Online Bank Fraud: New RBI Rules on Customer Liability

Part of the Personal Finance Guide 2026 → Banking, insurance and EPF — the protections that come first.
Personal Finance › Banking
RBI new rules on customer liability for online bank fraud and unauthorised electronic transactions

Quick Answer

From 1 January 2027, if money is stolen from your bank account through an unauthorised electronic transaction, your liability depends on who was at fault. If the bank was negligent, you owe nothing and the transaction is reversed — regardless of when you report. If the fault lay with a third-party intermediary, you owe nothing provided you report to your bank within 5 calendar days (and you should also file on Cyber Crime Helpline 1930). Only if the fraud resulted from your own negligence do you bear the loss — with a limited small-value compensation available.

Why the 2017 Framework Is Being Replaced

India's existing rules on customer liability in unauthorised electronic banking transactions date to 2017. That framework introduced the concept of limited liability for customers and shifted some responsibility to banks. But digital banking has changed substantially since then — UPI was nascent in 2017, payment aggregators and third-party application providers are now mainstream, and the fraud ecosystem has grown more complex.

On 24 June 2026, the RBI issued the Reserve Bank of India (Commercial Banks – Responsible Business Conduct) Third Amendment Directions, 2026 (circular RBI/2026-27/167, DOR.MCS.REC.No.130/01-01-032/2026-27) to overhaul the framework. The new directions expand coverage beyond "unauthorised transactions" to a broader category of "fraudulent electronic banking transactions" (EBTs) — including card-present and card-not-present fraud. They will apply to all electronic banking transactions undertaken on or after 1 January 2027.

The two most significant changes are definitional clarity — the directions now spell out exactly what constitutes bank negligence and customer negligence — and a new compensation mechanism for small-value fraud victims in negligence cases who report on time.

Three Scenarios: Who Pays What

The new framework allocates loss based on where the fault lies. The scenarios below cover the full spectrum.

Scenario Customer liability What this means in practice
Bank negligence Zero — reported or not Bank failed to send mandatory transaction alerts, lacked 24×7 reporting channels, or suffered a system malfunction or internal breach. You get zero liability and a full reversal regardless of whether — or when — you reported it.
Third-party breach, reported ≤ 5 calendar days Zero Fraud caused by a payment aggregator, TPAP, payment gateway, telecom provider, or other intermediary; you report it to the bank within 5 calendar days. Zero liability and a full reversal.
Third-party breach, reported > 5 calendar days As per the bank’s policy Reporting after the 5-day window removes the automatic zero-liability protection. Your liability is then determined by your bank’s board-approved customer-protection policy.
Customer negligence You bear the loss until you report — with limited small-value relief You shared a PIN/OTP, ignored a specific bank warning that a transaction was likely a scam, downloaded a malicious app, or failed to update your contact details. You are liable for the loss up to the point you report. If your gross loss is ₹50,000 or less and you reported to both the bank and 1930 / NCRP within 5 days, you may receive 85% of the net loss or ₹25,000 (whichever is lower), once in your lifetime.

One principle runs across all these scenarios: any loss from transactions that occur after you have reported the fraud to your bank is borne by the bank, not you (paragraph 76O). That is why reporting speed matters more than anything else below.

The 5-Calendar-Day Reporting Rule

The 2026 directions make the reporting window 5 calendar days — a meaningful tightening from the old framework, which used working days. In practice, a fraud that occurs on a Friday now means you have until Wednesday (at the latest) to report, not the following Wednesday as might have been the case under a working-day count.

Two different reports matter here, and they do different jobs:

  • To your bank — through any channel (app, branch, phone, or the bank's 24×7 reporting number, which banks are now required to maintain). Reporting to the bank within 5 calendar days is what triggers zero liability in a third-party-breach case.
  • To the National Cyber Crime Reporting Portal or Cyber Crime Helpline 1930 — India's national fraud reporting infrastructure. This is required, together with the bank report, to claim the small-value compensation in a customer-negligence case.

For the small-value compensation in a negligence case, both reports must be lodged within 5 calendar days — reporting to your bank alone is not enough. For zero liability in a third-party-breach case, the trigger is reporting the fraud to your bank within 5 calendar days; filing on 1930 is strongly advised in every case and supports any criminal recovery.

