See Full Document Text
RBI/2022-23/158
CO.DPSS.OVRST.No.S1619/06-08-005/2022-2023 December 26, 2022
The Chairman / Managing Director / Chief Executive Officer
Banks, Non-bank Payment System Operators (PSOs) and
Credit Card issuing Non-Banking Financial Companies (NBFCs)
Madam / Dear Sir,
Central Payments Fraud Information Registry β Migration of Reporting to DAKSH
As announced in the Monetary Policy Statement 2019-20 on August 07, 2019, the Reserve
Bank of India (RBI) had operationalised the Central Payments Fraud Information Registry
(CPFIR) in March 2020 with reporting of payment frauds by scheduled commercial banks and
non-bank Prepaid Payment Instrument (PPI) issuers.
2. To streamline reporting, enhance efficiency and automate the payments fraud
management process, the fraud reporting module is being migrated to DAKSH β Reserve
Bankβs Advanced Supervisory Monitoring System. The migration will be effective from
January 01, 2023, i.e., entities shall commence reporting of payment frauds in DAKSH from
this date. In addition to the existing bulk upload facility to report payment frauds, DAKSH
provides additional functionalities, viz. maker-checker facility, online screen-based reporting,
option for requesting additional information, facility to issue alerts / advisories, generation of
dashboards and reports, etc. The reporting guidelines are mentioned in the Annex.
3. These directions are issued under Section 10 (2) read with Section 18 of Payment and
settlement Systems Act, 2007 (Act 51 of 2007).
Yours faithfully,
(P. Vasudevan)
Chief General Manager(Annex to Circular CO.DPSS.OVRST.No.S1619/06-08-005/2022-2023 dated December 26,
2022)
Annex
CPFIR β Reporting Guidelines
β’ All RBI authorised Payment System Operators (PSOs) / providers and payment system
participants operating in India are required to report all payment frauds, including
attempted incidents, irrespective of value, either reported by their customers or detected
by the entities themselves. This reporting was earlier facilitated through Electronic Data
Submission Portal (EDSP) and is being migrated to DAKSH.
β’ The responsibility to submit the reported payment fraud transactions shall be of the issuer
bank / PPI issuer / credit card issuing NBFCs, whose issued payment instrument has been
used in the fraud.
β’ Entities are required to validate the payment fraud information reported by the customer
in their own systems to ensure the authenticity and completeness, before reporting the
same to RBI on individual transaction basis.
β’ Entities are required to report payment frauds (domestic and international) to CPFIR as
per the specified timelines (currently within 7 calendar days from date of reporting by
customer / date of detection by the entity).
β’ Entities may continue to report payment frauds as per the extant reporting format using
the bulk upload facility in DAKSH or report individual payment frauds online using the
screen-based facility under the Incident Module of the DAKSH platform.
β’ After go-live of payment fraud reporting in DAKSH effective January 01, 2023, entities
shall not be able to report any payment frauds in EDSP. Entities may, however, continue
to update and close payment frauds that were reported in EDSP until December 31, 2022.
Reserve Bank shall subsequently migrate the historical data from EDSP to DAKSH.
β’ The reporting format remains unchanged (Appendix).
β’ Though some elements / fields of the Reporting Format are indicated as βOptionalβ, entities
shall strive to include them as part of initial reporting itself and only in exceptional cases
be reported as updates.Appendix
CPFIR β Payment Fraud Reporting
The data collection file format is a combination of a single Header row and one or more data rows.
The Header row is used to collect the metadata information about the data submitted by the
reporting entity and data row contains details of the payment fraud reported.
Header Format
Field Name Field Length Comments Example
Return Code 3 Must be βPFRβ (Payment Fraud Reporting) PFR
I β To identify the file has come for inserting the
records for initial reporting
1
Flag I or U
U β To identify file has come for updating the
records already reported
Reporting Upto 7 digit As per the Centralised Information System for
010
Entity Code Banking Infrastructure (CISBI) of RBI
File Submission 8
Must be βDDMMYYYYβ 21012020
Date
20 Number of data rows present in the submitted
Record Count 1
file excluding header
Note:
β’ All individual fields must be separated by a colon (:).
β’ Header record must end with semi-colon (;)
Example:
PFR:I:010:21012020:1;
Data Row Format
Mandatory
Field
Field Name (M) / Guidelines Comments
Length
Optional (O)
Internal Alphanumeric field that Only alphanumeric,
identifier used can be used by reporting underscore, hyphen
20 O
by bank / non- entity for their internal and multiple spaces
bank entity reference, if required. are allowed.If fraud reported by
Was the fraud
Customer β Y;
reported by 1 M
If fraud detected by Bank
customer ?
