Process of obtaining the Payment Gateway License in India
How to get a Payment Gateway license in India? Well, to make it easy to get a payment gateway license, India has formulated the following steps for the payment gateway registration process:
Step 1: Application Filing
Apply for a Payment Gateway license. File the payment gateway application via FORM A addressed to the Chief Manager of the Department of PSS.
Step 2: Pay the Registration Fee
Don't forget to pay the payment gateway registration cost along with the application.
Step 3: Application Assessment
Once you file a Payment Gateway license application, RBI will start its assessment. It will check the details you've mentioned in your applications.
Step 4: Application Scrutiny
Once RBI finds that you've provided the correct application, they start scrutinizing the application based on the following points:
- What technical standards are implemented in developing the proposed payment system?
- What security systems are implemented to conduct electronic transactions through your payment system?
- What is the method of transfer used in your payment system?
- What is the method of dispensing the payment instructions to the user, and how does it affect their payment obligations?
- How financially stable is the applicant?
- What are the terms and conditions to govern the relationship between the payment providers and the customers?
- What are the monetary and credit policies you've implemented?
- How long after the authorization can the applicant start conducting the payment gateway business?
Step 5: Grant of Certification
Once the RBI authorizes your application, it will send you the payment gateway certification for conducting payment gateway business in FORM B. Once the application is filed, the RBI will take 6 months to grant the payment gateway certificate unless there are issues with the application form.
Security-related Recommendations for the Payment Gateway License
The RBI has issued some important Security-related recommendations for the licensed Payment Gateway Systems that they must adhere to. Some of these recommendations are discussed in this article in the following subheadings.
Information Security Governance
The Payment Gateway Licensed System (PGS) must conduct a comprehensive security risk assessment of its people, IT, business process environment, etc. This assessment must be done to identify risk exposures with remedial measures and residual risks.
These security checks can be one of the following:
- Internal security audit: An annual security audit by an independent security auditor
- CERT-In impaneled auditor: The PGS must submit the reports on risk assessment, security compliance posture, security audit reports, and security incidents presented to the Board.
Data Security Standards
The Payment Gateway Licensed System must implement the best data security standards and practices, such as:
- PCI-DSS
- PA-DSS
- Latest encryption standards
- Transport channel security
- Security Incident Reporting
The PGS must report security incidents or cardholder data breaches to the RBI within the stipulated timeframe. The PGS must also submit monthly cyber security incident reports with root cause analysis and preventive actions undertaken to the RBI.
Merchant Onboarding
The Payment License System must undertake a comprehensive security assessment during the merchant onboarding process to ensure the merchants adhere to these minimal baseline security controls.
Cyber Security Audit and Reports
The Payment Gateway Licensed System must carry out and submit the following to the IT Committee:
- Quarterly internal and annual external audit reports
- Bi-annual Vulnerability Assessment / Penetration Test (VAPT) reports
- PCI-DSS, including Attestation of Compliance (AOC)
- Report of Compliance (ROC) compliance report
- Along with the observations noted, if any, including corrective or preventive actions planned with an action closure date
Information Security
The Payment Gateway system must review the Board-approved information security policy annually. The security policy must consider aspects the following aspects:
- Objectives, scope, ownership, and responsibility for the policy
- Information security organizational structure
- Information security roles and responsibilities
- Maintenance of asset inventory and registers
- Data classification
- Authorization
- Exception
- Knowledge and skill sets required
- Periodic training and continuous professional education
- Compliance review and penal measures for non-compliance with policies
- IT Governance
The Payment License System must frame an IT policy for regular management of IT functions and ensure detailed documentation of procedures and guidelines is implemented. In addition, the strategic plan and policy must be reviewed annually.
Board-level IT Governance framework
Involvement of Board
The major role of the Board or the Top Management of the Payment License system must involve the following:
- Approving information security policies
- Establishing necessary organizational processes or functions for information security
- Providing necessary resources
IT Steering Committee
The Payment License system must create an IT Steering Committee with representations from various business functions as appropriate.
The Committee then must assist the Executive Management in implementing the IT strategy approved by the Board. Lastly, It must have well-defined objectives and actions.
Enterprise Information Model
The Payment License system must establish and maintain an enterprise information model to enable application development as well as decision-supporting activities consistent with the Board-approved IT strategy.
The model shall facilitate the optimal creation, use, and sharing of information by a business in a way that maintains integrity and is flexible, functional, timely, secure, and resilient to failure.
Cyber Crisis Management Plan
The Payment License system must also prepare a comprehensive Cyber Crisis Management Plan approved by the IT strategy committee. It must include components such as the following:
- Detection
- Containment
- Response
- Recovery