Digital Frauds
RBI OKs compensation mechanism for small-value digital fraud in new norms
This story was originally published at 19:48 IST on 24 June 2026
Register to read our real-time news.Informist, Wednesday, Jun. 24, 2026
--RBI issues norms on limiting customer liability in digital transactions
--RBI: Norms on customer liability in digital transaction effective Jan 1
NEW DELHI – The Reserve Bank of India laid out a mechanism to compensate victims of small-value frauds in digital banking transactions. The central bank said customers may be compensated up to INR 25,000 in frauds with a gross loss amount up to INR 50,000. The mechanism will only be active for the calendar year 2027.
The victim must be an individual and have reported the fraudulent electronic banking transaction to the National Cyber Crime Portal or helpline within five days of its occurrence. The loss has to be established to be bona fide by the customer's bank and the remedy can only be claimed once during the lifetime. The compensation shall be 85% of the loss amount netting out any recoveries either before or after the compensation has been paid, or INR 25,000, whichever is lesser, the RBI said. RBI Governor Sanjay Malhotra had proposed the mechanism on Feb. 6 and the regulator had issued draft norms of Mar. 6 for the same.
For frauds under INR 29,412, the RBI will pay 65% of the compensation amount, with the customer's bank responsible for the remaining 20% in case of a cross-border transaction. The beneficiary bank where the defrauded amount is first credited will pay 10% and the customer bank 10% in the case of a domestic transaction. Where the full compensation amount of INR 25,000 has to be paid, the RBI will pay INR 19,118, over 76% of the due. The remainder will either be paid wholly by the customer bank or split between customer and beneficiary banks, depending on whether the transaction is cross-border or domestic.
"The customer's bank shall, within five calendar days of receipt of the application from a customer, compensate the customer as given above," the RBI said. This was part of the regulator's revised norms on the framework of limiting customer liability in digital transactions, which amended the directions on responsible business conduct of banks. The new norms will be effective Jan. 1, pushed back from the proposed Jul. 1 in the draft.
"The compensation shall be payable for losses incurred on fraudulent EBTs (electronic banking transactions) occurring up to one year from the effective date of these Directions," the revised norms said. "A bank shall retain the records, related to the compensation paid and amount claimed by it for reimbursement under the mechanism for audit, supervision and review purposes, for two years from the date of closure of the compensation mechanism."
The final norms change the definition of electronic banking transactions from the draft and map it to the definition of an electronic funds transfer. These relate to a debit or credit instruction, authorisation or order to a bank through electronic means and cover origination through point-of-sale machines, automated teller machines, and phone and internet banking, among others. However, transfers through cheques do not fall into electronic banking transactions, a clarification that was sought from the draft, the RBI said.
Instead of a wider definition as proposed in the draft, the RBI has given separate definitions for fraudulent transactions, where customer credentials are obtained through fraudulent means. The final norms also clearly define unauthorised transactions which do not have the customer's consent and are caused by a bank's negligence or a third-party breach.
"Transactions involving dispute(s) between a customer and merchant do not fall under the ambit of these Directions," the regulator said in response to a clarification sought during the feedback process.
The central bank has outlined what would constitute negligence by banks and customers, a key factor in determining liability in digital fraud cases. According to the final framework, negligence by banks may include failure to implement mandated security systems, not sending mandatory transaction alerts, not providing channels to report fraud or loss of payment instruments, failure to act promptly after customer notification, or system malfunctions and internal frauds leading to unauthorised electronic banking transactions.
Banks' negligence includes not providing 24X7 channels for reporting fraudulent transactions or the loss of debit or credit cards. Banks must provide multiple such channels, including phone banking, and must provide a number in the transaction alert SMS for customers to voice objections. However, the final norms clarified that banks do not have to provide all possible remedial channels 24X7.
Customer negligence may include not updating their registered mobile number or email address, failing to report fraudulent transactions promptly, ignoring specific warnings issued by banks about possible scams, or failing to exercise reasonable care in usage of credentials like writing down and storing the PIN or downloading malicious apps, the RBI said.
Banks must create a policy to cover aspects or customer protection in electronic banking transfers, the RBI said. They must also put in place a suitable mechanism for monitoring complaints of fraud and periodically report these transactions to the board or one of its committees for review. They will also be required to send email alerts for all electronic banking transactions wherever customers have provided email addresses. Customers availing electronic banking services must provide mobile numbers and, where available, email addresses to the bank.
To improve monitoring and early detection of fraud, the RBI has mandated instant SMS alerts for all electronic banking transactions above INR 500. For transactions up to INR 500, banks may decide whether to send alerts as per their internal policy. Though stakeholders had asked to dilute the policy and allow other modes of notification, the regulator said the SMS route was mandatory and applicable to all categories of customers.
Customers will have access to the compensation mechanism if the fraudulent transaction was their fault. However, losses occurring after the fraud has been reported to the bank will be borne entirely by the bank.
"A customer shall be entitled to zero liability and reversal of the transaction in cases where the fraudulent EBT (electronic banking transactions) occurs due to negligence / deficiency on the part of the bank, irrespective of whether the transaction is reported by the customer or not," the RBI said.
Banks will be required to examine complaints, determine liability and respond to customers within a maximum of 45 calendar days from the date of receiving the complaint, the RBI said. For cross-border transactions, the timeline may stretch to 60 days, the regulator said. This is longer than the 30 days specified in the draft norms. End
Reported by Aaryan Khanna
Edited by Akul Nishant Akhoury
For users of real-time market data terminals, Informist news is available exclusively on the NSE Cogencis WorkStation.
Cogencis news is now Informist news. This follows the acquisition of Cogencis Information Services Ltd. by NSE Data & Analytics Ltd., a 100% subsidiary of the National Stock Exchange of India Ltd. As a part of the transaction, the news department of Cogencis has been sold to Informist Media Pvt. Ltd.
Informist Media Tel +91 (11) 4220-1000
Send comments to feedback@informistmedia.com
© Informist Media Pvt. Ltd. 2026. All rights reserved.
To read more please subscribe


