RBI Proposes Uniform Account-Blocking Rules for Cyber-Fraud Cases
RBI’s draft framework would standardise AI-led monitoring, transaction-level debit holds, customer alerts and grievance handling for cyber-fraud-linked accounts. For retailers, it could affect payment acceptance, merchant settlements and consumer trust. Comments are due October 2; implementation is proposed from April 1, 2027.
What happened
Reserve Bank of India · RBI has proposed uniform bank procedures for cyber-fraud-linked accounts, including AI-led monitoring, transaction-level debit holds,
Key facts
- ₹1,000 transaction threshold for automated mule-transaction flags
- 60-day maximum temporary debit hold
- 20-day account-holder response window
- 10-day bank review period
- April 1, 2027 proposed effective date
Why this matters
Retailers should assess payment-provider readiness for transaction holds, faster customer alerts and grievance workflows to limit checkout disruption and protect trust ahead of the proposed 2027 rollout.
What to watch
- Final RBI framework wording after the October 2 consultation deadline, especially definitions of cyber-fraud-linked accounts and scope for merchant accounts.
- Mandated timelines for debit holds, customer notifications, unblocking decisions and grievance redressal.
- Whether payment aggregators and acquirers must impose merchant-level monitoring, data sharing or settlement reserves.
- Rules on refund processing when a customer or merchant account is under a fraud-related restriction.
- Pilot announcements, supervisory guidance or bank circulars specifying AI-monitoring thresholds and false-positive controls.