HomeAnalysisRBI Cyber Fraud Framework Could End Blanket Account Freezes

RBI Cyber Fraud Framework Could End Blanket Account Freezes

The Reserve Bank of India’s proposed cyber fraud framework could change how banks restrict accounts suspected of being linked to cyber fraud or money-mule activity. Instead of automatically stopping all debit transactions in every case, the draft proposes placing a temporary debit hold on the disputed amount wherever that is possible, while allowing the customer to continue using the rest of the account.

The proposal addresses a problem that sits at the intersection of digital banking, financial crime enforcement and household security. A full debit freeze can prevent a customer from accessing salary credited to an account, paying an equated monthly instalment, settling electricity bills or meeting school-fee obligations, even when the investigation concerns only one transaction. The RBI’s draft attempts to create a more proportionate and time-bound process without removing banks’ ability to restrict funds suspected to be connected to fraud.

The framework is contained in a draft amendment to the RBI’s Know Your Customer directions. It proposes a standard operating procedure for banks dealing with suspicious accounts and transactions linked to cyber fraud and money-mule activity. The central bank has invited comments from stakeholders and the public until October 2, 2026. The proposed rules may take effect from April 1, 2027, although banks could choose to implement the standard operating procedure earlier. The final rules will be issued after the feedback is reviewed.

## From account-level restrictions to transaction-level holds

Under the proposal, a bank’s transaction-monitoring system may place a temporary debit hold on a transaction of Rs 1,000 or more if it appears to be connected to cyber fraud or money-mule activity. The threshold does not mean that every transaction of Rs 1,000 or above will be frozen automatically. The bank would assess the transaction pattern, the customer’s profile and other indicators before treating it as suspicious.

The draft also refers to the use of artificial intelligence and machine-learning-based monitoring systems. These systems are expected to help banks identify patterns that may indicate suspicious activity, although the supplied report does not establish how individual banks would design, train or audit those systems. The proposal therefore combines automated detection with a process for reviewing the customer’s explanation and supporting documents.

The most significant operational change is the distinction between disputed funds and the wider account. If a particular transaction is suspected to be connected to cyber fraud, the bank could hold that amount temporarily instead of stopping debit access across the entire account. This would leave the customer with access to other legitimate funds while preserving the disputed amount for investigation.

The draft does not eliminate full-account restrictions. If the bank considers the entire account to be a suspicious money-mule account, it may place a temporary debit hold on the whole account. The proposed approach is therefore not an automatic ban on account-wide action. It is an attempt to match the extent of the restriction to the nature of the suspicion: a disputed transaction where the concern is specific, and the full account where the account itself is considered suspicious.

## A defined opportunity for the customer to respond

The draft also creates a formal response process for customers. Once a temporary debit hold is imposed, the bank would have to inform the customer. The customer would receive 20 days to explain the legitimacy of the transaction or account and submit documents relating to identity, the reason for the transaction or the source of the funds.

If the customer responds, the bank would have to examine the explanation and decide within 10 days of receiving it. If the response is found satisfactory, the bank would have to remove the temporary debit hold immediately and inform the customer. This introduces a specific decision period into a process that can otherwise leave customers uncertain about why their banking access has been restricted.

If the customer does not respond, the bank would have to decide within 30 days from the date on which the temporary debit hold was imposed. Where the explanation is not satisfactory, the bank may continue the hold and refer the matter to the jurisdictional police authority through the National Cybercrime Reporting Portal-Citizen Financial Cyber Fraud Reporting and Management System, or NCRP-CFCFRMS.

The bank would also have to tell the customer why the hold was continued and why the matter was referred to the police authority. This requirement is important because the proposed framework treats communication as part of the process rather than as an optional update after the restriction has already affected the customer’s finances.

## The proposed outer limit on a bank’s action

The RBI draft proposes a maximum period of 60 days for a temporary debit hold when there is no separate direction from a law-enforcement agency or competent authority. This would prevent a bank from keeping a disputed amount under its own temporary restriction indefinitely.

