[By Yash Somraj Roy]
The author is a student of Hidayatullah National Law University, Raipur.
Introduction
Recently, the Reserve Bank of India (“RBI”) under the Payments and Settlements Systems Act, 2007 has issued new due diligence guidelines for its Aadhaar-enabled Payment System (“AePS”) touchpoint operators. Enforceable from 1st January 2026 the guidelines look to reinforce the regulatory oversight of banks, regarding agents transacting with them. The new, stringent directives come as a solution to the high occurrences of identity theft and fraud in the AePS and Business Correspondent Model ecosystem.
An AePS touch point operator in brief, is an agent who facilitates banking transactions of customers through their Aadhar number and Biometric data. The RBI to ensure credibility and better functioning of the AePS touchpoint operators, has introduced a new set of guidelines for improved due diligence. The guidelines primarily introduce four significant safeguards as a way to reduce fraudulent attempts. To begin with, the guidelines stipulate for rigorous due diligence methods for AePS touchpoint operators before onboarding them with a bank. Furthermore, the guidelines also advocate for a “one-operator-one-bank” rule establishing that an agent would not be able to operate with multiple banks simultaneously.
In addition to this, the guidelines also propose for a constant risk-based monitoring of AePS touchpoint operators by banks as part of their fraud-control framework. Ultimately, the guidelines state that every AePS touchpoint operator (“ATO”), idle for a period of more than three months must undergo Re-Know Your Customer (“KYC”) and must be re-verified subsequently before resuming transactions. Interestingly, while the RBI has taken a positive approach to curb fraudulent practices by reinventing the AePS. It has blindsided several challenges and implications which arise out of the new guidelines.
The author through this blog analyses the several shortcomings vis-à-vis the newly issued guidelines and delves into the implications arising out of it. Additionally, the blog analyses the quandary on how the absence of a central registry, indirectly makes it stricter for banks to prove their non-liability. Lastly, the author through this blog recommends several policy responses along with solutions and explores the way ahead for the seamless execution of the newly issued guidelines.
The Lack of Centralised Monitoring Platform: A Major Inadequacy
As set forth above, there are several lapses and implications which arise out of the newly issued AePS guidelines. One such major implication is the lack of a centralised monitoring platform. In absence of a central database, each bank only has the option of relying on its own modalities even in instances of inadequate competency. One such subsequent major challenge which arises due to the lack of a centralised monitoring platform is duplicate onboarding.
Duplicate onboarding is when, an ATO who is already affiliated with one bank, registers themselves with another bank using a slightly altered name or identity. The absence of a centralised platform plays a key role here, as without it there is no automated screening of ATOs, and each bank’s KYC process is forced to evaluate each application independently. Thus, this eventually also acts as a threat to the RBI’s “one-operator-one-bank” policy as the lack of a centralised monitoring system makes it easier for ATOs to commit fraud.
Perhaps most consequentially, the lack of a centralised monitoring platform fragments fraud detection and renders it rather ineffective. Although the National Payments Corporation of India (“NPCI”) provides banks with a mechanism to report and flag non-compliant agents. It does little to stop these said agents, to re-enter the AePS with altered identities. Hence, this allows for an ATO to simply function indefinitely by utilising numerous identities in multiple banks. In essence, while the RBI’s newly introduced guidelines take initiative to strengthen the defences of individual banks. The guidelines due to the absence of a nation-wide platform to monitor ATOs, do little to curb fraudulent practices which operate across multiple institutions.
Exploring the Lesser-Noticed Implications in the Framework
Owing to the centralised monitoring concern, there are several other ramifications which arise, that the RBI might have failed to notice. The absence of specificity vis-à-vis the three-month inactivity rule and the uneven standards of monitoring across banks give rise to several loopholes and legal lacunae which ATOs could use to rationalize acts of fraud.
