RBI’s Draft Amendment on Banking Fraud: What Changes for You After July 2026
RBI’s Draft Amendment on Banking Fraud: What Changes for You After July 2026
A plain-language breakdown of the Reserve Bank of India’s proposed rules on customer protection in electronic banking transactions — and how they redefine who pays when fraud happens.
Background: Why This Revision Was Needed
Digital payments in India have exploded over the last five years. UPI transactions alone crossed 100 billion in a single year. But with that growth came an uncomfortable companion: a sharp rise in online banking fraud, ranging from SIM-swap scams and phishing attacks to the more insidious “authorised push payment” fraud, where victims are tricked into sending money themselves.
The existing rules under the RBI’s Responsible Business Conduct Directions, 2025 dealt primarily with unauthorised transactions — situations where someone else used your account without your knowledge. But they left a grey area: what about cases where you made the payment, but were deceived into doing it? Or where the bank’s own system was breached?
The Draft Third Amendment Directions, 2026, issued under Section 35A of the Banking Regulation Act, 1949, attempts to fill exactly those gaps. It applies to commercial banks (excluding Small Finance Banks, Payments Banks, Regional Rural Banks, and Local Area Banks) and takes effect for transactions on or after July 1, 2026.
The New Vocabulary: Key Terms Defined
One of the most substantive changes in this amendment is the introduction of precise definitions that didn’t exist before. Legal clarity matters enormously here — because the category your fraud falls into determines whether you get your money back.
| Term | What It Means in Plain Language |
|---|---|
| Authorised Transaction | A transaction you (or a registered third party) genuinely approved — through OTP, PIN, standing instruction, biometric, or other authentication. |
| Authorised but Fraudulent Transaction | You technically “approved” the payment, but only because you were deceived — someone posed as a legitimate entity, coerced you, or manipulated you into willingly sending money to a scammer. |
| Unauthorised Transaction | Any transaction that does not meet the definition of an authorised transaction — i.e., carried out without your genuine consent. |
| Fraudulent Electronic Banking Transaction | An umbrella term covering both the “authorised but deceptive” category above and any genuinely unauthorised transaction. |
| Bank Negligence | Failure by the bank to put in place mandated security systems, send required alerts, provide reporting channels, act on your complaint, or prevent internal fraud / system breaches. |
| Customer Negligence | Sharing your PIN/OTP/password, failing to report fraud promptly, ignoring specific scam warnings from your bank, writing down PINs with cards, or downloading malicious apps. |
| Third-Party Breach | The deficiency lies neither with you nor with your bank — it’s elsewhere in the payment ecosystem: a payment aggregator, payment gateway, TPAP (like a UPI app provider), or telecom operator. |
Who Bears the Loss? The Liability Framework
This is the heart of the amendment. The rules establish a clear burden-of-proof principle: the bank must prove customer liability, not the other way around. This reversal of the default is significant. You don’t have to prove you were innocent — the bank has to prove you were negligent.
A crucial point: once you report the fraud to your bank, any further losses in your account are entirely the bank’s responsibility. This creates a strong incentive for banks to act swiftly on complaints.
Banks also retain discretion to waive customer liability entirely, even in cases where you might technically be at fault. This is a softer provision, but it exists.
The Compensation Scheme for Small Losses
This is the most novel provision in the entire draft — and the one that deserves the most attention. For the first time, the RBI is proposing a structured, funded compensation mechanism for small-value fraud victims, co-financed by the Reserve Bank itself.
How Much Will You Get?
The compensation is 85% of your net loss (after any recovered amounts are deducted), or ₹25,000 — whichever is lower. The bank must pay this within 5 calendar days of receiving your application.
Who Pays?