The RBI has also tightened bank investigation timelines: domestic fraud complaints must be resolved and communicated within 45 calendar days; cross-border cases within 60 calendar days. For credit-card fraud specifically, banks must issue a shadow reversal of the disputed amount within 5 calendar days of receiving the complaint — even while the investigation is ongoing.

Compensation for Small-Value Frauds (Up to ₹50,000)

Here is a point most coverage gets wrong: the widely quoted “85% or ₹25,000” figure is not a cap on what you can recover. In the fault-free cases above — bank negligence, or a third-party breach reported within 5 days — you get a full reversal of the transaction, not a capped amount.

The 85%/₹25,000 figure is a separate safety net for the one scenario that would otherwise leave you fully exposed: fraud caused by your own negligence (paragraph 76T). For a bona fide individual victim, including a sole proprietor, who suffers a gross loss of up to ₹50,000 in such a case, the directions provide:

  • Compensation of 85% of the net loss, or ₹25,000, whichever is lower — payable once in the customer’s lifetime.
  • To qualify, both the bank report and the 1930 / NCRP report must be lodged within 5 calendar days of the incident, and the loss must be established as bona fide.
  • It covers individual customers and sole proprietors. Corporate accounts are not in scope.

This compensation is part-funded by the RBI itself, and it is a time-limited scheme: it applies to frauds occurring in the first year from the effective date — that is, roughly 1 January 2027 to end-2027. For customer-negligence losses above ₹50,000, no compensation mechanism applies — the customer bears the loss up to the point of reporting.

This mechanism is new. The 2017 framework had a zero-liability structure but no separate compensation for small losses in negligence cases. The 2026 directions add it.

What Banks Are Required to Do From 1 January 2027

The directions impose specific obligations on banks, breaching which constitutes "bank negligence" and results in zero customer liability:

  • Instant SMS alerts for all electronic banking transactions above ₹500. Email alerts are also required where an email address is on record.
  • 24×7 channels for customers to report fraudulent transactions or loss of a debit/credit card.
  • Diligent response to customer fraud notifications — the bank cannot delay or dismiss a report.
  • Investigate and communicate within 45 calendar days for domestic cases, 60 calendar days for cross-border cases.
  • Shadow reversal within 5 calendar days for disputed credit-card transactions.
  • Systems and procedures adequate to ensure safety and security of all electronic banking transactions.

Exactly What to Do If Your Account Is Hit

The 5-day window is unforgiving. If you discover a fraudulent transaction, the steps below apply from 1 January 2027 under the new framework:

  • Report to your bank immediately. Use the bank's 24×7 helpline, app, or nearest branch. Note the complaint reference number and timestamp. Banks are required to maintain 24×7 channels — if yours does not, that itself constitutes bank negligence.
  • Report on the National Cyber Crime Reporting Portal (cybercrime.gov.in) or call 1930. Do this in every case; it is a condition for the small-value compensation and supports any criminal recovery.
  • Do both within 5 calendar days of the fraud date — not the date you discovered it. If you received no SMS alert and discovered the fraud only later, the absence of the alert is itself bank negligence, which may affect the liability analysis. Keep evidence of when you first became aware.
  • Preserve all evidence — screenshots of the transaction, the SMS (or absence of one), any messages from the fraudster, and acknowledgement receipts from both reports.
  • Follow up on the complaint — if the bank does not communicate an outcome within 45 calendar days (domestic), escalate to the RBI Ombudsman.

Bottom Line

From 1 January 2027, your liability for bank account fraud depends on one question: who was negligent? If the bank was — no liability, full reversal. If a third party was and you reported to the bank within 5 days — no liability. If you were — you bear the loss until you report, with a limited one-time small-value relief. The 5-day rule is the single most actionable requirement. Do not wait for a weekly statement to discover a fraud.

General Disclosure: This article is for educational purposes only and does not constitute financial, legal, or banking advice. Banking regulations are subject to amendment, and individual circumstances vary. Consult your bank or a qualified professional for advice specific to your situation.
AI Assistance Disclosure: This article was researched and drafted with AI assistance and reviewed by Utkarsh Garg, Editor, and verified against the primary RBI circular — the Reserve Bank of India (Commercial Banks – Responsible Business Conduct) Third Amendment Directions, 2026 (RBI/2026-27/167, dated 24 June 2026).
Editorial Note: Figures and clauses in this article have been verified against the primary RBI notification (rbi.org.in/Scripts/NotificationUser.aspx?Id=13543), cross-referenced with reporting in Business Standard and Naavi.org. Liability outcomes reflect paragraphs 76K to 76U of the directions.

