Customer Liability in Unauthorised Electronic Banking Transactions
Whose fault, and how fast you reported it. Those two facts decide who pays, and the rules change on 1 January 2027.
When money leaves a customer's account through an electronic transaction the customer did not authorise, who bears the loss? RBI answers this with a fixed framework, not case-by-case goodwill. Liability depends on two things: whose fault the fraud was (the bank's, the customer's, or neither) and how quickly the customer told the bank.
This rule is changing. RBI's 2017 framework applies to transactions up to 31 December 2026. A revised framework applies to transactions from 1 January 2027. RBI issued it on 24 June 2026 for commercial banks, with matching directions the same day for small finance, payments, regional rural, local area and co-operative banks. The IIBF courseware (2025 edition) describes the 2017 rules, so learn those first, then the changes.
You save ₹300
- Full 120-question mocks
- Cyber law coverage
- Module-wise practice
One payment, no subscription · Valid for 2 months
The 2017 Framework (Transactions Up to 31 December 2026)
| Situation | Customer's liability |
|---|---|
| Fraud, negligence or deficiency on the bank's part | Zero, whether or not the customer reported it |
| Third-party breach (fault lies elsewhere in the system), reported within 3 working days of the bank's alert | Zero |
| Third-party breach, reported within 4-7 working days | The transaction value or the cap below, whichever is lower |
| Third-party breach, reported after 7 working days | As per the bank's Board-approved policy |
| Customer negligence, such as sharing payment credentials | The entire loss until the customer reports it; the bank bears everything after the report |
Caps for a 4-7 Working Day Delay (2017 Framework)
| Type of account | Maximum liability per transaction |
|---|---|
| Basic Savings Bank Deposit (BSBD) account | ₹5,000 |
| Savings accounts; prepaid instruments and gift cards; current or overdraft accounts of MSMEs; current or overdraft accounts of individuals with annual average balance up to ₹25 lakh; credit cards with limit up to ₹5 lakh | ₹10,000 |
| All other current or overdraft accounts; credit cards with limit above ₹5 lakh | ₹25,000 |
Other 2017 Rules Examiners Like
- check_circleWorking days are counted by the customer's home branch schedule, excluding the day the bank's communication was received.
- check_circleThe bank must credit the amount (a shadow reversal) within 10 working days of the customer's notification, without waiting for any insurance claim.
- check_circleThe complaint must be resolved and liability established within the time in the bank's policy, but not more than 90 days from receipt.
- check_circleThe burden of proving customer liability lies on the bank.
- check_circleCustomers must register for SMS alerts, and SMS alerts must be sent for electronic transactions; banks must offer reporting channels such as a toll-free helpline, website, SMS, email, IVR and the home branch.
Quick practice on banking operations. No signup.
What Changes From 1 January 2027
Third-party breach: zero-liability window
2017 framework
3 working days from the bank's communication
Revised framework
5 calendar days from the date of the transaction
Third-party breach reported late
2017 framework
Capped liability for 4-7 working days, then Board policy
Revised framework
As per the bank's policy
Customer negligence
2017 framework
Defined briefly (e.g. sharing credentials)
Revised framework
Defined in detail, including ignoring the bank's specific scam warnings, downloading malicious apps and not updating a changed mobile number
Bank negligence
2017 framework
Not separately defined
Revised framework
Includes missing mandated security systems, not sending mandatory alerts, no 24x7 reporting channel, not acting on a customer's report, and system failures or internal frauds
Time to decide the complaint
2017 framework
Up to 90 days
Revised framework
Up to 45 calendar days (domestic) or 60 calendar days (cross-border)
Credit card provisional credit
2017 framework
Shadow reversal within 10 working days
Revised framework
Shadow reversal within 5 calendar days
SMS alerts
2017 framework
For all electronic transactions
Revised framework
Mandatory instant SMS above ₹500; email alerts wherever an email is registered
| Point | 2017 framework | Revised framework |
|---|---|---|
| Third-party breach: zero-liability window | 3 working days from the bank's communication | 5 calendar days from the date of the transaction |
| Third-party breach reported late | Capped liability for 4-7 working days, then Board policy | As per the bank's policy |
| Customer negligence | Defined briefly (e.g. sharing credentials) | Defined in detail, including ignoring the bank's specific scam warnings, downloading malicious apps and not updating a changed mobile number |
| Bank negligence | Not separately defined | Includes missing mandated security systems, not sending mandatory alerts, no 24x7 reporting channel, not acting on a customer's report, and system failures or internal frauds |
| Time to decide the complaint | Up to 90 days | Up to 45 calendar days (domestic) or 60 calendar days (cross-border) |
| Credit card provisional credit | Shadow reversal within 10 working days | Shadow reversal within 5 calendar days |
| SMS alerts | For all electronic transactions | Mandatory instant SMS above ₹500; email alerts wherever an email is registered |
New: Compensation Even When the Customer Was Tricked
For transactions from 1 January 2027, a bona fide individual victim (including a sole proprietor) whose loss falls under customer negligence, with a gross loss up to ₹50,000, gets 85% of the net loss or ₹25,000, whichever is less, once in a lifetime. The fraud must be reported both to the bank and on the National Cyber Crime Reporting Portal or 1930 within five calendar days. RBI funds most of it, with the customer's bank and the beneficiary bank sharing the rest. The scheme covers frauds occurring up to one year from its effective date.
How the IIBF Exam Tests This
Expect numeric scenarios: a savings account customer reports a third-party breach on day 5, so what is the maximum liability? (₹10,000 or the transaction value, if lower.) The traps are counting calendar days instead of working days under the 2017 rules, forgetting that bank negligence means zero liability regardless of reporting, and confusing the 10-day shadow reversal with the 90-day resolution limit. The amendment was issued on 24 June 2026, before the 30 June 2026 cut-off IIBF applies to sittings from September 2026 to February 2027, so it can be tested alongside the 2017 rules.
FAQs
What is zero liability in unauthorised electronic transactions?expand_more
Under RBI's rules the customer loses nothing if the fraud was the bank's fault, or if the fault lay elsewhere in the system and the customer reported it in time: within 3 working days under the 2017 rules, or within 5 calendar days for transactions from 1 January 2027.
How many days do I have to report a fraudulent transaction to my bank?expand_more
Report at once. Zero liability for a third-party breach needs a report within 3 working days of the bank's alert under the 2017 rules, and within 5 calendar days of the transaction under the revised rules from 2027. Anything lost after you report is the bank's loss.
Will the bank refund money if I shared my OTP?expand_more
Sharing an OTP is customer negligence, so you bear the loss up to the time you report it. For transactions from 1 January 2027, you may still get a one-time compensation of 85% of the net loss up to ₹25,000, if the loss is up to ₹50,000 and you report to the bank and 1930 within five calendar days.
How long can a bank take to resolve an unauthorised transaction complaint?expand_more
Up to 90 days under the 2017 rules. For transactions from 1 January 2027, up to 45 calendar days for domestic and 60 for cross-border transactions.
Next steps
- UPI Fraudarrow_forward
- Online Banking Fraudarrow_forward
- RBI Fraud Reportingarrow_forward
- Reporting Cyber Crimearrow_forward
120 questions, 2 hours, scored instantly.
