Key Management System (Cards) – FAQs
Important Advisory on Ownership of keys
NPCI is not responsible for loss or compromise of keys after received by custodians. It is the Bank and the custodian's responsibility to keep the key safe and secure.
What is the validity of Custodian Authorization letter?
The Custodian Authorization letter is valid for 30 days from the issuing.
What are the mandatory checks in the custodian authorization letter before attaching it in production key confirmation stage?
Date, Note, Bank seal should present after filling the details in letter.
What is the process for raising C-flow request for production keys?
There is no separate process for Production Key generation. In every cflow request where the Bank needs to go-live, the request reaches Production movement stage after approvals from other NPCI teams – and here the Keys are generated and shared.
Do the Keys expire?
Keys, once used in the production movement, will never expire. However once the keys are issued, bank should go live in production within the prescribed TAT of 90 days; if not done, the bank needs to procure new set of keys from NPCI.
Can NPCI generate AES keys?
No, NPCI doesn't generate AES keys. Currently, NPCI only generates 3DES keys.
Bank lost old keys and want to recover the same old keys. Is it possible?
This will not be possible as NPCI doesn't store keys sent to the Bank.
Does Bank need to procure different switch keys for Acquirer and Issuer setup?
The Switch Keys depend on the ASPs. In case you have the same ASP for both Acquirer and Issuer, then the same set of keys can be used. In case the ASP is different for the Acquirer and the Issuer, then each ASP will have a different set of keys.
Can bank can get the existing keys which are already issued?
No, It is the bank responsibility to store the keys as NPCI doesn't store the Keys issued to the member Banks.