RBI_draft

RBI’s Draft Amendment on Banking Fraud: What Changes for You After July 2026

RBI Policy Analysis

RBI’s Draft Amendment on Banking Fraud: What Changes for You After July 2026

A plain-language breakdown of the Reserve Bank of India’s proposed rules on customer protection in electronic banking transactions — and how they redefine who pays when fraud happens.

March 2026 · Draft for Public Comment · Applicable from July 1, 2026

Background: Why This Revision Was Needed

Digital payments in India have exploded over the last five years. UPI transactions alone crossed 100 billion in a single year. But with that growth came an uncomfortable companion: a sharp rise in online banking fraud, ranging from SIM-swap scams and phishing attacks to the more insidious “authorised push payment” fraud, where victims are tricked into sending money themselves.

The existing rules under the RBI’s Responsible Business Conduct Directions, 2025 dealt primarily with unauthorised transactions — situations where someone else used your account without your knowledge. But they left a grey area: what about cases where you made the payment, but were deceived into doing it? Or where the bank’s own system was breached?

The Draft Third Amendment Directions, 2026, issued under Section 35A of the Banking Regulation Act, 1949, attempts to fill exactly those gaps. It applies to commercial banks (excluding Small Finance Banks, Payments Banks, Regional Rural Banks, and Local Area Banks) and takes effect for transactions on or after July 1, 2026.

📌 Scope Note These directions apply specifically to commercial banks. If you bank with a Small Finance Bank, Payments Bank, RRB, or Local Area Bank, these particular rules do not directly apply to you — though similar protections may exist under other RBI frameworks.

The New Vocabulary: Key Terms Defined

One of the most substantive changes in this amendment is the introduction of precise definitions that didn’t exist before. Legal clarity matters enormously here — because the category your fraud falls into determines whether you get your money back.

Mindmap showing key definitions in RBI Draft Amendment 2026
Term What It Means in Plain Language
Authorised Transaction A transaction you (or a registered third party) genuinely approved — through OTP, PIN, standing instruction, biometric, or other authentication.
Authorised but Fraudulent Transaction You technically “approved” the payment, but only because you were deceived — someone posed as a legitimate entity, coerced you, or manipulated you into willingly sending money to a scammer.
Unauthorised Transaction Any transaction that does not meet the definition of an authorised transaction — i.e., carried out without your genuine consent.
Fraudulent Electronic Banking Transaction An umbrella term covering both the “authorised but deceptive” category above and any genuinely unauthorised transaction.
Bank Negligence Failure by the bank to put in place mandated security systems, send required alerts, provide reporting channels, act on your complaint, or prevent internal fraud / system breaches.
Customer Negligence Sharing your PIN/OTP/password, failing to report fraud promptly, ignoring specific scam warnings from your bank, writing down PINs with cards, or downloading malicious apps.
Third-Party Breach The deficiency lies neither with you nor with your bank — it’s elsewhere in the payment ecosystem: a payment aggregator, payment gateway, TPAP (like a UPI app provider), or telecom operator.
⚠️ Important Nuance The “authorised but fraudulent” category is genuinely new and significant. If you were tricked by a scammer impersonating your bank, a government officer, or a delivery executive — and you entered the OTP yourself — that still counts as a fraudulent transaction under these rules. This is a meaningful expansion of protection beyond the earlier “unauthorised only” framework.

Who Bears the Loss? The Liability Framework

This is the heart of the amendment. The rules establish a clear burden-of-proof principle: the bank must prove customer liability, not the other way around. This reversal of the default is significant. You don’t have to prove you were innocent — the bank has to prove you were negligent.

Mindmap showing complaint processing and liability framework in RBI Draft Amendment 2026
Scenario
Reporting Timing
Your Liability
Bank’s fault (negligence / system breach / internal fraud)
Anytime — or even if unreported
ZERO — full reversal required
Third-party breach (payment gateway, UPI app, telecom, etc.)
Within 5 calendar days
ZERO — full reversal required
Third-party breach
After 5 calendar days
Partial — compensation scheme applies (Para 76T)
Customer negligence (shared OTP, ignored warnings, etc.)
Before reporting
YOURS — until you report it
Any transaction (regardless of fault)
After you report to bank
BANK’s — all losses post-reporting are bank’s responsibility

A crucial point: once you report the fraud to your bank, any further losses in your account are entirely the bank’s responsibility. This creates a strong incentive for banks to act swiftly on complaints.

Banks also retain discretion to waive customer liability entirely, even in cases where you might technically be at fault. This is a softer provision, but it exists.

The Compensation Scheme for Small Losses

This is the most novel provision in the entire draft — and the one that deserves the most attention. For the first time, the RBI is proposing a structured, funded compensation mechanism for small-value fraud victims, co-financed by the Reserve Bank itself.

✅ Key Eligibility Criteria To qualify, you must: (1) be an individual (not a business), (2) have suffered a gross loss of up to ₹50,000, (3) have reported the fraud to both the National Cyber Crime Portal / Helpline (1930) and your bank within 5 calendar days of the incident, and (4) not have previously claimed this compensation from any bank (it’s a once-in-a-lifetime benefit).

How Much Will You Get?

The compensation is 85% of your net loss (after any recovered amounts are deducted), or ₹25,000 — whichever is lower. The bank must pay this within 5 calendar days of receiving your application.

Mindmap showing compensation for small value frauds in RBI Draft Amendment 2026

Who Pays?

