Corporate Services Contact Us
Financial Fraud: RBI Guidelines For Unauthorised Transactions
Banking
Updated On : June 3, 2025

Financial Fraud: RBI Guidelines For Unauthorised Transactions

Written By : Umashri Jana

Listen to this article   

Table of Contents

Digital payments have become an ordinary part of everyday life. Salaries are credited electronically, bills are paid through UPI, cards are stored in mobile applications, and internet banking supports a large share of everyday transactions.  

However, that comfort has also made online banking fraud more personal, more sudden, and sometimes more legally confusing for the ordinary account holder.

The problem is not only that money disappears. The bigger problem is what happens after that. Banks ask whether the customer shared an OTP. Customers say they never authorised the transaction. Police may ask for screenshots, complaint numbers, and account details. 

Reporting timelines are important because the RBI framework links customer protection to the speed with which unauthorised transactions are reported. 

What Counts as an Unauthorised Transaction?

An unauthorised transaction is not just one that a customer regrets later. It is a debit or financial movement that happens without the customer’s valid permission. 

For example, the following transactions fall within this category, depending on the facts:

  • Card-not-present transactions
  • Hacked net banking transfers
  • Malware-led debits
  • Cloned card withdrawals
  • Mobile banking transactions carried out without the customer's authorisation. 

At this stage, advice from a cybercrime lawyer may help a victim identify the most effective legal and procedural steps. This happens especially when the bank casually blames the customer without checking transaction logs, complaint timing, device compromise, or the possibility of a third-party breach. 

Therefore, the first legal question is simple but not small: did the customer authorise the transaction, or did somebody else access the banking system without valid authority? 

In many online banking fraud cases, that line becomes blurred because scammers use phishing links, remote access apps, SIM swaps, fake KYC calls, or OTP interception to create the appearance of customer consent.

Why RBI’s Customer Liability Framework Matters

 

The present framework primarily flows from the Reserve Bank of India's directions on customer protection relating to unauthorised electronic banking transactions. These directions establish the principles governing customer liability, reporting timelines, provisional credit, and grievance handling in cases involving unauthorised debits.

The RBI guidelines on unauthorised transactions were introduced to prevent banks from shifting every digital fraud loss onto the customer. Since banks operate payment systems, issue cards, authenticate transactions, monitor suspicious activity, and generate transaction alerts, the regulatory framework places corresponding responsibilities on them when unauthorised transactions occur.

Accordingly, banks cannot treat themselves as passive observers once an unauthorised transaction is reported. They are expected to examine the transaction, assess the circumstances in which it occurred, and process the complaint in accordance with the customer-protection framework.

At the same time, the framework recognises that customers also have a role in protecting their accounts. Prompt reporting of suspicious transactions is therefore an important factor. A customer who reports an unauthorised debit immediately is generally entitled to stronger protection than one who waits for an extended period before notifying the bank.

Consequently, customer liability is closely linked to reporting timelines. The framework seeks to balance customer protection with reasonable expectations of vigilance, creating a structured approach for determining responsibility when an unauthorised transaction occurs.

Broadly, the RBI framework recognises three situations:

 

  • The loss results from negligence, deficiency, or fraud attributable to the bank.
  • Neither the bank nor the customer is at fault, and the loss arises from a third-party breach.
  • The customer contributes to the loss by sharing credentials or failing to observe basic security precautions.

 

The distinction between these situations is significant because the extent of customer liability may vary depending on the facts of the case, the timing of the report, and the circumstances surrounding the unauthorised transaction. For this reason, a proper examination of transaction records, complaint timelines, security alerts, and communication history often becomes central to resolving disputes arising from online banking fraud.

Customer Liability: The Practical Comparison

The following comparison explains how liability typically applies to unauthorised electronic banking transactions. The applicable liability limits are governed by RBI directions and may vary depending on the type of account, payment instrument, and the facts of the case. Individual facts still matter, and banks must examine the transaction trail rather than reject claims with copy-paste language.