/ non-bank entity β N;
Was it an
If attempted fraud β Y;
attempted 1 M
Else β N;
fraud ?
Payment Three digit code from the
transaction master data code list
3 M
instrument provided in Annex of this
used document.
Three digit code from the
Payment
master data code list
system 3 M
provided in Annex of this
category
document.
System System involved to be
involved in selected from the master
10 M
the fraudulent data provided in Annex
transaction of this document.
Payment Three digit code from the
channel used master data code list
3 M
for fraudulent provided in Annex of this
transaction document.
Three digit code from the
Nature of
master data code list
fraudulent 3 O
provided in Annex of this
transaction
document.
Date of
occurrence of
the fraud as
identified by 8 Must be DDMMYYYY
the bank /
non-bank
If Fraud
entity
Reported by
Date of
Customer =
detection of
No; M
the fraud by 8 Must be DDMMYYYY
bank / non-
bank entity
Date of
entering in the 8 Must be DDMMYYYY
system
Date of
occurrence of
the fraud
8 Must be DDMMYYYY
transaction If Fraud
reported by Reported by
customer Customer =
Yes; M
Time of
occurrence of 8 Must be HH:MM:SS
the fraudtransaction
reported by
customer
Reporting
date of fraud
by the
8 Must be DDMMYYYY
customer to
bank / PPI
issuer / PSO
Date of
entering the
fraud by the
8 Must be DDMMYYYY
bank / PPI
issuer / PSO
in the system
Unique Transaction
Reference No. generated
by the payment system
Unique
that has processed the
Transaction Only alphanumeric,
payment transaction.
Reference underscore and
35 M For attempted frauds that
No. of the hyphen are allowed.
do not have any UTR,
fraudulent
entities may specify
transaction
ATTEMPTEDXXXX
where XXXX is a
sequence number.
Is the fraud a
If domestic transaction -
domestic 1 M
Y; else β N;
transaction?
Only alphabets,
numbers, dot,
parentheses, single
quote / apostrophe,
Reporting
ampersand, comma,
customer 100 Name of the customer
If Fraud hyphen, forward
name
Reported by slash, back slash,
Customer = underscore and
Yes; M multiple spaces are
allowed.
Only numeric, single
Reporting
space, plus (1st char)
customer 15
and hyphen are
mobile no.
allowed.
Reporting
Standard characters
customer e- 50 O
accepted in e-mail
mail
Only alphabets,
Any other
numbers, hyphen,
detail of the
100 O dot, comma, single
reporting
quote, colon, semi
customer
colon, forward slashand multi-spaces
between them are
allowed.
Was any PA / If PA / PG involved β Y;
1 M
PG Involved ? else β N;
Only alphabets,
numbers, hyphen,
dot, comma, single
If PA / PG quote, colon, semi
If PA / PG
involved, the colon, forward slash,
100 Involved = Y;
name may be parentheses,
M
provided ampersand, back
slash, @ sign, hash,
+ and multiple spaces
are allowed.
Was any third
If third party PSP
party PSP 1 M
involved -Y; else N;
involved ?
Only alphabets,
numbers, hyphen,
dot, comma, single
If third party If Third party quote, colon, semi
PSP involved, PSP colon, forward slash,
100
the name may involved = Y; parentheses,
be provided M ampersand, back
slash, @ sign, hash,
+, multiple spaces
are allowed.
Amount
involved (INR If Attempted Only numbers are
actuals) in the 20 Fraud = N; Amount in rupees allowed.
fraudulent M
transaction
Amount
recovered
Only numbers are
(INR actuals)
20 O Amount in rupees allowed.
in the
fraudulent
transaction
Was
insurance If insurance coverage
1 O
coverage available β Y; else β N;
available ?
Only alphabets,
Name of numbers, hyphen,
insurer and dot, comma, single
If Insurance
per quote, double quotes,
2000 Coverage =
transaction ampersand, colon,
Y; M
coverage semicolon,
amount parentheses, forward
slash, dollar, euro,pound, rupee, krona,
back slash, multiple
spaces and line break
are allowed.
Amount
recovered If Insurance Only numbers are
due to 20 Coverage = allowed.
