Device binding
Also known as: mobile app device binding
Definition
Device binding links a customer's mobile banking app to a specific registered device, using a combination of hardware, software and service information, so that stolen credentials alone are not enough to use the account from another phone.
More about Device binding
RBI's Digital Payment Security Controls Directions, 2026 for small finance banks and for urban co-operative banks say the bank shall ensure device binding of the mobile application, implemented through a combination of hardware, software and service information [1][2].
If the bank allows several devices to be registered, the user must be notified of every new device registration [1][2]. By contrast, checking whether a device is rooted or jailbroken is something the bank may explore rather than a mandatory control [1][2].
How this relates to LCode Technologies
LCode Technologies' D-Secure includes device binding and session handling among its application binary security controls for mobile banking apps.
Frequently asked questions
Is device binding mandatory for mobile banking apps in India?
For small finance banks and urban co-operative banks, yes: RBI's 2026 Digital Payment Security Controls Directions for those banks say the bank shall ensure device binding of its mobile app. Other institutions should check the Directions for their own category.
Related reading
Sources
- Reserve Bank of India (Small Finance Banks – Digital Payment Security Controls) Directions, 2026 (RBI/DoS/2026-27/420, 31 Jul 2026) — Reserve Bank of India
- Reserve Bank of India (Urban Co-operative Banks – Digital Payment Security Controls) Directions, 2026 (RBI/DoS/2026-27/438, 31 Jul 2026) — Reserve Bank of India
