Table of Contents

India’s regulations for cross-border card payments aren’t being tightened, it’s being restructured.
Three terms before we proceed ahead
- Card-not-present (CNP): Any card payment where the card isn’t physically swiped — so, all online checkout.
- Authentication: The step where the customer’s bank confirms it’s really them, usually with a one-time password sent by SMS.
- 3DS: The global standard (Visa calls it Visa Secure, Mastercard calls it Identity Check) that lets your checkout ask the customer’s bank to authenticate a payment before you charge it.
On October 1, 2026, new obligations for Indian card issuers will reshape cross-border transactions. For foreign businesses and PAs, authorisation rates will depend on whether their checkout is configured to meet these requirements.
An Indian card on an overseas checkout has historically sat outside India’s AFA regime for non-recurring cross-border payments. Without an authentication request, the issuer can approve or decline based on its internal risk model – No OTP required.
This is the status quo that Oct 1 dismantles.
| Overseas businesses and acquirers on non-3DS rails face maximum disruption: After October 1, all cross-border, non-recurring CNP transactions must be authenticated via AFA. | Overseas businesses & acquirers alreadyon a properly implemented 3DS 2.x rail will also see little disruption. Covered later in the article. |
Only a few global teams are auditing now. This piece is for both groups – Overseas Businesses & PAs.
Understanding the RBI Guideline
The Reserve Bank of India (RBI) deadline that matters:
- October 1, 2026:
- Indian card issuers must register their BINs with card networks for AFA validation.
- Indian card issuers must validate all non-recurring cross-border CNP transactions, where a request is raised by an overseas merchant or acquirer as per section 10 (a).
- Lastly, card issuers must put a risk-based mechanism in place to handle all cross-border CNP transactions as per section 10 (b).
- Indian card issuers must register their BINs with card networks for AFA validation.
Who is responsible for what?
- The Reserve Bank of India (RBI) is the regulator.
- Indian Card Issuers bear the compliance obligation, and
- Card Networks are the intermediary registry layer.
Thus, the obligation to build sits with Indian issuers. The obligation to raise the authentication request sits with foreign merchants & acquirers.
Non-recurring transactions
All non-recurring cross-border transactions will be validated post October 1, 2026 by Indian issuer. The mechanism only fires when an overseas business or acquirer raises an authentication request.
Any transaction reaching the Indian issuer with authentication request falls under section 10 (b) automatically. Indian Issuers will apply the risk model, run multiple checks and in absence of authentication, soft decline it leading to a payment retry.
Recurring transactions — the second asymmetry
Recurring payments on Indian cards, domestic or cross-border, follow a separate RBI e-mandate framework
- AFA is required for mandate registration, changes, withdrawals, and transactions above the threshold.
- Pre-debit notification is mandatory at least 24 hours before each charge.
- Registered mandates can be debited without AFA up to ₹15,000, subject to category-specific limits.
The implication for stored cards: Registering a mandate requires AFA and therefore 3DS. A stored card charged through non-3DS rails cannot register a mandate. Those unregistered card-on-file charges are treated as non-recurring and fall back under 10(a), a rail that is closing.
Section 10 changes none of that. 10(a) excludes recurring transactions entirely.
What 10(b) adds is that every cross-border recurring charge now passes through an issuer risk mechanism built specifically for cross-border. Read the two limbs together and the asymmetry is deliberate: non-recurring in the first, all in the second.
Understanding the Impact
Non-Recurring Cross-Border CNP Transactions
What Happens Today
Most one-time payments on Indian cards at overseas checkouts reach the issuer without customer authentication, either because no authentication was requested.
The October 1 guideline redraws the rules.
| If your checkout already uses 3DS | If your checkout does not use 3DS |
| Transactions may pass, but not untouched.Transaction reaches the issuer with 2FA: Static + Dynamic.Issuers see this as a safer, liability-free transaction and approve it.With BIN registration, risk shifts from network stand-in to issuer ACS.Expect higher challenge rates. | This is where payments start breaking.Non-3DS flows lack authentication.From October 1, 2026, issuers assume full liability on approved transactions.To manage the risk, issuers can use real-time risk engines to decline single-factor, non-3DS requests.Expect declines on all non-3DS flows. |
What to do
- Measure now, & Measure the right thing: Analyze 90–120 days of Indian card payments. Isolate unauthenticated transactions—that’s your exposure. That volume is at risk from October 1, 2026.
- Route all Indian-issued cards through 3DS. Treat it as a requirement, not an optimisation.
- Send richer transaction data. Device, account history, and purchase context can improve approval rates and reduce challenges.
- Separate failures from declines. Retry timeouts; don’t retry refusals.
OTP isn’t the only path either. Payment aggregators in India, like Cashfree Payments are working card networks and strategic partners letting cardholders authenticate with a device fingerprint or face scan instead.
Subscriptions and recurring payments
What Changes
Your renewals won’t be interrupted for verification. The transactions will be scored under the new risk model developed for this guideline. New models decline conservatively in month one. Expect a dip in October and a recovery over the following weeks.
- Audit every recurring Indian card charge. Distinguish registered mandates from stored cards.
- Review your price points. Annual plans may trigger authentication on every renewal as the amount exceeds the threshold; Monthly plans that are smaller may authenticate only at signup and continue without authentication every month.
- Build in a buffer for the 24-hour notice. Don’t charge as soon as the window opens.
Every number above is recoverable.
Take the simpler route instead of rebuilding the checkout. The rule applies when payments are collected by a provider outside India. Collect in India, and the payment is domestic—outside the October 1 rule.
You also unlock UPI, RuPay Cards and Netbanking, the payment methods Indian customers actually use.
The path is regulated and doesn’t require an Indian entity or infrastructure build.
That’s why we built Cross-Border Collections by Cashfree; India’s first licensed cross-border payment provider, with businesses and PAs across 40 countries collecting from Indian customers without an Indian entity.
- Offer the payment methods that Indians actually use: UPI, RuPay cards and netbanking
- Subscriptions and recurring payments on UPI, Cards & Netbanking
- EMI and bank offers to make high-value purchases affordable
- Compliance that is built for India, not adapted for it
Talk to the product leader building India payment infrastructure for global businesses — and the person whose reading of the non-3DS question runs through this piece.
Schedule a Connect with Saurabh Singhal, Group Product Manager at Cashfree Payments.