menu
close_24px

 

RBI DPSC

RBI DPSC stands for the Reserve Bank of India's Digital Payment Security Controls, a Master Direction that sets mandatory security requirements for digital payments in India.

The RBI itself issues dozens of circulars and directions across the banking sector. DPSC is the one specifically about digital payment security and the one most relevant to a mobile banking or payments app.

Issued February 18, 2021, it applies to Scheduled Commercial Banks, Small Finance Banks, Payments Banks, and credit-card-issuing NBFCs, with a six-month window to comply.

Why it's unusually mobile-specific

Most compliance frameworks treat mobile as one channel among several. DPSC dedicates an entire chapter, Chapter 4, specifically to Mobile Payments Applications Security Controls, giving more mobile-specific attention than most international frameworks give.

Its requirements read like a mobile security checklist:

  • Device binding tied to hardware and software identifiers,
  • Root and jailbreak detection before an app is allowed to run,
  • Phased deactivation of older app versions within a defined window,
  • Detection of remote-access applications that could enable screen-sharing fraud, and
  • Code obfuscation.

Why this exists

India's digital payments volume is enormous, and mobile is how nearly all of it happens.

The directions explicitly extend to third-party payment apps, the kind built by fintechs rather than banks themselves, reflecting how much of India's payment infrastructure now runs through apps a bank doesn't directly build or control.

Where Appknox fits

Appknox tests the specific technical controls DPSC's mobile chapter requires:

  • Root and jailbreak detection,

  • Code obfuscation,

  • Secure local storage, and

  • Certificate validation.

Appknox also maps findings to the relevant DPSC requirement automatically, alongside the other regional and framework mappings.

See Appknox's compliance frameworks: Compliance at Appknox


Check out the full testing methodology: Appknox Automated Vulnerability Assessment.

Frequently asked questions

What does RBI DPSC stand for?

RBI DPSC stands for the Reserve Bank of India's Digital Payment Security Controls, a Master Direction setting mandatory security requirements for digital payments in India.

Who does RBI DPSC apply to?

RBI DPSC applies to scheduled Commercial Banks (excluding Regional Rural Banks), Small Finance Banks, Payments Banks, and credit-card-issuing NBFCs, including their third-party payment applications.

Why does DPSC have a dedicated mobile chapter?

Because mobile is how most digital payments in India actually happen, the RBI chose to write specific, detailed requirements for that channel rather than treat it as a generic extension of internet banking.

When did DPSC take effect?

The Master Direction was issued on February 18, 2021, with a six-month compliance window for regulated entities.

Does Appknox support RBI DPSC compliance?

Yes. Appknox tests for the specific mobile security controls required by DPSC and automatically maps findings to the relevant requirements.

Related: What is SAMA? | What is MAS TRM? | Appknox Automated Vulnerability Assessment


By Aadarsh Anand, Security Researcher, Appknox Security Research Team

Appknox is an enterprise mobile application security testing platform. This page was written by Appknox's security research team based on direct experience mapping automated and manual testing findings to RBI DPSC and other regional regulatory frameworks across BFSI clients.

This page was drafted with AI assistance and reviewed and verified by the Appknox security research team.