2.72 billion attacks hit Banking and Financial Services, a 113% jump year-on-year, according to the Indusface State of Application Security Report 2026. RBI’s Annual Report 2025-26 shows bank fraud amounts hit Rs 48,021 crore in FY26, up 46% from FY25.
The one bright spot: digital payment fraud collapsed from 13,332 cases and Rs 517 crore in FY25 to just 293 cases and Rs 29 crore in FY26. That is what enforced compliance delivers. The risk did not vanish; it migrated to lending APIs, where advances frauds now account for 85% of all bank fraud by value.
RBI’s Master Direction (RBI/2020-21/74) has been in effect since August 2021. The digital fraud numbers prove the framework works. The lending fraud numbers prove that incomplete coverage does not. In August 2025, the FREE-AI Committee report (Framework for Responsible and Ethical Enablement of Artificial Intelligence) added new obligations for AI-enabled systems. This guide covers key application security requirements in both the circulars and maps these requirements to AppTrana WAAP capabilities.
The 60-Second RBI Application Security Compliance Check
| Area | RBI Requirement | AppTrana Coverage |
| AI Cybersecurity
(FREE-AI — advisory) |
Continuous AI risk identification; AI tools encouraged for dynamic threat detection — FREE-AI Rec 19 | Continuous DAST on AI application surfaces, real-time threat detection on AI interfaces, 24×7 expert support |
| AI Adversarial Testing
(FREE-AI — advisory) |
Structured red-teaming across the AI lifecycle, frequency proportionate to risk (higher for high-risk apps); trigger-based testing on major changes — FREE-AI Rec 20
|
AI Pen testing, continuous DAST between cycles. Only WAF vendor with bundled DAST and pen testing |
| AI Audit Readiness
(FREE-AI — advisory) |
Risk-based audit framework covering data, model, and decision outputs; internal audits for AI applications, third-party audits for high-risk use cases, with the audit framework itself reviewed at least biennially — FREE-AI Rec 24
|
Inbuilt AI powered DAST continuously audits AI application surfaces. SwyftComply autonomously remediates findings via virtual patching and delivers an expert verified zero open vulnerabilities report within 72 hours. Code fixes follow on normal development cycle. 365-day auditable WAF decision logs support audit readiness. |
| Application and API Security | Secure communication protocols and encryption across all payment channels — Clause 13. Security controls for how applications handle, store, and protect payment data, tested against OWASP MASVS/ASVS, ISO 12812, NIST — Clause 31. Sensitive data masking — Clause 32. |
TLS enforcement, OWASP Top 10 and API Top 10 protections, positive security model, behavioural abuse detection, and PAN/Aadhaar data masking in WAF logs. |
| Vulnerability Remediation | Time-bound, no recurrence, verified — Clause 26 | Autonomous virtual patching via SwyftComply. Zero open unprotected vulnerabilities within 72 hours at the edge. Code fixes follow on normal development cycle. |
| WAF and DDoS | Explicitly mandated — Clause 15 | AI-powered WAAP, unmetered DDoS protection, active block mode from day one |
| VAPT | Half-yearly Vulnerability Assessment, annual Pen Testing — Clause 24. Continuous scanning — Clause 25 | Continuous DAST with authenticated scanning and AI penetration testing intergrated at risk based protection |
| Incident Response and AI Incident Reporting | Updated contacts, payment incident SOPs — Clause 40.
Timely reporting of AI-related incidents under a regulator-established framework — FREE-AI Rec 22. |
Real-time incident characterisation, 24×7 managed expert support, structured audit-ready security event logs, real-time SIEM integration, near real-time incident dashboards, 365-day log retention. |
Note: FREE-AI Committee recommendations are currently advisory. Given the RBI’s pattern of converting committee recommendations into circulars, regulated entities deploying AI systems should treat these as near-term compliance obligations.
Deep dive: RBI Compliance Requirements for Web, AI and API Apps
Here is what each requirement means in practice and where most teams fall short.
Requirement 1: AI Cybersecurity (FREE-AI Rec 19, 20, 24)
In August 2025, the RBI’s FREE-AI Committee (Framework for Responsible and Ethical Enablement of Artificial Intelligence) published recommendations requiring regulated entities to embed AI-specific security controls across their operations. Three recommendations directly apply to cybersecurity:
- Rec 19 requires continuous identification of potential security risks arising from AI use across hardware, software, and processes, with dynamic threat detection and response mechanisms in place.
- Rec 20 requires structured adversarial testing across the full AI lifecycle, with frequency proportionate to the risk level of the application. Trigger-based testing should also be considered when major changes are made to the AI environment.
