The Double-Edged Sword of Instant Payments
Unified Payments Interface (UPI) has fundamentally changed how India transacts. What once required cash, cards, or clunky net banking portals now happens in seconds with a simple scan or tap. The convenience is unparalleled, driving digital payment volumes
to record highs. In 2024, UPI transactions crossed 131 billion, a more than tenfold increase in just four years. But this frictionless experience has a well-documented side effect: it makes impulse spending easier than ever. When the gap between wanting something and owning it is just a six-digit PIN, our brains barely have time to ask, "Do I really need this?" Studies have confirmed this, with one finding that around 75% of respondents reported spending more since they started using UPI. The ease removes the psychological 'pain of paying' that comes with handing over physical cash, opening the door to more frequent and less considered purchases.
The 24-Hour Rule: Myth vs. Reality
So, what about a mandatory waiting period to stop these impulse buys? The idea of a 24-hour cooling-off rule for online shopping payments via UPI is an appealing one for anyone who has ever woken up to a purchase confirmation email they barely remember authorising. However, despite the headline, no such rule currently exists for online shoppers. The concept seems to merge several different security features and proposals into one, creating a powerful but ultimately inaccurate idea. You cannot, at present, rely on a system-wide 24-hour hold to save you from a late-night shopping spree. The existing 'cooling-off' periods within the UPI framework are designed for a very different purpose: preventing fraud, not buyer's remorse.
UPI's Real 'Cooling-Off' Periods
While a shopping-specific rule is a myth, UPI does employ time-based restrictions as a security measure in high-risk scenarios. These are not about curbing your spending habits but about protecting your account from unauthorised access. For instance, when you register for UPI on a new device or change your SIM card, banks often impose a temporary, lower transaction limit for the first 24 hours. This might be capped at around ₹5,000. The logic is that if a fraudster has gained access to your account, this brief lockdown period limits the potential damage they can inflict. Similarly, a cooling-off period often applies when you add a new person as a payment beneficiary. You might be restricted from sending large amounts to that new contact immediately, giving the system time to ensure the activity is legitimate. These are targeted safety nets, not broad controls on consumer behaviour.
The Actual Proposal: A One-Hour Pause to Fight Fraud
The conversation around payment delays gained significant traction in April 2026, when the Reserve Bank of India (RBI) released a discussion paper on new measures to combat rising digital fraud. One of the key suggestions was a mandatory one-hour cooling-off period for certain digital transfers. However, the details are crucial. This proposed delay was for person-to-person (P2P) transfers over ₹10,000, not for merchant payments. This means it was designed to stop scams where a person is tricked into sending money to a criminal, giving them an hour-long window to realise the fraud and cancel the transaction. The proposal explicitly suggested that online shopping and other regular merchant payments would be exempt to avoid disrupting everyday commerce. As of mid-2026, this remains a proposal under discussion, not a live rule.
The Bigger Debate: Security Versus Speed
The RBI's proposal has sparked a vital debate about the future of instant payments. On one hand, introducing a deliberate delay—or 'friction'—into the system could be a powerful tool against fraud, which has surged alongside UPI's growth. A one-hour pause could give victims and banks a critical window to act. An expert noted it could also reduce impulsive transactions that fraudsters often exploit. On the other hand, industry stakeholders have raised concerns that such a blanket rule could undermine the very promise of UPI: its instantaneity. They argue it might erode user trust and that more sophisticated, risk-based security checks would be better than a one-size-fits-all delay. The challenge lies in finding the sweet spot between seamless convenience and robust protection.