Frequently Asked Questions

If money is stolen from my bank account, do I have to pay anything?

From 1 January 2027, it depends on who was at fault. If the bank was negligent — for example, it failed to send a mandatory transaction alert or its system was breached — your liability is zero regardless of when you reported it, and the transaction is reversed. If the fault lay with a third party (a payment app, gateway, or telecom provider) and you reported it to your bank within 5 calendar days, your liability is again zero and the bank bears the loss. You should also file on the Cyber Crime Helpline 1930 in every case. Only where the fraud resulted from your own negligence do you bear the loss.

What is the 5-day reporting rule under the new RBI framework?

Under the RBI (Commercial Banks – Responsible Business Conduct) Third Amendment Directions, 2026, reporting a fraudulent electronic banking transaction to your bank within 5 calendar days is what triggers zero liability in a third-party-breach case. Separately, to claim the small-value compensation available in a customer-negligence case, you must report to both your bank and the National Cyber Crime Reporting Portal or Helpline 1930 within 5 calendar days. The 2026 directions measure the window in calendar days, not working days as the old 2017 framework did.

How much compensation can I get for a small-value bank fraud?

It depends on who was at fault. If you were not at fault — the bank was negligent, or a third party was and you reported within 5 calendar days — you are entitled to a full reversal of the transaction, not a capped amount. The 85% of net loss or ₹25,000 (whichever is lower) compensation applies specifically to fraud caused by your own negligence: for a bona fide individual or sole proprietor with a gross loss up to ₹50,000, once in a lifetime, provided the loss is bona fide and you reported to both your bank and the National Cyber Crime Helpline 1930 within 5 calendar days. It is a time-limited scheme covering frauds in the first year from 1 January 2027. For negligence losses above ₹50,000, no compensation mechanism applies.

What actions count as my negligence under RBI’s 2026 directions?

The new directions define customer negligence explicitly. It includes: sharing your PIN, password, or OTP with another person (whether intentionally or not); writing down your PIN and storing it with your card; ignoring a specific, directed warning from your bank that a transaction is likely a scam; downloading malicious apps; and failing to update your registered mobile number or email address with your bank. If a fraud occurs due to your negligence, you bear the loss up to the point you report it to the bank — though a one-time small-value compensation of up to 85% or ₹25,000 may apply to bona fide losses up to ₹50,000.

When do the new RBI bank fraud liability rules come into effect?

The RBI (Commercial Banks – Responsible Business Conduct) Third Amendment Directions, 2026 will apply to electronic banking transactions undertaken on or after 1 January 2027. The circular (RBI/2026-27/167) was issued on 24 June 2026. Parallel versions cover small finance banks, payments banks, local area banks, regional rural banks, and co-operative banks.

Sources

1. Reserve Bank of India (Commercial Banks – Responsible Business Conduct) Third Amendment Directions, 2026 — primary notification RBI/2026-27/167, DOR.MCS.REC.No.130/01-01-032/2026-27, dated 24 June 2026. rbi.org.in/Scripts/NotificationUser.aspx?Id=13543 (paras 76K to 76U).

2. Business Standard, "RBI issues Amendment Directions on Review of Framework of Limiting Customer Liability in Digital Transactions" (25 Jun 2026) — corroborating coverage: 5 calendar days, 85%/₹25,000, ₹500 SMS threshold, 45/60-day timelines, 5-day shadow reversal.

3. Naavi.org, "RBI updates 'Limited Liability Circular' for Bank Frauds" (26 Jun 2026) — verbatim insertion text for bank negligence (4(20B)) and customer negligence (4(20C)).

Comments

Most Read

RBI Broker Lending Rules 2026: What Margin Traders Must Know

WPI Hits 42-Month High (8.3%) — April 2026 Breakdown

ESOP & RSU Tax India 2026: Exercise, Sale & Schedule FA