Situation

Reporting Timeline

Customer Liability

Practical Meaning

Bank negligence, deficiency, or contributory fraud

Even if delayed

Zero liability

The bank bears the loss because the failure sits on its side of the system.

Third-party breach, no customer negligence

Within 3 working days

Zero liability

Quick reporting fully protects the customer, provided the facts support unauthorised access.

Third-party breach, no customer negligence

4 to 7 working days

Limited liability

The customer may be subject to capped liability, depending on the account/card type and transaction value.

Third-party breach, delayed reporting

After 7 working days

As per bank policy

The bank’s board-approved policy becomes important, and recovery may become harder.

Customer negligence, such as sharing OTP or password

Until reported

The customer bears the loss till reporting

After reporting, further unauthorised debits should not be charged to the customer.

This structure is important because banks sometimes use “OTP used” as a full stop. But legally, that should not always end the inquiry. 

Malware, SIM swap, vishing, device compromise, and fake banking interfaces may create complex fact situations. Therefore, a proper complaint must describe how the transaction occurred, when the alert came, and when the bank received the report.

What Customers Should Do Immediately After Financial Fraud

The first few hours are crucial. This is because delay gives fraudsters time to move funds through mule accounts, wallets, merchants, or layered transfers. Delay may also weaken the customer's position when liability is assessed later. 

A victim should immediately block the card, freeze affected channels, report to the bank through official customer care or branch channels, and obtain a complaint acknowledgement. 

In addition, the customer should file a complaint through the national cybercrime reporting mechanism or helpline, especially where the facts indicate cyber fraud involving phishing, UPI manipulation, remote access, or identity misuse.

Some documents should be preserved without editing or excessive cleanup. So, keep the following documents:

  • SMS alert
  • Email alert
  • Bank statement
  • Transaction ID
  • Complaint acknowledgement
  • Screenshots of suspicious messages
  • Caller numbers
  • App names
  • Any communication with the fraudster. 

Also, write down the timeline while your memory is fresh. Later, small details become big evidence.

Bank’s Duties After Receiving the Complaint

Once the bank receives information about an unauthorised transaction, it cannot simply say “customer fault” and close the matter. It must examine the complaint, prevent further loss, acknowledge the complaint, and process the claim in accordance with the customer liability framework. 

Additionally, the bank has to maintain systems for fraud detection, alerts, risk assessment, and customer education.

In eligible cases, banks are expected to provide provisional credit or a shadow reversal within the timelines prescribed under the applicable RBI framework. That credit does not always mean the dispute has finally ended. 

However, it gives immediate relief and prevents the customer from carrying the entire burden while the bank investigates.

The complaint should be resolved within the applicable grievance redressal period. If the bank rejects the claim, it should provide reasons. A vague statement such as “transaction was successful” does not answer the legal issue. 

The real issue is whether the customer validly authorised it and whether the bank’s security systems functioned properly.

UPI Fraud, OTP Sharing, and the Grey Area

UPI fraud creates a slightly different problem. Many victims technically press the button themselves because a fraudster manipulates them through a fake refund, a QR code, a collect request, an investment pitch, a delivery update, or a customer-care impersonation. 

In such cases, the bank may argue that the transaction was authorised by the customer, even though consent was obtained through deception.

That is where legal analysis becomes more layered. A voluntary payment made under deception may not always fit neatly into “unauthorised transaction” treatment. Still, it may remain a criminal offence and justify cybercrime reporting, account-freezing requests, police action, and complaint escalation. 

Therefore, victims should not assume that nothing can be done merely because they clicked or approved something.

In online banking fraud matters, facts decide the route. If the transaction happened without customer participation, the RBI liability framework becomes central. If the customer was tricked into approving payment, criminal remedies and cyber complaint mechanisms become equally important. 

Sometimes, both routes must run together because banks, payment intermediaries, and law enforcement all hold different pieces of the puzzle.

When the Bank Refuses a Refund

A bank refusal is not the end of the road. However, it should be handled with documents, not just frustration. 

