Direct Tax
Consulting
ESG Advisory
Indirect Tax
Growth Advisory
Internal Audit
BFSI Audit
Industry Audit
Valuation
RBI Services
SEBI Services
IRDA Registration
AML Advisory
IBC Services
Recovery of Shares
NBFC Compliance
IRDA Compliance
Finance & Accounts
Payroll Compliance Services
HR Outsourcing
LPO
Fractional CFO
General Legal
Corporate Law
Debt Recovery
Select Your Location
Online Payment gateway enables online transfer of money by aligning with different entities. They have become an indispensable part of the online platform.
It is like a business solution in software terms to the website or e-commerce platform organizers in order to receive online payments from anywhere in the world. It needs to be secured as well in its working as stakeholders sensitive data is stored in it for transactional purposes.
Technically a Payment Gateway facilitates the transfer of information between a payment portal & the front end payment processor / acquiring bank.
Example: CC Avenue, Paypal, PayU, Razor pay etc.
PCI – DSS guidelines help in the protection of card details and another relevant information whilst the transaction happens.
The Payment Card Industry Data Security Standard is a collection of security criteria aimed at protecting card information throughout and beyond financial transactions. Most companies into Merchant banking or crypto or card issuance, compliance do get PCI ready for ensuring uber level security in all the dealings. It ensures high-security environment. PCI DSS is managed by the Payment Card Industry Security Standard Council. It is an independent association that was created by major card brands. For E.g.: VISA, MASTERCARD, AMEX, JCB etc. The Payment Card Industry Security Standards Council (PCI SSC) was launched on September 7, 2006, to manage the ongoing evolution of the Payment Card Industry (PCI) security standards with a core focus on improving payment account security throughout the transaction process and safeguarding the consumer interest.
There are more than 900 payment providers all over the world.
In India only a bank can become an Online Payment Gateway practically, all others can just operate as Payment aggregators like Pay TM. This is RBI’s mandate in this regard. These are regulated by Payment & Settlement’s Act, 2007 & Payment & Settlement’s System Regulations, 2008.
RBI stipulates that non-bank persons issuing payment instruments are required to maintain their outstanding balance in an escrow account with any scheduled commercial bank. The permitted debits and credits that can be affected in and from the said escrow account are also specifically mentioned in the guidelines, as reproduced below:
Thus, Online Payment Gateways in a simple layman language can include all entities that collect monies received from customers for payment to merchants using any electronic/online payment mode, for goods and services availed by them and subsequently facilitate the transfer of these monies to the merchants in final settlement of the obligations of the paying customers.
Conclusively one needs to acquire PCI-DSS VPAT (Vulnerability Penetration Acceptance Test) Certificate
The Reserve Bank of India, on April 11, 2025, posted a Press Release No. 2025-2026/96 on their...
Hong Kong is widely recognized as a leading global business hub, known for its free-market econ...
With India’s growing economy, Non-Banking Financial Companies (NBFCs) have expanded significa...
With the rise of digitalization, the global cryptocurrency market is expanding at an unpreceden...
Non-Banking Finance Companies (NBFCs) are an integral part of India's financial system as they...
Are you human?: 1 + 4 =
Easy Payment Options Available No Spam. No Sharing. 100% Confidentiality
The Payment Gateway Audit Checklist for India is designed to meet the regulatory and security requirements of the m...
25 Jun, 2024
Since online transactions are commonplace, companies must provide dependable and secure payment options to satisfy...
04 Oct, 2024