To see how our expertise can help you, let’s talk
Discuss your unique business challenges and get technology recommendations.
20/10/2023
The Reserve Bank of India (RBI) stated in a circular dated 7th September 2021, that it would start initiating card-on-file tokenisation for e-commerce businesses which have been booming of late. A number of businesses have been shifting their operations online, adapting the digital payment ecosystem. These guidelines prohibit payment gateways, payment aggregators, and acquiring banks from storing customer card information, which is critical, on their servers. These rules have been laid out w.e.f 1st January 2022.
The circular further states that only card networks like Visa, MasterCard, RuPay, and a few others along with the issuing banks are allowed to store the card details during tokenisation. The basic aim behind token authentication was to tackle online frauds as well as protect customer’s valuable information from data breaches and thefts. While the new RBI guidelines prohibit entities to save card information, it has offered an alternative called ‘Card-on-File Tokenisation.’
The process where the original card number of the cardholder which is written on the card and is used for transactions is replaced by a term called ‘token’ is called ‘Card-on-File Tokenisation.’ This process activates enhanced protection as the customer’s card number is converted into tokens, hiding the actual numbers.
The exchange of tokens take place between the token requestor and the network, which gives customers a thorough payment experience, which is secure and reliable to the core. The data that is exchanged is securely stored safely in a vault, and is accessible only by the card networks. This provides a robust layer of protection which prevents hackers from committing any kind of online frauds related to cards.
When customers use their cards to make any transaction via a tokenisation-based authentication server, this is the process that takes place:
This enables maximum security as the actual card number stays hidden and the transaction also takes place seamlessly.
In conclusion, card-on-file tokenization has come across as a vital safeguard in the modern banking landscape. By adhering to best practices and guidelines laid by the RBI, banks can power their tokenization process and enhance security of customer data in a significant manner.
Discuss your unique business challenges and get technology recommendations.