The stalled Alipay+ proposal is an argument for rules, not for sides. India needs a country-neutral Trusted Payments Corridor Standard: trust measured before approval, tested while the corridor runs, and withdrawable without harm to UPI at home.
Introduction
On 3 September, Reuters reported that a proposal to link UPI with Alipay+ had stalled. It cited three unnamed sources. The proposal, made in January, would reportedly have let Indian travellers pay at more than 150 million merchants on the Alipay+ network. One source spoke of political grounds at the Ministry of External Affairs; two described law-enforcement worries about cyberfraud and money-laundering pathways; a third said every bilateral corridor gets this scrutiny, only sharper for China-linked entities. Nothing official has followed. The honest reading is narrow: a report, not a decision; stalled, not rejected; concerns, not findings; and no public evidence that Alipay+ has mishandled Indian data or helped launder money.
Expanding UPI
The episode matters less for what it says about one company than for what it reveals about India’s method. UPI cleared 24.51 billion transactions worth Rs 29.82 lakh crore in August, on NPCI’s figures. It is accepted, partner by partner, in ten countries, according to the Finance Ministry, with Uzbekistan agreeing on 30 August and awaiting a switch-on date. At the BRICS summit in New Delhi last week, leaders acknowledged work on linking payment systems while conceding that no single model fits every member. And on 15 September the government introduced a merchant discount rate on a limited slice of higher-value UPI merchant payments, 0.4 per cent above Rs 2,000 from 15 October, capped at Rs 300, with person-to-person transfers, small merchants and consumers untouched; a petition against it is already before the Supreme Court.
India, in other words, is inside international payment integration, asking for more of it, and has begun to price its own system at home. What it lacks, on the public record, is a single published standard explaining how a foreign payment corridor is judged: what may cross, who can reach it, under whose law, whether regulators can see and act, who answers to the customer, and how the link can be ended. Whatever confidential review takes place, the Alipay+ story shows what happens in that vacuum: the reasons reach the public through anonymous sources, or not at all.
Two mistakes are available. The first is unsafe openness: approving a link without knowing what crosses, without remedies when it fails, and without any way to unwind the dependency. The second is defensive stagnation: blocking connection because risk can never be zero, at the cost of reach and of a compliance burden only the largest can carry. What belongs between them is a standard that facilitates connection where demonstrable benefits justify the residual risk after proportionate mitigation, restricts where a material risk cannot yet be managed, reassesses when the facts change, and is designed to fail safely.
What’s at Stake
What needs protecting is not payment data in the abstract. One coffee bought abroad tells no one anything. The object is the financial graph: the web that emerges when millions of transactions are linked to merchants, times, places and devices. Banks, card networks and technology platforms hold such graphs too. What changes when the graph crosses a border is its jurisdiction: who can compel access to it, whether Indian regulators can inspect it, what it can be combined with, and whether India can end the arrangement without disorder. That is what sovereignty should mean here: India’s lawful capacity, consistent with its citizens’ rights, to set and enforce the terms on which such data is accessed, processed, and inferred from; to supervise the arrangement; to protect the customer; and to close it cleanly. Privacy, financial crime, system integrity and strategic dependency are different risks; only the last is national security. UPI should export Indian payment capability, not India’s financial graph, regulatory dependence or exposure to coercion.
Need for Data Protection and Regulation
India is not starting from nothing. RBI’s 2018 direction keeps payment-system data stored in India, and its 2019 clarification allows processing abroad inside a 24-hour return window. These rules reach Indian operators and their service providers. But a corridor also involves foreign counterparties and the entities behind them, beyond India’s direct supervisory reach, where audit rights exist only by contract or a counterpart regulator’s consent. The return window says where data must rest, not what can be learned from it in processing. And nothing on the public record requires that a corridor be capable of ending without disturbing UPI at home.