The customer should ask for written reasons, preserve the complaint number, collect the investigation response, and verify whether the bank considered reporting time, system logs, suspicious beneficiary patterns, transaction location, device information, and customer alerts.

If the bank fails to respond properly, the customer may escalate the grievance through the bank’s nodal officer or principal nodal officer. 

Subject to eligibility requirements and the prescribed procedure, the complaint may be escalated under the RBI Integrated Ombudsman Scheme, provided the customer follows the required escalation path. In suitable cases, consumer law remedies may also arise if banking services are deficient.

Additionally, criminal proceedings may continue separately. A refund dispute with the bank and a criminal complaint against fraudsters are not the same thing. One concerns liability and service standards. The other concerns are investigation, money tracing, account freezing, and prosecuting offenders. Although both may overlap, neither automatically replaces the other.

Common Mistakes That Weaken a Claim

Many customers lose valuable time because they feel embarrassed. That is understandable, but it is dangerous. Scammers thrive on hesitation. Moreover, banks often strictly enforce reporting timelines, so silence can hurt the claim more than the original mistake.

Avoid these mistakes after a suspicious debit:

  • Do not delete messages, call logs, emails, or screenshots. This is because even seemingly awkward evidence may help reconstruct the chain of fraud later.
  • Do not rely only on a phone call to the bank. Avoid it unless an acknowledgement or complaint number is generated.
  • Do not keep using the same compromised device for banking without checking apps, permissions, remote access tools, and malware risk.
  • Do not accept oral rejection from bank staff as final. This is because formal remedies usually require written complaint records and written responses.

Legal Depth: Customer Negligence Is Not a Magic Word

Banks sometimes use the phrase “customer negligence” too loosely. Legally, negligence should mean more than the mere occurrence of loss. If every successful fraud were automatically treated as customer negligence, the purpose of the customer protection framework would be significantly diluted.  

Therefore, the bank should show what the customer did, how that conduct caused the loss, and why the transaction passed security controls.

At the same time, customers also have responsibilities. Sharing OTPs, PINs, CVVs, passwords, screen access, or banking credentials with strangers can seriously undermine a refund claim. 

However, even then, once the bank is informed, future unauthorised transactions should not be shifted to the customer. That cut-off point matters and should be clearly recorded.

The more balanced view is this: digital banking safety is shared, but not equally shared in every case. Banks possess stronger systems, data, monitoring tools, and technical control. Customers possess immediate reporting duties and confidentiality duties. 

Consequently, liability should be fixed after examining both sides, not by mechanically blaming the weaker party.

Money Can Move Fast, but Legal Action Must Move Faster

Unauthorised banking transactions are not merely technical glitches. They are legal events with financial, criminal, and evidentiary consequences. The customer’s strongest protection lies in fast reporting, clear documentation, and refusal to accept vague rejection. 

Therefore, in every suspected online banking fraud situation, the first response should be immediate, written, and traceable.

Although the RBI framework gives customers meaningful protection, it is not automatic in every case. Timing, negligence, bank conduct, and evidence all matter.

FAQs

1. What is an unauthorised banking transaction?

An unauthorised banking transaction is a debit or transfer made without the customer’s valid consent through card, net banking, mobile banking, UPI, or similar channels.

2. How soon should a customer report financial fraud?

A customer should report it immediately, preferably within three working days, as prompt reporting can significantly reduce or eliminate liability under the RBI’s framework.

3. Can a bank deny a refund if the OTP was used?

Yes, it may deny, but OTP use alone should not end the inquiry. Malware, SIM swap, phishing, or vishing may still require proper investigation.

4. Where should victims complain after bank fraud?

After bank fraud, victims should do the following:

  1. Complain to the bank
  2. Preserve acknowledgement
  3. File a cybercrime complaint
  4. Escalate to the banking ombudsman if the bank's response is unsatisfactory.

5. Is UPI fraud always treated as an unauthorised transaction?

Not always. If the victim approved the payment after being deceived or manipulated by a fraudster, criminal remedies may become central, though bank escalation and cybercrime reporting remain important.