The funding split is what makes this scheme genuinely novel. It’s not just your bank absorbing the cost:

Illustration 1 — Loss of ₹40,000 with ₹15,000 recovered before compensation

Gross loss reported₹40,000
Recovery credited to you before payment₹15,000
Net loss₹25,000
Compensation (85% of ₹25,000)₹21,250
RBI contributes₹16,250
Your bank contributes₹2,500
Beneficiary bank contributes₹2,500

Illustration 2 — Loss of ₹40,000, no prior recovery (₹25,000 cap applies)

Gross loss reported₹40,000
Compensation (capped at ₹25,000)₹25,000
RBI contributes₹19,118
Your bank contributes₹2,941
Beneficiary bank contributes₹2,941

If money is recovered after compensation is paid, the scheme recalculates and redistributes proportionally — so the compensation amount is adjusted and excess is returned to the contributing parties. The amendment includes detailed illustrations for these scenarios (Illustrations 2 and 3 in the original document).

🕐 Time Limit on the Scheme The compensation is only payable for fraudulent transactions occurring within one year from the effective date of these directions. After that window, this specific compensation mechanism expires (presumably to be reviewed and renewed). This is a significant limitation — it means the scheme is currently framed as a pilot or transitional measure.

What Banks Must Now Do

The draft places significant new compliance obligations on banks. Here’s what you should expect your bank to implement by July 2026:

Mindmap showing customer protection policy for Banks in RBI Draft Amendment 2026

Mandatory Alerts

Banks must send instant SMS alerts for all electronic transactions above ₹500. For transactions up to ₹500, it’s the bank’s call. Email alerts are required wherever you’ve provided an email address. These are in addition to (not instead of) any push notifications or in-app alerts. Notably, banks cannot charge you for SMS alerts sent to comply with these regulations.

24×7 Reporting Channels

Banks must provide round-the-clock access across multiple channels — phone banking, SMS, email, IVR, a dedicated toll-free helpline, and the ability to walk into your home branch. The transaction alert SMS itself must contain a number you can SMS back to immediately flag an objection. The bank’s homepage must have a direct link for reporting fraud.

Complaint Registration and Timelines

Every report of fraud must be registered as a formal complaint, with an immediate acknowledgement including a complaint number and timestamp. The bank must respond — establishing liability and confirming reversal or compensation — within 30 calendar days. In cases of zero liability, the reversal must be value-dated to the original transaction date so you don’t lose interest.

Transparency on Rejected Claims

If your complaint is rejected (i.e., the bank decides you’re liable), the bank must give you the specific reason along with supporting evidence — OTP logs, SMS logs, transaction logs. No more vague rejections.

Board-Level Oversight

Banks must set up a mechanism to report fraud statistics (volumes, values, categories) to their Board or a Board Committee periodically. This is designed to ensure accountability at the highest governance level.

Your Responsibilities as a Customer

The framework is protective, but it’s not a blank cheque. Your liability is real if you’ve been negligent. The rules explicitly define customer negligence as:

  • Sharing your PIN, OTP, or password — even unintentionally
  • Not notifying the bank promptly after discovering fraud
  • Ignoring clear, specific warnings from your bank that a transaction looks like a scam
  • Careless credential management (like writing your PIN on your ATM card)
  • Downloading malicious or unverified apps
⚠️ The OTP Paradox Here’s a tension worth noting: sharing an OTP is defined as customer negligence. But being tricked into sharing an OTP by a convincing scammer (who calls pretending to be your bank) is also described in the “authorised but fraudulent” category — which attracts compensation. The distinction will likely come down to how “specific, directed, and clear” your bank’s warning was before you shared the OTP. This ambiguity may generate disputes.

Quick Action Guide: If Fraud Happens to You

1

Call Your Bank Immediately

Use the toll-free helpline or reply to the transaction SMS alert. Every minute matters.

2

File on Cyber Crime Portal

Go to cybercrime.gov.in or call 1930. Note down your complaint number.

3

Do Both Within 5 Days

The 5-calendar-day window is critical for zero liability and compensation eligibility.

4

Request the Application Form

If your loss is under ₹50,000, ask the bank for the compensation application form (Annex II(1)).

5

Keep All Records

Save the transaction alert, your complaint number, bank’s acknowledgement, and all communications.

6

Expect a Response in 30 Days

The bank is required to resolve your complaint within 30 calendar days of receipt.

Mindmap showing customer action flow for fraud reporting in RBI Draft Amendment 2026

My Take: Progress, But Questions Remain

This amendment is a genuine step forward. The definitional clarity alone — especially the formal recognition of “authorised but fraudulent” transactions — is something practitioners and customer advocates have been asking for. The burden-of-proof shift to banks is meaningful, as is the RBI co-funding the compensation scheme rather than putting it entirely on banks.

That said, a few open questions are worth watching:

The one-year compensation window feels like a hedge. It signals that the RBI is treating this as a trial run rather than a permanent entitlement. What happens after one year? Will it be renewed? Extended? Modified? The draft is silent on this.

The OTP ambiguity mentioned earlier is real. The line between “customer negligence” (sharing an OTP) and “authorised but fraudulent” (being tricked into sharing an OTP) is likely to be litigated in grievance forums. Banks may default to the negligence classification to avoid liability.

The draft is currently open for public comment. If you have views — as a customer, a banking professional, or a researcher — this is the time to submit feedback to the RBI.

Disclaimer: This article is based on the Draft RBI (Commercial Banks – Responsible Business Conduct) Third Amendment Directions, 2026, as published in March 2026. This is a draft document and the final directions, once notified, may differ from what is described here. Nothing in this article constitutes legal or financial advice. Readers are encouraged to consult the original RBI circular and seek professional guidance for specific situations.

Based on RBI Draft Directions (DOR.MCS.REC.No./01-01-032/2025-26) · March 2026

This article is for informational purposes only. It is not legal or financial advice.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.