What actually binds a foreign firm is that access to India’s regulated payment system is conditional. RBI can attach conditions to NPCI as the authorised operator; NPCI and NIPL can carry them into scheme rules and partner agreements; a foreign partner accepts them in contract. Contract is the first layer of enforcement, not the last. It cannot override another country’s law or create regulatory jurisdiction. Hence, preserving evidence, freezing funds and inspecting systems abroad depend in part on counterpart regulators, financial-intelligence channels and treaties. The question for any corridor is whether the available combination gives adequate capability for its level of risk. The same logic should apply, by function, to comparable arrangements, including card networks where the law allows. A tourism pilot should not carry the burden of a multi-country gateway.
Eight Questions
The standard I propose asks eight questions of every corridor. What must cross, and is it the minimum needed for payment, security, and remedies? Who controls the partner, in law and in fact, including exposure to compelled access abroad? Can RBI see it, with records producible in India within a published period? Who answers to the customer, through one accountable Indian interface, with the amount, the rate and any charge shown before confirming? Can fraud be chased across the border, with capability shown before the corridor scales and money held reported separately from money returned? Can it be slowed, restricted or suspended without touching domestic UPI, and has that been tested? What may the data be used for, beyond fraud and security analytics within limits? And can the whole thing be unwound, with a plan agreed before approval for unsettled transactions, refunds, disputes and records?
A few rules keep the standard honest. Approval is ongoing, not permanent: reviewed on a schedule and reopened on material changes in ownership, control, critical third parties, hosting, data flows, legal position, or risk profile, and after a serious incident. Restriction is equally reversible. The clock runs from a complete file, not a covering letter. Criteria and high-level reasons are public; thresholds and protected security material are not. And even where the evidence cannot be published, a decision should say, to the extent the law permits, which public risk category it engages: legal compulsion, supervisory visibility, reciprocity, continuity or concentration. A named category is what an unexplained stall lacks.
Consider a student paying a semester’s fees abroad. Under such a corridor, a tokenised reference and an amount would cross, not a device profile or a spending history. If the payment were stolen, the request to hold the funds would run on the Indian leg through the student’s own bank. One Indian interface would handle status, complaints, and refunds. If the corridor were suspended, pending payments would complete, disputes would continue, and the student would be told which rail to use next. That is not today’s rails. It is what approval would have to establish.
MDR for Sustainability
The new merchant fee is context, not proof. It shows UPI’s governance moving from adoption to sustainability, to who pays for security, fraud handling and service; whether the charge helps or harms is a question for the court and the market. Its lesson for corridors is narrower: a rail cannot be judged by nominal cost or merchant reach alone. This essay does not promise that UPI abroad will be cheaper. It asks only that the traveller be told, before pressing confirm, what will leave the account.
Legal Conundrum
Who decides follows the law as it is. RBI leads the prudential determination under the Payment and Settlement Systems Act; NPCI and NIPL certify and contract; the home ministry, I4C and FIU-IND supply the financial-crime assessment; CERT-In the cyber input; MEA and counterpart regulators the instruments of cooperation. Four things could begin now: RBI could add the standard to its Vision 2028 cross-border review; NPCI and NIPL could obtain and maintain data, access and legal-flow maps for every live corridor; the fraud agencies could test cooperation with partners by exercise rather than by waiting for a victim; and every approval could carry a resolution plan and review triggers.
The objections are serious. RBI already reviews corridors: true, and what changes is publication, tiering, a timetable and reassessment. Public criteria can be gamed: which is why methods and thresholds stay confidential. Country-neutral language can hide a China-specific veto: which is why the same sheet applies to every jurisdiction and in both directions, with outcomes differing only where law, reciprocity, architecture or exposure differ. Jurisdiction matters when law matters; nationality alone is not evidence. Compliance favours incumbents and may slow expansion: proportionate intensity and a pilot tier address the first. The US Trade Representative’s 2026 complaint that India’s payment policies disadvantage American suppliers is another reason to prefer a published functional test to an unexplained stall.
Conclusion
A mature payment power does not decide whom to trust. It establishes what any system must prove, what risks it will accept, what rights its citizens retain, and how to unwind every dependency safely. Call it trusted interoperability: connect where the benefits justify the residual risk after proportionate mitigation. Internationalisation and sovereignty are not opposing objectives. Good architecture is what lets India pursue both.