Legal information notice: this article provides general information and isn't a substitute for advice from a qualified lawyer.
Yes, a bank can refuse compensation for cyber fraud — but only on specific, legally defined grounds, not simply because it prefers not to pay. Understanding exactly what makes a refusal valid versus invalid is genuinely useful before you even file your claim, since it tells you what to expect and what to push back on. Here’s the honest breakdown.
Under the RBI’s liability framework, a bank can only validly deny or reduce compensation on two grounds: proven customer negligence — meaning the bank can actually demonstrate you knowingly shared your OTP, PIN, or password, not simply that fraud occurred — or reporting delay, where you genuinely reported the transaction beyond the 3-day (zero liability) or 7-day (limited liability) windows. Anything outside these two categories is not a legitimate basis for refusal.
A vague reference to “policy” or “risk” isn’t one of the two legitimate grounds — insist on knowing specifically whether the bank is claiming negligence or a reporting delay.
For a negligence claim, ask what specific evidence shows you shared your credentials — for a delay claim, check the bank’s stated timeline against your own records of when you reported.
Your own transaction alert timestamps and complaint records are exactly what determines whether a reporting-delay claim is accurate — don’t take the bank’s stated timeline at face value without checking.
Where the stated ground doesn’t hold up against the evidence, put your challenge in writing, specifically identifying the gap — an unsupported negligence claim, or an inaccurate reporting timeline.
A bank that maintains an unsupported refusal after a specific, evidence-based challenge should be escalated through the RBI’s Complaint Management System.
The most important thing to internalize here: the burden of proof is on the bank, not you. A bank cannot validly refuse compensation simply because it’s plausible you might have been negligent — it must actually demonstrate this with real evidence. If a bank’s refusal reads more like a general policy statement than a specific finding about your case, that’s a strong sign it doesn’t meet the required standard.
Being deceived by a sophisticated scam — a convincing phishing page, a fake customer care call, a fraudster impersonating bank staff — is not the same as negligence, even though you technically took some action (clicking a link, sharing information believing it was legitimate). Banks sometimes conflate “you did something” with “you were negligent,” but the regulation specifically distinguishes deception from carelessness.
Reporting delay is a more objective, factual question than negligence, and it’s worth checking your own records carefully — sometimes a bank’s system shows a delayed complaint-logging time that doesn’t actually reflect when you first called or attempted to report, which is exactly the kind of discrepancy worth raising directly.
| Bank's Stated Reason | Legitimate or Not? |
|---|---|
| Specific evidence you shared your OTP/PIN | Legitimate — if actually proven, not just asserted |
| You reported after 7 working days, with proof | Legitimate — but check the timeline is accurate |
| 'Company policy' or 'high risk' with no specifics | Not legitimate — demand the actual basis |
| You were deceived by a convincing scam | Not negligence — this is third-party breach |
Challenge a refusal directly with your bank first, in writing. Escalate to the RBI Ombudsman if the bank maintains an unsupported denial.
Challenging a refusal with your bank and escalating to the RBI Ombudsman are both completely free.
Most cases where the refusal clearly doesn’t meet either legitimate ground can be challenged and escalated without a lawyer. Legal help becomes valuable where the bank’s evidence is genuinely contested or ambiguous.
Need professional legal help with this?
Find a Lawyer on VidyodayFor the complete liability framework this analysis is based on, see our pillar guide on RBI rules on unauthorized electronic transactions. If you’re at the escalation stage already, our guide on bank refusing refund after cyber fraud covers the step-by-step process to push this forward.
No — the transaction amount alone isn’t a legitimate ground for refusal; the same negligence/reporting-delay analysis applies regardless of the amount involved.
Ask specifically what this means and how it establishes negligence on your part — unusual patterns could just as easily indicate the fraudster’s activity, not evidence of anything you did wrong.
A bank’s board-approved policy can address situations beyond the core RBI framework (like the “beyond 7 days” scenario), but it can’t override the zero/limited liability protections within the framework’s own terms.
Reconstruct your timeline from call logs, app screenshots, or email timestamps — any documentation showing when you first attempted to report strengthens your position against a disputed delay claim.
This alone generally isn’t a valid basis for refusal unless the bank can show this specifically constituted negligence relevant to how the fraud occurred — a vague app-version argument doesn’t meet the evidentiary standard.
Insist on a written decision with reasons — a bank should provide this, and its absence is itself worth raising when you escalate.
A prior unrelated dispute shouldn’t affect the assessment of a current, separate claim on its own merits — each case should be evaluated on its own facts.
This is still worth scrutinising against the same two-ground standard — if there’s no legitimate basis for a reduction, you can push for the full amount rather than accepting a partial settlement.
This article is for general information only and does not constitute legal advice. Whether a specific refusal is valid depends on the actual facts and evidence involved — consult a cyber law lawyer for guidance specific to your situation.