NEWS

RBI proposes to freeze only disputed amounts in cyber fraud cases

RBI proposes a framework which will enable banks to temporarily freeze only the amount under suspicion of being potentially linked to cyber fraud, and not the entire account.

The Reserve Bank of India (RBI) has proposed a framework which will enable banks to temporarily freeze only the amount under suspicion of being potentially linked to cyber fraud, and not the entire account.

The process could be triggered when a bank’s transaction-monitoring system flags a suspected money-mule transaction of Rs 1,000 or more. The bank then can place a temporary debit hold on the amount.

Banks can use artificial intelligence and machine-learning tools to identify transactions that are unusual or disproportionate to the customer’s declared profile, or linked to a known cyberfraud network.

The proposal follows a Supreme Court order dated 4 August 2026, directing the central bank to prescribe and circulate a standard operating procedure for temporary debit holds on amounts or accounts linked to money-mule activity and cyber-enabled financial fraud.

The proposed framework seeks to replace the drastic approach of freezing an entire account with a more targeted and time-bound approach. An account-level restriction should be used only in exceptional circumstances and as a last resort.

Customers will be given 20 days from the date of the temporary debit hold to submit an explanation or justification. They will need to establish the legitimacy of a transaction by providing proof of identity, details of its context or documents showing the source of the funds.

The bank will have 10 days to assess the explanation and supporting evidence. If the bank is satisfied that the transaction is genuine, the freeze will have to be lifted immediately.

If the customer fails to respond within 20 days or the explanation does not dispel the suspicion of cyber fraud, the bank will refer the matter to the jurisdictional police or competent law-enforcement authority through the National Cybercrime Reporting Portal (NCRP)/Citizen Financial Cyber Fraud Reporting and Management System (CFCFRMS).

The bank will also have to tell the customer why the hold was being continued and why the case had been referred.

Banks cannot simply keep the funds frozen indefinitely. Once the matter is referred, law enforcement will have a further window to issue a statutory restraint order or other instructions. 

If a law-enforcement agency or competent authority directs the bank to continue the restriction, the bank will have to comply. But if no such instruction is received within 30 days of the referral, the bank will have to remove the debit hold on the 31st day.

Overall, the temporary debit hold cannot continue beyond 60 days from the date it was first imposed, unless a competent authority directs otherwise.

The draft directions are open for public comments until 2 October and are proposed to take effect from 1 April 2027. Individual banks can, however, adopt the framework earlier.