RBI notification RBI/2026-27/171 · 24 Jun 2026
Official title
Reserve Bank of India (Regional Rural Banks - Responsible Business Conduct) Third Amendment Directions, 2026
Summary
Check the official recordThe Reserve Bank of India updates instructions for Regional Rural Banks regarding customer protection in fraudulent electronic banking transactions. Regional Rural Banks must formulate a policy for customer protection, implement fraud detection, and provide 24x7 reporting channels. Banks must send instant SMS alerts for transactions exceeding ₹500. The policy establishes liability frameworks where banks bear losses for their own negligence or third-party breaches reported within five days. A compensation mechanism for small value fraudulent transactions up to ₹50,000 is introduced for bona fide victims. These directions apply to electronic banking transactions undertaken on or after January 1, 2027.
What you must do
Key dates
Who is affected
Thresholds
If you do not comply
RBI/2026-27/171 DOR.MCS.REC.No.134/01-01-036/2026-27 June 24, 2026
Reserve Bank of India (Regional Rural Banks - Responsible Business Conduct) Third Amendment Directions, 2026
Instructions on ‘Customer Protection - Limiting Liability of Customers in Unauthorised Electronic Banking Transactions’ for Regional Rural Banks (hereinafter referred to collectively as “RRBs” and individually as an “RRB”) have been consolidated in the Reserve Bank of India (Regional Rural Banks – Responsible Business Conduct) Directions, 2025. On a review, it has been decided to issue revised instructions on the subject.
In exercise of the powers conferred by Section 35A of the Banking Regulation Act, 1949, the Reserve Bank, being satisfied that it is necessary and expedient in public interest so to do, hereby issues the Amendment Directions hereinafter specified.
Short Title and Commencement
(1) These Directions shall be called the Reserve Bank of India (Regional Rural Banks - Responsible Business Conduct) Third Amendment Directions, 2026.
(2) These Directions shall apply in cases of electronic banking transactions undertaken by customers of an RRB on or after January 1, 2027.
(1) In paragraph 4, the following definitions shall be inserted after sub-paragraph 4(6A), namely:
“4(6.1A) Card Not Present transaction shall have the same meaning as given in the Reserve Bank of India (Authentication Mechanisms for Digital Payment Transactions) Directions, 2025.
4(6.1B) Card Present transaction shall have the same meaning as given in the Reserve Bank of India (Authentication Mechanisms for Digital Payment Transactions) Directions, 2025.”
(2) In paragraph 4, the following definition shall be inserted after sub-paragraph 4(10C), namely:
“4(10D) Electronic banking transaction (EBT) shall have the same meaning as ‘electronic funds transfer’ given in Section 2(c) of the Payment and Settlement Systems Act, 2007 and inter alia include both Card Not Present and Card Present transactions.”
(3) In paragraph 4, the following definition shall be inserted after sub-paragraph 4(15), namely:
“4(15A) Fraudulent electronic banking transaction (Fraudulent EBT) means an EBT executed by a third-party using the credentials obtained from the customer through fraudulent means or executed by the customer by granting approval under coercion or duress from the third-party, and / or an unauthorised EBT as defined at paragraph 4(26B) below.”
(4) In paragraph 4, the following definitions shall be inserted after sub-paragraph 4(20A), namely:
“4(20B) Negligence by a customer inter alia includes the following actions by the customer:
(i) failing to exercise reasonable care in usage of credentials such as PIN, password, OTP or other details (e.g., providing credentials for carrying out transactions to another person, whether intentionally or otherwise, writing down and storing the PIN with a debit / credit card, etc.); or
(ii) not notifying the RRB promptly after finding out about a fraudulent EBT, or loss of a debit / credit card; or
(iii) not paying attention to specific, directed and clear warnings from the RRB that a prospective transaction is likely a scam; or
(iv) downloading malicious apps; or
(v) failing to update her / his registered mobile number / email address with the RRB in case of change.
