RBI30 Jul 2026master-directionPrepared by Complied AI

Reserve Bank of India (Commercial Banks – Fraud Risk Management) Directions, 2026

RBI/DoS/2026-27/412 DoS.CO.FMG.6/23.04.001/2026-27 July 31, 2026 Reserve Bank of India (Commercial Banks – Fraud Risk Management) Directions, 2026 Table of Contents Chapter I - Preliminary A. Short Title and Commencement B. Applicability C. Definitions Chapter II - Governance and Oversight A. Governance Structure for F…

Source details

Source
Reserve Bank of India
Type
master-direction
Published by source
30 Jul 2026
Coverage area
banking

Document text

Prepared for reading; wording retained from the source.

Verify official record

RBI/DoS/2026-27/412 DoS.CO.FMG.6/23.04.001/2026-27 July 31, 2026

Reserve Bank of India (Commercial Banks – Fraud Risk Management) Directions, 2026

Table of Contents

  • Chapter I - Preliminary
  • Chapter II - Governance and Oversight
  • Chapter III – Early Detection of Frauds - Framework for Early Warning Signals and Red Flagging of Accounts
  • Chapter IV - General Instructions
  • Chapter V - Reporting of Frauds to Law Enforcement Agencies
  • Chapter VI - Reporting to Reserve Bank of India
  • Chapter VII - Cheque Related Frauds - Reporting to Law Enforcement Agencies and Reserve Bank of India
  • Chapter VIII - Other Instructions
  • Chapter IX - Reporting Cases of Theft, Burglary, Dacoity and Robbery
  • Chapter X - Repeal and Other Provisions

Introduction

These Directions are issued with a view to providing a framework for prevention, early detection, and timely reporting of incidents of fraud by banks to Law Enforcement Agencies (LEAs) and Reserve Bank of India (RBI) and dissemination of information by RBI and matters connected therewith or incidental thereto.

In exercise of the powers conferred under Section 21 and Section 35-A of the Banking Regulation Act, 1949, and all other provisions / laws enabling RBI in this regard, RBI being satisfied that it is necessary and expedient in public interest so to do, hereby issues the Directions hereinafter specified.

Chapter I - Preliminary

A. Short Title and Commencement

  1. These Directions shall be called the Reserve Bank of India (Commercial Banks - Fraud Risk Management) Directions, 2026.
  2. These Directions shall come into effect immediately upon issuance.

B. Applicability

  1. These Directions shall be applicable to Commercial Banks (hereinafter collectively referred to as 'banks' and individually as 'bank').

For the purpose of these Directions, ‘Commercial Banks’ is the term applied to banking companies (other than Small Finance Banks, Payments Banks, and Local Area Banks), corresponding new banks, and the State Bank of India, as defined respectively under clauses (c), (da), and (nc) of Section 5 of the Banking Regulation Act, 1949.

C. Definitions

  1. In these Directions, unless the context states otherwise, the terms herein shall bear the meaning assigned to them below: (1) ‘Central Fraud Registry (CFR)’ is a web-based searchable database maintained by RBI. Fraud related data, including the updates thereof, directly flow to CFR from online reporting by the bank through Fraud Monitoring Returns (FMRs). (2) ‘CRILC’ is the Central Repository of Information on Large Credits as referred to in the Reserve Bank of India (Commercial Banks – Supervisory Returns) Directions, 2026. (3) ‘Date of classification’, for the purpose of reporting under FMR, is the date when due approval from the competent authority has been obtained for such classification, and the reasoned order is passed. (4) ‘Date of detection’ to be reported in FMR, is the actual date when the fraud came to light in the concerned branch / audit / department of the bank, as the case may be, and not the date of approval by the competent authority of the bank. (5) ‘Date of occurrence’, for the purpose of reporting under FMR, is the date when the actual misappropriation of funds has started taking place, or the event occurred, as evidenced / reported in the audit or other findings. (6) 'Red Flagged Account' is one where suspicion of fraudulent activity is thrown up by the presence of one or more Early Warning Signal (EWS) indicators, alerting / triggering deeper investigation from potential fraud angle and requiring initiation of preventive measures by all banks.

Chapter II - Governance and Oversight

A. Governance Structure for Fraud Risk Management

  1. The bank shall put in place a Board approved Policy on Fraud Risk Management delineating roles and responsibilities of Board / Board Committees and Senior Management of the bank. The policy shall inter alia contain measures towards prevention, early detection, investigation, staff accountability, monitoring, recovery, and reporting of frauds as well as a framework for Early Warning Signals (EWS) and Red Flagging of Accounts (RFA).

