The Reserve Bank of India’s proposed cyber fraud framework could change how banks restrict customer accounts during investigations. Instead of automatically blocking an entire account when one transaction is suspected to be linked to cyber fraud or money-mule activity, banks may be permitted to place a temporary debit hold on the disputed amount wherever possible.
The proposal addresses a problem that has become increasingly consequential for ordinary account holders: a fraud investigation may protect the banking system, but a blanket debit freeze can also prevent customers from accessing legitimate savings, salaries and funds needed for loan instalments, utility bills and education expenses. The RBI’s draft attempts to separate those two concerns by allowing action against the money under suspicion without necessarily disabling the rest of the account.
The framework is contained in a draft change to the RBI’s Know Your Customer directions. It proposes a standard operating procedure for banks dealing with suspicious accounts and transactions connected with cyber fraud and money-mule activity. The stated objective is to create a common and time-bound process for banks, while reducing avoidable hardship for genuine customers whose accounts become part of an investigation.
## The proposed shift from accounts to transactions
Under the draft, a bank’s transaction-monitoring system may place a temporary debit hold on a transaction of Rs 1,000 or more if it appears suspicious in connection with cyber fraud or money-mule activity. The threshold does not mean that every transaction of Rs 1,000 or above will be frozen automatically. The bank would be expected to assess the transaction using its pattern, the customer’s profile and other indicators before treating it as suspicious.
The proposal also refers to the use of artificial intelligence and machine-learning-based monitoring systems. These tools would be part of the bank’s process for identifying unusual transactions, although the supplied material does not establish how individual banks would design, validate or review those systems.
The most important operational distinction is between a disputed transaction and an account that is itself considered suspicious. If the concern relates to a specific transfer, the proposed approach would allow the bank to hold that amount temporarily while leaving other legitimate funds available for use. If the entire account is assessed as a suspected money-mule account, the draft would still permit a temporary debit hold on the full account.
This is not a complete prohibition on account freezes. Rather, it establishes a graduated response in which the extent of the restriction is linked to the nature of the suspicion. That distinction matters because a customer may be connected to a disputed transaction without the entire balance being connected to the alleged fraud.
## RBI cyber fraud framework adds a response window
The draft also proposes a formal opportunity for the customer to explain the transaction or account activity. Once a temporary debit hold is imposed, the bank would have to inform the customer. The customer would then receive 20 days to submit an explanation and provide documents relating to identity, the purpose of the transaction or the source of the funds.
If the customer responds, the bank would have to examine the explanation and decide within 10 days of receiving it. If the response is satisfactory, the temporary debit hold would have to be removed immediately and the customer informed of the decision.
If the customer does not respond, the bank would have to reach a decision within 30 days from the date on which the temporary debit hold was imposed. Where the explanation is not considered satisfactory, the bank could continue the hold and refer the matter to the police authority with jurisdiction through the National Cybercrime Reporting Portal and Citizen Financial Cyber Fraud Reporting and Management System, or NCRP-CFCFRMS.
The bank would also have to inform the customer why the hold was continued and why the matter was referred to the police authority. This creates a procedural sequence where the customer is not merely told that an account has been restricted but is given a defined period to establish the legitimacy of the transaction or funds.
The draft proposes a maximum period of 60 days for a temporary debit hold when there is no separate direction from a law-enforcement agency or competent authority. If the matter is referred to the police or another competent authority, subsequent action could follow their instructions. The proposed limit is intended to prevent a bank-level restriction from continuing indefinitely without further institutional action.
## Court interventions shaped the proposal
The RBI’s draft follows judicial scrutiny of full-account debit freezes in cyber fraud cases. According to the supplied report, the Supreme Court directed the RBI in an order dated 4 August 2026 to prepare a standard operating procedure for temporary debit holds in cases involving money-mule activity and cyber fraud.
The Allahabad High Court also addressed the issue in August 2026. In one case, where the investigating agency had identified only a specific disputed amount, the court directed the bank to maintain a lien over Rs 36,000 while allowing the rest of the account to operate. In another matter in September, the court directed that the disputed amount be held while the account was opened for normal use.
The court’s approach, as described in the report, does not prevent future action. If a new complaint is received or an investigating agency issues further directions, the account may again be dealt with according to law. The principle is narrower: the restriction should correspond to the amount and nature of the matter identified at that stage of the investigation.
This judicial context explains why the RBI proposal is not simply a banking technology measure. It is also an attempt to establish an administrative boundary between financial crime control and the customer’s ability to use undisputed funds. Banks need to act quickly when suspicious money moves through the system, but the response must also identify what is actually under suspicion and who has authority to extend the restriction.
## A common process for banks
At present, the practical consequences of a cyber fraud flag can be significant for customers. A full debit restriction may affect salary credits already received, scheduled loan repayments, electricity bills, school fees and everyday payments. The draft’s transaction-specific approach is designed to reduce that disruption where the bank can isolate the disputed amount.
The proposal also seeks to make banks follow comparable timelines. The 20-day customer response period, the 10-day decision period after a response and the 30-day outer period where there is no response are intended to prevent cases from remaining unresolved solely at the bank’s level. The 60-day maximum for a temporary hold, subject to directions from law-enforcement or competent authorities, adds another boundary to the process.
However, the effectiveness of these safeguards would depend on how banks classify transactions, communicate with customers and assess documents. The source material does not provide operational details on the evidence required in different cases, the internal review structure at banks or the method for handling disputes over an automated alert. It also does not establish how quickly customers would regain access after a bank decides that their explanation is satisfactory beyond the draft’s requirement that the hold be removed immediately.
The reference to artificial intelligence and machine learning adds another institutional question. Automated monitoring may help banks identify suspicious patterns at scale, but the proposed framework places the immediate consequence—a debit hold—within a process that still needs customer notification, document review and a reasoned decision. The draft, as described, therefore combines automated detection with human and institutional review rather than treating an automated alert as proof of fraud.
## The policy is not yet final
The proposed framework remains a draft. The RBI has invited comments from stakeholders and the public until 2 October 2026. The proposed rules may come into effect from 1 April 2027, although individual banks could decide to implement the standard operating procedure earlier. The final rules will be issued after the feedback is reviewed.
That consultation period is important because the framework will determine how banks balance speed, customer access and investigative requirements. A system that is too slow to hold suspected proceeds may allow money to move further through the financial network. A system that is too broad or too difficult to challenge may impose the costs of investigation on customers whose remaining funds are unrelated to the disputed transaction.
The draft’s central idea is therefore one of proportionality: hold the amount that is linked to the suspicion where that link can be identified, and use a full-account restriction where the account itself is considered suspicious. The approach does not remove the role of police agencies or other competent authorities. It sets out how a bank-level restriction could operate before, or while awaiting, further directions.
For customers, the proposed change would mean that a cyber fraud investigation need not automatically cut off access to every rupee in an account. It would also create a formal opportunity to provide documents and a schedule for the bank to decide what happens next. For banks and investigators, the framework would require faster classification, clearer communication and closer alignment between transaction-level evidence and the restriction imposed.
The next steps are the public consultation ending on 2 October 2026, the RBI’s review of feedback and the possible implementation of final rules from 1 April 2027. Until the final framework is issued, the proposed transaction-specific hold, customer response window and 60-day limit remain draft provisions rather than settled rights for account holders.

