Nasscom makes recommendations to RBI on Card-on-File tokenisation

BIN ranges are required to identify if EMI is supported by a card network or not. BIN ranges also help in identifying routing of a transaction.

Nasscom
Nasscom logo
Neha Alawadhi New Delhi
3 min read Last Updated : Dec 09 2021 | 9:02 PM IST
Providing a tiered timeline to merchants for compliance and allowing them to store the first few digits of a card (BIN range) to ascertain the network, issuer, card type, are among the key suggestions made by industry body National Association of Software and Services Companies to the Reserve Bank of India on facilitating compliance with Card-on-File Tokenisation (CoFT). 

"The RBI circular dated September 07, 2021, allows storing limited data – last four digits of actual card number and card issuer’s name – for transaction tracking and reconciliation purposes. Merchants require first few digits of a card (BIN range) to ascertain the network, issuer, card type for several purposes. Given that BIN ranges are information available publicly and cannot uniquely identify a card, storing of the BIN range does not impinge on the customer security," Nasscom said Thursday, detailing its submission to the RBI. 

BIN ranges are required to identify if EMI is supported by a card network or not. BIN ranges also help in identifying routing of a transaction. 

The ranges also help in fraud detection. Further, most offers run against specific cards by specific banks have an aggregation requirement i.e., 2-3 times per card for a given duration or one time per card per merchant etc. 

For such use cases, a unique identifier (card hash) or BIN is required to apply offer validations, view offers against a specific card, and for processing cashback. Without an option to store BIN number, these offers will cease to exist.

In March 2020, the Reserve Bank of India (RBI) released “Guidelines on Regulation of Payment Aggregators and Payment Gateways” under S. 10(2) of the Payment Systems and Settlement Act, 2007. The Guidelines recognise Payment Aggregators (PAs) and Payment Gateways (PGs) as intermediaries playing a crucial role in facilitating payments in the digital space and ensure that consumers are protected in online space.

Of these,two clauses require PAs and merchants to not store card credentials within their databases or servers. With merchants and PAs not allowed to store card data, there were several industry concerns including – card data security, fraud risks, impact on customer service and product innovation. 

To address the concerns, the industry had made suggestions to the RBI including considering card-on-file tokenisation (CoFT) as a viable alternative to card-on-file (CoF) in a graded manner. 

Nasscom has further suggested that the RBI provide a tiered timeline for compliance to merchants, so they can build on issuer banks and card networks as they are ready with their integrated solutions. 

It has also suggested "RBI monitored compliance to ensure that the regulated entities adhere to the timeline and the transition to CoFT does not adversely disrupt the ecosystem like e-mandate on recurring transactions".

One subscription. Two world-class reads.

Already subscribed? Log in

Subscribe to read the full story →
*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

Topics :NasscomRBI

Next Story