The funding split is what makes this scheme genuinely novel. It’s not just your bank absorbing the cost:
Illustration 1 — Loss of ₹40,000 with ₹15,000 recovered before compensation
Illustration 2 — Loss of ₹40,000, no prior recovery (₹25,000 cap applies)
If money is recovered after compensation is paid, the scheme recalculates and redistributes proportionally — so the compensation amount is adjusted and excess is returned to the contributing parties. The amendment includes detailed illustrations for these scenarios (Illustrations 2 and 3 in the original document).
What Banks Must Now Do
The draft places significant new compliance obligations on banks. Here’s what you should expect your bank to implement by July 2026:
Mandatory Alerts
Banks must send instant SMS alerts for all electronic transactions above ₹500. For transactions up to ₹500, it’s the bank’s call. Email alerts are required wherever you’ve provided an email address. These are in addition to (not instead of) any push notifications or in-app alerts. Notably, banks cannot charge you for SMS alerts sent to comply with these regulations.
24×7 Reporting Channels
Banks must provide round-the-clock access across multiple channels — phone banking, SMS, email, IVR, a dedicated toll-free helpline, and the ability to walk into your home branch. The transaction alert SMS itself must contain a number you can SMS back to immediately flag an objection. The bank’s homepage must have a direct link for reporting fraud.
Complaint Registration and Timelines
Every report of fraud must be registered as a formal complaint, with an immediate acknowledgement including a complaint number and timestamp. The bank must respond — establishing liability and confirming reversal or compensation — within 30 calendar days. In cases of zero liability, the reversal must be value-dated to the original transaction date so you don’t lose interest.
Transparency on Rejected Claims
If your complaint is rejected (i.e., the bank decides you’re liable), the bank must give you the specific reason along with supporting evidence — OTP logs, SMS logs, transaction logs. No more vague rejections.
Board-Level Oversight
Banks must set up a mechanism to report fraud statistics (volumes, values, categories) to their Board or a Board Committee periodically. This is designed to ensure accountability at the highest governance level.
Your Responsibilities as a Customer
The framework is protective, but it’s not a blank cheque. Your liability is real if you’ve been negligent. The rules explicitly define customer negligence as:
- Sharing your PIN, OTP, or password — even unintentionally
- Not notifying the bank promptly after discovering fraud
- Ignoring clear, specific warnings from your bank that a transaction looks like a scam
- Careless credential management (like writing your PIN on your ATM card)
- Downloading malicious or unverified apps
Quick Action Guide: If Fraud Happens to You
Call Your Bank Immediately
Use the toll-free helpline or reply to the transaction SMS alert. Every minute matters.
File on Cyber Crime Portal
Go to cybercrime.gov.in or call 1930. Note down your complaint number.
Do Both Within 5 Days
The 5-calendar-day window is critical for zero liability and compensation eligibility.
Request the Application Form
If your loss is under ₹50,000, ask the bank for the compensation application form (Annex II(1)).
Keep All Records
Save the transaction alert, your complaint number, bank’s acknowledgement, and all communications.
Expect a Response in 30 Days
The bank is required to resolve your complaint within 30 calendar days of receipt.
My Take: Progress, But Questions Remain
This amendment is a genuine step forward. The definitional clarity alone — especially the formal recognition of “authorised but fraudulent” transactions — is something practitioners and customer advocates have been asking for. The burden-of-proof shift to banks is meaningful, as is the RBI co-funding the compensation scheme rather than putting it entirely on banks.
That said, a few open questions are worth watching:
The one-year compensation window feels like a hedge. It signals that the RBI is treating this as a trial run rather than a permanent entitlement. What happens after one year? Will it be renewed? Extended? Modified? The draft is silent on this.
The OTP ambiguity mentioned earlier is real. The line between “customer negligence” (sharing an OTP) and “authorised but fraudulent” (being tricked into sharing an OTP) is likely to be litigated in grievance forums. Banks may default to the negligence classification to avoid liability.
The draft is currently open for public comment. If you have views — as a customer, a banking professional, or a researcher — this is the time to submit feedback to the RBI.
