The Debate Around a Priceless Service
For years, the magic of UPI has been its speed, simplicity, and the fact that it’s free for users. However, behind the scenes, running this massive digital infrastructure costs money. Banks and payment service providers, who maintain the systems that process
billions of transactions, have long argued that the current zero-fee model is not sustainable. The government has consistently reassured the public that person-to-person (P2P) UPI payments will remain free for consumers. Yet, the discussion about finding a sustainable revenue model to fund UPI's continued expansion and security has intensified.
Could Merchant Fees Be the Answer?
The most likely change won't affect you sending money to a friend. Instead, the focus is on merchant transactions. In August 2026, the government passed legislation that creates a legal pathway to reintroduce a Merchant Discount Rate (MDR) on some UPI payments. An MDR is a fee that businesses pay to accept digital payments. The proposal is not for a blanket charge; rather, it would likely apply only to a limited category of merchant transactions above a certain value, for example, those exceeding ₹2,000. This approach aims to make the ecosystem financially viable for banks and fintech companies without burdening small vendors or consumers making everyday purchases. Even if introduced, officials have stated the rate would be nominal and significantly lower than charges on credit or debit cards.
A New Era of Fraud Prevention
As UPI's popularity has surged, so have attempts by fraudsters to exploit users. In response, the National Payments Corporation of India (NPCI) and the Reserve Bank of India (RBI) are rolling out significant security upgrades. The most visible change, effective from June 2026, is the mandatory display of a recipient's official bank-registered name before a transaction is confirmed. This measure is designed to combat impersonation scams where fraudsters use fake nicknames or business names to trick people into sending money. Apps can no longer show names from your contact list or those set by a merchant in a QR code; only the verified banking name is permitted.
Slowing Down to Speed Up Safety
To tackle sophisticated social engineering scams, the RBI is exploring more structural changes. One key proposal involves introducing a short, deliberate delay for certain high-value transactions, giving users a window to cancel a payment if they suspect fraud. Another significant move is the mandate for Two-Factor Authentication (2FA) for all digital payments, which came into effect in April 2026. This rule requires transactions to be verified by at least two independent factors, such as your PIN combined with device-binding, making it much harder for criminals to succeed with phishing or SIM-swap attacks.
The Centralised Fight Against Scammers
Regulators are also working on system-wide solutions. This includes proposals for a universal 'kill switch' allowing users to instantly block all payment functions on their account if they suspect a breach. There is also discussion around creating a centralized fraud reporting registry, which would enable all banks and payment apps to quickly identify and block fraudulent accounts across the entire ecosystem. For users, the dispute resolution process is also becoming more structured and efficient, with a clear framework for raising chargebacks on fraudulent or failed transactions and getting quicker resolutions. These backend changes aim to build a more resilient and trustworthy network for everyone.














