
















The Reserve Bank of India (RBI) has proposed a one-time compensation for victims of small-value digital banking fraud, offering up to 85% of a net loss (or Rs 25,000, whichever is lower) for losses up to Rs 50,000, under draft amendments to its responsible business conduct framework.
The RBI has released draft amendments to its Responsible Business Conduct Directions, setting the customer protection framework for electronic banking.
The amendments define “fraudulent electronic banking transactions” to include both certain authorised and unauthorised fraudulent transactions. The RBI also identifies when a technically authorised transaction may still be considered fraudulent.
The RBI defines the following types of such transactions:
The RBI has invited comments on the draft directions until April 6, 2026. If notified, the amendments will apply to the Responsible Business Conduct Directions for all types of regulated banks. These directions will govern electronic banking transactions conducted on or after July 1, 2026.
The draft amendments require banks to adopt a formal policy on customer protection for electronic banking transactions and to clearly define customers’ rights and obligations in the event of fraud. Banks must also specify timelines for resolving complaints and disclose their grievance redressal and escalation procedures
In addition, they must publish these policies on their websites and implement programmes to increase customer awareness about emerging payment fraud and safe digital banking practices.
At the same time, banks must strengthen their internal systems to detect and mitigate fraud risks. This includes deploying robust fraud detection and prevention mechanisms, assessing risks arising from fraudulent electronic transactions, and implementing measures to mitigate potential losses and liabilities.
Furthermore, banks must ensure that their systems and procedures comply with digital payment security controls and are designed to make customers feel safe when conducting electronic transactions.
The amendments introduce stricter requirements for transaction alerts. Banks must obtain customers’ mobile numbers for electronic banking services. Where available, they should also collect email addresses. Banks must send instant SMS alerts for all electronic banking transactions above Rs 500, and email alerts when possible. Other notifications, like in-app or push alerts, may supplement these.
Banks must also provide customers with multiple channels to report fraudulent transactions or the loss of payment instruments. These channels must operate 24×7. They may include phone banking, SMS, email, IVR systems, dedicated toll-free helplines, and home branch reporting.
Additionally, banks must include a number in the SMS alert so customers can notify the bank immediately of objections, and provide a direct reporting link on their homepages. Upon receiving a complaint, banks must immediately register it, assign a complaint number and timestamp, and take steps to prevent further unauthorised transactions.
Banks must examine each complaint and determine liability based on the circumstances of the transaction. They must respond to the customer within the timelines set by their policies, but no later than 30 days. Importantly, the bank must prove customer liability in disputes involving fraudulent electronic banking transactions
The draft directions identify three scenarios: bank negligence, customer negligence, and breaches elsewhere in the payment system.
First, the RBI states that negligence by a bank may arise when it fails to implement the required safeguards for electronic banking transactions. This includes situations where the bank fails to implement mandated security systems and procedures, fails to send required transaction alerts, or does not provide channels for customers to report fraudulent transactions or loss of payment instruments. Similarly, negligence may arise if the bank fails to act diligently after a customer reports suspicious activity, or if system malfunctions, security breaches, or internal fraud result in unauthorised transactions.
Conversely, customer negligence may arise when the customer shares sensitive credentials such as PINs, passwords, or OTPs with another person, fails to promptly report a fraudulent transaction or a lost payment instrument, or ignores clear warnings issued by the bank that a transaction may be a scam. Customers may also act negligently if they fail to exercise reasonable care in safeguarding their credentials. For example, they may write down a PIN alongside a card or download malicious applications that compromise their accounts.
The directions also cover situations in which neither the bank nor the customer is at fault. In these cases, problems may arise from intermediaries such as third-party app providers, payment gateways, aggregators, or telecom providers.
Meanwhile, the proposed compensation mechanism applies to individuals who suffer losses of up to Rs 50,000 due to fraudulent electronic banking transactions. To qualify, the customer must report the fraud to both the bank and the National Cyber Crime Reporting Portal (NCRP) or helpline within five days of the transaction.
In such cases, a bona fide victim may receive compensation equal to 85% of the net loss or Rs 25,000, whichever is lower, once during their lifetime. Of the compensation paid, 65% will be borne by the RBI, with the customer’s bank and the beneficiary bank each contributing 10%.
Finally, the draft directions require banks to establish internal monitoring mechanisms to track complaints involving fraudulent electronic banking transactions. Banks must periodically report the number and value of such cases to their Board or a designated committee, which must then review complaint handling, grievance redressal, and compensation processes and take steps to improve systems and procedures.
While the draft introduces a structured compensation mechanism for digital banking fraud, its scope remains limited. For example, the scheme applies only to small-value frauds. Many larger fraud cases, with losses running into lakhs, fall outside this framework. These cases will continue to rely primarily on bank investigations or on law enforcement recovery efforts.
At the same time, the eligibility requirements may limit the number of victims who can access the compensation. Customers must report the fraudulent transaction to their bank and to the NCRP or helpline within 5 days of its occurrence. The directions also allow compensation only once per customer, meaning victims who suffer fraud more than once may not be able to claim relief again.
Additionally, the contribution structure may also prove difficult to apply in some cases. Under the proposal, the RBI, the customer’s bank, and the beneficiary bank share the compensation amount. However, if fraudsters transfer stolen funds to crypto wallets or other non-bank payment channels, the beneficiary institution may not be a bank, which could complicate the application of this contribution structure.
Notably, the draft framework focuses on fraud within the banking system and does not address crypto-related fraud, which falls outside RBI banking regulations.
Also Read
For You
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。