A UPI payment feels like a single tap. Behind it sits a chain of participants: the customer’s app, the PSP bank that connects it to the UPI platform, NPCI’s switching infrastructure and the issuer and beneficiary banks that move the money. Every link handles authentication data, account identifiers and transaction records.

NPCI (National Payments Corporation of India) sets the rules for that system and they have grown considerably more specific about security. For a team building or operating a UPI application, NPCI Compliance now reaches into governance, audited infrastructure and the behaviour of code running on a consumer device nobody controls.

What Are NPCI Compliance Requirements for UPI Apps?

Where the Requirements Come From

NPCI owns and operates the UPI platform and prescribes the rules, guidelines and liabilities that apply to participants. It approves the participation of issuer banks, PSP banks, Third Party Application Providers (TPAPs) and Prepaid Payment Instrument issuers and can audit participants directly or through a third party.

Who They Apply To

Responsibilities differ by role. A PSP bank is a UPI member: it onboards and registers customers, authenticates them at registration and must ensure that a TPAP working through it is adequately secure and its app audited. A TPAP participates through a PSP bank, follows the requirements that bank and NPCI prescribe and stores UPI transaction data only in India.

What Compliance Looks Like in Practice

Nothing here ends at launch. NPCI Compliance is a continuing obligation attached to participation and the NPCI compliance standards that apply to an organization follow from the role it plays.

Why Are These Requirements Important for UPI?

Transaction security depends heavily on what the application controls. A UPI PIN entered on a compromised handset, an OTP read by another app or a tampered build that alters a payee address can each turn a legitimate session into a fraudulent transaction.

Application integrity matters for a related reason. UPI apps ship to devices the operator cannot inspect and once an attacker can modify and redistribute a build, the protections developers wrote become optional.

PSP banks also answer for the security of the TPAPs they onboard, so thin controls at one participant become someone else’s exposure. Consistent NPCI compliance standards keep that shared risk manageable.

What Are the Key Requirements for UPI Apps?

NPCI’s UPI Information Security Compliance Framework 2025 has three tiers of expectations – governance controls, security measures and operational review.

Information Security

Governance sits at the top: board oversight, a designated CISO independent of IT operations and documented policies covering objectives, scope, ownership and compliance. CERT-In and NCIIPC guidance are cited alongside NPCI’s framework, so NPCI Compliance sits alongside RBI’s Master Direction on Digital Payment Security Controls.

Data Protection

Encryption, secure storage, masking and deletion all appear as controls, with data privacy addressed separately. NPCI also requires TPAPs to store UPI transaction data only in India. NCPI 2025 mobile application security circular adds specific key-protection requirements, including AES-256 or an equally stringent encryption algorithm.

Application Security

This area covers SDK handling and device binding, API security and hardening and patching. NPCI went further in May 2025 with a mobile application security framework circular for PSPs, ASPs and TPAPs, listing app-level controls and marking each mandatory or recommended.

Security Testing

Testing appears under operational review as VAPT, source code review, application security assessment and closure of findings. KPMG describes the audit as a pre-onboarding activity and annual thereafter, performed by a CERT-In empanelled auditor at the entity’s cost and covering the entire UPI infrastructure and application, frontend and backend. Onboarded entities submit an annual report with no open findings by 31 December.

Access Control

Identity and access management spans privileged access, authorization, multi-factor authentication, whitelisting and role definitions. The PSP bank authenticates the end user during registration. For transactions, the UPI PIN remains a core authentication method, while NPCI also supports optional on-device biometric authentication for eligible transactions.

Monitoring

Requirements include alerts and tracking, log oversight and retention and reporting to regulators. Incident management covers logging, investigation and reporting. Fraud management is separate: detection, prevention and reporting. The May 2025 circular adds an app-side duty: alerting monitoring systems when a threat is detected.

What Security Controls Should UPI Apps Have?

Several controls in NPCI’s mobile application security framework are marked mandatory, falling into a few groups.

Device and source checks:

Root and root cloaking detection, with apps disallowed from installing on rooted devices, plus installation source validation so an app refuses to run unless it came from an authorised store.

Runtime integrity:

Continuous memory integrity checks and runtime verification that watches system calls, file access and network activity for deviations.

Code and key protection:

Debugging prevention, code obfuscation and encryption of cryptographic keys.

Network protection:

SSL pinning limited to a few public keys against man-in-the-middle attacks.

Device configuration:

Detection of developer options, USB debugging and active USB connections.

Root access matters here because it lets an attacker reach memory the system would otherwise isolate. A further set of measures is recommended rather than mandated: virtual device detection, device blacklisting, APK locking, an app lock using a passcode or biometric and prevention of dynamic instrumentation.

What Security Risks Can Affect UPI Apps?

Reverse engineering:

A released build is decompiled to read business logic, find hardcoded values and map how the app reaches backend services, shortening the path to most other attacks.

Code tampering and repackaging:

A modified build can be signed again and distributed outside official stores, which is why installation source validation is mandatory and entities must watch for rogue copies.

Rooted and jailbroken devices:

Rooted and jailbroken devices weaken app isolation, allowing privileged tools to access files, memory or runtime processes that are normally restricted.

Runtime manipulation, debugging and hooking:

An attacker attaches to a live process, observes values as they are computed and changes program flow. Dynamic instrumentation frameworks make that repeatable across devices.

Sensitive data exposure:

Tokens in unprotected storage or account details in verbose logs can be collected later by other software on the device.

