loaderimg
image
Cyber Law

RBI Rules on Unauthorized Electronic Transactions: When Is the Bank Liable?

Share this article WhatsApp Facebook X

Legal information notice: this article provides general information and isn't a substitute for advice from a qualified lawyer.

Whatever specific type of banking fraud has happened to you — a single unauthorized UPI transfer, a cloned card, a compromised net banking login, a whole string of transactions in one night — one regulation ultimately decides whether the bank has to give your money back: the RBI’s framework on customer liability for unauthorized electronic banking transactions. This is the complete, authoritative breakdown of exactly how it works.

The Core Rule: Zero, Limited, or Full Liability

Under the RBI’s circular “Customer Protection — Limiting Liability of Customers in Unauthorised Electronic Banking Transactions” (dated 6 July 2017, and still the governing framework as of this writing), your liability for an unauthorized electronic transaction falls into exactly one of three categories, determined by two things: who caused the breach, and how quickly you reported it.

Zero Liability: The Strongest Protection

You owe nothing — the bank must credit the full amount back — in two situations. First, where the transaction resulted from a deficiency or negligence on the bank’s own side (a system failure, inadequate security, an internal breach), regardless of when you reported it. Second, where it was a genuine third-party breach — meaning neither you nor the bank was at fault, such as a sophisticated phishing or vishing scam — and you reported it to the bank within 3 working days of receiving the transaction alert.

Limited Liability: A Capped Loss

If you report a genuine third-party breach between 4 and 7 working days after the alert, your liability is capped — generally somewhere between ₹5,000 and ₹25,000 depending on your specific account or card type, rather than the full transaction amount. Beyond 7 working days, your liability reverts to whatever your bank’s own board-approved customer protection policy specifies, which can mean bearing the full loss.

Understanding Your Protection: Process at a Glance

01
Determine Who's at Fault
Bank negligence, third party, or you
02
Report Within 3 Working Days
For zero liability on a third-party breach
03
Bank Must Investigate — Not You
Burden of proof is on the bank
04
Provisional Credit Within 10 Days
Pending the full investigation
05
Final Resolution Within 90 Days
Or compensation for the delay
Step 1: Understand Which Category Your Case Falls Into

Was this a bank system failure, a scam where you were deceived (third-party breach), or did you knowingly share your OTP/PIN/password (genuine negligence)? This classification is what everything else depends on.

Step 2: Report Within 3 Working Days for the Strongest Protection

The clock starts from when you received the bank’s transaction alert (SMS/email/app notification), not from when the transaction actually happened — check your alert timestamps carefully.

Step 3: Let the Bank Prove Negligence — Not the Other Way Around

This is the single most important, most overlooked detail: the burden of proving you were negligent lies with the bank, not with you. You don’t need to prove your innocence; the bank needs to prove your fault.

Step 4: Expect Provisional Credit Within 10 Working Days

The bank is required to credit the disputed amount to your account within 10 working days of your complaint, even before the full investigation concludes — this isn’t optional or discretionary on the bank’s part.

Step 5: The Full Complaint Must Resolve Within 90 Days

If your bank takes longer than 90 days to fully resolve your complaint, you’re entitled to compensation for the delay, separate from the underlying disputed amount itself.

Need Legal Help? Get expert legal help from experienced professionals with ApniLaw legal services across India. Advertisement

The burden-of-proof rule deserves real emphasis because it’s so often misunderstood or quietly ignored in practice: banks sometimes act as though the customer must demonstrate they weren’t negligent, when the regulation places that burden squarely on the bank. If your bank denies a claim by simply asserting negligence without concrete evidence, this is worth challenging directly — an unsupported assertion isn’t proof.

Courts have reinforced this customer-protective stance. The Supreme Court has held that banks must use the best available technology to detect and prevent unauthorised transactions — meaning a bank can’t simply point to a customer’s action as the sole cause of fraud while ignoring its own responsibility to run adequate fraud-detection systems in the first place.

