The bank is quoting one paragraph of the rule and leaving out three. The Reserve Bank's circular of 6 July 2017, "Customer Protection - Limiting Liability of Customers in Unauthorised Electronic Banking Transactions", does treat sharing credentials as customer negligence. It also says the bank must prove it, that your liability stops the moment you report, and that the bank carries the loss in full where its own systems fell short. Which of those governs your case depends on facts the bank has and you do not, which is why the first move is a written demand for them.
What does the RBI circular actually say about sharing an OTP?
The three limbs of the 2017 circular. Paragraph 6 gives a customer zero liability where the loss arises from contributory fraud, negligence or deficiency on the part of the bank, whether or not the customer reported it, and in a third-party breach where the deficiency lies neither with the bank nor with the customer, provided the customer notifies the bank within three working days of receiving the bank's communication about the transaction. Paragraph 7 provides that where the loss is due to negligence by a customer, "such as where he has shared the payment credentials, the customer will bear the entire loss until he reports the unauthorised transaction to the bank. Any loss occurring after the reporting of the unauthorised transaction shall be borne by the bank." Paragraph 12 provides that "the burden of proving customer liability in case of unauthorised electronic banking transactions shall lie on the bank."
Three further paragraphs matter because banks breach them regularly. Paragraph 5 requires the bank to send SMS alerts for every electronic transaction, to let you object by replying to the alert, to give round-the-clock reporting channels, to acknowledge your report immediately with a complaint number, and to log the date and time its alert reached you and your response reached it, which the circular says "shall be important in determining the extent of a customer's liability". Paragraph 9 requires a shadow credit of the disputed amount within ten working days of your report. Paragraph 10 requires the complaint to be resolved and your liability, if any, established within ninety days, failing which the bank pays the compensation anyway.
Is being tricked into reading out an OTP "negligence"?
This is the contested point, and I will not pretend it is settled. The 2017 circular does not define negligence. Its only illustration is sharing payment credentials, and a bank will say that reading an OTP to a caller is exactly that. The reply is that the same document puts the burden on the bank, so the bank must show, with its own logs, that the OTP was generated for that transaction, was delivered to your registered number, and was then keyed in by the fraudster, and that no alert, fraud filter or velocity check on its side failed. A bank that cannot produce those logs has not discharged paragraph 12, and the question of what you said on a call never arises.
The Bombay High Court applied that method in a judgment of 6 April 2026 in Subodh C. Korde v Union of India, Writ Petition 11990 of 2023. The facts were a SIM swap rather than a shared OTP, and the customer had shared nothing, but the reasoning is the one to borrow: the bank asserted it had sent OTPs, could not place a single original alert log before the court, and its own investigation showed the fraudulent logins came from a different IP than the customer's genuine transactions. The court held the bank had failed to prove negligence, found the customer entitled to zero liability, and directed the refund with interest. Where you did read out the OTP, the argument is harder and the outcome turns on the bank's other failures, so build the written record around those.
One date to know. The Reserve Bank issued amended directions on 24 June 2026 which apply to transactions on or after 1 January 2027. They expressly list, as customer negligence, "providing credentials for carrying out transactions to another person, whether intentionally or otherwise". For transactions after that date the deception argument gets weaker. The same directions widen the bank's duties, define bank negligence to include not sending mandatory alerts and not acting diligently on a report, cut the complaint deadline to 45 days for domestic transactions, and introduce a one-time compensation for small-value frauds up to Rs 50,000, at 85 per cent of the net loss or Rs 25,000, whichever is lower, provided you reported on the portal or 1930 and to the bank within five calendar days. For a transaction today, the 2017 circular still governs.
What should my written complaint say?
- The date and time you first reported, with the complaint number and the 1930 or cybercrime.gov.in acknowledgement
- A demand that the bank state, in writing, the paragraph of the circular it relies on and the evidence for it, citing paragraph 12
- A request for the alert dispatch log for the transaction, with delivery time stamps, the device and IP details recorded against each debit, and whether its fraud detection system flagged anything
- A request for the shadow credit under paragraph 9, ten working days from your report
- A note that under paragraph 10 the complaint must be resolved within ninety days
- A request for the bank's board-approved customer protection policy, which paragraph 7 requires it to give you at account opening and display publicly
Where do I escalate?
- The bank's grievance cell, then its nodal or principal nodal officer, in writing, insisting on a reasoned reply rather than a call.
- The RBI Ombudsman under the Reserve Bank Integrated Ombudsman Scheme, 2026, in force from 1 July 2026. File after thirty days without a satisfactory reply, and within ninety days of the reply or of that period expiring, online at cms.rbi.org.in. It is free, there is no ceiling on the amount in dispute, compensation for consequential loss can reach Rs 30 lakh with a further Rs 3 lakh for time and harassment, and an FIR is not treated as the same grievance. An advocate cannot represent you unless the advocate is the victim.
- A consumer complaint for deficiency in service under the Consumer Protection Act, 2019, before the District Commission for claims up to Rs 50 lakh, filed where you reside under Section 34(2)(d), within two years under Section 69(1). It can carry compensation and costs alongside the refund.
Run the criminal track in parallel. The caller committed cheating by personation using a computer resource under Section 66D of the Information Technology Act, 2000, and cheating under Section 318(4) of the Bharatiya Nyaya Sanhita, 2023. Our guide on UPI and bank fraud under the RBI rules walks through each band, and the answer on choosing between the Ombudsman and the consumer commission explains the sequence.
Where these complaints actually turn
In my experience the case is won or lost on one request: show me the logs. Banks decline hundreds of these disputes with a form letter saying the customer "must have shared the OTP", and most cannot produce a delivery record when a written demand citing paragraph 12 arrives, because the alert went out from a vendor's system and nobody kept the receipt. Do not argue about what you said on the call. Ask what the bank can prove, in writing, and let the ninety-day clock run against it. The related answer on UPI used without your knowledge deals with the cleaner case where nothing was shared at all.