← Back to Insights
Why Financial Institutions Are Going Passwordless — and What RBI's 2025 Rules Change
By AssureLocker Team

Why Financial Institutions Are Going Passwordless — and What RBI's 2025 Rules Change

Passwords and SMS OTPs are the soft underbelly of Indian digital finance — and RBI's new authentication regime quietly opens the door to something phishing-resistant. Here is what passkeys actually fix, and what they don't.

A customer at a mid-size NBFC gets a call. The voice is calm, knows her loan account number, and says a payment has failed. She's walked to a page that looks exactly like her lender's. She types her password. Then, when the six-digit code lands on her phone, she reads that out too. Ninety seconds later the money is gone — and from the lender's logs, nothing looks wrong. A valid password. A valid OTP. A "successful" authentication.

That is the uncomfortable truth about how most Indian financial institutions still verify who is logging in: the two things standing between a customer's account and an attacker are both shareable secrets. A password can be reused, leaked, or phished. An SMS OTP can be read aloud, intercepted via SIM swap, or entered on a spoofed page. Neither knows which website it is being handed to. That single gap is what the passwordless shift is really about.

The numbers are no longer abstract

The scale has moved past anecdote. The RBI Annual Report 2024-25 recorded 13,516 digital payment fraud cases worth ₹520 crore, with digital payments now making up 56.5% of all reported banking frauds (RBI, via TaxGuru). The Finance Ministry told the Lok Sabha that ₹805 crore was lost across 10.64 lakh UPI fraud incidents in just the first eight months of FY26 (Business Standard summary). And an RBI bulletin flagged account-takeover fraud rising 310% year-on-year, with neobanks and wallets the favoured targets (JISA Softech).

Most of this is not exotic hacking. It is the industrialisation of stolen secrets. Credential stuffing — bots replaying username-password pairs leaked from unrelated breaches — drove 22% of all breaches in 2025, off the back of 193 billion-plus credential-stuffing attempts in a single year, per Akamai (Darknet.org.uk). The bet is simple: people reuse passwords, so a credential from a low-security forum eventually unlocks a high-value banking or brokerage account.

What actually changes with RBI's 2025 Directions

On 25 September 2025, the RBI issued its Authentication Mechanisms for Digital Payment Transactions Directions, 2025, with a compliance deadline of 1 April 2026 (Khaitan & Co). Two things matter here.

First, it is principle-based, not method-prescriptive — RBI deliberately avoided naming a single blessed technology. Second, and more importantly, it explicitly encourages moving beyond SMS OTP toward device-bound alternatives: biometrics, device-native features, hardware tokens and tokenisation (Mondaq analysis).

To be precise — and this is where a lot of vendor copy overclaims — RBI has not banned SMS OTP. The Directions expand the acceptable set rather than forcing a cutover. But the regulatory direction of travel is unmistakable: the "additional factor" is expected to become something bound to a device, not a code in transit.

Where passkeys fit — and where they don't

A passkey (built on the FIDO2 / WebAuthn standards) replaces the shared secret with a cryptographic key that lives on the user's device and never leaves it. The decisive property is that a passkey is bound to the specific origin it was created for. Hand it to a look-alike phishing page and it simply refuses to work — there is no code to read aloud, nothing to relay. NIST formally recognised passkeys as AAL2-compliant in SP 800-63-4, finalised July 2025 (Authsignal), and regulated players have started shipping: ANZ Plus moved to fully passwordless web banking in mid-2025, with Revolut and others already live.

But honesty matters. Passkeys close the phishing and credential-reuse door; they do not stop authorised-push-payment scams where a genuine user is socially engineered into approving a real transaction. They shift the hard problem from "was this the right secret?" to "is this the right person, and did they mean to do this?" — which is exactly the layer institutions still have to own.

The identity underneath the login

Passwordless login answers "is this the same device as last time?" It does not answer "who is this account-holder, and is that verification something I can rely on and prove later?" — the deeper question every lender, and every DPDP Data Fiduciary, is now accountable for.

This is the posture AssureLocker is built around. Our own identity layer is passkey-first and phishing-resistant by design — no reusable passwords in the customer path. Underneath it, AssureVerifID provides source-verified, reusable identity: DigiKYC for individuals and DigiKYB for businesses, where each verification is tamper-evident and independently checkable rather than a screenshot in a folder. A lender doesn't just see that a login succeeded; it sees a verification it can stand behind on audit day.

The boundary is deliberate. AssureLocker is a technology provider — it never lends, prices, sanctions or moves funds. It makes the institution's own identity judgement faster to reach and easier to prove. As a pre-revenue company building toward its first pilots, we're not claiming production scars we haven't earned; we're building the assurance layer the passwordless era will need.

If your April 2026 authentication roadmap has surfaced the harder question — not just how customers log in, but whether the identity behind the login is one you can prove — that's the conversation to have.

Explore AssureVerifID and reusable, source-verified identity →

About AssureLocker

AssureLocker is the independent evidence-and-control layer for regulated lending — starting with co-lending. Across four suites — AssureCLA (co-lending assurance), AssureSCF (supply-chain finance), AssureVerifID (reusable identity) and AssureLens(credit-velocity intelligence), on one neutral layer — we make a lender’s controls and evidence fast, reproducible and governed. We are a technology provider: we never lend, price, or decide credit.

Read more on the AssureLocker blog · assurelocker.com