Picture a semi-urban retail client who relies on a basic feature phone to manage her small-cap SIP. She hears about the *99# USSD service, which allows her to check her bank balance and initiate transactions without an internet connection, and asks if this is a safe way to manage her mutual fund redemptions. As an MFD, your immediate task is to distinguish between the convenience of technology and the underlying security architecture of offline mobile banking in the Indian ecosystem.
The *99# service, governed by the National Payments Corporation of India, enables banking via Unstructured Supplementary Service Data (USSD). While it is a revolutionary tool for financial inclusion, it operates differently from encrypted mobile apps. When a client initiates a transaction offline, the security relies entirely on the T-PIN (Transaction PIN) and the registered mobile number.
If the SIM card is cloned or the handset is stolen while logged in, the barrier to unauthorized access is significantly lower than in app-based environments, which often utilize two-factor authentication involving dynamic device binding and biometric verification.
For an MFD, the risk here is not just technical but behavioral. If you recommend this channel to a client, you must educate them on the absolute necessity of never sharing their T-PIN or leaving their phone unattended while a session is active. Unlike a modern banking app that forces a logout, an USSD session can sometimes remain “live” in the background if the user does not properly terminate the connection.
In a worst-case scenario, an unauthorized user could potentially initiate a fund transfer from the bank account linked to an SIP mandate, leading to a ripple effect where the mutual fund folio transaction fails or, worse, results in unintended account debits.
Always steer your clients toward authorized, secure channels like the AMC’s official mobile application or a secured investor portal whenever they have access to a smartphone. When a client must use offline methods, your value lies in teaching them the protocol for “emergency only” usage. Ensure they understand that their folio security is only as strong as the weakest point of access, which is often the mobile handset itself, rather than the fund house’s server.
Nuance
Check Your Understanding
An investor approaches you, concerned about the security of using the *99# USSD service for mutual fund related banking transactions. Which of the following is the most appropriate advice an MFD should provide regarding the security of this channel?
Regarding the operational risks of using USSD-based mobile banking for an MFD’s client, which statement accurately reflects the primary security concern?
This is a companion read for Section 9.8 — Financial Transactions with Mutual Funds from Ace the NISM Mutual Fund Distributors Exam by Akhilesh Gururani, available on Amazon Kindle.
Copyright © 2026 Akhilesh Gururani. All rights reserved.