYY customer to bank / PPI issuer / PSO Date of entering the fraud by the 8 Must be DDMMYYYY bank / PPI issuer / PSO in the system Unique Transaction Reference No. generated by the payment system Unique that has processed the Transaction Only alphanumeric, payment transaction. Reference underscore and 35 M For attempted frauds that No. of the hyphen are allowed. do not have any UTR, fraudulent entities may specify transaction ATTEMPTEDXXXX where XXXX is a sequence number. Is the fraud a If domestic transaction - domestic 1 M Y; else – N; transaction? Only alphabets, numbers, dot, parentheses, single quote / apostrophe, Reporting ampersand, comma, customer 100 Name of the customer If Fraud hyphen, forward name Reported by slash, back slash, Customer = underscore and Yes; M multiple spaces are allowed. Only numeric, single Reporting space, plus (1st char) customer 15 and hyphen are mobile no. allowed. Reporting Standard characters customer e- 50 O accepted in e-mail mail Only alphabets, Any other numbers, hyphen, detail of the 100 O dot, comma, single reporting quote, colon, semi customer colon, forward slashand multi-spaces between them are allowed. Was any PA / If PA / PG involved – Y; 1 M PG Involved ? else – N; Only alphabets, numbers, hyphen, dot, comma, single If PA / PG quote, colon, semi If PA / PG involved, the colon, forward slash, 100 Involved = Y; name may be parentheses, M provided ampersand, back slash, @ sign, hash, + and multiple spaces are allowed. Was any third If third party PSP party PSP 1 M involved -Y; else N; involved ? Only alphabets, numbers, hyphen, dot, comma, single If third party If Third party quote, colon, semi PSP involved, PSP colon, forward slash, 100 the name may involved = Y; parentheses, be provided M ampersand, back slash, @ sign, hash, +, multiple spaces are allowed. Amount involved (INR If Attempted Only numbers are actuals) in the 20 Fraud = N; Amount in rupees allowed. fraudulent M transaction Amount recovered Only numbers are (INR actuals) 20 O Amount in rupees allowed. in the fraudulent transaction Was insurance If insurance coverage 1 O coverage available – Y; else – N; available ? Only alphabets, Name of numbers, hyphen, insurer and dot, comma, single If Insurance per quote, double quotes, 2000 Coverage = transaction ampersand, colon, Y; M coverage semicolon, amount parentheses, forward slash, dollar, euro,pound, rupee, krona, back slash, multiple spaces and line break are allowed. Amount recovered If Insurance Only numbers are due to 20 Coverage = allowed. Insurance Y; M cover Only alphabets, numbers, dot, parentheses, single quote / apostrophe, Beneficiary 100 O Name of the Beneficiary ampersand, comma, name hyphen, forward slash, back slash, underscore and multiple spaces are allowed. Only numeric, single Beneficiary space, plus (1st char) 15 O mobile and hyphen are allowed. Beneficiary e- Standard characters 50 O mail accepted in e-mail Beneficiary Only numbers and account 50 O alphabets are number allowed. Bank Working Code from Beneficiary 7 O CISBI. For Non-Bank the bank code provided by DPSS Beneficiary Part 1 Code to be branch (part 1 7 O provided here as per the code) CISBI Only numbers and Beneficiary 11 O IFSC for the Branch alphabets are branch IFSC allowed. Only numbers and Beneficiary 10 O alphabets are PAN card no. allowed. Beneficiary Only numbers are debit / credit 16 O allowed. card no.Only alphabets, Beneficiary numbers, + and PPI card / 50 O multiple spaces are wallet no. allowed. Only alphabets, numbers, @ sign, dot and hyphen are allowed in standard pattern. Beneficiary @ is mandatory for 50 O UPI ID UPI ID. In case the transaction is based on UPI Number that should be entered. (@ is not required) Only alphabets, numbers, hyphen, dot, single quote, colon, semi colon, Name of forward slash, destination 100 O parentheses, PPI issuer ampersand, back slash, @ sign, hash, + and multiple spaces are allowed. Only alphabets, numbers, forward slash, parentheses, dot, ampersand, Destination comma, colon, star, 50 O merchant ID hash, underscore, single quote / apostrophe, + and multiple spaces are allowed. Only alphabets, numbers, forward slash, parentheses, dot, ampersand, Destination comma, colon, star, merchant 100 O hash, underscore, name single quote / apostrophe, + andmultiple spaces are allowed. Only alphabets, Destination 50 O numbers, hyphen, payment dot, comma, singlegateway / quote, colon, aggregator semicolon, forward slash, parentheses, Ampersand, Back slash, @, hash, + and multiple spaces are allowed. Destination Only alphabets and 50 O ATM ID numbers are allowed. Only alphabets, numbers, hyphen, dot, comma, single Suspect 100 O Website address quote, colon, semi website used colon, forward