loader image

Rs 48,021 Crore in Bank Fraud: What RBI’s 2026 Directions on Customer Liability Actually Change

Rs 48,021 Crore in Bank Fraud: What RBI’s 2026 Directions on Customer Liability Actually Change

By Anand Kr. Maurya*

RBI 2026 Customer Liability Directions

Banks and financial institutions reported 10,114 fraud cases worth Rs 48,021 crore in the year ending March 2026, a jump of 46% over the year before, according to the Reserve Bank’s own Annual Report for 2025-26, released on May 29, 2026. On June 24, 2026, against that backdrop, the Reserve Bank issued a revised framework governing electronic banking fraud, the Reserve Bank of India Commercial Banks Responsible Business Conduct Third Amendment Directions, 2026, effective January 1, 2027. This article sets out what the Directions actually change in law, what they leave untouched, and how the position compares with the frameworks in place in the United Kingdom, the United States and the United Arab Emirates.

The Data Behind the Directions

The Reserve Bank’s own tables show a sharp shift in where India’s fraud losses now sit. In 2023-24, card, internet and digital payment fraud, the category the new consumer protection Directions are built to police, accounted for 28,836 cases worth Rs 1,452 crore, 80.4% of all fraud cases that year. By 2025-26, this had fallen to 293 cases worth Rs 29 crore, just 2.9% of cases and roughly 0.05% of total value. Over the same three years, fraud in the advances category, loans and credit facilities extended by banks, rose from Rs 8,917 crore to Rs 40,774 crore, and now accounts for 84.9% of everything banks report as fraud by value. The new Directions address consumer facing digital transactions in detail. The larger and faster growing category, corporate and institutional lending fraud, is governed separately, under the Reserve Bank’s Master Directions on Fraud Risk Management and the classification framework it administers.

The Statutory History

Paragraph 76K of the 2026 Directions places the burden of proving customer liability in a fraud complaint on the bank. This is a continuation of existing law rather than a new position. The Reserve Bank’s circular of July 6, 2017, Customer Protection, Limiting Liability of Customers in Unauthorised Electronic Banking Transactions, already provided at paragraph 12 that the burden of proving customer liability shall lie on the bank, in near identical terms. Zero liability for bank negligence, irrespective of whether the customer reported the transaction, was already set out at paragraph 6 of the 2017 circular. The legal position on burden of proof has therefore remained consistent since 2017. What the 2026 Directions change sits elsewhere, in the structure of liability, the timelines, and the compensation mechanism.

What the 2026 Directions Change

Three structural changes stand out. First, the 2017 circular’s tiered liability table, which capped a customer’s exposure at Rs 5,000, Rs 10,000 or Rs 25,000 depending on account type and reporting delay, is removed. Under paragraphs 76L to 76N of the 2026 Directions, a customer now has either zero liability, where the fraud results from bank negligence or a third party breach reported within 5 calendar days, or liability limited strictly to the period before they report the transaction. Second, resolution timelines are shortened. The 2017 circular allowed banks 90 days to resolve a complaint and 10 working days to shadow reverse a disputed amount. Paragraph 76Q of the 2026 Directions caps resolution at 45 calendar days for domestic fraud and 60 for cross border fraud, and paragraph 76R requires shadow reversal of disputed credit card transactions within 5 calendar days. Third, paragraph 76T introduces a funded compensation mechanism that did not exist before, paying 85% of net loss or Rs 25,000, whichever is lower, for losses up to Rs 50,000, financed 65% by the Reserve Bank and split between the customer’s bank and the bank that received the funds.

The Judicial Backdrop

The 2026 Directions do not operate in isolation from the courts. In State Bank of India v. Rajesh Agarwal, (2023) 6 SCC 1, decided on March 27, 2023, the Supreme Court held that the principle of audi alteram partem must be read into the Reserve Bank’s Master Directions on Frauds, and that a borrower is entitled to a hearing before an account is classified as fraudulent, given the civil consequences that follow, including a bar on institutional finance. The Reserve Bank’s own 2025-26 Annual Report records that 314 legacy fraud cases worth Rs 30,199 crore were reclassified during the year specifically to ensure compliance with that judgment. Since advances fraud now constitutes 84.9% of reported fraud by value, the due process standard set in Rajesh Agarwal, and not the consumer facing provisions in the 2026 Directions, governs the category where the largest sums are actually at stake.

