惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

GbyAI
GbyAI
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
C
Cisco Blogs
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
IT之家
IT之家
博客园 - 【当耐特】
V
V2EX
博客园_首页
T
Tailwind CSS Blog
Last Week in AI
Last Week in AI
G
Google Developers Blog
The Last Watchdog
The Last Watchdog
C
CXSECURITY Database RSS Feed - CXSecurity.com
博客园 - 司徒正美
N
Netflix TechBlog - Medium
F
Fortinet All Blogs
Know Your Adversary
Know Your Adversary
S
Schneier on Security
V
Vulnerabilities – Threatpost
T
The Exploit Database - CXSecurity.com
Vercel News
Vercel News
量子位
G
GRAHAM CLULEY
T
Threatpost
D
Darknet – Hacking Tools, Hacker News & Cyber Security
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
C
Cybersecurity and Infrastructure Security Agency CISA
S
Security @ Cisco Blogs
B
Blog
Stack Overflow Blog
Stack Overflow Blog
T
Tor Project blog
A
About on SuperTechFans
博客园 - 叶小钗
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
月光博客
月光博客
S
Securelist
博客园 - 聂微东
Cloudbric
Cloudbric
N
News and Events Feed by Topic
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
H
Help Net Security
N
News | PayPal Newsroom
P
Privacy & Cybersecurity Law Blog
Schneier on Security
Schneier on Security
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
W
WeLiveSecurity
Martin Fowler
Martin Fowler
K
Kaspersky official blog
S
Security Affairs
TaoSecurity Blog
TaoSecurity Blog

Comments for MEDIANAMA

Sony and Jio oppose TRAI’s proposal seeking to regulate FAST services Instagram Hit With Cease And Desist Order Over PG-13 Ratings NHRC issues notice to MeitY over lapses in children’s data protection on major online platforms RTI: Sahyog Portal to Handle Data on Non-Consensual Intimate Images, But Privacy Measures Not Shared Explained: RBI’s Draft Amendments for Bank Policies and Customer Protection in Fraudulent Digital Transactions DPDP Rules And AI: How India’s Personal Data Framework Will Affect Data Collection And Retention Groww to Go Public as SEBI Approves IPO Proposal Groww to Go Public as SEBI Approves IPO Proposal US-Based Investment Management Firm Set To Acquire 23% Stake In Groww AMC For Rs 580 Crore US-Based Investment Management Firm Set To Acquire 23% Stake In Groww AMC For Rs 580 Crore Internet shutdown in 5 districts in Manipur for 3 days after bombing in Bishnupur district Event Announcement: Understanding Nepal’s Social Media Ban, September 12, #NAMA Event Announcement: Understanding Nepal’s Social Media Ban, September 12, #NAMA NHRC issues notice to MeitY over lapses in children’s data protection on major online platforms Reliance Q3FY26 Revenue Up 10%, Jio Subscribers Over 500 Mn RTI: Sahyog Portal to Handle Data on Non-Consensual Intimate Images, But Privacy Measures Not Shared Offshore Betting Platform Usage Increased Nearly 14% After Online Gambling Ban: CUTS Survey DPDP Rules And AI: How India’s Personal Data Framework Will Affect Data Collection And Retention Instagram Hit With Cease And Desist Order Over PG-13 Ratings How To Register Online Games Under Draft Online Gaming Rules Report Says 64% Instagram Safety Tools For Teens Are Ineffective Paytm Money & JioBlackRock Launch AI-Led Active Equity Fund IRDAI Blocks Insurance Underwriting for VC-Funded Fintechs Claude Opus 4 and 4.1 Can Now End Harmful Conversations
Explained: RBI’s Draft Amendments for Bank Policies and Customer Protection in Fraudulent Digital Transactions
2026-04-10 · via Comments for MEDIANAMA

The Reserve Bank of India (RBI) has proposed a one-time compensation for victims of small-value digital banking fraud, offering up to 85% of a net loss (or Rs 25,000, whichever is lower) for losses up to Rs 50,000, under draft amendments to its responsible business conduct framework.

The RBI has released draft amendments to its Responsible Business Conduct Directions, setting the customer protection framework for electronic banking.

The amendments define “fraudulent electronic banking transactions” to include both certain authorised and unauthorised fraudulent transactions. The RBI also identifies when a technically authorised transaction may still be considered fraudulent.

The RBI defines the following types of such transactions:

  • Transactions executed by a third party using credentials obtained fraudulently from the customer.
  • Transactions carried out by the customer under pressure or threat from a third party.
  • Transactions in which a customer is tricked into sending money to a scammer posing as a legitimate recipient. 

The RBI has invited comments on the draft directions until April 6, 2026. If notified, the amendments will apply to the Responsible Business Conduct Directions for all types of regulated banks. These directions will govern electronic banking transactions conducted on or after July 1, 2026.

How will banks tackle digital fraud?

