Introduction

Every digital fraud alert a bank sends out today tells only part of the story. A fraudster caught moving money through one bank’s mule account has often already opened five more, spread across other banks, wallets and payment apps, long before any single institution connects the dots. India’s fraud detection systems have largely been built bank by bank, each one guarding its own transaction history, which means the fraud that threatens the payments ecosystem, the kind that hops accounts and institutions within minutes, has consistently outpaced the ability of any one player to catch it alone.

The Government’s answer to that gap now has a name and a legal structure. The India Digital Payment Intelligence Corporation (IDPIC) is meant to be the shared nervous system this ecosystem has been missing. Its existence was recently confirmed on the floor of the Rajya Sabha by Finance Minister Nirmala Sitharaman, who described it as a real time fraud intelligence and alert sharing mechanism built in consultation with the Reserve Bank of India (RBI). What makes IDPIC worth examining closely is that it did not appear overnight. It was incorporated in October 2025, got its leadership in February 2026, and has been quietly built out over the better part of a year before this week’s parliamentary statement gave it formal recognition.

From DPIP to IDPIC: Building the Institutional Architecture

IDPIC traces back to the RBI’s long discussed Digital Payments Intelligence Platform, a project the finance ministry had been pressing the RBI to expedite. That project now has legal form. IDPIC is a Section 8 not for profit company incorporated under the Companies Act, 2013, operating under the regulatory oversight of the Department of Financial Services and the RBI. State Bank of India and Bank of Baroda are its promoter institutions. SBI alone invested ₹100 crore to acquire a 50% stake as initial promoter, and both banks required a specific exemption under Section 19(2) of the Banking Regulation Act, 1949, to hold more than 30% of IDPIC’s paid up share capital, an exemption granted by the Department of Financial Services until 16 October 2026.

How the Intelligence Layer Is Meant to Work

IDPIC’s stated mandate is to function as a national collective intelligence grid, aggregating fraud signals, transaction data and risk markers from banks, NBFCs, payment networks, aggregators, PPIs and fintech companies into a single platform. It deploys artificial intelligence, machine learning and big data analytics, including a self-learning model trained on 13 months of anonymised transaction history and connected account graph analysis, to move fraud detection from a reactive exercise to predictive risk scoring.

Participating institutions are meant to access real time transaction risk scores through a standardised API, allowing fraud intelligence generated in one part of the payments ecosystem to inform decisions across the entire network almost instantly. The underlying premise is straightforward. Digital payment fraud, particularly fraud that moves through mule accounts, telecom identifiers and cross bank transaction chains, travels faster than any single institution can detect acting alone.

Where IDPIC Sits Within the Existing Framework

IDPIC does not operate in isolation. The Indian Computer Emergency Response Team has already set up a National Cyber Coordination Centre that monitors cyberspace at the metadata level, and a dedicated Computer Security Incident Response Team for the Financial Sector functions under CERT-In’s supervision to issue sector specific alerts. The RBI, working with the National Payments Corporation of India, has also driven adoption of the Financial Fraud Risk Indicator through the Digital Intelligence Platform, which the Government credits with preventing roughly ₹660 crore in fraud losses over a six-month period, alongside the MuleHunter.AI tool used to identify mule accounts. IDPIC is intended to sit above and connect these existing tools rather than replace them, functioning as the aggregation layer that gives banks a shared, real time view instead of each institution working from its own fragmented data.

Compliance Implications for Regulated Entities

For banks, NBFCs, payment aggregators and fintech companies, IDPIC’s design raises a set of practical compliance questions that will need attention as onboarding proceeds. Participation will likely require sharing transaction level and possibly customer level data with a third-party entity, which means institutions will need to examine this data flow against their obligations as Data Fiduciaries under the Digital Personal Data Protection Act, 2023, including the purpose limitation and data minimisation principles that govern how personal data collected for one purpose can be shared for another such as fraud intelligence. 

Institutions will also need contractual clarity on IDPIC’s own status, whether it functions as a Data Fiduciary in its own right or as a processor acting on instructions from participating banks, since that classification will determine who bears primary liability if shared fraud intelligence data is itself compromised. Existing obligations under the RBI’s cybersecurity and IT governance frameworks, including incident reporting timelines, will also need to be read alongside whatever reporting protocol IDPIC eventually prescribes for its members.

There is also a governance dimension worth watching. IDPIC being structured as a Section 8 company promoted by two public sector banks, rather than as a statutory regulator or a wholly owned RBI subsidiary, is a deliberate design choice that allows private and foreign banks, NBFCs and fintech companies to participate on a membership basis without the entity itself exercising direct regulatory power. 

That structure gives IDPIC operational flexibility, but it also means the terms on which member institutions share and receive fraud intelligence, including data retention periods, permissible onward use of pooled intelligence and dispute resolution mechanisms between members, will likely be governed by membership agreements rather than by statute or regulation in the first instance. Institutions negotiating those agreements should treat them with the same scrutiny they would apply to any data sharing arrangement with a third party processor, particularly given the volume and sensitivity of the transaction data involved.

AMLEGALS Remarks

IDPIC represents a genuine shift in how India intends to approach digital payment fraud, moving from institution by institution detection toward a shared, real time intelligence layer built on AI, machine learning and cross ecosystem data aggregation. The structure behind it, a Section 8 company promoted by SBI and Bank of Baroda under RBI oversight, gives the initiative institutional weight that earlier fraud prevention tools did not carry individually. For regulated entities, the immediate task is not to wait for a formal onboarding mandate but to start mapping what participation will actually require, particularly the personal data flows into IDPIC’s intelligence grid and how those flows sit against DPDPA obligations and existing RBI cybersecurity requirements. Getting that mapping done early, before participation becomes standard practice across the sector, remains the lower risk position.

For any queries or feedback feel free to contact @khilansha.mukhija@amlegals.com or hiteashi.desai@amlegals.com. 

Leave a Reply

Your email address will not be published. Required fields are marked *

 

Disclaimer & Confirmation

As per the rules of the Bar Council of India, law firms are not permitted to solicit work and advertise. By clicking on the “I AGREE” button below, user acknowledges the following:

    • there has been no advertisements, personal communication, solicitation, invitation or inducement of any sort whatsoever from us or any of our members to solicit any work through this website;
    • user wishes to gain more information about AMLEGALS and its attorneys for his/her own information and use;
  • the information about us is provided to the user on his/her specific request and any information obtained or materials downloaded from this website is completely at their own volition and any transmission, receipt or use of this site does not create any lawyer-client relationship; and that
  • We are not responsible for any reliance that a user places on such information and shall not be liable for any loss or damage caused due to any inaccuracy in or exclusion of any information, or its interpretation thereof.

However, the user is advised to confirm the veracity of the same from independent and expert sources.