Banks routinely tell customers that sharing an OTP is contributory negligence and ends the matter. That is not what the RBI framework says.
The RBI framework
The Reserve Bank's directions on limiting liability of customers in unauthorised electronic banking transactions set out a graded structure:
- Zero liability where the loss is due to a contributory fraud, negligence or deficiency on the part of the bank, regardless of whether the customer reported it; and in third-party breach cases where neither the bank nor the customer is at fault, if the customer notifies the bank within three working days.
- Limited liability, capped by account type, where notification is made within four to seven working days.
- Beyond seven working days, liability is as per the bank's board-approved policy.
- Where the customer's own negligence caused the loss, such as sharing credentials, the customer bears the loss until the transaction is reported, and the bank bears it after that point.
The framework also requires banks to reverse the disputed amount within 10 working days of notification, and to resolve the complaint within 90 days.
The limited liability band is capped in money terms, and the caps are low: broadly Rs 5,000 for a basic savings bank deposit account, Rs 10,000 for ordinary savings accounts, prepaid instruments, small enterprise current accounts and credit cards within the specified limit, and Rs 25,000 for larger current, cash credit and overdraft accounts and higher limit cards. Take the exact figure and account category from the current directions before conceding anything, because banks sometimes apply the highest band to an account that does not belong in it.
The directions say in terms that the burden of proving customer liability in an unauthorised electronic banking transaction lies on the bank. You do not have to prove you were not negligent. The bank has to prove that you were, and it has to do so with evidence rather than with an assumption drawn from the fact that a one time password was used. Put that in the first written complaint, and ask the bank to state what evidence it relies on.
Two further requirements matter because banks breach them regularly. Banks must register customers for SMS alerts, and email alerts where available, and must let a customer respond by replying to the alert rather than hunting for a web page. They must also provide round the clock access through multiple channels for reporting an unauthorised transaction. If no alert reached you, or it arrived after the money left, or the reporting channel did not work, that is a deficiency on the bank's own side, which takes the case into the zero liability limb regardless of when you reported. Our guide to recovering money lost to UPI and bank fraud under the RBI rules works through how each limb is argued.
Everything turns on when you reported it. A phone call to a helpline is not proof. Email the branch and the nodal officer the same day, keep the complaint reference number, and file on the cybercrime portal and helpline 1930 immediately. The written, timestamped record is what decides the liability band.
The escalation
- Written complaint to the bank, and insist on a written response with reasons.
- Escalate to the bank's nodal or principal nodal officer.
- After 30 days without a satisfactory reply, complain to the RBI Ombudsman under the Reserve Bank Integrated Ombudsman Scheme, 2021, through the CMS portal. It is free, needs no lawyer, and covers all RBI-regulated entities under one scheme.
- In parallel or afterwards, a consumer complaint for deficiency in service, which can also claim compensation for mental agony and costs.
The first hours matter more than the first weeks
Money moved by fraud is layered through mule accounts quickly, so recovery usually depends on a freeze reaching the beneficiary bank before the balance is withdrawn. Report on the cyber crime helpline 1930 and on the reporting portal at once, giving the beneficiary account or UPI handle, the transaction references, the times and the amounts. That report generates an acknowledgment number, which is itself a dated record of when you first complained. Change your credentials, but do not close the account, because the statement and the alert history are your evidence. Our note on recovering money lost to online fraud covers the parallel police track.
What strengthens the case
Evidence that the bank's own systems failed: no SMS or email alert, alerts sent after the transaction, transactions continuing after you reported, or a failure to act on the freeze request. Ask for the transaction logs and the audit trail; the bank's reluctance to produce them is itself telling.
Ask for named records rather than for the file: the transaction log with timestamps, the device and IP details recorded against each transaction, the alert dispatch log, and the internal investigation report. Where the transactions came from a device that was never yours, the bank's own logs prove it, which is why the request is resisted. Rapid transfers to newly added beneficiaries, at an hour the account has never been used, are also exactly what a monitoring system is meant to catch, and a bank that failed to flag them is poorly placed to call the customer careless.
If the escalation fails
The Ombudsman is free and needs no lawyer, but a consumer commission can award compensation for harassment and costs alongside the refund. Our guide on how to file a consumer complaint covers the pleading. Either way the annexures are the same: the statement showing the debits, the dated complaint to the bank, the cyber crime acknowledgment, and the alert history.