slash, hash and no spaces are allowed. Only alphabets, numbers, hyphen, dot, comma, single Suspect quote, colon, semi mobile app 100 O colon, forward slash, used hash and multiple spaces between them are allowed. Only alphabets, numbers, hyphen, dot, comma, single Suspect quote, colon, semi 50 O device ID colon, forward slash, hash and multiple spaces between them are allowed. Only numbers, dot Suspect IP 50 O and colon are Address allowed. Suspect IMEI Only alphabets and 20 O number numbers are allowed. Only alphabets, numbers, hyphen, dot, comma, single Suspect quote, colon, semi 50 O geotag ID colon, forward slash and multiple spaces between them are allowed. Only alphabets, numbers, hyphen, Any other dot, comma, single details of 100 O quote, colon, semi suspect colon, forward slash, hash and multiplespaces between them are allowed. Only alphabets, numbers, hyphen, dot, comma, single quote, double quotes, ampersand, colon, Initial inputs semi colon, on modus Fraud related 2000 O parentheses, forward operandi of information, if any slash, dollar, euro, fraud pound, rupee, krona, line break and multiple spaces between them are allowed. Only alphabets, numbers, hyphen, dot, comma, single quote, double quotes, ampersand, colon, Modus semi colon, Fraud related updates, if operandi – 2000 O parentheses, forward any update 1 slash, dollar, euro, pound, rupee, krona, line break and multiple spaces between them are allowed. Only alphabets, numbers, hyphen, dot, comma, single quote, double quotes, ampersand, colon, Modus semi colon, Fraud related updates, if operandi – 2000 O parentheses, forward any update 2 slash, dollar, euro, pound, rupee, krona, line break and multiple spaces between them are allowed. Only alphabets, numbers, hyphen, dot, comma, single quote, double quotes, Modus Fraud related updates, if ampersand, colon, operandi – 2000 O any semi colon, update 3 parentheses, forward slash, dollar, euro, pound, rupee, krona, line break andmultiple spaces between them are allowed. Only alphabets, numbers, hyphen, dot, comma, single quote, double quotes, ampersand, colon, Modus semi colon, Fraud related updates, if operandi – 2000 O parentheses, forward any update 4 slash, dollar, euro, pound, rupee, krona, line break and multiple spaces between them are allowed. Only alphabets, numbers, hyphen, dot, comma, single quote, double quotes, ampersand, colon, Modus semi colon, Fraud related updates, if operandi – 2000 O parentheses, forward any update 5 slash, dollar, euro, pound, rupee, krona, line break and multiple spaces between them are allowed. False alert – transaction Must be Y/N, after 1 O was not a investigation done fraud Fraud was registered with Law Enforcement 1 O Y/N to be provided Agencies (LEA) / sub- judice Only alphabets, numbers, hyphen, dot, comma, single If fraud was quote, double quotes, registered Details to be provided if ampersand, colon, with LEA, 500 O the above field response semicolon, details of is YES parentheses, forward case reported slash, dollar, euro, pound, rupee, krona, line break and multiple spacesbetween them are allowed. Has the fraud incident been 1 M Must be Y/N closed? Date should be lesser than or equal to Details to be provided if Date of If Fraud current date and the above field response closure of 8 Closed = Y; greater than or equal is yes in DDMMYYYY fraud M to occurrence date as format well as detection date. Only alphabets, numbers, hyphen, dot, comma, single quote, double quotes, ampersand, colon, Justification If Fraud Details to be provided if semicolon, for closure of 2000 Closed = Y; the above field response parentheses, forward fraud M is yes slash, dollar, euro, pound, rupee, krona, line break and multiple spaces between them are allowed. Only alphabets, numbers, hyphen, dot, comma, single quote, double quotes, ampersand, colon, Any other semicolon, information 2000 O parentheses, forward pertaining to slash, dollar, euro, the fraud pound, rupee, krona, line break and multiple spaces between them are allowed. Only alphabets, numbers, hyphen, dot, comma, single quote, double quotes, Steps taken ampersand, colon, to address / semicolon, prevent such 2000 O parentheses, forward frauds in slash, dollar, euro, future pound, rupee, krona, line break and multiple spaces between them are allowed.Note: β€’ Mandatory fields once submitted cannot be modified (except for fraud closed which can be updated from No to Yes). β€’ Once a fraud is closed, no updates are permitted. β€’ The output file generated for successful records shall contain a Fraud Reference Number (FRN) assigned to all successfully inserted records. The FRN shall begin with β€˜F’ for actual frauds and β€˜A’ in case of attempted frauds. The same FRN must be used