The 60-day limit would not necessarily end the matter if it had already been referred to the police or another competent agency. Further action could follow the directions of that agency. The proposal therefore sets a limit on the bank’s temporary action while leaving room for an investigation to continue under the direction of an authorised authority.

This division of responsibility matters. Banks can identify unusual transactions and restrict access to funds, but a continuing investigation may require police or other agency action. The draft attempts to define the point at which a bank’s initial response must become a documented decision or an inter-agency referral.

## Why the courts have focused on the disputed amount

The RBI’s proposal follows a judicial concern about the consequences of freezing entire bank accounts when the investigation identifies only a specific disputed sum. The report states that the Supreme Court, in an order dated August 4, 2026, directed the RBI to prepare a standard operating procedure for temporary debit holds in cases involving money-mule activity and cyber fraud.

The report also refers to two August and September 2026 directions from the Allahabad High Court. In one matter, the court said that when an investigating agency had identified only a particular amount as disputed, the entire account could not be placed under a debit restriction. The bank was directed to maintain a lien on the disputed Rs 36,000 while allowing the rest of the account to be operated.

In another case in September, the court directed that the disputed amount remain blocked while the account was opened for normal use. At the same time, the court clarified that a new complaint or a direction from an investigating agency could lead to further action in accordance with law.

These directions illustrate the institutional problem the RBI is trying to address. A cyber-fraud investigation requires speed because funds can move quickly between accounts. But a blanket restriction can also impose immediate costs on people whose accounts contain legitimate income and savings. The proposed transaction-level hold is an administrative attempt to preserve both objectives: secure the amount under suspicion while limiting collateral disruption to the customer.

## What changes for banks and customers

For banks, the draft would create a common procedure for identifying suspicious transactions, communicating a hold, assessing customer responses and referring cases to the police. It would also require decisions within specified periods. The use of transaction-monitoring systems, including AI and machine learning, indicates that detection will increasingly rely on automated assessments of transaction patterns and customer profiles.

For customers, the practical change would be the possibility of retaining access to legitimate funds when the concern is limited to one transaction. The customer would also have a defined period to provide documents and an explanation. However, the proposal does not mean that every customer will automatically avoid an account-level hold. A bank may still restrict the entire account if it considers the account itself to be a suspected money-mule account.

The distinction between a disputed amount and a suspicious account will therefore be central to implementation. The draft sets out the proposed process, but the supplied material does not establish how banks will apply the distinction in difficult or borderline cases. Nor does it specify how customers will challenge a decision beyond the bank’s review and referral process.

The proposed framework also places importance on the quality of information available to banks. A customer’s profile, transaction history, identity documents and explanation of the source or purpose of funds may influence whether a hold is removed, continued or referred. That makes timely communication by the bank and a customer’s ability to produce relevant documents important parts of the system.

## The larger urban banking question

Digital banking has become part of the basic operating system of urban households. Salaries, loan repayments, utility payments and school fees increasingly depend on uninterrupted access to bank accounts. When that access is restricted, the effect is not limited to a banking inconvenience; it can interrupt the everyday functioning of a household.

At the same time, cities provide the dense digital and financial networks through which cyber fraud can move rapidly. Banks need mechanisms that can respond quickly to suspicious transfers, while legitimate customers need protection from restrictions that exceed the scope of the investigation. The RBI’s draft recognises this tension by proposing a process that is targeted, reviewable and time-bound.

The evidence supplied establishes that the framework is still only a draft. Its final form will depend on feedback received by October 2, 2026, and the RBI’s review before issuing the final rules. The developments to monitor are whether the transaction-level approach remains in the final directions, how banks distinguish disputed funds from fully suspicious accounts, and whether the proposed timelines and 60-day limit are retained. Until then, the proposal signals a shift away from treating every cyber-fraud-linked account as an all-or-nothing restriction case.


RELATED ARTICLES

Most Popular

Latest News