And there's no compromise in privacy. Android doesn't allow apps to access data from the fingerprint sensor. All authentication goes through Android core system APIs.
Ever heard of zero day vulnerabilities & backdoors?
Not only do hackers not have any kind of access to biometric info stored on your phone (that would be an Android vulnerability anyway, nothing to do with NPCI), you can absolutely change your biometrics on your phone. Just rescan your finger and it will generate a completely new key, even if it's the same finger.
That's like saying NHAI is not at fault because they made the best highway with min 150kmph speed limit knowing that majority travels in cars with 2 star out of 5 star international safety rating. Also, high resolution fingerprints were easily available for anyone to download from land registry websites of many states which were used by fraudsters so much that some states have now started masking fingerprints & aadhaar numbers on uploaded scanned deeds but not all states.
But most importantly, what is the point of this nonsense of using biometrics for upi txns. Let's make it clear with some examples for before & after this upi biometric nonsense:
Scenario 1: Person is traveling with mobile & get robbed in a lonely place. Robbers beat the man up to force him to unlock his mobile & do the transfers by entering his upi pin.
New Scenario 1: Person is traveling with mobile & get robbed in a lonely place. Robbers beat the man a bit & place his finger on mobile to do the upi txns.
Scenario 2: Person fall victim to a phishing call by someone posing as cbi officer & do the upi txn by entering upi pin.
New scenario 2: Person fall victim to a phishing call by someone posing as cbi officer & do the upi txn by placing their finger on mobile.
Scenario 3: Person forgot their upi pin so use reset & spend 2 min searching for their debit card details to reset the upi pin.
New Scenario 3: No need to remember any upi pin so person saved 2 mins.
So basically for saving 2 mins NPCI wants to put a person's biometrics at risk which can never be changed unlike upi pin. If this is not nonsense then I don't know what is.