What Changed
RBI's circular on limiting customer liability in unauthorised electronic banking transactions sets out zero-liability, limited-liability and full-liability scenarios depending on where the fault lies and how quickly the customer reports the transaction. It also places clear obligations on banks: prompt notification to customers of transactions, and defined timelines for provisional credit once a complaint is raised.
Why It Matters
The liability outcome for any individual case is only as fair — and as fast — as the bank's ability to establish, quickly, whether a transaction was genuinely unauthorised. That determination depends directly on fraud monitoring and investigation capability, not on the liability policy document itself.
Who Is Impacted
Scheduled commercial banks, Regional Rural Banks, Small Finance Banks and Payments Banks are all directly covered; customer-facing fraud, disputes and grievance-redressal teams are the functions most exposed operationally.
What Institutions Should Review
- Whether customer transaction alerts (SMS/app/email) are sent promptly enough to start the customer's own reporting clock as early as possible.
- Whether the provisional-credit timeline is consistently met once a complaint is logged, and whether that is tracked as an SLA.
- How quickly fraud investigation teams can distinguish 'unauthorised' from 'authorised but manipulated' transactions — the two are decided very differently under the framework.
- Whether dispute and fraud-case data feed a common record, so a customer does not have to repeat their case to two different teams.
What This Means for FRM Technology and Controls
This connects customer protection with fraud prevention capability directly: an FRM platform that can rapidly reconstruct a transaction's context — device, location, authentication method, prior behaviour — shortens the time to a liability determination and materially improves the customer experience around a fraud incident, independent of the underlying loss outcome.
Liability determination speed is itself a control worth measuring. A bank that can conclusively establish 'unauthorised' vs. 'authorised' within hours, backed by device and behavioural evidence, meets both the letter of the customer-protection framework and the spirit of it.
Sources & References
External links open in a new tab. RBI is used as the primary source wherever an RBI regulation or direction is discussed; NPCI and MHA/I4C are used where directly applicable. A third-party article is never used as the principal source where the official circular or direction is available.