4(20C) Negligence by an RRB inter alia includes the following actions by the RRB:
(i) not putting in place the mandated systems and procedures to ensure safety and security of EBTs; or
(ii) not sending mandatory alerts for EBTs; or
(iii) not providing 24x7 channels for reporting of fraudulent EBTs or loss of debit / credit card; or
(iv) not acting diligently upon a customer notification regarding unauthorised EBT(s) or loss of debit / credit card; or
(v) system malfunctions / security breaches / internal frauds leading to unauthorised EBTs.”
(5) In paragraph 4, the following definition shall be inserted after sub-paragraph 4(25), namely:
“4(25A) Shadow reversal means the temporary / provisional credit, of the amount involved in fraudulent EBT(s), provided by an RRB to a customer on receipt of notification from the customer, before the completion of internal investigation or settlement of insurance claim, if any, or any other settlement to be made with other parties. While the customer shall not be allowed to use such amount, he / she will not bear any additional burden of interest / charges.”
(6) In paragraph 4, the following definition shall be inserted after sub-paragraph 4(26), namely:
“4(26.1A) Third-party breach means a situation where the deficiency lies neither with the RRB nor with the customer but lies elsewhere in the system and includes deficiency on the part of an intermediary such as a Third-Party Application Provider (TPAP), Payment Aggregator (PA), Payment Gateway (PG), Telecom Service Provider (TSP), etc.”
(7) In paragraph 4, the following definition shall be inserted after sub-paragraph 4(26A), namely:
“4(26B) Unauthorised electronic banking transaction (Unauthorised EBT) means an EBT which is not authorised by a customer and inter alia includes an EBT occurring on account of negligence by an RRB and / or a third-party breach.”
(8) In Chapter IV on ‘Customer Guidance and Protection’, the section E. Customer Protection – Limiting Liability of Customers in Unauthorised Electronic Banking Transactions and paragraphs 116 to 128 thereunder shall be deleted and substituted with the following section and paragraphs, namely:
“EA. Customer Protection in Fraudulent Electronic Banking Transactions
EA.1 Policy
128A. An RRB, keeping in view the instructions contained in these Directions, shall formulate a policy to cover aspects of customer protection in EBTs, such as:
(1) channels for alerting customers about occurrence of EBTs and reporting of fraudulent EBTs;
(2) define the rights and obligations of customers in case of EBTs, including fraudulent EBTs, after taking into account the risks to customers arising out of customer negligence / RRB negligence / banking system frauds / third-party breaches in specified scenarios;
(3) timeline for resolution of complaints and disclosure to customer; and
(4) mechanism for creating customer awareness on their rights and obligations in EBTs along with the risks involved.
The policy must be transparent, non-discriminatory and shall be displayed on the RRB’s website along with the details of grievance handling / escalation procedure.
128B. An RRB shall design its systems and procedures to make customers feel safe about carrying out EBTs. To achieve this, the RRB shall put in place:
(1) appropriate systems and procedures to ensure safety and security of EBTs carried out by customers, including those mandated under the Reserve Bank of India (Authentication Mechanisms for Digital Payment Transactions) Directions, 2025 and other relevant instructions issued by the Reserve Bank on related matters, as amended from time to time;
(2) robust and dynamic fraud detection and prevention mechanism;
(3) mechanism to assess the risks (for example, gaps in the RRB’s existing systems) arising from fraudulent EBTs and measure the liabilities arising out of such events;
(4) appropriate measures to mitigate the risks and protect themselves against the liabilities arising therefrom; and
(5) a system of continually and repeatedly making the customers aware about evolving electronic banking and payments related frauds and the ways to protect themselves from such frauds.
EA.2 Alerts for EBTs
128C. An RRB shall ask its customer, availing the facility of EBTs (other than ATM cash withdrawals), to mandatorily provide her / his mobile number and wherever available, email address. The RRB shall verify the mobile number and email address provided by the customer at the time of onboarding and subsequently at pre-defined intervals prescribed in its policy.