The Reserve Bank of India has introduced draft guidelines to unify how banks handle accounts implicated in cyber frauds, focusing on targeted transaction holds, timely customer notifications, and defined grievance redressal protocols.
- Banks must immediately freeze flagged transactions over ₹1,000 using automated AI tools.
- Temporary holds capped at 60 days without regulatory or court orders.
- Customers have 20 days to respond before escalation to authorities.
What happened
The Reserve Bank of India released a draft proposal establishing uniform standard operating procedures for banks to follow when accounts or transactions are suspected of involvement in cyber fraud. The RBI’s new framework incorporates modern technologies including AI and machine learning to automatically detect suspicious financial activity, particularly transactions above ₹1,000 flagged as potentially linked to money mule accounts.
Under the draft rules, banks must impose immediate temporary holds on only the suspicious transaction amounts instead of freezing entire accounts, except in specific cases. Customers are notified promptly, and a strict timeline governs the duration of holds, customer responses, and potential escalation to law enforcement through designated cybercrime reporting portals.
Why it matters
Cyber fraud continues to cause significant financial losses in India, with recent figures showing tens of thousands of crores lost annually. This regulatory initiative arrives after the Supreme Court mandated the creation of a time-bound, uniform protocol to protect consumers and improve efficiency in fraud management.
By deploying AI-driven transaction monitoring and clearly defining limits on debit holds, the RBI aims to minimize unnecessary account freezes that inconvenience innocent customers while still empowering banks to act swiftly against fraudsters. The framework also strengthens grievance redressal mechanisms by requiring banks to appoint dedicated nodal officers responsible for resolving complaints within 30 days.
What to watch next
The RBI has opened these draft guidelines for public feedback until October 2, 2026, with an anticipated implementation date of April 1, 2027. Banks may adopt the rules earlier if they wish. Financial institutions and technology providers will likely focus on integrating these AI-powered monitoring solutions and adapting operational protocols to comply with the new mandates.
Monitoring how stakeholders respond to the consultation and any changes in the final rules will be important. Additionally, tracking the effectiveness of these measures in reducing cyber fraud losses and improving customer trust will shape future regulatory updates and technology deployments in India’s banking sector.