A change is coming, but not yet: the RBI’s 2025 Directions (under the broader “Responsible Business Conduct” framework) will eventually replace this 2017 circular with an updated regime — but this only applies to transactions from 1 January 2027 onward. Until then, the framework described here remains the governing law for any dispute you’re facing today.

Need Immediate Legal Help?

Get Legal Help from ApniLaw Sponsored

Zero vs Limited vs Full Liability at a Glance

The Complete Liability Framework

SituationYour Liability
Bank's own negligence/system failureZero — regardless of when you report
Genuine third-party breach, reported within 3 working daysZero
Genuine third-party breach, reported in 4-7 working daysLimited — capped, typically ₹5,000-₹25,000
Reported beyond 7 working daysYour bank's own board-approved policy applies
Genuine customer negligence (knowingly shared OTP/PIN)Full liability until reported, then bank's policy applies

Where Do You File?

Report to your bank directly through its app, net banking, branch, or helpline. Escalate unresolved or wrongly denied claims to the RBI’s Complaint Management System (Banking Ombudsman).

Does It Cost Anything?

Filing a complaint with your bank and escalating to the RBI Ombudsman are both completely free.

Can You Handle This Without a Lawyer?

Most cases where the facts are clear and reported promptly can be handled directly with the bank and, where necessary, the RBI Ombudsman. A lawyer becomes valuable specifically where the bank disputes the facts, denies a well-documented claim, or the amount involved is substantial.

What Happens After You Report?

  • Your bank is required to acknowledge and begin investigating your complaint immediately
  • A provisional credit should follow within 10 working days, regardless of whether the investigation is complete
  • The bank’s final liability determination must be based on actual evidence of negligence, which the bank itself must establish
  • Full resolution is expected within 90 days, or you’re entitled to compensation for the additional delay

Need professional legal help with this?

Find a Lawyer on Vidyoday

For the specific process depending on exactly what happened to you, see our guides on unauthorized IMPS transactions, unauthorized NEFT/RTGS transfers, and internet banking fraud. If your bank has already denied your claim, our guide on can a bank refuse compensation for cyber fraud breaks down valid versus invalid grounds for refusal.

Key Takeaways

  • Your liability comes down to two questions: who caused the breach, and how fast you reported it — report within 3 working days for zero liability on a genuine third-party breach.
  • The burden of proving you were negligent lies with the bank, not with you — this is the single most important, most overlooked protection in the entire framework.
  • Provisional credit within 10 working days is mandatory, not discretionary — it doesn’t wait for the full investigation to conclude.
  • A 2025 update to this framework exists but only takes effect for transactions from 1 January 2027 — the 2017 circular described here governs any dispute today.

Frequently Asked Questions

Yes — the RBI’s liability framework covers electronic banking transactions broadly, including credit cards, debit cards, mobile banking, and internet banking, across commercial banks, small finance banks, and payment banks.

Genuinely sharing your OTP, PIN, or password with someone, or clearly reckless handling of your credentials — being deceived by a sophisticated, convincing scam is treated as third-party breach, not negligence.

No — the bank must actually establish negligence with evidence; an unsupported assertion doesn’t meet the burden of proof the regulation places on the bank.

Follow up every phone report with a written complaint (email or the bank’s formal complaint channel) as soon as possible — this creates the documented timeline your liability determination depends on.

No — the zero/limited liability principles apply regardless of the transaction amount when the underlying criteria (breach type, reporting timeline) are met.

Each transaction is generally assessed on its own reporting timeline from when you were alerted to it — report every transaction as soon as you become aware of it, rather than waiting to compile a complete list.

Yes — where the bank fails to resolve your complaint within 90 days, you’re entitled to compensation for that delay specifically, separate from the disputed transaction amount.

Bank policies in this area must still be board-approved and transparent — an unreasonable or opaque policy can itself be challenged through the RBI Ombudsman.

Vidyoday
Vidyoday Editorial Team
Cyber Law & Banking Fraud
Reviewed and published by Vidyoday.
Disclaimer:

This article is for general information only and does not constitute legal advice. Liability determinations depend on the specific facts of each case — consult a cyber law lawyer for guidance specific to your situation.

Leave a Comment