- Rec 24 requires a comprehensive risk-based audit framework covering input data, model and algorithm, and output behaviour, with internal audits for all AI applications and third-party audits for high-risk use cases, reviewed at least biennially.
Where most teams fall short: AI security is treated as a pre-deployment checkpoint. Most teams have no ongoing process for evaluating AI models already running in production. Every major change to the AI environment is a potential trigger for a fresh security assessment, not just a scheduled annual review.
Requirement 2: Application and API Security (Clauses 13, 31, 32)
The Master Direction sets three obligations covering how regulated entities handle, protect, and transmit payment data:
- Clause 13 requires all digital payment channel communication to adhere to a secure protocol standard, with appropriate levels of encryption implemented across the payment ecosystem.
- Clause 31 requires security controls covering how applications handle, store, and protect payment data. APIs for secure data storage and communication must be implemented and used correctly. Testing must verify for OWASP Top 10, OWASP Mobile Top 10, and platform-specific risks, with reference standards including OWASP MASVS, OWASP ASVS, ISO 12812, and NIST threat catalogues
- Clause 32 requires sensitive customer information including account numbers and card numbers to be masked or redacted when transmitted via SMS or email.
Where most teams fall short: Encryption is enforced on primary payment endpoints but breaks down across third-party integrations and secondary channels. Security testing is treated as a launch gate rather than an ongoing requirement, with mobile application testing frequently skipped between releases. Sensitive data masking is applied at the display layer but payment data routinely appears unmasked in server logs, debug outputs, and SIEM exports, creating an audit liability that surfaces only during incident investigations.
Requirement 3: Vulnerability Remediation (Clause 26)
The Master Direction and FREE-AI together set parallel remediation obligations for web applications and AI systems:
- Clause 26 requires regulated entities to compare results from earlier vulnerability scans to verify that vulnerabilities have been addressed through patching, compensating control, or documented residual risk acceptance with necessary approval. The same vulnerability cannot reappear in the next scan. All identified vulnerabilities must be fixed in a time-bound manner.
Where most teams fall short: A high severity finding surfaces mid-sprint. The code fix goes live three weeks later with no compensating control in place and nothing documented. That is a compliance liability with a paper trail.
Requirement 4: WAF and DDoS Protection (Clauses 15, 51)
The Master Direction sets two obligations covering application-layer protection for internet-facing payment platforms:
- Clause 15 explicitly requires regulated entities to implement a WAF and DDoS mitigation techniques to secure digital payment products and services offered over the internet.
- Clause 51 requires regulated entities to assess authentication-related attack risks on internet banking websites and implement appropriate controls based on that assessment, including adaptive authentication, strong CAPTCHA with anti-bot features, and server-side validation. DNS cache poisoning prevention and virtual keyboard support are also required.
Where most teams fall short: Auditors increasingly treat a WAF in monitoring mode as an incomplete control, since detection without enforcement does not demonstrate the intent of Clause 15. Infrastructure-level rate limiting does not handle short-burst attacks engineered to stay under detection thresholds. According to the Indusface State of AppSec Report, over 70% of BFS applications faced at least one monthly short-burst DDoS attack in 2025, with static rate-limiting stopping only 40% of attacks. The remaining 60% required AI behavioural models to detect and mitigate.
Requirement 5: VAPT (Clauses 24, 25, 27 and FREE-AI Rec 20)
The Master Direction sets four interconnected obligations covering the full vulnerability assessment and penetration testing lifecycle:
- Clause 24 requires VA at least every six months and PT at least annually. In addition, VA and PT must be conducted whenever a new digital payment application or IT infrastructure is introduced, or when any major change is made to an existing application or infrastructure. Testing must cover OWASP compliance standards.
- Clause 25 recommends that regulated entities run automated VA scanning tools continuously or on a more frequent basis across all critical, public-facing, or customer data-holding systems.
- Clause 26 requires no recurrence of known vulnerabilities and time-bound remediation, as covered in Requirement 3.
- Clause 27 requires all vulnerability scanning to be performed in authenticated mode, either through agents running locally or remote scanners with administrative rights on the system being tested.
- FREE-AI Rec 20 adds a parallel obligation for AI applications, requiring structured adversarial testing across the full AI lifecycle. Trigger-based testing should be considered whenever major changes are made to the AI environment.
Where most teams fall short: Trigger-based testing under Clause 24(a) is the most commonly missed requirement. A major update goes live, VA and PT are skipped, and the gap surfaces when the auditor asks for testing evidence tied to that specific change. Unauthenticated scanning misses configuration vulnerabilities and privilege escalation paths that only appear with legitimate system access.
Requirement 6: Incident Response (Clauses 18, 40, FREE-AI Rec 22)
The Master Direction and FREE-AI together set three obligations covering incident detection, response, and reporting:
- Clause 18 recommends that mobile and internet banking applications maintain effective logging and monitoring capabilities to track user activity, security changes, and identify anomalous behaviour and transactions.