About the Author
Umashri Jana

Adv. Umashri Jana

Advocate Umashri Jana is an emerging legal professional with a Bachelor of Laws (B.A. LL.B. Hons) from Adamas University and 6 months of practical experience. She is steadily building her presence in the legal field through her dedication, discipline, and growing expertise in civil, criminal, family, and consumer law. She has appeared before various courts in West Bengal, including District & Sessions Courts and Sub-Divisional Courts, and is known for her attention to detail, strong research skills, and client-focused approach. Despite being early in her career, Advocate Jana demonstrates clarity, diligence, and professionalism in handling diverse legal matters, consistently striving to provide effective and empathetic legal support to her clients.

Our Expert Lawyers in Banking Cyber Crime Mail Fraud

Abhimanyu

Abhimanyu Shandilya

From Kolkata

Recommended blog article

Practical Steps When Your Aadhaar Is Misused - Legal & Technical Remedies
Posted On : July 29, 2026

Practical Steps When Your Aadhaar Is Misused - Legal & Technical Remedies

Imagine a scenario: you have received an SMS saying your loan application has been successfully submitted and approved. But, in reality, you have never applied for it in the first place. Here your fir...

Consequences of Ignoring a Legal Notice in Cheque Bounce, Property and Consumer Cases
Posted On : July 24, 2026

Consequences of Ignoring a Legal Notice in Cheque Bounce, Property and Consumer Cases

Many people mistake a legal notice for a court order. Also, treating it like an ordinary complaint or an angry letter might cause serious trouble.  When a legal notice is ignored, the situation c...

Submit your legal query

Categories

Disclaimer

The Bar Council of India does not permit advertisement or solicitation by advocates in any form or manner. By accessing this website (www.vidhikarya.com), you acknowledge and confirm that you are seeking information relating to VIDHIKARYA LEGAL SERVICES LLP (The LAW FIRM) of your own accord and that there has been no form of solicitation, advertisement or inducement by VIDHIKARYA LEGAL SERVICES LLP or its members.
The content of this website is for informational purposes only and should not be interpreted as soliciting or advertisement. The User agrees that he/she is visiting the site on his own volition to seek more information about the firm and its Advocates.
The contents of this website are the intellectual property of VIDHIKARYA LEGAL SERVICES LLP.

Vidhikarya Official support e-mail Contact Vidhikarya by phone Number vidhikarya whatsapp Number
{ "@context": "https://schema.org", "@type": "FAQPage", "mainEntity": [ { "@type": "Question", "name": "What is an unauthorised banking transaction?", "acceptedAnswer": { "@type": "Answer", "text": "An unauthorised banking transaction is a debit or transfer made without the customer’s valid consent through card, net banking, mobile banking, UPI, or similar channels." } }, { "@type": "Question", "name": "How soon should a customer report financial fraud?", "acceptedAnswer": { "@type": "Answer", "text": "A customer should report it immediately, preferably within three working days, as prompt reporting can significantly reduce or eliminate liability under the RBI’s framework." } }, { "@type": "Question", "name": "Can a bank deny a refund if the OTP was used?", "acceptedAnswer": { "@type": "Answer", "text": "Yes, it may deny, but OTP use alone should not end the inquiry. Malware, SIM swap, phishing, or vishing may still require proper investigation." } }, { "@type": "Question", "name": "Where should victims complain after bank fraud?", "acceptedAnswer": { "@type": "Answer", "text": "After bank fraud, victims should do the following: Complain to the bank. Preserve acknowledgement. File a cybercrime complaint. Escalate to the banking ombudsman if the bank's response is unsatisfactory." } }, { "@type": "Question", "name": "Is UPI fraud always treated as an unauthorised transaction?", "acceptedAnswer": { "@type": "Answer", "text": "Not always. If the victim approved the payment after being deceived or manipulated by a fraudster, criminal remedies may become central, though bank escalation and cybercrime reporting remain important." } } ] }