Disclaimer

This is to inform that by clicking on the link, you will be leaving our www.sc.com/in and entering a website operated by other parties:

Such links are only provided on our website for your convenience and Standard Chartered Bank does not control or endorse such websites, and is not responsible for their contents.

The use of such website is also subject to the terms of use and other terms and guidelines, if any, contained within each such website. In the event that any of the terms contained herein conflict with the terms of use or other terms and guidelines contained within any such website, then the terms of use and other terms and guidelines for such website shall prevail.

Thank you for visiting our www.sc.com/in

Proceed

Tokenisation- Online Card Transactions

As per RBI mandate starting 1st January 2022, clear card number, CVV and Expiry date and any other sensitive information related to cards cannot be stored by merchants for processing online transactions.

Instead tokenised card details will be used in place of actual card details for future online purchases. Effective 1st Jan’22, clients can either choose to verify his card and do onetime tokenisation or enter full card number, CVV and expiry date every time to complete their online transactions.

To know more, please read below:

  1. What is tokenisation?
    Tokenisation refers to replacement of actual or clear card number with an alternate code called the “Token”. This shall be unique for a combination of card, token requestor (i.e. the entity which accepts request from the client for tokenisation of a card and passes it on to the card network to issue a corresponding token) and the merchant (token requestor and merchant may or may not be the same entity).
  2. Where will these Tokens get used?
    Once created, the Tokenised card details will be used in place of an actual card number for future online transactions initiated or instructed by the card holder.
  3. What is the benefit of tokenisation?
    A tokenised card transaction is considered safer as the actual card details are not shared / stored with the merchants to perform the transaction.
  4. How can the tokenisation be carried?
    Step 1 – The card holder can get the card tokenised by initiating a request on the website/app provided by the merchant.
    Step 2 – The token requestor / merchant will forward the request directly to Visa / Mastercard, with the consent of Standard Chartered Bank.
    Step 3 – Once VISA/ Mastercard receives the request from Token requester, it will issue a token corresponding to the combination of the card, the token requestor, and the merchant.
  5. How does the process of registration for a tokenisation request work?
    The registration for a tokenisation request is done only with explicit client consent through Additional Factor of Authentication (AFA), and not by way of a forced / default / automatic selection of check box, radio button, etc.
  6. Is the Tokenisation guideline applicable for both Credit and Debit cards?
    Yes. Starting 1st Jan 2022, both Debit and Credit cards have to be Tokenised
  7. Is Tokenisation applicable for International Card on File transactions?
    No. Tokenisation is applicable only for Domestic transactions.
  8. How can I manage my tokenised cards?
    Card holders can call up the Standard Chartered Bank client contact centre to manage their tokenised cards. Card holders can place request for delete, suspend, resume of tokens through the contact centre team.
  9. Will tokenisation have any impact on the POS transactions that the card holder does at merchant outlets?
    No. Tokenisation is only required for carrying out the online transactions
  10. What are the charges that the card holder needs to pay for availing this service?
    The client need not pay any charges for availing the service of Tokenising the card.
  11. Who can perform tokenisation and de-tokenisation?
    Tokenisation and de-tokenisation can be performed only by the card issuing Bank or Visa / Mastercard who are referred as authorised card networks.
  12. Are the client’s card details safe after tokenisation?
    Actual card data, token and other relevant details are stored in a secure encrypted mode by the card issuing Bank and / or authorised card networks. Token requestor / merchants cannot store full card number or any other card detail.
  13. Is tokenisation of card mandatory for a client?
    No, a client can choose whether or not to let his / her card tokenised. If not Tokenised, starting 1st Jan 2022, the card holder must enter the full card number, CVV and Expiry date every time to complete their online transactions.
  14. Is there any limit on the number of cards that a client can request for tokenisation?
    A client can request for tokenisation of any number of cards to perform a transaction.
  15. Can the client select which card to be used in case he / she has more than one card tokenised?
    For performing any transaction, the client shall be free to use any of the cards registered with the token requestor / merchant.
  16. Once tokenised, how will the client see the card details on the merchant page?
    The client will see the last 4 digits of the card on the merchant page
  17. What will happen to the token once the client’s card gets replaced or renewed or reissued or upgraded?
    The client should again visit the merchant page and create a fresh token to be able to do online transactions. It will also be applicable for wallets like Samsung Pay where once card is replaced/renewed or reissued/upgraded, client needs to do re-provisioning for creating a token.
  18. Will the card tokenisation need to be done at every merchant?
    Yes. A token must be unique to the card at a specific merchant. If the client intends to have save his/her card at different merchants, then tokens must be created at all the merchants.
  19. If the card holder is having 3 different cards, then is the card holder expected to create 3 different tokens at the same merchant.
    Yes. As mentioned earlier, token must be unique for a combination of card and merchant.
  20. Can a card issuer refuse tokenisation of a particular card?
    Based on risk perception, etc., card issuers may decide whether to allow cards issued by them to be registered by a token requestor / merchant.