Legal information notice: this article provides general information and isn't a substitute for advice from a qualified lawyer.
Whatever specific type of banking fraud has happened to you — a single unauthorized UPI transfer, a cloned card, a compromised net banking login, a whole string of transactions in one night — one regulation ultimately decides whether the bank has to give your money back: the RBI’s framework on customer liability for unauthorized electronic banking transactions. This is the complete, authoritative breakdown of exactly how it works.
Under the RBI’s circular “Customer Protection — Limiting Liability of Customers in Unauthorised Electronic Banking Transactions” (dated 6 July 2017, and still the governing framework as of this writing), your liability for an unauthorized electronic transaction falls into exactly one of three categories, determined by two things: who caused the breach, and how quickly you reported it.
You owe nothing — the bank must credit the full amount back — in two situations. First, where the transaction resulted from a deficiency or negligence on the bank’s own side (a system failure, inadequate security, an internal breach), regardless of when you reported it. Second, where it was a genuine third-party breach — meaning neither you nor the bank was at fault, such as a sophisticated phishing or vishing scam — and you reported it to the bank within 3 working days of receiving the transaction alert.
If you report a genuine third-party breach between 4 and 7 working days after the alert, your liability is capped — generally somewhere between ₹5,000 and ₹25,000 depending on your specific account or card type, rather than the full transaction amount. Beyond 7 working days, your liability reverts to whatever your bank’s own board-approved customer protection policy specifies, which can mean bearing the full loss.
Was this a bank system failure, a scam where you were deceived (third-party breach), or did you knowingly share your OTP/PIN/password (genuine negligence)? This classification is what everything else depends on.
The clock starts from when you received the bank’s transaction alert (SMS/email/app notification), not from when the transaction actually happened — check your alert timestamps carefully.
This is the single most important, most overlooked detail: the burden of proving you were negligent lies with the bank, not with you. You don’t need to prove your innocence; the bank needs to prove your fault.
The bank is required to credit the disputed amount to your account within 10 working days of your complaint, even before the full investigation concludes — this isn’t optional or discretionary on the bank’s part.
If your bank takes longer than 90 days to fully resolve your complaint, you’re entitled to compensation for the delay, separate from the underlying disputed amount itself.
The burden-of-proof rule deserves real emphasis because it’s so often misunderstood or quietly ignored in practice: banks sometimes act as though the customer must demonstrate they weren’t negligent, when the regulation places that burden squarely on the bank. If your bank denies a claim by simply asserting negligence without concrete evidence, this is worth challenging directly — an unsupported assertion isn’t proof.
Courts have reinforced this customer-protective stance. The Supreme Court has held that banks must use the best available technology to detect and prevent unauthorised transactions — meaning a bank can’t simply point to a customer’s action as the sole cause of fraud while ignoring its own responsibility to run adequate fraud-detection systems in the first place.
A change is coming, but not yet: the RBI’s 2025 Directions (under the broader “Responsible Business Conduct” framework) will eventually replace this 2017 circular with an updated regime — but this only applies to transactions from 1 January 2027 onward. Until then, the framework described here remains the governing law for any dispute you’re facing today.
| Situation | Your Liability |
|---|---|
| Bank's own negligence/system failure | Zero — regardless of when you report |
| Genuine third-party breach, reported within 3 working days | Zero |
| Genuine third-party breach, reported in 4-7 working days | Limited — capped, typically ₹5,000-₹25,000 |
| Reported beyond 7 working days | Your bank's own board-approved policy applies |
| Genuine customer negligence (knowingly shared OTP/PIN) | Full liability until reported, then bank's policy applies |
Report to your bank directly through its app, net banking, branch, or helpline. Escalate unresolved or wrongly denied claims to the RBI’s Complaint Management System (Banking Ombudsman).
Filing a complaint with your bank and escalating to the RBI Ombudsman are both completely free.
Most cases where the facts are clear and reported promptly can be handled directly with the bank and, where necessary, the RBI Ombudsman. A lawyer becomes valuable specifically where the bank disputes the facts, denies a well-documented claim, or the amount involved is substantial.
Need professional legal help with this?
Find a Lawyer on VidyodayFor the specific process depending on exactly what happened to you, see our guides on unauthorized IMPS transactions, unauthorized NEFT/RTGS transfers, and internet banking fraud. If your bank has already denied your claim, our guide on can a bank refuse compensation for cyber fraud breaks down valid versus invalid grounds for refusal.
Yes — the RBI’s liability framework covers electronic banking transactions broadly, including credit cards, debit cards, mobile banking, and internet banking, across commercial banks, small finance banks, and payment banks.
Genuinely sharing your OTP, PIN, or password with someone, or clearly reckless handling of your credentials — being deceived by a sophisticated, convincing scam is treated as third-party breach, not negligence.
No — the bank must actually establish negligence with evidence; an unsupported assertion doesn’t meet the burden of proof the regulation places on the bank.
Follow up every phone report with a written complaint (email or the bank’s formal complaint channel) as soon as possible — this creates the documented timeline your liability determination depends on.
No — the zero/limited liability principles apply regardless of the transaction amount when the underlying criteria (breach type, reporting timeline) are met.
Each transaction is generally assessed on its own reporting timeline from when you were alerted to it — report every transaction as soon as you become aware of it, rather than waiting to compile a complete list.
Yes — where the bank fails to resolve your complaint within 90 days, you’re entitled to compensation for that delay specifically, separate from the disputed transaction amount.
Bank policies in this area must still be board-approved and transparent — an unreasonable or opaque policy can itself be challenged through the RBI Ombudsman.
This article is for general information only and does not constitute legal advice. Liability determinations depend on the specific facts of each case — consult a cyber law lawyer for guidance specific to your situation.