Aadhaar Alert! RBI Tightens the Screws on AePS Touchpoint Operators

Aadhaar Alert! RBI Tightens the Screws on AePS Touchpoint Operators

Brief Overview:

With the intent of mitigating frauds sustained through Aadhaar Enabled Payment System (“AePS”) pursuant to identity thefts and exposure of customer credentials, new guidelines have been issued pertaining to onboarding of AePS touchpoint operators (“ATOs”) by acquiring banks.

Technical Details:

The Reserve Bank of India (“RBI”) has issued directions to maintain the security and integrity of the AePS (as operated by the National Payments Corporation of India), namely ‘Aadhaar Enabled Payment System – Due Diligence of AePS Touchpoint Operators’ on 27th June 2025 (“ATO Directions”). The AePS plays a key role in advancing financial inclusion by enabling interoperable banking transactions using Aadhaar-based authentication.

The ATO Directions will take effect from 1st January 2026.

Certain measures introduced by the RBI are as follows:

1) Mandatory due diligence of all ATOs by acquiring banks, aligned with customer due diligence procedure for individuals, stipulated in paragraph 16 of Part-I, Chapter-VI of the ‘Master Direction – Know Your Customer Direction, 2016’ (as updated from time to time) dated 26th February 2016 as issued by RBI. In case, due diligence of ATOs have already taken place in their capacity as ‘business correspondents’ or ‘sub-agents’, then the same may be used.

2) Periodic updation of KYC of ATOs to be carried out by acquiring banks.

3) Acquiring bank shall be required to carry out KYC of ATOs who remain inactive for over 3 (three) months, before enabling them to transact further.

4) Ongoing monitoring must be carried out by the acquiring banks of the ATO’s activities by using transaction monitoring systems and set operational parameters based on their risk profiles.

5) Fraud risk reviews must be performed periodically by reviewing the operational parameters, to reflect emerging fraud trends.

6) System-level controls shall be introduced by acquiring banks to ensure technological integrations like ‘Application Programming Interface’ (APIs) are used strictly to equip AePS operations.

For further details, please see:  

Aadhaar Enabled Payment System – Due Diligence of AePS Touchpoint Operators

For any queries/clarifications, please feel free to ping us and we will be happy to chat:

Similar Articles

Subscribe to our Newsletter

Explore

DISCLAIMER

The Bar Council of India prohibits advocates from soliciting work or advertising. By clicking ‘AGREE’ below, the user acknowledges that no solicitation has been made, and this website serves as a resource for general information about Juris Corp at the user’s own risk. The information provided here neither constitutes legal advice nor creates a lawyer-client relationship. The links provided are not endorsements by Juris Corp, and Juris Corp is not responsible for any linked content. Users are advised to seek independent legal advice for any legal issues.