RBI notification RBI/DoS/2026-27/412 · 31 Jul 2026
Summary
Check the official recordThe Reserve Bank of India issued new directions for commercial banks to prevent, detect, and report fraud. Banks must establish a Board-approved Fraud Risk Management Policy and a Special Committee of the Board to oversee fraud monitoring. The framework mandates an Early Warning Signal system for credit and non-credit transactions. Banks must adhere to principles of natural justice, including issuing show cause notices and reasoned orders, before classifying any account as fraud. The directions specify reporting thresholds for Law Enforcement Agencies and the Reserve Bank of India. Banks must report fraud incidents within 14 days of classification. These directions replace previous fraud risk management guidelines and take effect immediately.
What you must do
Key dates
Who is affected
Thresholds
Exceptions
If you do not comply
RBI/DoS/2026-27/412 DoS.CO.FMG.6/23.04.001/2026-27 July 31, 2026
These Directions are issued with a view to providing a framework for prevention, early detection, and timely reporting of incidents of fraud by banks to Law Enforcement Agencies (LEAs) and Reserve Bank of India (RBI) and dissemination of information by RBI and matters connected therewith or incidental thereto.
In exercise of the powers conferred under Section 21 and Section 35-A of the Banking Regulation Act, 1949, and all other provisions / laws enabling RBI in this regard, RBI being satisfied that it is necessary and expedient in public interest so to do, hereby issues the Directions hereinafter specified.
For the purpose of these Directions, ‘Commercial Banks’ is the term applied to banking companies (other than Small Finance Banks, Payments Banks, and Local Area Banks), corresponding new banks, and the State Bank of India, as defined respectively under clauses (c), (da), and (nc) of Section 5 of the Banking Regulation Act, 1949.
(1) ‘Central Fraud Registry (CFR)’ is a web-based searchable database maintained by RBI. Fraud related data, including the updates thereof, directly flow to CFR from online reporting by the bank through Fraud Monitoring Returns (FMRs). (2) ‘CRILC’ is the Central Repository of Information on Large Credits as referred to in the Reserve Bank of India (Commercial Banks – Supervisory Returns) Directions, 2026. (3) ‘Date of classification’, for the purpose of reporting under FMR, is the date when due approval from the competent authority has been obtained for such classification, and the reasoned order is passed. (4) ‘Date of detection’ to be reported in FMR, is the actual date when the fraud came to light in the concerned branch / audit / department of the bank, as the case may be, and not the date of approval by the competent authority of the bank. (5) ‘Date of occurrence’, for the purpose of reporting under FMR, is the date when the actual misappropriation of funds has started taking place, or the event occurred, as evidenced / reported in the audit or other findings. (6) 'Red Flagged Account' is one where suspicion of fraudulent activity is thrown up by the presence of one or more Early Warning Signal (EWS) indicators, alerting / triggering deeper investigation from potential fraud angle and requiring initiation of preventive measures by all banks.
In this context, ‘Board’ will refer to ‘Board of Directors’ in case of a domestic bank, and ‘Local Advisory Board’ in case of a Foreign Bank operating in India.
(1) Issuance of a detailed Show Cause Notice (SCN) to the Persons (including Third Party Service Providers and Professionals, inter-alia, architects, valuers, chartered accountants, advocates and other professionals / service providers), Entities and their Promoters / Whole-time and Executive Directors against whom allegation of fraud is being examined. The SCN shall provide complete details of transactions / actions / events basis which declaration and reporting of a fraud is being contemplated under these Directions. As non-whole-time directors (like nominee directors and independent directors) are normally not in charge of, or responsible to the company for the conduct of business of the company, the bank may take this into consideration before proceeding against such directors under these Directions. (2) The bank shall provide a reasonable time of not less than 21 days to the Persons / Entities on whom the SCN was served to respond to the said SCN. (3) The bank shall have a well laid out system for issuance of SCN and examination of the responses / submissions made by the Persons / Entities prior to declaring such Persons / Entities as fraudulent. (4) The bank shall serve a reasoned Order on the Persons / Entities conveying its decision regarding declaration / classification of the account as fraud or otherwise. Such Order(s) must contain relevant facts / circumstances relied upon, the submission made against the SCN and the reasons for classification as fraud or otherwise.
Explanation: The requirement of ensuring compliance to the principles of natural justice is applicable to all Persons / Entities and their Promoters / Whole-time and Executive Directors classified as fraud by the bank. In other words, this requirement is applicable in all cases of fraud classification which may have civil consequences (i.e., penal measures, caution listing) as observed in the Judgement of the Hon’ble Supreme Court dated March 27, 2023 (Civil Appeal No. 7300 of 2022 in the matter of State Bank of India & Ors. Vs. Rajesh Agarwal & Ors.)
The Board shall review the Fraud Risk Management Policy at least once in three years, or more frequently, as may be prescribed by the Board.
Special Committee of the Board for Monitoring and Follow-up of cases of Frauds:
(1) The bank shall constitute a Committee of the Board to be known as ‘Special Committee of the Board for Monitoring and Follow-up of cases of Frauds’ (SCBMF) with a minimum of three members of the Board, consisting of a whole-time director and a minimum of two independent directors / non-executive directors. The Committee shall be headed by one of the independent directors / non-executive directors. (2) SCBMF shall oversee the effectiveness of the Fraud Risk Management in the bank. SCBMF shall review and monitor cases of frauds, including root cause analysis, and suggest mitigating measures for strengthening the internal controls, risk management framework and minimising the incidence of frauds. The Board of the bank shall decide the coverage and periodicity of such reviews. The coverage may include, among others, categories / trends of frauds, industry / sectoral / geographical concentration of frauds, delay in detection / classification of frauds and delay in examination / conclusion of staff accountability. (3) The Board of the bank shall decide the threshold amount of fraud cases to be placed before the SCBMF, after duly taking into account the scale and complexity of its operations.