Insurance Y; M
cover
Only alphabets,
numbers, dot,
parentheses,
single quote /
apostrophe,
Beneficiary
100 O Name of the Beneficiary ampersand, comma,
name
hyphen, forward
slash, back slash,
underscore and
multiple spaces are
allowed.
Only numeric, single
Beneficiary space, plus (1st char)
15 O
mobile and hyphen are
allowed.
Beneficiary e- Standard characters
50 O
mail accepted in e-mail
Beneficiary Only numbers and
account 50 O alphabets are
number allowed.
Bank Working Code from
Beneficiary
7 O CISBI. For Non-Bank the
bank
code provided by DPSS
Beneficiary Part 1 Code to be
branch (part 1 7 O provided here as per the
code) CISBI
Only numbers and
Beneficiary
11 O IFSC for the Branch alphabets are
branch IFSC
allowed.
Only numbers and
Beneficiary
10 O alphabets are
PAN card no.
allowed.
Beneficiary
Only numbers are
debit / credit 16 O
allowed.
card no.Only alphabets,
Beneficiary
numbers, + and
PPI card / 50 O
multiple spaces are
wallet no.
allowed.
Only alphabets,
numbers, @ sign, dot
and hyphen are
allowed in standard
pattern.
Beneficiary @ is mandatory for
50 O
UPI ID UPI ID.
In case the
transaction is based
on UPI Number that
should be entered.
(@ is not required)
Only alphabets,
numbers, hyphen,
dot, single quote,
colon, semi colon,
Name of
forward slash,
destination 100 O
parentheses,
PPI issuer
ampersand, back
slash, @ sign, hash,
+ and multiple spaces
are allowed.
Only alphabets,
numbers, forward
slash, parentheses,
dot, ampersand,
Destination comma, colon, star,
50 O
merchant ID hash, underscore,
single quote /
apostrophe, + and
multiple spaces are
allowed.
Only alphabets,
numbers, forward
slash, parentheses,
dot, ampersand,
Destination
comma, colon, star,
merchant 100 O
hash, underscore,
name
single quote /
apostrophe, +
andmultiple spaces
are allowed.
Only alphabets,
Destination
50 O numbers, hyphen,
payment
dot, comma, singlegateway / quote, colon,
aggregator semicolon, forward
slash, parentheses,
Ampersand, Back
slash, @, hash, + and
multiple spaces are
allowed.
Destination Only alphabets and
50 O
ATM ID numbers are allowed.
Only alphabets,
numbers, hyphen,
dot, comma, single
Suspect
100 O Website address quote, colon, semi
website used
colon, forward slash,
hash and no spaces
are allowed.
Only alphabets,
numbers, hyphen,
dot, comma, single
Suspect
quote, colon, semi
mobile app 100 O
colon, forward slash,
used
hash and multiple
spaces between them
are allowed.
Only alphabets,
numbers, hyphen,
dot, comma, single
Suspect quote, colon, semi
50 O
device ID colon, forward slash,
hash and multiple
spaces between them
are allowed.
Only numbers, dot
Suspect IP
50 O and colon are
Address
allowed.
Suspect IMEI Only alphabets and
20 O
number numbers are allowed.
Only alphabets,
numbers, hyphen,
dot, comma, single
Suspect quote, colon, semi
50 O
geotag ID colon, forward slash
and multiple spaces
between them are
allowed.
Only alphabets,
numbers, hyphen,
Any other
dot, comma, single
details of 100 O
quote, colon, semi
suspect
colon, forward slash,
hash and multiplespaces between them
are allowed.
Only alphabets,
numbers, hyphen,
dot, comma, single
quote, double quotes,
ampersand, colon,
Initial inputs
semi colon,
on modus Fraud related
2000 O parentheses, forward
operandi of information, if any
slash, dollar, euro,
fraud
pound, rupee, krona,
line break and
multiple spaces
between them are
allowed.
Only alphabets,
numbers, hyphen,
dot, comma, single
quote, double quotes,
ampersand, colon,
Modus semi colon,
Fraud related updates, if
operandi β 2000 O parentheses, forward
any
update 1 slash, dollar, euro,
pound, rupee, krona,
line break and
multiple spaces
between them are
allowed.
Only alphabets,
numbers, hyphen,
dot, comma, single
quote, double quotes,
ampersand, colon,
Modus semi colon,
Fraud related updates, if
operandi β 2000 O parentheses, forward
any
update 2 slash, dollar, euro,
pound, rupee, krona,
line break and
multiple spaces
between them are
allowed.
