Case Brief
What Happened
By an order dated October 10, 2023, RBI imposed a monetary penalty of ₹5.39 crore on Paytm Payments Bank Limited. The penalty was for non-compliance with provisions of the KYC Directions, 2016, the RBI Guidelines for Licensing of Payments Banks, enhancement of maximum end-of-day balance requirements, cyber security framework requirements, guidelines on reporting unusual cyber security incidents, and security requirements for mobile banking applications including the UPI ecosystem. RBI said a special scrutiny and a comprehensive system audit revealed deficiencies such as failure to identify beneficial owners for entities onboarded for payout services, lack of monitoring and risk profiling for payout transactions, breach of the end-of-day balance ceiling in certain customer advance accounts, delayed cyber incident reporting, failure to implement a device-binding control measure, and V-CIP infrastructure allowing connections from IP addresses outside India. After considering the bank’s response and oral submissions, RBI held the non-compliance substantiated and imposed the penalty under the Banking Regulation Act, 1949.