In this context, ‘Board’ will refer to ‘Board of Directors’ in case of a domestic bank, and ‘Local Advisory Board’ in case of a Foreign Bank operating in India.

  1. The Policy shall also incorporate measures for ensuring compliance with principles of natural justice¹ in a time-bound manner, which at a minimum, shall include: (1) Issuance of a detailed Show Cause Notice (SCN) to the Persons (including Third Party Service Providers and Professionals, inter-alia, architects, valuers, chartered accountants, advocates and other professionals / service providers), Entities and their Promoters / Whole-time and Executive Directors against whom allegation of fraud is being examined. The SCN shall provide complete details of transactions / actions / events basis which declaration and reporting of a fraud is being contemplated under these Directions. As non-whole-time directors (like nominee directors and independent directors) are normally not in charge of, or responsible to the company for the conduct of business of the company, the bank may take this into consideration before proceeding against such directors under these Directions. (2) The bank shall provide a reasonable time of not less than 21 days to the Persons / Entities on whom the SCN was served to respond to the said SCN. (3) The bank shall have a well laid out system for issuance of SCN and examination of the responses / submissions made by the Persons / Entities prior to declaring such Persons / Entities as fraudulent. (4) The bank shall serve a reasoned Order on the Persons / Entities conveying its decision regarding declaration / classification of the account as fraud or otherwise. Such Order(s) must contain relevant facts / circumstances relied upon, the submission made against the SCN and the reasons for classification as fraud or otherwise.

Explanation: The requirement of ensuring compliance to the principles of natural justice is applicable to all Persons / Entities and their Promoters / Whole-time and Executive Directors classified as fraud by the bank. In other words, this requirement is applicable in all cases of fraud classification which may have civil consequences (i.e., penal measures, caution listing) as observed in the Judgement of the Hon’ble Supreme Court dated March 27, 2023 (Civil Appeal No. 7300 of 2022 in the matter of State Bank of India & Ors. Vs. Rajesh Agarwal & Ors.)

  1. The Board shall review the Fraud Risk Management Policy at least once in three years, or more frequently, as may be prescribed by the Board.

  2. Special Committee of the Board for Monitoring and Follow-up of cases of Frauds: (1) The bank shall constitute a Committee of the Board to be known as ‘Special Committee of the Board for Monitoring and Follow-up of cases of Frauds’ (SCBMF) with a minimum of three members of the Board, consisting of a whole-time director and a minimum of two independent directors / non-executive directors. The Committee shall be headed by one of the independent directors / non-executive directors. (2) SCBMF shall oversee the effectiveness of the Fraud Risk Management in the bank. SCBMF shall review and monitor cases of frauds, including root cause analysis, and suggest mitigating measures for strengthening the internal controls, risk management framework and minimising the incidence of frauds. The Board of the bank shall decide the coverage and periodicity of such reviews. The coverage may include, among others, categories / trends of frauds, industry / sectoral / geographical concentration of frauds, delay in detection / classification of frauds and delay in examination / conclusion of staff accountability. (3) The Board of the bank shall decide the threshold amount of fraud cases to be placed before the SCBMF, after duly taking into account the scale and complexity of its operations.

  3. The Senior Management shall be responsible for implementation of the fraud risk management policy approved by the Board of the bank. The Senior Management of the bank shall also place a periodic review of incidents of fraud before Board / Audit Committee of Board (ACB), as appropriate.

  4. The bank shall put in place a transparent mechanism to ensure that Whistle Blower complaints on possible fraud cases / suspicious activities in account(s) are examined and concluded appropriately under its Whistle Blower Policy.

  5. The bank shall set-up an appropriate organisational structure for institutionalisation of Fraud Risk Management within its overall risk management functions / department. Fraud Risk Management includes prevention, early detection, investigation, staff accountability, monitoring, recovery, analysis, reporting of frauds and other related aspects under the Board approved Policy. A senior official in the rank of at least a General Manager or equivalent shall be responsible for monitoring and reporting of frauds.

Showing 1,374 of 5,568 words

Research the source law

Find the provision behind this update.

No high-confidence provision match was found. Browse the law library, choose the affected provision and ask against the exact statutory text.

Browse source laws