Banks routinely tell customers that sharing an OTP is contributory negligence and ends the matter. That is not what the RBI framework says.
The RBI framework
The Reserve Bank's directions on limiting liability of customers in unauthorised electronic banking transactions set out a graded structure:
- Zero liability where the loss is due to a contributory fraud, negligence or deficiency on the part of the bank, regardless of whether the customer reported it; and in third-party breach cases where neither the bank nor the customer is at fault, if the customer notifies the bank within three working days.
- Limited liability, capped by account type, where notification is made within four to seven working days.
- Beyond seven working days, liability is as per the bank's board-approved policy.
- Where the customer's own negligence caused the loss, such as sharing credentials, the customer bears the loss until the transaction is reported, and the bank bears it after that point.
The framework also requires banks to reverse the disputed amount within 10 working days of notification, and to resolve the complaint within 90 days.
Everything turns on when you reported it. A phone call to a helpline is not proof. Email the branch and the nodal officer the same day, keep the complaint reference number, and file on the cybercrime portal and helpline 1930 immediately. The written, timestamped record is what decides the liability band.
The escalation
- Written complaint to the bank, and insist on a written response with reasons.
- Escalate to the bank's nodal or principal nodal officer.
- After 30 days without a satisfactory reply, complain to the RBI Ombudsman under the Reserve Bank Integrated Ombudsman Scheme, 2021, through the CMS portal. It is free, needs no lawyer, and covers all RBI-regulated entities under one scheme.
- In parallel or afterwards, a consumer complaint for deficiency in service, which can also claim compensation for mental agony and costs.
What strengthens the case
Evidence that the bank's own systems failed: no SMS or email alert, alerts sent after the transaction, transactions continuing after you reported, or a failure to act on the freeze request. Ask for the transaction logs and the audit trail; the bank's reluctance to produce them is itself telling.