for reporting Updates. β€’ The format for reporting updates is same as the format for initial reporting (Insert). Only the FRN generated during initial (Insert) reporting must be appended at the start of the record followed by pipe (|). β€’ Although some fields are marked as optional, entities are advised to report maximum available data to facilitate analysis and strengthen the ecosystem. β€’ All data elements to be separated by pipe (|). β€’ No additional character to be included at the end of each record. Example: Insert record CAN15112022000043446|Y|N|DEC|CAN|VISA|POS|OTH|||16112022|07112022|14:15:03|1411 2022|16112022|231108479433|Y|SANDEEP R PATEL|1234567890|||N||N||18805.62||Y|National - 100000|0.00||||||||||||||||||||||||SUSPECTED FRAUD TRANSACTION|||||||N||N|||| Example: Update record F010161120221|CAN15112022000043446|Y|N|DEC|CAN|VISA|POS|OTH|||16112022|0711202 2|14:15:03|14112022|16112022|231108479433|Y|SANDEEP R PATEL|1234567890|||N||N||18805.62||Y|National - 100000|0.00||||||||||||||||||||||||SUSPECTED FRAUD TRANSACTION|||||||N||N||||Annex Payment Transaction Instrument Payment Transaction Instrument Code Payment Transaction Instrument BNK Bank Account PAI Paper Instruments DEC Debit Cards (including tokenised debit card or virtual debit card) CRC Credit Cards (including tokenised credit card or virtual credit card) PPI Pre-paid Payment Instruments (wallet or physical card) OTH Other Payment System Category Payment System Code Payment System Involved ROP RBI Operated Payment Systems (RTGS / NEFT) NPCI Operated Payment Systems (IMPS, NACH, UPI, BBPS, NETC, NOP CTS, AEPS, BHIM Aadhaar Pay) CAN Card Networks (VISA, Mastercard, Rupay, Diners, Amex) ATM ATM Networks PII Prepaid Payment Instrument Issuers CMO Cross-Border Money Transfer Operators TRD Trade Receivables Discounting System (TReDS) IMO Instant Money Transfer Operators INB Intra-Bank (Banks’ Core Banking System) OTH Other Payment System Involved : Payment System Payment System Name of Payment System Involved Code Based on input in 3C – Payment system category, the name of payment system used – RBI operated Real Time Gross Settlement RTGS payment systems National Electronic Funds Transfer NEFT NPCI Operated Payment Systems Immediate Payment Service IMPS National Automated Clearing House NACH Unified Payments Interface UPI Bharat Bill Payment System BBPS National Electronic Toll Collection NETC Cheque Truncation System CTS Aadhaar enabled Payment System AEPS BHIM Aadhaar Pay BHIMAP Card Networks (Visa, Mastercard, Rupay, Diners, American Express Banking Corp., AMEX Amex) USA Diners Club International Ltd., USA DINERSMasterCard Asia / Pacific Pte. Ltd., MASTER Singapore National Payments Corporation of NPCI India (RuPay) Visa Worldwide Pte. Limited, VISA Singapore ATM Networks (list of authorised ATM networks); Bank of India BOIATM Euronet Services India Private EURATM Limited National Payments Corporation of NFSATM India (NFS) Punjab National Bank PNBATM State Bank of India SBIATM Other – On Us Transaction ONUS Prepaid Payment Instrument Issuers Prepaid Payment Instrument Issuers PPI-NA – Not Applicable Cross-Border Money Transfer Operators (list of Bahrain Financing Company, BSC (C) BFCBSC authorised MTSS Principals); Continental Exchange Solutions Inc, CESUSA USA Fast Encash Money Transfer Services FEMTSL Ltd. Mastercard Transaction Services (Canada) Inc.(formerly Transfast Inc., TICCAN Canada and Global Foreign Exchange Inc.) MoneyGram Payment Systems Inc, MGPUSA USA. Muthoot Finserve USA Inc. {formerly MUTUSA Royal Exchange (USA) Inc.} UAE Exchange Centre LLC, UAE UAEECL Wall Street Exchange Centre LLC, WSEUAE UAE Western Union Financial Services WUFUSA Incorporated, USA TReDS (list of authorised TReDS entities); A.TREDS Limited ATREDS Mynd Solutions Private Limited MTREDS Receivables Exchange of India RTREADS Limited (RXIL) Instant Money Transfer Operators – Not Instant Money Transfer Operators – IMTP-NA Applicable; Not Applicable; Intra-Bank – Not Applicable; Intra-Bank – Not Applicable; INTRA-NA Others – Not Applicable; Others – Not Applicable; OTH-NAPayment Channel Used Payment Channel Code Payment Channel Used BRN Branch INT Internet (Online) MBL Mobile ITB Internet Banking MOB Mobile Banking ATM ATM POS POS BCA BC Agent IVR IVR MOT MOTO OTH Others Nature of Fraud Fraud Nature Code Nature of Fraud ACH Account Hacking / Compromise / Identity theft PHH Phishing RMD Remote Capture of Device LSI Lost / Stolen Device / Instrument CRS Card Skimming VIS Vishing SMI Smishing SIS SIM Swap WBC Website Cloning / Fraudulent Link FRA Fraudulent App EHC Email Hacking / Compromise FMP Forgery / Modification of Payment MRC Merchant Collusion CLR Collect Payment Request OTH Other

Continue your research