Only alphabets,
numbers, hyphen,
dot, comma, single
quote, double quotes,
Modus
Fraud related updates, if ampersand, colon,
operandi β 2000 O
any semi colon,
update 3
parentheses, forward
slash, dollar, euro,
pound, rupee, krona,
line break andmultiple spaces
between them are
allowed.
Only alphabets,
numbers, hyphen,
dot, comma, single
quote, double quotes,
ampersand, colon,
Modus semi colon,
Fraud related updates, if
operandi β 2000 O parentheses, forward
any
update 4 slash, dollar, euro,
pound, rupee, krona,
line break and
multiple spaces
between them are
allowed.
Only alphabets,
numbers, hyphen,
dot, comma, single
quote, double quotes,
ampersand, colon,
Modus semi colon,
Fraud related updates, if
operandi β 2000 O parentheses, forward
any
update 5 slash, dollar, euro,
pound, rupee, krona,
line break and
multiple spaces
between them are
allowed.
False alert β
transaction Must be Y/N, after
1 O
was not a investigation done
fraud
Fraud was
registered
with Law
Enforcement 1 O Y/N to be provided
Agencies
(LEA) / sub-
judice
Only alphabets,
numbers, hyphen,
dot, comma, single
If fraud was quote, double quotes,
registered Details to be provided if ampersand, colon,
with LEA, 500 O the above field response semicolon,
details of is YES parentheses, forward
case reported slash, dollar, euro,
pound, rupee, krona,
line break and
multiple spacesbetween them are
allowed.
Has the fraud
incident been 1 M Must be Y/N
closed?
Date should be lesser
than or equal to
Details to be provided if
Date of If Fraud current date and
the above field response
closure of 8 Closed = Y; greater than or equal
is yes in DDMMYYYY
fraud M to occurrence date as
format
well as detection
date.
Only alphabets,
numbers, hyphen,
dot, comma, single
quote, double quotes,
ampersand, colon,
Justification If Fraud Details to be provided if semicolon,
for closure of 2000 Closed = Y; the above field response parentheses, forward
fraud M is yes slash, dollar, euro,
pound, rupee, krona,
line break and
multiple spaces
between them are
allowed.
Only alphabets,
numbers, hyphen,
dot, comma, single
quote, double quotes,
ampersand, colon,
Any other
semicolon,
information
2000 O parentheses, forward
pertaining to
slash, dollar, euro,
the fraud
pound, rupee, krona,
line break and
multiple spaces
between them are
allowed.
Only alphabets,
numbers, hyphen,
dot, comma, single
quote, double quotes,
Steps taken ampersand, colon,
to address / semicolon,
prevent such 2000 O parentheses, forward
frauds in slash, dollar, euro,
future pound, rupee, krona,
line break and
multiple spaces
between them are
allowed.Note:
β’ Mandatory fields once submitted cannot be modified (except for fraud closed which can
be updated from No to Yes).
β’ Once a fraud is closed, no updates are permitted.
β’ The output file generated for successful records shall contain a Fraud Reference Number
(FRN) assigned to all successfully inserted records. The FRN shall begin with βFβ for actual
frauds and βAβ in case of attempted frauds. The same FRN must be used for reporting
Updates.
β’ The format for reporting updates is same as the format for initial reporting (Insert). Only
the FRN generated during initial (Insert) reporting must be appended at the start of the
record followed by pipe (|).
β’ Although some fields are marked as optional, entities are advised to report maximum
available data to facilitate analysis and strengthen the ecosystem.
β’ All data elements to be separated by pipe (|).
β’ No additional character to be included at the end of each record.