- Clause 40 requires regulated entities to maintain updated contact details of all service providers, intermediaries, external agencies, and other stakeholders for coordination in incident response. A mechanism to regularly update and verify these contacts must be in place. Specific SOPs to handle payment ecosystem incidents must also be formulated.
- FREE-AI Rec 22 requires financial sector regulators to establish a dedicated AI incident reporting framework for regulated entities and FinTechs, encouraging timely detection and reporting of AI-related incidents through a tolerant, good-faith approach.
Where most teams fall short: teams often don’t realize their log-retention window is too short until they are already in the middle of an incident investigation, by which point the evidence is gone. A 30-day retention policy, for example, frequently isn’t enough to reconstruct the full attack timeline. Clause 40’s contact list is often set up once and never kept current after that.
Where AppTrana Maps to RBI Requirements
AppTrana addresses key Master Direction requirements and FREE-AI obligations from a single platform, removing the vendor boundary gaps that create compliance risk.
AI Cybersecurity — Continuous DAST covers web and API surfaces connected to AI systems. Real-time threat detection, 24×7 expert support, and SIEM integration address Rec 19 obligations for dynamic threat detection and response across hardware, software, and processes.
AI Adversarial Testing — AppTrana’s inbuilt DAST and AI penetration testing directly address Rec 20 structured adversarial testing obligations, making AppTrana the only WAF vendor with both integrated.
AI Audit Readiness — SwyftComply delivers zero-vulnerability audit ready reports within 72 hours. DAST-based application audit via Indusface WAS covers input data and application surfaces. Rec 24 audit requirements are supported across data, model, and output layers.
Application and API Security — TLS enforcement satisfies Clause 13’s requirement for secure, encrypted payment channels. OWASP Top 10 (web application) and OWASP API Top 10 protections, plus a positive security model, satisfy Clause 31’s requirement for tested application and API data-handling controls. Adaptive rate limiting and behavioural abuse detection separately address business-logic abuse on payment APIs. PAN, Aadhaar, and other sensitive-data masking in WAF logs satisfies Clause 32.
Vulnerability Remediation — SwyftComply deploys application-specific security rules at the edge autonomously, closing the exposure window before the code fix reaches a sprint. The virtual patch is the documented compensating control Clause 26 permits. An expert verified report showing zero open vulnerabilities is provided within 72 hours, with virtual patches as the documented compensating controls Clause 26 permits.
WAF and DDoS — Inline in active block mode from day one with a zero false positive guarantee, satisfying Clause 15. Behavioural DDoS mitigation handles short-burst and AI-driven attacks. Anti-bot detection and intelligent CAPTCHA with server-side validation satisfy Clause 51.
VAPT — AppTrana runs continuous automated scanning across OWASP Top 10 web application, OWASP API Top 10, and business logic attack categories, with authenticated scanning for deeper visibility into configuration and session vulnerabilities. Vulnerability assessment and penetration testing are delivered by Indusface certified security researchers as part of the standard service, satisfying Clauses 24, 25, 26, and 27.
Incident Response — Real-time anomaly detection satisfies Clause 18. 24×7 expert support characterises incidents immediately, giving security teams accurate information to initiate Clause 40 SOPs. 365-day full-verbosity log retention supports FREE-AI Rec 22 obligations, providing the structured audit-ready evidence trail required for AI-related incident reporting.
Sources
- RBI Master Direction on Digital Payment Security Controls, RBI/2020-21/74 (Feb 18, 2021; effective Aug 2021) — rbi.org.in
- RBI FREE-AI Committee Report, “Framework for Responsible and Ethical Enablement of Artificial Intelligence” (Aug 13, 2025) — rbi.org.in
- RBI Annual Report 2025-26, fraud statistics (released May 29, 2026), as reported by Business Standard and Business Upturn
- Indusface State of Application Security 2026 report (released March 12, 2026) and accompanying press coverage / Indusface blog
- RBI circular on Storage of Payment System Data, DPSS.CO.OD No.2785/06.08.005/2017-18 (Apr 6, 2018) — data-residency basis for the sales-prep note above.
- General RBI supervisory practice on CERT-In empanelled auditors for VA/PT evidence (see e.g. RBI cybersecurity framework compliance guidance) — basis for the CERT-In sales-prep note above; confirm Indusface’s specific empanelment status separately.
The next RBI audit will test whether your controls actually exist. Start a free trial with AppTrana and fix your compliance gaps before the deadline.
Stay tuned for more relevant and interesting security articles. Follow Indusface on Facebook, Twitter, and LinkedIn.