The draft amendments require banks to adopt a formal policy on customer protection for electronic banking transactions and to clearly define customers’ rights and obligations in the event of fraud. Banks must also specify timelines for resolving complaints and disclose their grievance redressal and escalation procedures

 In addition, they must publish these policies on their websites and implement programmes to increase customer awareness about emerging payment fraud and safe digital banking practices.

At the same time, banks must strengthen their internal systems to detect and mitigate fraud risks. This includes deploying robust fraud detection and prevention mechanisms, assessing risks arising from fraudulent electronic transactions, and implementing measures to mitigate potential losses and liabilities.

Furthermore, banks must ensure that their systems and procedures comply with digital payment security controls and are designed to make customers feel safe when conducting electronic transactions.

Transaction Alerts And Reporting Mechanisms

The amendments introduce stricter requirements for transaction alerts. Banks must obtain customers’ mobile numbers for electronic banking services. Where available, they should also collect email addresses. Banks must send instant SMS alerts for all electronic banking transactions above Rs 500, and email alerts when possible. Other notifications, like in-app or push alerts, may supplement these.

Banks must also provide customers with multiple channels to report fraudulent transactions or the loss of payment instruments. These channels must operate 24×7. They may include phone banking, SMS, email, IVR systems, dedicated toll-free helplines, and home branch reporting.

Additionally, banks must include a number in the SMS alert so customers can notify the bank immediately of objections, and provide a direct reporting link on their homepages. Upon receiving a complaint, banks must immediately register it, assign a complaint number and timestamp, and take steps to prevent further unauthorised transactions. 

Banks must examine each complaint and determine liability based on the circumstances of the transaction. They must respond to the customer within the timelines set by their policies, but no later than 30 days. Importantly, the bank must prove customer liability in disputes involving fraudulent electronic banking transactions

How Negligence Will Be Established

The draft directions identify three scenarios: bank negligence, customer negligence, and breaches elsewhere in the payment system. 

First, the RBI states that negligence by a bank may arise when it fails to implement the required safeguards for electronic banking transactions. This includes situations where the bank fails to implement mandated security systems and procedures, fails to send required transaction alerts, or does not provide channels for customers to report fraudulent transactions or loss of payment instruments. Similarly, negligence may arise if the bank fails to act diligently after a customer reports suspicious activity, or if system malfunctions, security breaches, or internal fraud result in unauthorised transactions. 

Conversely, customer negligence may arise when the customer shares sensitive credentials such as PINs, passwords, or OTPs with another person, fails to promptly report a fraudulent transaction or a lost payment instrument, or ignores clear warnings issued by the bank that a transaction may be a scam. Customers may also act negligently if they fail to exercise reasonable care in safeguarding their credentials. For example, they may write down a PIN alongside a card or download malicious applications that compromise their accounts.

The directions also cover situations in which neither the bank nor the customer is at fault. In these cases, problems may arise from intermediaries such as third-party app providers, payment gateways, aggregators, or telecom providers.

Compensation For Small Value Frauds And Monitoring

Meanwhile, the proposed compensation mechanism applies to individuals who suffer losses of up to Rs 50,000 due to fraudulent electronic banking transactions. To qualify, the customer must report the fraud to both the bank and the National Cyber Crime Reporting Portal (NCRP) or helpline within five days of the transaction. 

In such cases, a bona fide victim may receive compensation equal to 85% of the net loss or Rs 25,000, whichever is lower, once during their lifetime. Of the compensation paid, 65% will be borne by the RBI, with the customer’s bank and the beneficiary bank each contributing 10%.

Finally, the draft directions require banks to establish internal monitoring mechanisms to track complaints involving fraudulent electronic banking transactions. Banks must periodically report the number and value of such cases to their Board or a designated committee, which must then review complaint handling, grievance redressal, and compensation processes and take steps to improve systems and procedures.

Why This Matters

While the draft introduces a structured compensation mechanism for digital banking fraud, its scope remains limited. For example, the scheme applies only to small-value frauds. Many larger fraud cases, with losses running into lakhs, fall outside this framework. These cases will continue to rely primarily on bank investigations or on law enforcement recovery efforts.

At the same time, the eligibility requirements may limit the number of victims who can access the compensation. Customers must report the fraudulent transaction to their bank and to the NCRP or helpline within 5 days of its occurrence. The directions also allow compensation only once per customer, meaning victims who suffer fraud more than once may not be able to claim relief again. 

Additionally, the contribution structure may also prove difficult to apply in some cases. Under the proposal, the RBI, the customer’s bank, and the beneficiary bank share the compensation amount. However, if fraudsters transfer stolen funds to crypto wallets or other non-bank payment channels, the beneficiary institution may not be a bank, which could complicate the application of this contribution structure.

Notably, the draft framework focuses on fraud within the banking system and does not address crypto-related fraud, which falls outside RBI banking regulations.

Also Read