Example: Insert record
CAN15112022000043446|Y|N|DEC|CAN|VISA|POS|OTH|||16112022|07112022|14:15:03|1411
2022|16112022|231108479433|Y|SANDEEP R
PATEL|1234567890|||N||N||18805.62||Y|National - 100000|0.00||||||||||||||||||||||||SUSPECTED
FRAUD TRANSACTION|||||||N||N||||
Example: Update record
F010161120221|CAN15112022000043446|Y|N|DEC|CAN|VISA|POS|OTH|||16112022|0711202
2|14:15:03|14112022|16112022|231108479433|Y|SANDEEP R
PATEL|1234567890|||N||N||18805.62||Y|National - 100000|0.00||||||||||||||||||||||||SUSPECTED
FRAUD TRANSACTION|||||||N||N||||Annex
Payment Transaction Instrument
Payment Transaction
Instrument Code Payment Transaction Instrument
BNK Bank Account
PAI Paper Instruments
DEC Debit Cards (including tokenised debit card or virtual debit card)
CRC Credit Cards (including tokenised credit card or virtual credit card)
PPI Pre-paid Payment Instruments (wallet or physical card)
OTH Other
Payment System Category
Payment System Code Payment System Involved
ROP RBI Operated Payment Systems (RTGS / NEFT)
NPCI Operated Payment Systems (IMPS, NACH, UPI, BBPS, NETC,
NOP
CTS, AEPS, BHIM Aadhaar Pay)
CAN Card Networks (VISA, Mastercard, Rupay, Diners, Amex)
ATM ATM Networks
PII Prepaid Payment Instrument Issuers
CMO Cross-Border Money Transfer Operators
TRD Trade Receivables Discounting System (TReDS)
IMO Instant Money Transfer Operators
INB Intra-Bank (Banksβ Core Banking System)
OTH Other
Payment System Involved : Payment System Payment System
Name of Payment System
Involved Code
Based on input in 3C β Payment system category,
the name of payment system used β RBI operated Real Time Gross Settlement RTGS
payment systems
National Electronic Funds Transfer NEFT
NPCI Operated Payment Systems Immediate Payment Service IMPS
National Automated Clearing House NACH
Unified Payments Interface UPI
Bharat Bill Payment System BBPS
National Electronic Toll Collection NETC
Cheque Truncation System CTS
Aadhaar enabled Payment System AEPS
BHIM Aadhaar Pay BHIMAP
Card Networks (Visa, Mastercard, Rupay, Diners, American Express Banking Corp.,
AMEX
Amex) USA
Diners Club International Ltd., USA DINERSMasterCard Asia / Pacific Pte. Ltd.,
MASTER
Singapore
National Payments Corporation of
NPCI
India (RuPay)
Visa Worldwide Pte. Limited,
VISA
Singapore
ATM Networks (list of authorised ATM networks); Bank of India BOIATM
Euronet Services India Private
EURATM
Limited
National Payments Corporation of
NFSATM
India (NFS)
Punjab National Bank PNBATM
State Bank of India SBIATM
Other β On Us Transaction ONUS
Prepaid Payment Instrument Issuers
Prepaid Payment Instrument Issuers PPI-NA
β Not Applicable
Cross-Border Money Transfer Operators (list of
Bahrain Financing Company, BSC (C) BFCBSC
authorised MTSS Principals);
Continental Exchange Solutions Inc,
CESUSA
USA
Fast Encash Money Transfer Services
FEMTSL
Ltd.
Mastercard Transaction Services
(Canada) Inc.(formerly Transfast Inc.,
TICCAN
Canada and Global Foreign Exchange
Inc.)
MoneyGram Payment Systems Inc,
MGPUSA
USA.
Muthoot Finserve USA Inc. {formerly
MUTUSA
Royal Exchange (USA) Inc.}
UAE Exchange Centre LLC, UAE UAEECL
Wall Street Exchange Centre LLC,
WSEUAE
UAE
Western Union Financial Services
WUFUSA
Incorporated, USA
TReDS (list of authorised TReDS entities); A.TREDS Limited ATREDS
Mynd Solutions Private Limited MTREDS
Receivables Exchange of India
RTREADS
Limited (RXIL)
Instant Money Transfer Operators β Not Instant Money Transfer Operators β
IMTP-NA
Applicable; Not Applicable;
Intra-Bank β Not Applicable; Intra-Bank β Not Applicable; INTRA-NA
Others β Not Applicable; Others β Not Applicable; OTH-NAPayment Channel Used
Payment Channel Code Payment Channel Used
BRN Branch
INT Internet (Online)
MBL Mobile
ITB Internet Banking
MOB Mobile Banking
ATM ATM
POS POS
BCA BC Agent
IVR IVR
MOT MOTO
OTH Others
Nature of Fraud
Fraud Nature Code Nature of Fraud
ACH Account Hacking / Compromise / Identity theft
PHH Phishing
RMD Remote Capture of Device
LSI Lost / Stolen Device / Instrument
CRS Card Skimming
VIS Vishing
SMI Smishing
SIS SIM Swap
WBC Website Cloning / Fraudulent Link
FRA Fraudulent App
EHC Email Hacking / Compromise
FMP Forgery / Modification of Payment
MRC Merchant Collusion
CLR Collect Payment Request
OTH Other