Overlay attacks:

A malicious app draws a fake input surface over the real one to capture a PIN or OTP. NPCI’s BHIM UPI guidelines cover the user side, asking partner apps to show safety messages telling customers to enter the UPI PIN only on the PIN page.

How Can Organizations Prepare for NPCI Requirements?

Identify What Applies

An issuer bank, a PSP bank and a TPAP are not in the same position and entity type shapes what an auditor looks for. Settle that first.

Map Controls and Find the Gaps

Set those requirements against controls that already exist. Most find partial coverage: encryption and access management usually in reasonable shape, app-level runtime controls thinner. What the mapping leaves uncovered becomes the remediation backlog.

Test, Remediate and Document

Assessment and testing follow, then remediation and revalidation of each fix. Document control ownership and collect evidence as work happens, since an audit turns on what can be demonstrated.

Keep Controls Current

None of this produces NPCI Compliance by itself. That depends on the requirements applicable to the entity and on the assessment process, which for UPI participants involves a CERT-In empanelled auditor. Monitoring and reassessment continue, since releases and updated circulars change what the NPCI compliance standards demand.

How to Assess a UPI App for Security?

A useful assessment combines static and dynamic work. Static analysis reads the shipped binary the way an attacker would: exposed secrets, weak cryptographic usage, logic that gives away too much. Dynamic testing exercises the running app, including behaviour on a rooted device, under a debugger and when instrumentation tooling is present.

Targeted checks worth running alongside that work:

  • Sensitive data storage and whether encryption is applied where it should be
  • Session handling and authentication flows
  • API traffic, including certificate pinning and response validation
  • Logs, for anything sensitive that leaks into them
  • Third-party libraries, which inherit risk from projects nobody on the team maintains
  • Overlay and screen capture behaviour, tested on a real device

An application assessment is one input into a broader review. It is not NPCI certification and does not replace the audit covering infrastructure, backend systems and governance.

Best Practices for UPI Security and Compliance

Build Security Into the Development Lifecycle:

Threat modelling and secure code review cost less before a build ships than after an audit finding.

Protect Application Code and Integrity:

Obfuscation, integrity verification and anti-tampering support the NPCI compliance standards that treat application integrity as a control.

Detect Compromised Devices and Runtime Threats:

Root, jailbreak, emulator and hooking detection tell an app what environment it is in. It needs a defined response.

Protect Sensitive Data:

Keep sensitive values out of plain storage and logs, encrypt what must persist and minimise permissions.

Test Applications Regularly:

Retest after meaningful releases, rather than just before a deadline. The gap between them is where findings accumulate.

Monitor Security After Release:

Route app-side threat alerts to analysts who can act on them and decide in advance which responses follow.

Maintain Compliance Evidence and Documentation:

Record control ownership, test results and remediation history while the work is fresh, not months later.

Review Controls as Requirements Change:

NPCI updates its circulars and platform changes shift what is practical, so schedule reviews instead of waiting for audits.

How DoveRunner Helps Secure UPI and Payment Applications

DoveRunner works on the application layer of this problem. Its platform applies runtime application self-protection to Android and iOS builds, with real-time defences against source code tampering, debugging and network sniffing, plus a dashboard for threat activity.

The mapping to the risks above is direct. Code protection and obfuscation address reverse engineering. Integrity and anti-tampering controls address modified or repackaged builds. Root, jailbreak and emulator detection address execution on compromised devices, while anti-debugging protections address runtime manipulation. For sensitive application data, DoveRunner provides AES-256 based encryption and its on-premise option supports data localisation requirements.

DoveRunner does not certify UPI applications and does not provide NPCI certification, so using it will not make an organization compliant on its own. It can support the application security measures that contribute to an organization’s broader NPCI Compliance efforts.

Frequently Asked Questions About NPCI Requirements

What Are NPCI Requirements for UPI Apps?

They are the rules and guidelines NPCI prescribes for entities participating in UPI, spanning governance, information security, application security and audit obligations. NPCI owns and operates the platform and defines the roles, responsibilities and liabilities of participants, so NPCI Compliance is tied to continued participation.

Who Needs to Follow NPCI Requirements?

NPCI approves the participation of issuer banks, PSP banks, TPAPs and PPI issuers. KPMG’s summary of the UPI Information Security Compliance Framework 2025 also lists technology service providers, application service providers, voice-based service providers and IVR platforms among affected stakeholders.

What Security Requirements Apply to UPI Apps?

The framework covers governance, data security, identity and access management, network security, the application security lifecycle, incident response, fraud risk, data privacy, infrastructure security and API security. Operational review adds VAPT, logging and monitoring, business continuity and architecture review. App-specific controls come from NPCI’s mobile application security circular.

Is Mobile App Security Part of UPI Security?

Yes. NPCI issued a dedicated mobile application security framework for UPI in May 2025 addressed to PSPs, ASPs and TPAPs and the audit scope described by KPMG covers the UPI application including frontend and backend, not infrastructure alone.

How Can UPI Apps Protect Against Tampering?

NPCI’s mobile framework treats runtime code and data integrity protection as mandatory, including continuous memory integrity checks and runtime verification. Code obfuscation and encryption of cryptographic keys are mandatory as well and detected tampering should trigger a defined response rather than letting the app continue.

What Security Testing Is Needed for UPI Apps?

The UPI Information Security Compliance Framework 2025 places VAPT, source code review and application security assessment under operational review. KPMG notes the audit must be conducted by a CERT-In empanelled auditor, before onboarding and annually thereafter. Specific testing types beyond these should be confirmed against the applicable circulars.