Definitions That Will Bear on Future Disputes

The 2017 circular described categories of fault without defining them. The 2026 Directions insert, for the first time, itemised definitions of negligence by a bank and negligence by a customer. Negligence by a customer includes not heeding a specific, directed and clear warning from the bank that a transaction is likely a scam, alongside sharing an OTP or downloading a malicious application. Given that Indian banks now issue automated fraud warnings on most UPI transfers, the application of this standard to a routine, non-specific notification, as against a warning tailored to the transaction in question, is likely to be a point of contention in individual disputes before the Banking Ombudsman and in civil proceedings.

The International Comparison

The compensation mechanism at paragraph 76T can usefully be set against comparable frameworks abroad. India’s 2017 circular capped a customer’s exposure at Rs 5,000, Rs 10,000 or Rs 25,000 depending on account type, if reported within 4 to 7 working days, with 90 days allowed for a bank to resolve a complaint. The 2026 Directions replace this with a compensation cap of Rs 25,000 for losses up to Rs 50,000, resolved within 45 to 60 days.

In the United Kingdom, the Payment Systems Regulator has operated a mandatory reimbursement regime for authorised push payment fraud since October 7, 2024, requiring the sending and receiving institution to share the cost of a qualifying claim equally, up to a cap of GBP 85,000, with reimbursement due within 5 working days regardless of whose negligence caused the loss, close to Rs 90 lakh at the cap.

In the United States, Regulation E, codified at 12 CFR 1005.6, caps a consumer’s liability at USD 50 if reported within 2 business days of discovery, rising to USD 500 thereafter, with a provisional credit required within 10 business days of an error notice.

In the United Arab Emirates, the Central Bank’s Consumer Protection Standards require licensed institutions to inform customers how to report unauthorised transactions and of the consequences of sharing a PIN or password, but do not fix a numeric compensation cap or mandatory reimbursement timeline of the kind used in India, the United Kingdom or the United States, leaving apportionment of loss to the institution’s own policy. Set against this range, India’s Rs 50,000 cap is a fraction of the United Kingdom’s exposure, though the underlying zero liability principle for bank negligence is broader on paper than the fixed monetary tiers under United States law, and considerably more defined than the disclosure based approach followed in the United Arab Emirates.

Implications for Banks, Customers and Practice

For banks, the Directions require a documented, board approved policy distinguishing bank negligence, customer negligence and third party breach, supported by evidence, since the burden of establishing fault now rests with the institution in every contested case. For customers, the practical protection depends less on the burden of proof, already settled, than on whether a given warning or a given lapse meets the statutory definition now written into the Directions. For advocates practising in banking disputes, the shift worth preparing for is a body of Banking Ombudsman and civil decisions interpreting those definitions, layered onto a due process standard for advances fraud that the Supreme Court has already settled independently of these Directions.

Where These Disputes Will Actually Be Fought

The more important shift, in my reading, is procedural rather than substantive. Once the burden of proving fault sits with the bank as a matter of settled law, and the definitions of negligence are now written into the Directions rather than left open, a fraud complaint stops being a grievance a customer has to justify and becomes a claim the bank has to defend with evidence, alert logs, authentication records, and its own internal fraud detection trail. That changes where these disputes will actually be fought. The Banking Ombudsman, currently a forum for complaints a customer struggles to substantiate, becomes a forum where the bank must produce its case first, and I expect a rise in matters that previously settled quietly at that stage now being contested on the record, precisely because a bank with a weak evidentiary file has more to lose by fighting than by conceding. Where the Ombudsman route is exhausted or the sum involved exceeds its pecuniary limits, the same evidentiary shift carries into civil suits and consumer commission proceedings, where courts will now have to engage directly with whether a bank’s alert met the statutory description of a warning, a question of fact rather than law, and one on which appellate scrutiny has traditionally been light. For the Reserve Bank’s own supervisory channel, this means fraud disputes are likely to surface not as isolated customer grievances but as patterns, a bank that repeatedly fails the negligence standard across similar complaints exposes itself to supervisory action independent of any individual case. The practical consequence for dispute work in this space is that the fight has moved from the courtroom argument over principle, which is now settled, to the record itself, and the file that wins after January 1, 2027 will be the one built before the dispute ever reaches a forum.

This article reflects my personal, independent legal analysis of publicly available facts and regulatory instruments, undertaken purely for academic and theoretical understanding of Indian banking and financial regulatory law. It is not intended as, and should not be relied upon as, legal advice, and it does not represent any administrative, regulatory or professional opinion on behalf of, or any allegation against, the Reserve Bank of India, the Supreme Court of India, or any other entity named herein.


*Anand Kumar Maurya, Advocate, practising in Banking and Finance, Restructuring and Insolvency, Project and Infrastructure, and Arbitration Laws.