RBI Proposes Uniform Account-Blocking Rules for Cyber-Fraud Cases

RBI’s draft framework would standardise AI-led monitoring, transaction-level debit holds, customer alerts and grievance handling for cyber-fraud-linked accounts. For retailers, it could affect payment acceptance, merchant settlements and consumer trust. Comments are due October 2; implementation is proposed from April 1, 2027.

— Source publishedMon, 14 Sept, 2026, 23:36 IST·First seen Mon, 14 Sept, 2026, 23:43 IST·Source Inc42 · Buzz

What happened

Reserve Bank of India · RBI has proposed uniform bank procedures for cyber-fraud-linked accounts, including AI-led monitoring, transaction-level debit holds,

Key facts

  • ₹1,000 transaction threshold for automated mule-transaction flags
  • 60-day maximum temporary debit hold
  • 20-day account-holder response window
  • 10-day bank review period
  • April 1, 2027 proposed effective date

Why this matters

Retailers should assess payment-provider readiness for transaction holds, faster customer alerts and grievance workflows to limit checkout disruption and protect trust ahead of the proposed 2027 rollout.

What to watch

  • Final RBI framework wording after the October 2 consultation deadline, especially definitions of cyber-fraud-linked accounts and scope for merchant accounts.
  • Mandated timelines for debit holds, customer notifications, unblocking decisions and grievance redressal.
  • Whether payment aggregators and acquirers must impose merchant-level monitoring, data sharing or settlement reserves.
  • Rules on refund processing when a customer or merchant account is under a fraud-related restriction.
  • Pilot announcements, supervisory guidance or bank circulars specifying AI-monitoring thresholds and false-positive controls.