At the outset, the three-month inactivity rule is susceptible to manipulation. An ATO with minimal effort could circumvent this provision by executing dummy transactions once, within an interval of two or three months. This in turn means, that an ingenuous ATO by making a small withdrawal every three months would be able to bypass the Re-KYC protocols.
Due to the transactions occurring within the stipulated time, the legitimacy of them are not under suspicion by the banks and no pattern of misuse is detected. Resultantly, ATOs who are practically inactive, could continue to function indefinitely exploiting the aforementioned provision stated by the guidelines. Thereby, this loophole acts as a detrimental force against the AePS and the transparency which the guidelines look to implement.
Another subsequent loophole arises from the ambiguity which lies within the standards of monitoring across banks. Although, the new guidelines allow for banks to implement risk-based controls as they deem fit, it fails to consider the dissimilarity in manpower and competency each bank may have.
This consequently implies, that while some banks with higher resources and manpower may actively flag anomalies, others would not be able conduct regulatory oversight to that extent. Hence, an operator that does not meet the criteria of one bank would be able to continue operations in another. At its core, the RBI’s new guidelines for ATOs has inadvertently created a disparity which could lead to incorporation of increased fraudulent practices and illicit conduct in the AePS.
Who Pays When ATOs Go Rogue?
Under Section 7 of the Aadhaar Act, 2016 it is permittable by law to conduct Aadhar-based withdrawals for customer benefits and banking needs. Hence, the need of guidelines for the governance of ATOs is of utmost importance in the AePS. But a major conundrum which arises due to the newly issued guidelines is that whether the failure to mention a centralised monitoring platform indirectly means that bank has limited measures to prove its innocence?
Undoubtedly, banks hold an overwhelming portion of liability even when fraud is committed by an operator in the AePS. In the ‘Addendum to AePS Fraud Liability Guidelines’ the NPCI stated that “If the fraud or error has been committed by the acquirer bank or it’s BC, BC agent or CSP, the acquirer bank shall accept the responsibility of such fraud or error in AePS and refund the transaction amount to the issuer bank. If the fraud or error has been committed by the issuer bank, its BC, BC agent or CSP or its customer, then the issuer bank shall accept the responsibility of such fraud or error.”
This subsequently means that even in cases where an ATO is liable for fraud, the banks entailed in transactional relationships with the said ATO would be held accountable for redressal. The same was reiterated by the Honourable Apex Court in State Bank of India v. Pallabh Bhowmik & Ors when it opined that “It is the responsibility of the bank so far as unauthorised and fraudulent transactions are concerned.”
Thereby, a central registry could provide banks with safeguards to protect themselves from misplaced liabilities. As ATOs committing illicit activities can be kept in check through periodic oversight. Furthermore, proper reformative measures in the AePS as well as its guidelines would not only act as a preventive measure for banks from being primarily liable in fraudulent attempts but would also streamline the banking framework surrounding it.
Conclusion
It is beyond any doubt, that the new guidelines issued by the RBI are an acknowledgement of the several risks which exist within the AePS. While the guidelines do attempt to battle the same through Re-KYC, periodic reviews, and risk-based monitoring. It seems to overlook the multiple new lapses, loopholes and gaps which arise within the framework.
These loopholes may give rise to several predicaments – from duplicate onboarding to making deceptive financial transactions – meaning that ATOs entailing in illicit conduct could bypass the newly issued guidelines with ease. It must also be identified that while the NPCI does have a registry to flag non-compliant ATOs, it fails to have a periodic monitoring system to flag ATOs circumventing the NPCI registry with altered identities.
In conclusion, while the AePS guidelines do integrate reformative measures to curb fraud and illegal activities conducted by ATOs. Failing to address a centralised platform with a collective database of all ATOs is a major inadequacy which consists within it. Thereby, in order to seamlessly execute the AePS system in the coming years, the RBI must undoubtedly, look into the integration of several reformative measures, and in turn introduce well suited guidelines to overcome the challenges and implications which create hindrances for the AePS.
