NRB Introduces New Rules for Digital Payment Security

March 6th, 2025

Kathmandu – Nepal Rastra Bank (NRB) has revised the Unified Directive on Payment System, 2080, introducing new provisions to strengthen digital payment security. The Payment System Department has issued guidelines for licensed institutions to comply with the updated regulations.

According to the revised directive, a person cannot issue two or more cards of the same type (debit, credit, or prepaid) from the same account. However, this rule does not apply to cards issued under the domestic card scheme.

To enhance security in digital transactions, NRB now requires customers using mobile and internet banking services to verify that they are using an official VPN. Without an official VPN, users will not be able to log in to banking apps.

Additionally, payment system operators must conduct a Disaster Recovery and Data Center (DC-DR) drill at least once every two years. A report on the drill must be submitted to NRB within 15 days of completion.

Furthermore, licensed organizations must store their data only in centers approved by Nepal’s Information Technology Department. These data centers must comply with the ‘Data Center and Cloud Services (Operation and Management) Directive, 2081.’

Your Comment

Your email address will not be published. Required fields are marked *


*